Artifact GuideUKLawful Bases

UK GDPR Lawful Bases

Lawful Bases decisions under the UK GDPR should name the exact basis, explain why it fits the processing, and record the evidence that supports the choice.

Article 6 now contains the six familiar bases plus the UK-specific recognised legitimate interests route for the closed Annex 1 conditions. Keep that route separate from ordinary legitimate interests and complete any Article 9 or 10 analysis.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Article 6 now contains the six familiar bases - consent, contract, legal obligation, vital interests, public task, and ordinary legitimate interests - plus the UK-specific recognised legitimate interests basis inserted by the Data (Use and Access) Act 2025 and in force from 5 February 2026. The new basis is not a general shortcut: the processing must be necessary for a condition listed in Annex 1. Special-category or criminal-offence data still needs the separate Article 9 or 10 analysis.

Section 1

Which Article 6 basis fits the purpose?

Define the purpose first, then test necessity. Consent requires a real choice and valid, demonstrable agreement. Contract covers processing objectively necessary to perform a contract with the person or take requested pre-contract steps, not everything written into terms. Legal obligation requires a duty under law, not a contract. Vital interests normally protects someone's life and is generally reserved for life-or-death interests. Public task requires a task in the public interest or official authority with a clear basis in law.

Ordinary legitimate interests requires a three-part assessment: identify a legitimate purpose, show the processing is necessary, and balance it against the person's interests, rights, and freedoms. Public authorities cannot use it for processing carried out in performing their public tasks. Direct marketing may be a legitimate interest, but PECR consent rules can still apply and people have an absolute right to object to direct marketing.

under Article 6(1)(ea) is a separate UK basis. It applies only where processing is necessary for a condition in Annex 1, covering specified public-task disclosures, national or public security and defence, emergencies, crime, and safeguarding vulnerable people. It removes the ordinary balancing test for those closed conditions, but does not remove necessity, fairness, transparency, data minimisation, security, rights, or any other UK GDPR duty.

  • Record one purpose at a time; different purposes for the same data may need different bases.
  • Do not default to consent where refusal or withdrawal would not be a genuine choice, or where the processing is objectively necessary for another basis.
  • Do not repair invalid consent by switching retrospectively to another basis. Stop or restrict the processing, assess the correct basis on the current facts, and document any lawful prospective use.
  • For legal obligation or public task, identify the law, function, power, or duty and how it authorises or requires the processing.
  • For ordinary legitimate interests, keep the purpose, necessity, and balancing assessment with the processing record.
  • For , record the exact Annex 1 condition and each condition-specific requirement.
  • Do not use for a significant decision based solely on automated processing; identify another permitted basis and apply the safeguards required by Articles 22A to 22D.
Section 2

When is recognised legitimate interest available?

The public-task disclosure response condition can support a voluntary disclosure requested by an organisation that needs the information for a public task or official function. The requester must provide the information required by Annex 1. If disclosure is legally required, legal obligation is the likely Article 6 basis instead.

The other Annex 1 conditions address necessary processing for national security, public security or defence; responding to emergencies; detecting, investigating, or preventing crime or apprehending or prosecuting offenders; and safeguarding a child or an adult at risk. Apply the definitions and safeguards in the relevant condition rather than relying on the category name alone.

A public authority cannot use for processing in the performance of its own tasks. The basis is not an exemption and does not automatically supply an Article 9 condition for special category data or an Article 10 route for criminal-offence data. For example, a company responding voluntarily to a properly framed police request may be able to use the public-task disclosure condition; the police's own processing still needs its own lawful route.

  • Keep the request, requester identity, stated public task or official function, data requested, necessity analysis, and disclosure decision.
  • For safeguarding, record how the person meets the relevant child or adult-at-risk definition and why the processing is necessary.
  • For emergencies, record the event, threatened harm, urgency, data used, recipients, and why ordinary routes were insufficient.
  • Do not relabel routine fraud prevention, commercial risk, or general safety work without checking every requirement of the crime, security, or safeguarding condition.
Section 3

What additional conditions and rights must be checked?

Article 6 is only the first layer. Special category data needs an Article 9 condition and, for several UK conditions, a matching Data Protection Act 2018 Schedule 1 condition. Some Schedule 1 conditions require an appropriate policy document. Criminal-offence data needs Article 10 authority through official control or domestic law, including applicable Schedule 1 conditions.

The chosen basis changes some individual rights. Portability generally applies to automated processing based on consent or contract. The general right to object applies to public task, , and ordinary legitimate interests, while direct-marketing objections are absolute. Erasure is limited for legal-obligation and public-task processing. Withdrawal ends consent-based processing prospectively but does not undo processing that was lawful before withdrawal.

