Skip to main content
Category: Consent Principles

Lawfulness of Processing

Also known as: Lawful Basis, Legal Basis for Processing, Article 6 GDPR
Simply put

Lawfulness of processing is the GDPR requirement that an organisation must have a valid legal reason before it uses someone's personal data. The GDPR sets out a fixed list of these permitted reasons, and at least one must apply to any given use of personal data. In the context of cookies, consent is one of these reasons, but it is not the only one, and the appropriate reason depends on the specific purpose of the processing.

Formal definition

Under Article 6(1) of the EU GDPR (and the UK GDPR), processing of personal data is lawful only where at least one of six specified legal bases applies: consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest or exercise of official authority, and legitimate interests. Controllers must identify and, in practice, document the appropriate basis before processing begins, and guidance from authorities such as the ICO indicates that a basis cannot generally be swapped later without justification. Note that this GDPR requirement is distinct from, and additional to, the ePrivacy rules governing the placing of and access to information (such as cookies) on a user's device: satisfying an Article 6 basis for downstream processing of personal data does not by itself satisfy the separate prior-consent obligation typically required under EU ePrivacy law for non-essential cookies. This entry describes the general framework and does not resolve fact-specific questions about which basis is appropriate for a particular processing activity, nor does it address the additional conditions required for special category data under Article 9.

Why it matters

Lawfulness of processing sits at the foundation of GDPR compliance: if an organisation cannot point to a valid Article 6 basis, the processing of personal data is unlawful regardless of how well it handles security, transparency, or data subject rights. For teams working with cookies and tracking technologies, this matters because the data collected through analytics, advertising, and functional tools frequently constitutes personal data, and each processing purpose must be tied to an appropriate lawful basis.

A common and consequential error is treating the ePrivacy consent requirement and the GDPR lawful basis as a single hurdle. In most EU jurisdictions, placing or accessing non-essential cookies on a user's device generally requires prior consent under ePrivacy rules, while any subsequent processing of the personal data those cookies generate must additionally rest on an Article 6 basis. Satisfying one does not automatically satisfy the other, and organisations that assume a single consent covers everything may find gaps in their compliance posture. Where consent is the ePrivacy basis for a cookie, controllers should consider carefully whether consent is also the appropriate Article 6 basis for the downstream processing, since relying on a different basis may sit uneasily with the consent already obtained.

Choosing and documenting the right basis before processing begins also has practical downstream effects. Guidance from authorities such as the ICO indicates that a lawful basis generally cannot be swapped later without justification, so an ill-considered initial choice can be difficult to correct. This makes lawful basis a decision that privacy officers and legal counsel should make deliberately at the design stage rather than retrofit.

Who it's relevant to

Privacy officers and data protection officers
DPOs are typically responsible for mapping each processing purpose to an appropriate Article 6 basis and ensuring that choice is documented and defensible. For cookie-related processing, they should verify that the lawful basis is considered separately from the ePrivacy consent obligation and that the two are consistent.
Legal counsel and compliance teams
Legal teams advise on which basis fits a given activity and on the difficulty of changing a basis after processing has begun. Because the appropriate basis is fact-specific and guidance evolves, counsel play a central role in resolving contested interpretations that a general framework cannot settle.
Web developers and analytics implementers
Those deploying analytics, advertising, and functional technologies should understand that the data these tools collect may require a lawful basis for its processing, in addition to any consent needed before the cookie or similar technology is placed on a user's device. Technical implementation choices can affect which basis is workable.
Marketing and advertising compliance teams
Marketing operations relying on cookies, pixels, and similar tracking technologies need to confirm both that non-essential technologies are handled in line with ePrivacy consent expectations and that the downstream use of personal data rests on a suitable Article 6 basis, since a marketing purpose does not automatically justify a particular basis.

Inside Lawfulness of Processing

Legal Basis Requirement (GDPR Article 6)
Under the GDPR, any processing of personal data must rest on at least one of the lawful bases set out in Article 6, such as consent, contract, legal obligation, vital interests, public task, or legitimate interests. In the cookie context, the base most commonly relied upon for non-essential cookies is consent, though legitimate interests may be argued for certain limited processing where permitted.
Interaction with the ePrivacy Directive
Lawfulness of processing under the GDPR is distinct from, and additional to, the ePrivacy Directive's rules on placing or accessing information on a device. The ePrivacy rules generally require prior consent for non-essential cookies at the point of storage/access, while the GDPR governs the subsequent processing of any personal data that results. Both must typically be satisfied; satisfying one does not automatically satisfy the other.
Consent as a Lawful Basis
Where consent is the chosen basis, it must meet the GDPR standard of being freely given, specific, informed, and unambiguous, expressed through a clear affirmative action. This is the basis most directly relevant to analytics, advertising, and functional cookies in most EU jurisdictions.
Legitimate Interests and its Limits
Legitimate interests may serve as a basis for some processing, subject to a balancing test against the rights and interests of the individual. However, its availability for cookie-related processing is contested and constrained, particularly because the ePrivacy consent requirement for device access typically applies regardless of the GDPR basis chosen.
Scope of 'Personal Data'
Lawfulness of processing only engages the GDPR where personal data is involved. Identifiers set or read via cookies, pixels, local storage, SDKs, or fingerprinting can constitute personal data where they can single out or be linked to an individual, bringing the processing within scope.
Jurisdictional Variation
The lawfulness framework described here reflects EU law. The UK applies an analogous regime post-Brexit, while US state laws such as the CCPA/CPRA in California generally rely on transparency and opt-out mechanisms rather than an Article 6-style lawful basis requirement. Scope and terminology differ across regimes.

