Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Category: Consent Principles

Purpose Compatibility

Also known as: Compatibility Test, Compatible Purpose Assessment, Further Processing Compatibility
Simply put

Purpose compatibility is the question of whether personal data collected for one reason can later be used for a different reason without needing to go back to the individual. Under EU and UK data protection law, an organisation generally has to check whether the new use is compatible with the original purpose before proceeding. A different purpose is not automatically an incompatible one, but this has to be judged on the facts of each case.

Formal definition

Purpose compatibility refers to the assessment required under the purpose limitation principle (Article 5(1)(b) of the GDPR and UK GDPR) when a controller intends to further process personal data for a purpose other than that for which it was originally collected. Where the further processing is not based on consent or a legal obligation, the controller must carry out a compatibility assessment to determine whether the new purpose is compatible with the original one. Regulatory guidance indicates this assessment typically considers factors similar to a legitimate interests assessment, including the original and new purposes, individuals' reasonable expectations, and the impact on the people concerned; the Irish Data Protection Commission has confirmed that a different purpose is not necessarily an incompatible purpose and that incompatibility should be assessed on a case-by-case basis. Certain conditions, such as the taxation compatibility condition described in UK guidance, may treat specific further-processing purposes as compatible. This entry concerns the general purpose limitation framework and does not resolve how compatibility applies to any specific processing operation, which depends on facts not covered here; the interaction with the separate ePrivacy rules governing the placing of and access to cookies and similar technologies is outside the scope of this definition.

Why it matters

Purpose compatibility sits at the heart of the purpose limitation principle in Article 5(1)(b) of the GDPR and UK GDPR. Organisations rarely use personal data for only the single reason they first collected it, and the compatibility question determines whether a new use can proceed without returning to individuals for fresh consent or identifying a separate legal basis. Getting this wrong risks processing personal data unlawfully, which can undermine the fairness and transparency obligations that run throughout the framework. In the cookie and tracking context, data gathered through consented technologies may later be considered for analytics, product development, or other secondary uses, and the compatibility assessment is one of the tools that governs whether such reuse is permissible.

The assessment matters because it protects individuals' reasonable expectations. A person who provides data for one clearly stated reason should generally not find it repurposed in ways they could not have anticipated and that may adversely affect them. At the same time, EU and UK law does not treat every new purpose as prohibited: the Irish Data Protection Commission has confirmed that a different purpose is not necessarily an incompatible purpose and that incompatibility should always be assessed on a case-by-case basis. This means organisations cannot rely on blanket rules and must document their reasoning for each significant change in use.

Because compatibility is fact-dependent and its outcome affects lawfulness, it is an area where organisations benefit from careful, recorded assessment rather than assumptions. This entry describes the general purpose limitation framework only; it does not resolve how compatibility applies to any particular processing operation, and it does not address the separate ePrivacy rules that govern the placing of and access to cookies and similar technologies, which apply independently of the GDPR purpose limitation analysis.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for compliance need to identify when a proposed new use of personal data amounts to further processing and to run and document a compatibility assessment where consent or a legal obligation does not apply. Recording the analysis of original purpose, reasonable expectations, and impact supports accountability and helps demonstrate that the case-by-case standard has been met.
Legal counsel and compliance teams
Legal advisers assess whether a change in use can rely on compatibility or whether a separate route, such as fresh consent or another legal basis, is needed. They also consider whether defined conditions, such as the UK taxation compatibility condition, apply, and they advise on the residual uncertainty given that incompatibility depends on the specific facts.
Marketing and analytics teams
Teams that want to reuse data collected for one stated purpose, for example to build analytics or develop new products, should engage the compatibility question early. A different purpose is not automatically incompatible, but it cannot be assumed compatible either, and reuse of data derived from tracking technologies may also engage separate ePrivacy consent rules that fall outside this assessment.
Web developers and product teams
Those building systems that capture and store personal data should be aware that the purpose recorded at collection shapes what can later be done with that data. Clear purpose specification at the point of collection supports later compatibility analysis and helps align processing with individuals' reasonable expectations.

Inside Purpose Compatibility

Purpose limitation principle
The GDPR requirement that personal data be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes. Purpose compatibility is the assessment of whether a proposed further processing aligns with the original purpose for which the data was collected.
Compatibility assessment factors
Where further processing is not based on a new consent or a legal obligation, the GDPR sets out factors to weigh, including any link between the original and intended purposes, the context of collection and the relationship between controller and data subject, the nature of the data (for example whether special category data is involved), the possible consequences for individuals, and the existence of safeguards such as encryption or pseudonymisation.
Relationship to cookie-based data
In the cookie context, data collected through cookies, pixels, SDKs, or similar technologies for one declared purpose (for example analytics) may not automatically be reused for another purpose (for example advertising or profiling). Reusing such data typically requires re-evaluating compatibility and, in many EU cases, obtaining fresh, specific consent.
Interaction with consent
Where the original processing relied on consent, further processing for a new purpose generally cannot rest on a compatibility assessment alone and typically requires separate consent for that new, specific purpose, consistent with the GDPR standard that consent be specific and informed.
Distinction between ePrivacy and GDPR layers
Placing or accessing information on a device is governed by the ePrivacy rules and their national implementations, while the subsequent processing of any resulting personal data, including purpose compatibility questions, is governed by the GDPR. Compatibility analysis operates at the GDPR processing layer and does not by itself satisfy the separate consent requirement for storage or access on the device.

