Purpose Compatibility
Purpose compatibility is the question of whether personal data collected for one reason can later be used for a different reason without needing to go back to the individual. Under EU and UK data protection law, an organisation generally has to check whether the new use is compatible with the original purpose before proceeding. A different purpose is not automatically an incompatible one, but this has to be judged on the facts of each case.
Purpose compatibility refers to the assessment required under the purpose limitation principle (Article 5(1)(b) of the GDPR and UK GDPR) when a controller intends to further process personal data for a purpose other than that for which it was originally collected. Where the further processing is not based on consent or a legal obligation, the controller must carry out a compatibility assessment to determine whether the new purpose is compatible with the original one. Regulatory guidance indicates this assessment typically considers factors similar to a legitimate interests assessment, including the original and new purposes, individuals' reasonable expectations, and the impact on the people concerned; the Irish Data Protection Commission has confirmed that a different purpose is not necessarily an incompatible purpose and that incompatibility should be assessed on a case-by-case basis. Certain conditions, such as the taxation compatibility condition described in UK guidance, may treat specific further-processing purposes as compatible. This entry concerns the general purpose limitation framework and does not resolve how compatibility applies to any specific processing operation, which depends on facts not covered here; the interaction with the separate ePrivacy rules governing the placing of and access to cookies and similar technologies is outside the scope of this definition.
Why it matters
Purpose compatibility sits at the heart of the purpose limitation principle in Article 5(1)(b) of the GDPR and UK GDPR. Organisations rarely use personal data for only the single reason they first collected it, and the compatibility question determines whether a new use can proceed without returning to individuals for fresh consent or identifying a separate legal basis. Getting this wrong risks processing personal data unlawfully, which can undermine the fairness and transparency obligations that run throughout the framework. In the cookie and tracking context, data gathered through consented technologies may later be considered for analytics, product development, or other secondary uses, and the compatibility assessment is one of the tools that governs whether such reuse is permissible.
The assessment matters because it protects individuals' reasonable expectations. A person who provides data for one clearly stated reason should generally not find it repurposed in ways they could not have anticipated and that may adversely affect them. At the same time, EU and UK law does not treat every new purpose as prohibited: the Irish Data Protection Commission has confirmed that a different purpose is not necessarily an incompatible purpose and that incompatibility should always be assessed on a case-by-case basis. This means organisations cannot rely on blanket rules and must document their reasoning for each significant change in use.
Because compatibility is fact-dependent and its outcome affects lawfulness, it is an area where organisations benefit from careful, recorded assessment rather than assumptions. This entry describes the general purpose limitation framework only; it does not resolve how compatibility applies to any particular processing operation, and it does not address the separate ePrivacy rules that govern the placing of and access to cookies and similar technologies, which apply independently of the GDPR purpose limitation analysis.
Who it's relevant to
Inside Purpose Compatibility
Common questions
Answers to the questions practitioners most commonly ask about Purpose Compatibility.
