Skip to main content
Category: Consent Principles

Legal Basis for Processing

Also known as: Lawful Basis for Processing, Lawful Basis, Legal Ground for Processing, Article 6 Legal Basis
Simply put

A legal basis for processing is the legal justification an organisation must have before it processes someone's personal data under the EU or UK GDPR. The law sets out a fixed list of these justifications, such as the person's consent or the need to fulfil a contract, and an organisation must identify at least one that applies. Without a valid legal basis, processing personal data is generally unlawful in these jurisdictions.

Formal definition

Under Article 6(1) of the EU GDPR (and the equivalent UK GDPR provision), processing of personal data is lawful only if at least one of six legal bases applies: consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task carried out in the public interest or official authority (public task), and legitimate interests. The controller should identify and document the appropriate basis before processing begins, and the choice affects the data subject rights that apply and how processing may lawfully proceed. In the cookie context, this GDPR analysis is distinct from, and additional to, the separate consent requirement for storing or accessing information on a user's device under the ePrivacy Directive and its national implementations; satisfying one does not automatically satisfy the other. Note that additional or stricter conditions apply to special categories of personal data (which typically require an Article 9 condition as well), and this entry does not address non-EU/UK regimes, which structure lawfulness differently and often rely on opt-out rather than a defined list of bases.

Why it matters

Identifying a valid legal basis is the foundation of lawful processing under the EU and UK GDPR. Without one of the six bases set out in Article 6(1), processing personal data is generally unlawful in these jurisdictions, exposing organisations to regulatory enforcement and undermining individuals' trust. The choice of basis is not merely a formality: it shapes which data subject rights apply and how processing may lawfully proceed, so a poorly reasoned or undocumented choice can create compliance risk that surfaces later during an audit, complaint, or supervisory authority investigation.

In the cookie and tracking context, the legal basis analysis is a frequent source of confusion because it sits alongside a separate requirement. The ePrivacy Directive and its national implementations govern the storing of or access to information on a user's device, while the GDPR governs any subsequent processing of the personal data involved. Satisfying one of these regimes does not automatically satisfy the other. Organisations that treat a cookie banner consent as covering all downstream processing, or that assume a documented GDPR legal basis removes the need for ePrivacy consent, can leave a gap that regulators and litigants may scrutinise.

The basis chosen also matters because the options are not interchangeable. Where consent is relied on, it must meet the GDPR standard of being freely given, specific, informed, and unambiguous, and it can be withdrawn. Where legitimate interests is relied on, a balancing assessment is generally expected. Because supervisory authority guidance and enforcement positions continue to evolve, organisations should treat the selection and documentation of a legal basis as an ongoing exercise rather than a one-off decision.

Who it's relevant to

Privacy officers and data protection officers
Those responsible for compliance need to ensure that each processing activity is mapped to an appropriate Article 6 basis and that the reasoning is documented before processing begins. They should also keep this analysis current as supervisory authority guidance and enforcement positions evolve, and confirm whether special category data requires an additional Article 9 condition.
Legal counsel
Legal teams advise on which of the six bases genuinely applies to a given activity, including whether consent, legitimate interests, or another basis is the most defensible choice. They are also best placed to assess the interaction between the GDPR legal basis and the separate ePrivacy consent requirement for cookies, and to flag where the two regimes must both be satisfied.
Marketing and analytics compliance teams
Teams deploying cookies, pixels, SDKs, and similar tracking technologies need to understand that a cookie banner may address the ePrivacy consent requirement but does not by itself resolve the GDPR legal basis for downstream processing of the resulting personal data. Where consent is the basis, they should ensure it meets the GDPR standard and remains withdrawable.
Web developers and CMP implementers
Developers configuring consent management platforms and tag management should reflect the chosen legal bases accurately, ensuring that processing dependent on consent does not fire before valid consent is captured. Tools can support this alignment, but they do not replace the legal judgment required to select and document the correct basis.

Inside Legal Basis for Processing

Six legal bases under the GDPR
Article 6 of the GDPR sets out six lawful bases for processing personal data: consent, contract, legal obligation, vital interests, public task, and legitimate interests. At least one must apply for any processing of personal data to be lawful, and the appropriate basis depends on the specific purpose and context of the processing.
Interaction with the ePrivacy rules for cookies
The placing of and access to information on a user's device is generally governed by the ePrivacy Directive (as implemented nationally), which for non-exempt cookies typically requires prior consent. Where that cookie activity involves processing personal data, the GDPR then also applies and a legal basis under Article 6 is needed. In practice, where ePrivacy requires consent to set a cookie, consent commonly also serves as the GDPR basis for the related processing, though these are two distinct requirements and should not be conflated.
Consent as a basis
Consent under the GDPR must be freely given, specific, informed, and unambiguous, indicated by a clear affirmative action. It is the basis most closely associated with non-essential cookies and similar technologies in the EU. Consent can generally be withdrawn as easily as it was given.
Legitimate interests as a basis
Legitimate interests may support certain processing where it is balanced against the rights and freedoms of the individual, typically via a documented balancing assessment. Its availability for cookie-related activity is limited, because where the ePrivacy rules require consent to access or store information on a device, legitimate interests generally cannot substitute for that consent.
Geographic and regime-specific scope
The concept of a legal basis in this form is a feature of the GDPR and the UK GDPR. US state privacy frameworks such as the CCPA/CPRA in California operate differently, often relying on notice and opt-out rights rather than an enumerated set of lawful bases. Claims about legal bases should therefore be scoped to the applicable jurisdiction.
Documentation and accountability
Under the GDPR's accountability principle, controllers are generally expected to identify and be able to demonstrate the legal basis relied on for each processing purpose, and to inform individuals of it in privacy information. Where consent is the basis, this typically includes maintaining records of consent.