If a purpose changes, assess compatibility and whether the existing basis still fits. Consent for the old purpose does not cover a new incompatible purpose. A new legal obligation may supply a new basis; otherwise document the compatibility analysis and update privacy information before further processing where required.

  • Map Article 6, Article 9 or 10, Schedule 1, policy-document, transparency, rights, and retention decisions together.
  • Check PECR separately for cookies, storage and access technologies, and electronic marketing.
  • Check whether automated decisions, children, vulnerable people, or high-risk processing require additional safeguards or a DPIA.
  • Do not use a processor contract or international-transfer instrument as the lawful basis for the underlying processing.
Section 4

What should the lawful-basis record contain?

The controller should approve the purpose and lawful basis before processing starts. Product, operations, HR, marketing, or another business owner supplies the facts; privacy or legal reviewers test the conditions; engineering and vendors confirm what the system actually does. A processor follows the controller's documented instructions but must identify its own basis for processing outside those instructions.

For each purpose, keep the data subjects and categories, controller role, exact Article 6 basis, necessity analysis, supporting law or assessment, Article 9 or 10 route, Schedule 1 condition and policy document where required, rights impact, privacy-notice text, recipients, retention, systems, owner, approver, decision date, and review trigger.

  • Review the basis when the purpose, data, people, relationship, technology, recipients, legal authority, or choice offered to the person changes.
  • For consent, keep what the person was told, the affirmative action, purposes selected, timestamp, version, and withdrawal mechanism.
  • For contract, identify the requested service or pre-contract step and explain why it cannot reasonably be performed without the processing.
  • For legitimate interests, retain the completed assessment and reflect the interest in privacy information.
  • Update the record and privacy information before relying on a materially different purpose or basis.
Primary sources

References and citations

legislation.gov.uk
Referenced sections
  • Binding Article 6 and Annex 1 conditions, plus the principles and rights that continue to apply.
legislation.gov.uk
Referenced sections
  • Binding UK provisions and Schedule 1 conditions supplementing Articles 9 and 10.
ico.org.uk
Referenced sections
  • ICO documentation and accountability guidance for choosing, recording, explaining, and reviewing a lawful basis.
ico.org.uk
Referenced sections
  • ICO guidance on records of processing and the evidence needed to demonstrate accountability.
ico.org.uk
Referenced sections
  • ICO guidance on the five Annex 1 condition groups, required request information, necessity, public-authority restriction, and documentation.
Related guides

