Lawfulness of Processing
Lawfulness of processing is the GDPR requirement that an organisation must have a valid legal reason before it uses someone's personal data. The GDPR sets out a fixed list of these permitted reasons, and at least one must apply to any given use of personal data. In the context of cookies, consent is one of these reasons, but it is not the only one, and the appropriate reason depends on the specific purpose of the processing.
Under Article 6(1) of the EU GDPR (and the UK GDPR), processing of personal data is lawful only where at least one of six specified legal bases applies: consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest or exercise of official authority, and legitimate interests. Controllers must identify and, in practice, document the appropriate basis before processing begins, and guidance from authorities such as the ICO indicates that a basis cannot generally be swapped later without justification. Note that this GDPR requirement is distinct from, and additional to, the ePrivacy rules governing the placing of and access to information (such as cookies) on a user's device: satisfying an Article 6 basis for downstream processing of personal data does not by itself satisfy the separate prior-consent obligation typically required under EU ePrivacy law for non-essential cookies. This entry describes the general framework and does not resolve fact-specific questions about which basis is appropriate for a particular processing activity, nor does it address the additional conditions required for special category data under Article 9.
Why it matters
Lawfulness of processing sits at the foundation of GDPR compliance: if an organisation cannot point to a valid Article 6 basis, the processing of personal data is unlawful regardless of how well it handles security, transparency, or data subject rights. For teams working with cookies and tracking technologies, this matters because the data collected through analytics, advertising, and functional tools frequently constitutes personal data, and each processing purpose must be tied to an appropriate lawful basis.
A common and consequential error is treating the ePrivacy consent requirement and the GDPR lawful basis as a single hurdle. In most EU jurisdictions, placing or accessing non-essential cookies on a user's device generally requires prior consent under ePrivacy rules, while any subsequent processing of the personal data those cookies generate must additionally rest on an Article 6 basis. Satisfying one does not automatically satisfy the other, and organisations that assume a single consent covers everything may find gaps in their compliance posture. Where consent is the ePrivacy basis for a cookie, controllers should consider carefully whether consent is also the appropriate Article 6 basis for the downstream processing, since relying on a different basis may sit uneasily with the consent already obtained.
Choosing and documenting the right basis before processing begins also has practical downstream effects. Guidance from authorities such as the ICO indicates that a lawful basis generally cannot be swapped later without justification, so an ill-considered initial choice can be difficult to correct. This makes lawful basis a decision that privacy officers and legal counsel should make deliberately at the design stage rather than retrofit.
Who it's relevant to
Inside Lawfulness of Processing
Common questions
Answers to the questions practitioners most commonly ask about Lawfulness of Processing.