Artifact GuideUKLawful Bases

UK GDPR Lawful Bases

Lawful Bases decisions under the UK GDPR should name the exact basis, explain why it fits the processing, and record the evidence that supports the choice.

The six UK GDPR lawful bases are consent, contract, legal obligation, vital interests, public task, and legitimate interests. This guide turns them into an implementation-ready decision aid with ownership, evidence, and review steps, and it should be validated against jurisdiction-specific legal, contractual, and policy requirements before implementation.

Author
Sorena AI
Published
May 9, 2026
Updated
May 9, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated May 9, 2026
Overview

This page explains the six UK GDPR lawful bases - consent, contract, legal obligation, vital interests, public task, and legitimate interests - and gives a practical way to choose between them for a processing activity.

Section 1

What should teams decide about Lawful Bases under the UK GDPR?

Start by identifying the processing purpose and matching it to the lawful basis that fits the facts: consent for a clear permission-based use; contract where processing is needed to perform or take steps before a contract; legal obligation where the law requires the processing; vital interests where processing protects life; public task where the controller needs it to carry out a task in the public interest or official authority; or legitimate interests where the controller or a third party has a legitimate purpose that is not overridden by the individual's interests, rights, or freedoms.

A useful decision should name the exact basis, explain why the other bases do not fit, and keep the UK GDPR source, DPA 2018 context, role map, and supporting evidence together.

  • Define the exact Lawful Bases trigger and the business process it affects.
  • Record which role, product, system, customer group, or data flow is in scope.
  • Attach the source-linked rule, the owner, and the evidence field before approving the control.
  • Use the six lawful bases as the first decision step, then check whether special-category or criminal-offence data needs an additional condition.
  • Escalate uncertainty when the facts depend on thresholds, exemptions, cross-border activity, vulnerable users, or enforcement-sensitive wording.
Section 2

Who should own Lawful Bases, and what evidence should prove the decision?

Ownership should sit with the team that controls the processing purpose, system behavior, vendor terms, transfer mechanism, rights channel, breach process, or child-user journey.

Evidence should show role mapping, lawful basis, Article 9/10 basis where needed, transparency wording, DPIA outcome, DSAR response, breach assessment, transfer mechanism, processor terms, and ICO escalation note.

  • Name one accountable owner and one reviewer for the Lawful Bases workflow.
  • Keep source screenshots or source links, decision notes, implementation tickets, and approval records together.
  • Use dated evidence for deadlines, notices, risk assessments, contracts, user journeys, and regulator-facing records.
  • Review the evidence after product changes, new markets, new vendors, enforcement updates, or material changes in the source text.
Section 3

Which edge cases should teams check before relying on a Lawful Bases decision?

Most UK GDPR mistakes happen at the boundary between UK GDPR, DPA 2018, PECR, EU GDPR divergence, IDTA/Addendum transfer rules, children data, and processor/subprocessor duties.

Use this section before approving a new processing purpose, vendor, transfer, profiling flow, DSAR workflow, breach process, or child-facing product change.

  • Check whether the rule changes for minors, consumers, business users, public-sector bodies, regulated sectors, high-risk services, or cross-border transfers.
  • Separate binding law, regulator guidance, consultation material, standards, and enforcement commentary in the evidence record.
  • Do not rely on a previous answer if the data categories, user interface, vendor role, or contractual flow changed.
  • Track unresolved assumptions in an open-questions section and route legal interpretation points for review.
Section 4

How should teams operationalize Lawful Bases with proportionate controls?

Use a UK GDPR workflow that captures role, purpose, lawful basis, special-category status, DPIA trigger, rights/breach/transfer trigger, evidence, owner, and review date.

The output should be a lawful-basis note, DPIA decision, privacy notice update, DSAR record, breach assessment, transfer pack, processor clause map, or ICO response record.