Common questions

Answers to the questions practitioners most commonly ask about Legal Basis for Processing.

If we have valid consent for placing cookies under the ePrivacy rules, does that also cover our legal basis for processing the personal data collected?
Not necessarily. In most EU jurisdictions the ePrivacy Directive (and its national implementations) governs the act of placing or accessing information on a user's device, while the GDPR separately governs any processing of personal data that follows. Consent obtained for the storage or access step does not automatically satisfy the GDPR's requirement for a lawful basis for the subsequent processing, though in practice consent is often relied upon for both. Data protection authorities have generally emphasized that these are distinct legal questions, and the interplay between the two regimes remains an area where guidance continues to evolve. You should assess each step separately rather than assuming one consent covers everything.
Can we rely on legitimate interests instead of consent so that we don't need a cookie banner?
This is a common misconception and should be approached with caution. Where the ePrivacy rules require prior consent for placing or accessing information on a device, as they generally do for analytics, advertising, and similar non-essential cookies in the EU, legitimate interests under the GDPR does not remove that consent requirement. The two regimes operate in parallel. Legitimate interests may be relevant to certain downstream processing activities, but it typically cannot substitute for the consent needed to set the cookie in the first place. Whether legitimate interests is available at all depends on the specific facts, the jurisdiction, and evolving regulatory positions, so this should be assessed case by case rather than treated as a general workaround for consent.
How do we decide which legal basis applies to a given cookie or tracking technology?
Start by separating the two legal questions: the basis for placing or accessing information on the device under the applicable ePrivacy rules, and the basis for any resulting personal data processing under the GDPR (in the EU) or equivalent frameworks elsewhere. For non-essential cookies, pixels, SDKs, or similar technologies, prior consent is typically required in the EU for the placement step. For the processing step, you then identify an appropriate GDPR basis, which is often consent for the same activities. The analysis depends on the purpose of each technology, the data involved, and the jurisdiction, so it generally benefits from documented case-by-case assessment rather than a single blanket basis applied across all cookies.
What records should we keep to demonstrate the legal basis we rely on?
Under the GDPR's accountability principle, controllers are generally expected to be able to demonstrate the lawful basis relied upon for each processing activity. Where consent is the basis, this typically includes retaining consent records showing what the user was told, when consent was given, and the scope of that consent, often captured through a consent management platform's logging. Where another basis is used, documentation such as an assessment of that basis may be appropriate. The specific record-keeping expectations vary by jurisdiction and by the nature of the processing, and tools can support this logging but do not by themselves establish that the chosen basis is legally valid.
What happens to processing that relied on consent if the user later withdraws it?
Under the GDPR, consent must be as easy to withdraw as to give, and withdrawal generally means you must stop the processing that relied on that consent going forward. Withdrawal does not, by itself, affect the lawfulness of processing carried out before withdrawal. Practically, this means your systems and any CMP should be able to propagate a withdrawal so that the relevant cookies or technologies stop operating for that user and downstream processing ceases. The precise operational steps depend on your technical setup and on how the specific activity was configured, which falls outside a general definition.
Does the same legal basis analysis apply across the EU, the UK, and US state privacy laws?
No. The framing differs by regime and the scope of any claim should be stated accordingly. In the EU and the UK, the analysis typically involves both the ePrivacy rules and the GDPR (or UK GDPR), with consent commonly required for non-essential cookies on an opt-in basis. Several US state laws, such as those in California, often operate on an opt-out model rather than requiring prior opt-in consent and use their own concepts rather than the GDPR's lawful-basis structure. Because obligations and terminology vary between jurisdictions and continue to evolve, you should map your practices to each applicable regime separately rather than assuming one analysis transfers to another.

Common misconceptions

Consent obtained under the ePrivacy cookie rules automatically satisfies all GDPR requirements for the resulting data processing.
The ePrivacy rules govern storing or accessing information on a device, while the GDPR governs the subsequent processing of any personal data. These are separate requirements. Consent may serve both purposes in many cases, but a controller should still confirm that a valid Article 6 basis exists for each processing purpose rather than assuming one requirement covers the other.
Legitimate interests can be used to avoid asking for cookie consent for analytics or advertising.
Where national ePrivacy implementations require prior consent to place or access non-essential cookies, that consent requirement generally cannot be displaced by relying on legitimate interests. Legitimate interests may be relevant to some downstream processing, but it does not remove a consent obligation that applies to the device-access step in the EU.
The GDPR's list of legal bases applies the same way everywhere.
The framework of six legal bases is specific to the GDPR and the UK GDPR. Other regimes, such as US state privacy laws, structure lawfulness differently and often center on opt-out mechanisms and disclosures. Any statement about which basis applies should specify the governing jurisdiction.

Best practices

Map each distinct processing purpose to a specific Article 6 legal basis, and document the reasoning, rather than assuming a single basis covers all activities.
Treat the ePrivacy consent requirement and the GDPR legal basis as separate questions, and verify that both are satisfied for cookie-related processing in the EU.
Where you rely on consent, ensure it meets the GDPR standard of freely given, specific, informed, and unambiguous, avoid pre-ticked boxes or implied consent, and log and retain records of consent.
Where you consider legitimate interests, conduct and document a balancing assessment, and confirm it is not being used to bypass a consent requirement that applies under national ePrivacy rules.
Scope your analysis to each applicable jurisdiction (for example EU, UK, or specific US states) and avoid applying one regime's rules universally.
Reflect the chosen legal basis in your privacy information and consent management configuration, and revisit these choices as regulatory guidance evolves, treating tools such as CMPs as support for, not a substitute for, legal judgment.