Common questions

Answers to the questions practitioners most commonly ask about Lawfulness of Processing.

Does obtaining consent for cookies under the ePrivacy rules mean I have a lawful basis for processing the resulting personal data under the GDPR?
Not automatically. The two regimes address different steps. The ePrivacy Directive (and its national implementations) governs the placing of and access to information on a user's device, while the GDPR governs the processing of any personal data that follows. Consent obtained for storing or reading a cookie does not by itself supply a lawful basis for every downstream processing operation. In practice, where consent is the appropriate ground, controllers often rely on consent for both steps, but you should assess the GDPR lawful basis for the processing separately rather than assuming the ePrivacy consent covers it.
Is consent the only lawful basis I can use when processing data collected through cookies and similar technologies?
No. The GDPR sets out several lawful bases, and consent is only one of them. However, the interaction with the ePrivacy rules matters: where prior consent is required to place or access information on a device (as is typically the case for analytics, advertising, and functional cookies in most EU jurisdictions), controllers commonly rely on consent for the subsequent processing as well. For processing not tied to a consent-requiring cookie operation, other bases such as legitimate interests may in principle be considered, subject to assessment. Whether a given basis is appropriate depends on the facts and on relevant data protection authority guidance, which continues to evolve.
How do I decide which lawful basis applies to a specific cookie-related processing activity?
Start by separating the two questions: whether prior consent is needed to store or access information on the device (an ePrivacy question), and what lawful basis applies to the personal data processing that follows (a GDPR question). Strictly necessary cookies are generally exempt from the consent requirement, while analytics, advertising, and functional cookies typically require prior consent under EU law. Where consent is required at the ePrivacy stage, it is often the practical basis for the processing too. Document your reasoning for each activity, and note that the appropriate basis depends on facts not settled by a general definition and may differ by jurisdiction.
What should I record to demonstrate lawfulness of processing for cookie-based data?
Maintain records that show, for each processing activity, the purpose, the categories of data, and the lawful basis relied on, alongside evidence supporting the ePrivacy consent where applicable. Where consent is the basis, consent logging and record-keeping should capture that a clear affirmative action was taken and what the user was told at the time. A consent management platform can support this logging, but it supports compliance rather than guaranteeing it, and does not replace legal judgment. Keep records aligned with your broader accountability documentation.
Does lawfulness of processing work the same way outside the EU, for example under US state privacy laws?
No. The GDPR's lawful basis framework is specific to the EU (with a closely related approach in the UK). US state privacy laws such as the CCPA and CPRA in California take a different structure and often rely on opt-out mechanisms rather than requiring a pre-identified lawful basis for each processing activity. Because obligations vary between the EU, the UK, and individual US states, you should scope your lawfulness analysis to the jurisdictions whose residents you process, and flag where local requirements differ.
If a user withdraws consent, what happens to the lawfulness of processing already carried out?
Withdrawal of consent generally does not affect the lawfulness of processing that took place before withdrawal, but it does mean you should stop the relevant processing going forward unless another applicable basis genuinely supports it. In practice, you should ensure your systems can act on withdrawal, stop reading or setting the affected cookies, and update your records. Whether any alternative basis is available for continued processing depends on the facts and should be assessed case by case rather than assumed.

Common misconceptions

Obtaining cookie consent under the ePrivacy rules automatically makes the resulting data processing lawful under the GDPR.
The two regimes operate in parallel. ePrivacy governs the placing of and access to information on a device, while the GDPR governs the subsequent processing of personal data. Each has its own requirements, and compliance with one does not, on its own, satisfy the other.
Legitimate interests can always be used to avoid asking for cookie consent.
Legitimate interests is a potential GDPR basis subject to a balancing test, but its use for cookie-related processing is contested and limited. In most EU jurisdictions the ePrivacy consent requirement for accessing or storing information on a device still applies to non-essential cookies regardless of the GDPR basis relied upon.
The lawfulness requirement works the same way everywhere.
The Article 6 lawful basis structure is an EU (and broadly UK) concept. Several US state privacy laws instead rely on notice and opt-out approaches rather than requiring a lawful basis before processing. The applicable rules depend on the jurisdiction and the facts.

Best practices

Identify and document a specific lawful basis under GDPR Article 6 for each cookie-related processing activity, rather than assuming consent covers everything by default.
Treat the ePrivacy consent requirement and the GDPR lawful basis as separate obligations, and confirm that both are met for non-essential cookies in EU and UK contexts.
Where consent is relied upon, ensure it meets the freely given, specific, informed, and unambiguous standard through a clear affirmative action, avoiding pre-ticked boxes or implied consent.
Assess carefully before relying on legitimate interests for cookie processing, documenting any balancing test and recognizing that its availability is contested and may not remove the device-access consent requirement.
Map which cookies, pixels, SDKs, local storage, or fingerprinting techniques process personal data, since the lawfulness analysis only engages the GDPR where personal data is involved.
Confirm the applicable jurisdiction for each audience and adapt the lawful basis approach accordingly, since US state laws such as the CCPA/CPRA generally follow an opt-out model rather than requiring an Article 6 basis, and seek legal advice on unresolved points.