  • Create a short intake question that identifies the Lawful Bases scenario.
  • Map the answer to a required action, evidence field, owner, reviewer, and review date.
  • Link related artifact pages with descriptive anchors so users can move from scope to deadlines, controls, penalties, and templates.
  • Update the workflow when official source material changes or when internal evidence shows recurring exceptions.
Primary sources

References and citations

ico.org.uk
Referenced sections
  • Boundary and edge-case support for this artifact page.
"How are solely automated decision-making and relevant safeguards linked to fairness, and key questions to ask when considering"
assets.publishing.service.gov.uk
Referenced sections
  • UK government guidance for adequacy assessments and international data transfer context.
"guide to filling out the Manual Template"
ico.org.uk
Referenced sections
  • Operational implementation support for Lawful Bases.
"Detailed guidance A detailed overview of how to apply the principles of the UK GDPR to the use"
Related guides

Explore more topics

UK GDPR 72-hour Breach Reporting Guide
UK GDPR guidance for 72-hour Breach Reporting, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Adequacy Guide
UK GDPR guidance for Adequacy, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR AI And Automated Decisions Guide
UK GDPR guidance for AI And Automated Decisions, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Applicability Test Guide
Practical guidance for the UK GDPR applicability test, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Article 30 Records Guide
UK GDPR guidance for Article 30 Records, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Breach Notification Guide
UK GDPR guidance for Breach Notification, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Breach Workflow Guide
UK GDPR guidance for Breach Workflow, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Children And Age Appropriate Design Guide
UK GDPR guidance for Children And Age Appropriate Design, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Children's Code Guide
UK GDPR guidance for Children's Code, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Compliance Checklist
Practical guidance for the UK GDPR checklist, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Compliance FAQ
Practical guidance for the UK GDPR FAQ, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Compliance Guide
Practical guidance for the UK GDPR compliance, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Controller And Processor Status Guide
UK GDPR guidance for Controller And Processor Status, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Data Subject Rights Guide
UK GDPR guidance for Data Subject Rights, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Deadlines and Compliance Calendar Guide
UK GDPR guidance for Deadlines and Compliance Calendar, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR DPIA Workflow Guide
UK GDPR guidance for DPIA Workflow, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR DPIAs And DPOs Guide
UK GDPR guidance for DPIAs And DPOs, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR DSAR Workflow Guide
UK GDPR guidance for DSAR Workflow, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR IDTA Addendum and Transfer Risk Assessment Guide
UK GDPR guidance for IDTA addendum and transfer risk assessment, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR IDTA vs EU SCCs Guide
UK GDPR guidance for IDTA vs EU SCCs, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR PECR Cookies Guide
UK GDPR and PECR cookie guidance with practical consent, exemption, evidence, and source-linked implementation decisions.
UK GDPR penalties and fines Guide
UK GDPR guidance for penalties and fines, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Requirements Guide
Practical guidance for the UK GDPR requirements, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Transfer Workflow Guide
UK GDPR guidance for Transfer Workflow, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR Transfers, IDTA, and UK Addendum Guide
UK GDPR guidance for transfers, IDTA, and UK Addendum, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR UK vs EU Differences Guide
UK GDPR guidance for UK vs EU Differences, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR UK vs EU GDPR Differences Guide
UK GDPR guidance for UK vs EU GDPR Differences, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR vs Data Protection Act 2018 Guide
UK GDPR guidance for UK GDPR vs Data Protection Act 2018, with practical decisions, evidence, edge cases, and external source citations.
UK GDPR vs EU GDPR Guide
UK GDPR guidance for UK GDPR vs EU GDPR, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about 72-hour Breach Reporting under the UK GDPR?
UK GDPR guidance for 72-hour Breach Reporting, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Adequacy under the UK GDPR?
UK GDPR guidance for Adequacy, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about AI And Automated Decisions under the UK GDPR?
UK GDPR guidance for AI And Automated Decisions, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Article 30 Records under the UK GDPR?
UK GDPR guidance for Article 30 Records, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Children's Code under the UK GDPR?
UK GDPR guidance for Children's Code, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Controller And Processor Status under the UK GDPR?
UK GDPR guidance for Controller And Processor Status, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about DPIAs under the UK GDPR?
UK GDPR guidance for DPIAs, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about DPOs under the UK GDPR?
UK GDPR guidance for DPOs, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about IDTA addendum and transfer risk assessment under the UK GDPR?
UK GDPR guidance for IDTA addendum and transfer risk assessment, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Lawful Bases under the UK GDPR?
UK GDPR guidance for Lawful Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about PECR Cookies under the UK GDPR?
UK GDPR guidance for PECR Cookies, with practical decisions, evidence, edge cases, and external source citations.