Explore more topics

How do you choose a lawful basis under the UK GDPR?
Choose and document the UK GDPR lawful basis that fits each processing purpose, including recognised legitimate interest, in force since 5 February 2026.
UK Children's Code: Scope and 15 Standards
Decide whether an online service is likely to be accessed by UK children and apply the ICO Children's Code standards to product design and personal-data use.
UK GDPR 72-hour Breach Reporting Guide
Decide whether a UK personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report must contain, and when individuals must be told.
UK GDPR 72-Hour Breach Reporting: Decision Guide
Decide whether a personal data breach must be reported to the ICO, when the 72-hour clock starts, what the report needs, and when affected people must be told.
UK GDPR Adequacy Guide
Use UK transfer approval regulations by checking the destination, recipient, data, sector, effective status, scope limits, and review evidence.
UK GDPR Adequacy: When Can You Rely on It?
Check whether current UK adequacy regulations cover a restricted transfer, including partial coverage for Canada, Japan, and the US UK Extension.
UK GDPR AI and Automated Decisions Guide
Current UK GDPR rules for significant solely automated decisions, meaningful human involvement, Article 22B restrictions, and Article 22C safeguards.
UK GDPR AI and Automated Decisions: Articles 22A-22D
Apply the current UK rules for significant solely automated decisions, special-category restrictions, meaningful human involvement, and Article 22C safeguards.
UK GDPR Applicability Test Guide
Apply the UK GDPR material and territorial scope tests to one processing activity, including exclusions, non-UK organisations, roles, and evidence.
UK GDPR Article 30 Records Guide
Build UK GDPR Article 30 records for controller and processor activities, apply the narrow under-250 exception, and keep the records current and available to the ICO.
UK GDPR Article 30 Records: What to Document
See which controllers and processors need records of processing activities, what each record must contain, and how the under-250-employee exemption works.
UK GDPR Breach Notification Guide
Decide whether a personal data breach must be reported to the ICO or communicated to individuals, with deadlines, exceptions, content, and evidence.
UK GDPR Breach Workflow Guide
Run a UK GDPR personal data breach workflow from containment and awareness through risk assessment, ICO reporting, individual notice, and the breach record.
UK GDPR Children and Age Appropriate Design Guide
Apply UK GDPR children's protections and the Age Appropriate Design Code to online services likely to be accessed by children.
UK GDPR Children's Code Guide
A practical guide to Children's Code scope, its 15 standards, age 13 consent, evidence, exceptions, and product implementation.
UK GDPR Compliance Checklist
A verifiable UK GDPR checklist for scope, lawful processing, transparency, rights, governance, security, breaches, DPIAs, children, and transfers.
UK GDPR Compliance FAQ: Duties, Rights, and Decisions
Answer common UK GDPR questions on scope, lawful basis, records, DPIAs, DPOs, rights, breaches, children, automated decisions, and international transfers.
UK GDPR Compliance Guide
Build a UK GDPR compliance programme around processing records, lawful decisions, rights operations, security, incidents, DPIAs, suppliers, and transfers.
UK GDPR Controller and Processor Status Guide
Decide whether each party is a controller, joint controller, or processor under the UK GDPR, then record the role-specific duties, contract terms, and evidence.
UK GDPR Controller or Processor: How to Decide
Decide whether each party is a controller, joint controller, processor, or sub-processor, then record the contracts, responsibilities, and evidence the role requires.
UK GDPR Data Subject Rights Guide
Operate UK GDPR access, rectification, erasure, restriction, portability, objection, and automated-decision rights under the amended Article 12 timing rules.
UK GDPR Deadlines and Compliance Calendar Guide
Track UK GDPR deadlines for rights requests, privacy information, breach notification, DPIAs, and ICO prior consultation, with triggers and exceptions.
UK GDPR DPIA Workflow Guide
Screen UK GDPR processing for likely high risk, complete the required DPIA analysis before processing, reduce risk, and consult the ICO when high residual risk remains.
UK GDPR DPIA: When It Is Required and What to Record
Screen for likely high-risk processing, complete the Article 35 assessment before processing, and consult the ICO if high residual risk remains.
UK GDPR DPIAs and DPOs Guide
Decide when the UK GDPR requires a DPIA or DPO, what each must cover, when to consult the ICO, and what evidence to retain.
UK GDPR DPO: When Appointment Is Mandatory
Apply the three UK GDPR DPO triggers and document expertise, independence, reporting line, resources, tasks, contacts, and conflict controls.
UK GDPR DSAR Workflow Guide
Run a UK subject-access workflow using the current Article 12A clock, reasonable identity and clarification steps, proportionate searches, exemptions, redactions, and response evidence.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
Choose the UK IDTA or Addendum, complete the current Article 46 data protection test, add needed measures, and maintain evidence for restricted transfers.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and cited implementation decisions.
UK GDPR Penalties and Fines: Maximums and ICO Factors
Understand the UK GDPR £8.7 million or 2% and £17.5 million or 4% fine ceilings, which infringements fall into each band, and how the ICO sets a fine.
UK GDPR Requirements Guide
Map UK GDPR requirements by processing activity, role, lawful basis, data type, risk, rights, suppliers, automated decisions, and transfers.
UK GDPR Transfer Workflow Guide
Apply the UK GDPR restricted-transfer sequence: map the transfer, check Article 45A approval, choose an Article 46 safeguard and assessment, or justify a specific Article 49 derogation.
UK GDPR Transfers, IDTA, and UK Addendum Guide
Decide whether a UK restricted transfer exists, whether adequacy applies, how to use the IDTA or UK Addendum, and how to document the data protection test.
UK GDPR vs Data Protection Act 2018: How They Work Together
See when to use the UK GDPR, when the Data Protection Act 2018 adds a condition or exemption, and which regime covers law enforcement or intelligence processing.
UK GDPR vs EU GDPR: Scope, Regulators and Transfers
Determine whether UK GDPR, EU GDPR, or both apply, then separate representatives, regulators, transfer routes, national law, and post-Brexit UK amendments.
UK IDTA vs EU SCCs: Which Transfer Contract to Use
Choose between the UK IDTA and EU SCCs with the UK Addendum, complete the right documents, and record the separate UK and EU transfer assessments.
UK IDTA, Addendum, and Transfer Risk Assessment Guide
Decide when to use the UK IDTA or Addendum, complete the Article 46 data protection test, add supplementary measures, and keep the transfer under review.
UK vs EU GDPR Differences After the 2025 UK Reforms
Compare current UK and EU rules for recognised legitimate interests, rights requests, access searches, automated decisions, and international transfers.
UK vs EU GDPR Operations: Regulators, Breaches and Transfers
Configure separate UK and EU privacy operations for representatives, regulator contacts, rights requests, breach reporting, transfer tools, and evidence.
When do PECR cookie rules require consent?
Apply the current UK PECR rules to cookies and similar technologies, including consent, five exceptions, UK GDPR overlap, and evidence.