Legal Basis for Processing
A legal basis for processing is the legal justification an organisation must have before it processes someone's personal data under the EU or UK GDPR. The law sets out a fixed list of these justifications, such as the person's consent or the need to fulfil a contract, and an organisation must identify at least one that applies. Without a valid legal basis, processing personal data is generally unlawful in these jurisdictions.
Under Article 6(1) of the EU GDPR (and the equivalent UK GDPR provision), processing of personal data is lawful only if at least one of six legal bases applies: consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest or official authority (public task), and legitimate interests. The controller should identify and document the appropriate basis before processing begins, and the choice affects the data subject rights that apply and how processing may lawfully proceed. In the cookie context, this GDPR analysis is distinct from, and additional to, the separate consent requirement for storing or accessing information on a user's device under the ePrivacy Directive and its national implementations; satisfying one does not automatically satisfy the other. Note that additional or stricter conditions apply to special categories of personal data (which typically require an Article 9 condition as well), and this entry does not address non-EU/UK regimes, which structure lawfulness differently and often rely on opt-out rather than a defined list of bases.
Why it matters
Identifying a valid legal basis is the foundation of lawful processing under the EU and UK GDPR. Without one of the six bases set out in Article 6(1), processing personal data is generally unlawful in these jurisdictions, exposing organisations to regulatory enforcement and undermining individuals' trust. The choice of basis is not merely a formality: it shapes which data subject rights apply and how processing may lawfully proceed, so a poorly reasoned or undocumented choice can create compliance risk that surfaces later during an audit, complaint, or supervisory authority investigation.
In the cookie and tracking context, the legal basis analysis is a frequent source of confusion because it sits alongside a separate requirement. The ePrivacy Directive and its national implementations govern the storing of or access to information on a user's device, while the GDPR governs any subsequent processing of the personal data involved. Satisfying one of these regimes does not automatically satisfy the other. Organisations that treat a cookie banner consent as covering all downstream processing, or that assume a documented GDPR legal basis removes the need for ePrivacy consent, can leave a gap that regulators and litigants may scrutinise.
The basis chosen also matters because the options are not interchangeable. Where consent is relied on, it must meet the GDPR standard of being freely given, specific, informed, and unambiguous, and it can be withdrawn. Where legitimate interests is relied on, a balancing assessment is generally expected. Because supervisory authority guidance and enforcement positions continue to evolve, organisations should treat the selection and documentation of a legal basis as an ongoing exercise rather than a one-off decision.
Who it's relevant to
Inside Legal Basis for Processing
Common questions
Answers to the questions practitioners most commonly ask about Legal Basis for Processing.