Skip to main content
Category: Consent Principles

Article 6 Lawful Basis

Also known as: Legal Basis for Processing, Lawful Basis for Processing, GDPR Legal Basis
Simply put

An Article 6 lawful basis is one of the legally recognised reasons an organisation must have before it can process personal data under the GDPR. At least one of these bases must apply to any given processing activity, and one of the available options is the individual's consent. Without a valid lawful basis, processing personal data is generally unlawful in the EU and UK.

Formal definition

Article 6(1) of the GDPR (and, in the UK, the UK GDPR) establishes that processing of personal data is lawful only if and to the extent that at least one lawful basis applies. The available bases are consent, contract, legal obligation, vital interests, public task, and legitimate interests. A controller must identify and, in most cases, document the appropriate basis before processing begins; the correct basis depends on the specific purpose and factual context of the processing. In the cookie context, the Article 6 lawful basis governs the processing of any personal data that results from cookies or similar technologies, and is legally distinct from the separate consent requirement for storing or accessing information on a user's device under the ePrivacy regime. Consent obtained for the placing of a cookie does not automatically establish an Article 6 basis for all downstream processing, and vice versa. This entry describes the general framework only; the appropriate basis for a particular activity, and any interaction with ePrivacy rules, requires case-specific legal analysis.

Why it matters

For anyone handling cookies and similar tracking technologies, Article 6 is the gateway rule that determines whether the personal data those technologies generate can lawfully be processed at all. Under the GDPR and UK GDPR, processing personal data without at least one valid lawful basis is generally unlawful in the EU and UK. This means that even where an organisation has addressed the separate question of storing or accessing information on a user's device, it still needs to identify a lawful basis for what it does with any resulting personal data, such as building analytics profiles or serving targeted advertising.

A common and consequential misunderstanding is to treat the ePrivacy consent for placing a cookie as if it also settles the GDPR question. These are two distinct legal requirements. Consent obtained for placing a cookie does not automatically establish an Article 6 basis for all downstream processing of the data collected, and an Article 6 basis identified for downstream processing does not remove the need for consent to place the cookie where the ePrivacy regime requires it. Getting this relationship wrong can leave processing activities without a defensible legal footing even when a consent banner is in place.

Because the correct basis depends on the specific purpose and factual context of each processing activity, Article 6 is not a box-ticking exercise. Choosing consent, legitimate interests, contract, or another basis carries different obligations, documentation expectations, and consequences for the rights available to individuals. Organisations that map these bases carefully to each cookie-related purpose are better positioned to demonstrate accountability if a data protection authority asks how a particular processing activity is justified.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for accountability need to map an Article 6 lawful basis to each cookie-related processing purpose and, in most cases, document that choice. They should be particularly alert to the distinction between ePrivacy consent for placing a cookie and the separate GDPR basis for downstream processing, since conflating the two is a common source of gaps in compliance records.
Legal counsel
Because the appropriate basis depends on the specific purpose and factual context, and because its interaction with the ePrivacy regime requires case-specific analysis, legal advisers are typically asked to assess which of the six bases applies and whether a given activity can rely on consent, legitimate interests, or another basis. The framework described here is general; contested interpretations and evolving authority guidance mean these questions rarely have a single fixed answer across jurisdictions.
Web developers and marketing compliance teams
Teams implementing analytics, advertising, and tracking technologies need to understand that placing a cookie and lawfully processing the resulting personal data are governed by different rules. A consent banner addressing device access does not, on its own, establish an Article 6 basis for how the collected data is subsequently used, so implementation choices should be coordinated with the organisation's identified lawful bases.

Inside Article 6 Lawful Basis

The Six Lawful Bases
Article 6(1) of the GDPR sets out six alternative grounds for lawfully processing personal data: consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest or in the exercise of official authority, and legitimate interests. At least one must apply for processing to be lawful.
Consent (Article 6(1)(a))
Processing based on the data subject having given consent for one or more specific purposes. Where consent is relied upon, it must meet the GDPR standard of being freely given, specific, informed, and unambiguous, expressed through a clear affirmative action. This is the basis most commonly relevant to cookie-related processing that follows the placing of or access to information on a device.
Contract (Article 6(1)(b))
Processing necessary for the performance of a contract to which the data subject is party, or to take steps at their request prior to entering into a contract. The processing must be genuinely necessary to deliver the agreed service, not merely convenient for the controller.
Legal Obligation (Article 6(1)(c))
Processing necessary to comply with a legal obligation to which the controller is subject. The obligation must arise under EU or Member State law and be sufficiently clear.
Vital Interests (Article 6(1)(d))
Processing necessary to protect the vital interests of the data subject or another natural person. This basis is generally reserved for situations involving a threat to life or physical safety and is rarely relevant to cookie processing.
Public Task (Article 6(1)(e))
Processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. It typically applies to public authorities and bodies exercising defined functions.
Legitimate Interests (Article 6(1)(f))
Processing necessary for the legitimate interests pursued by the controller or a third party, except where overridden by the interests or fundamental rights and freedoms of the data subject. This basis requires a balancing assessment and is not available to public authorities acting in the performance of their tasks.
Relationship to the ePrivacy Rules
Article 6 governs the processing of personal data, but it operates alongside the ePrivacy Directive (and its national implementations), which separately governs the placing of and access to information on a user's device. For cookies and similar technologies, the ePrivacy consent requirement is generally engaged at the point of storage or access, and satisfying an Article 6 basis does not by itself discharge that separate ePrivacy obligation.

Common questions

Answers to the questions practitioners most commonly ask about Article 6 Lawful Basis.

Does obtaining cookie consent under the ePrivacy rules mean I have also satisfied Article 6 of the GDPR?
No. These are two distinct legal steps. The ePrivacy Directive (as implemented nationally) governs the placing of and access to information on a user's device, while Article 6 of the GDPR governs the separate question of whether any personal data processing that follows has a lawful basis. Consent for storing or reading a cookie does not automatically establish a GDPR lawful basis for the downstream processing of the data collected, though in practice the same consent may be relied upon for both where it is properly obtained. You should assess each layer separately and document the lawful basis for the processing itself.
Can I rely on legitimate interests under Article 6(1)(f) instead of consent for advertising or analytics cookies?
This is a common misconception. Where the ePrivacy rules require prior consent to place or access information on a device, that consent requirement generally cannot be displaced by relying on legitimate interests for the initial storage or access. Once consent has been given for the device-side operation, legitimate interests may in some cases be considered as a lawful basis for certain subsequent processing, but this is contested and heavily fact-dependent. In most EU jurisdictions, analytics and advertising cookies are treated as requiring consent, and regulators have generally viewed legitimate interests as an unsuitable basis where consent is the applicable standard. Legal advice is advisable before relying on this basis.
How do I decide which Article 6 lawful basis applies to processing that follows a cookie being set?
Start by identifying the specific processing activities and their purposes, then map each to the most appropriate basis among the six in Article 6(1). Consent is typically relevant where the ePrivacy rules already require it or where processing is not necessary for another purpose; contract or legal obligation may apply to some strictly necessary functions; and legitimate interests may be considered for certain purposes subject to a balancing assessment. This choice should be made per purpose rather than applied blanket, and it depends on facts not resolved by a definition alone. Where the analysis is uncertain, consult a data protection specialist.
Should I record the Article 6 lawful basis I have selected, and where?
Documenting the lawful basis for each processing activity supports accountability obligations under the GDPR and is generally reflected in a record of processing activities. Many organizations also state the lawful basis for each purpose in their privacy notice so that the processing is transparent to users. Where consent is the basis, consent logging and record-keeping are typically expected so you can demonstrate that valid consent was obtained. These records support compliance but do not by themselves guarantee it; the underlying analysis must be sound.
What happens to processing if a user withdraws consent for cookies?
Where consent is the Article 6 basis, withdrawal generally means you must stop the processing that relied on that consent going forward, though it does not typically render prior processing unlawful. You cannot usually switch to a different lawful basis, such as legitimate interests, simply to continue the same processing after consent is withdrawn, as regulators have generally viewed such switching with concern. Any related device-side operations governed by the ePrivacy rules should also cease. The practical mechanics depend on your systems and should be tested.
How does the choice of Article 6 basis differ across the EU, UK, and US state privacy laws?
The Article 6 lawful basis framework applies under the GDPR in the EU and, in substantially similar form, under the UK GDPR. US state privacy laws such as the CCPA and CPRA in California do not use an Article 6-style lawful basis structure and instead often rely on notice and opt-out mechanisms rather than a defined basis for each processing activity. Because of these differences, you should not apply an EU lawful basis analysis as if it were universal. Always confirm the geographic and legal scope of the processing and adapt your approach to each applicable regime.

Common misconceptions

Legitimate interests can be freely used as the lawful basis for cookie-based tracking to avoid asking for consent.
Where the ePrivacy rules require prior consent for placing or accessing information on a device, as they generally do for analytics and advertising cookies in the EU, relying on legitimate interests under GDPR Article 6 does not remove that separate consent requirement. Legitimate interests also involves a balancing test and is not automatically available for intrusive or profiling-related processing.
Having a valid Article 6 lawful basis means the cookie processing is fully compliant.
Article 6 addresses only the lawful basis for processing personal data under the GDPR. Compliance for cookies and similar technologies also depends on the separate ePrivacy consent and information requirements, and on other GDPR principles such as transparency, purpose limitation, and data subject rights. A lawful basis is necessary but not sufficient.
The lawful basis for processing can be freely swapped after the fact if one basis proves inconvenient.
The controller should identify the appropriate lawful basis before processing begins and be transparent about it. Switching bases retroactively, particularly moving away from consent that has been withdrawn, is generally viewed as problematic and can undermine both transparency and the validity of the processing.

Best practices

Identify and document a specific Article 6 lawful basis for each processing purpose before processing begins, rather than selecting one retrospectively.
Treat the ePrivacy consent requirement for placing or accessing cookies and similar technologies as a distinct obligation, and do not assume that an Article 6 basis satisfies it.
Where consent is relied upon, ensure it meets the GDPR standard of freely given, specific, informed, and unambiguous, obtained through a clear affirmative action, and record how and when it was obtained.
Where legitimate interests are considered, carry out and document a balancing assessment, and remember that this basis is generally not available to public authorities acting in their official tasks.
Map each cookie or tracking technology to a defined purpose and lawful basis so that the two are aligned and can be explained transparently to users and regulators.
Review lawful basis decisions against current guidance from the relevant data protection authority, recognizing that enforcement positions and interpretations may evolve over time and differ between the EU, the UK, and other jurisdictions.