Common questions

Answers to the questions practitioners most commonly ask about Purpose Compatibility.

Does obtaining consent for placing cookies under the ePrivacy rules also cover reusing the resulting data for a new, unrelated purpose?
No. These are distinct questions governed by distinct regimes. The ePrivacy Directive (and its national implementations) governs the placing of and access to information on a user's device, while the GDPR governs the subsequent processing of any personal data. Consent obtained for placing a cookie does not automatically authorize reusing the data collected through it for a further purpose. Where GDPR consent is the legal basis, a further purpose generally requires its own valid consent, because compatibility analysis is not typically available to extend consent-based processing. You should assess the ePrivacy consent for the cookie and the GDPR basis for each processing purpose separately.
If a new use of data seems related to the original purpose, can it always be treated as compatible so no fresh consent or notice is needed?
Not necessarily. Perceived relatedness is only a starting point, not a conclusion. Whether a further purpose is compatible with the original one depends on a multi-factor assessment that typically considers the link between the purposes, the context in which the data was collected, the nature of the data, the possible consequences for individuals, and the safeguards applied. Importantly, where the original processing relied on consent, compatibility analysis is generally not a substitute for obtaining consent for the new purpose. Compatibility is a case-by-case judgment, and the outcome depends on facts beyond this definition.
How does purpose compatibility relate to the consent purposes users select in a CMP?
Consent management platforms typically capture consent against defined purposes, and frameworks such as the IAB Transparency and Consent Framework organize processing into specified purpose categories. If your intended use falls outside the purposes a user actually consented to, you generally cannot rely on compatibility to bridge the gap for consent-based processing; you would typically need to present the new purpose and obtain consent. CMPs support this by structuring and logging purpose-specific choices, but they do not make the underlying legal judgment about whether a purpose is covered. That assessment remains a matter for legal and privacy review.
What should we document when we conclude a further purpose is compatible with the original one?
As a practical matter, it is generally advisable to record the reasoning behind the assessment: the original purpose and its stated legal basis, the proposed further purpose, and how the relevant factors (such as the link between purposes, the collection context, the nature of the data, potential impacts on individuals, and any safeguards) were weighed. This record supports accountability and can help demonstrate that a considered analysis took place. Requirements and regulator expectations vary by jurisdiction, and this documentation supports but does not by itself establish that a given use is lawful.
Does compatibility analysis apply differently in the EU, the UK, and US state regimes?
The concept of assessing whether a further use is compatible with the purpose for which data was collected is closely associated with EU and UK data protection law and applies within their legal frameworks, with guidance from the relevant data protection authorities that continues to evolve. US state privacy laws such as California's take a different structural approach, often centered on notice at collection, purpose limitation obligations, and opt-out rights rather than the same compatibility test. Because the mechanisms differ, you should scope any compatibility assessment to the applicable jurisdiction rather than assuming one regime's approach applies universally.
How does purpose compatibility interact with technologies that are not literally cookies, such as pixels, SDKs, local storage, or fingerprinting?
The regime that governs access to a device applies to these similar technologies in the same way it applies to cookies, so the initial ePrivacy analysis is comparable regardless of the technical mechanism. Once personal data is collected through any of these technologies, the GDPR analysis of purpose, including whether a further use is compatible with the original purpose, applies to that data. The technical form of the tracker does not change the purpose analysis; what matters is the legal basis for the processing and the purposes for which the data may be used.

Common misconceptions

If data was lawfully collected via a cookie, it can be reused for any related business purpose.
Lawful initial collection does not automatically permit further processing for a new purpose. Under the GDPR, further processing must be compatible with the original purpose, and where the original basis was consent, a new specific purpose generally requires fresh consent rather than a compatibility assessment.
A favourable compatibility assessment removes the need to address cookie consent.
Purpose compatibility is a GDPR processing concept and does not address the separate ePrivacy requirement to obtain consent before storing or accessing information on a user's device. The two obligations are distinct and both may apply.
The compatibility factors give controllers broad discretion to justify most reuse of cookie data.
The factors are cumulative considerations weighted against the individual's reasonable expectations and possible consequences. Reuse for purposes such as advertising or profiling that individuals would not reasonably expect is often difficult to justify as compatible, and interpretations continue to evolve through regulatory guidance and enforcement.

Best practices

Document at the point of collection the specific, explicit purposes for each cookie or similar technology, so that any later compatibility assessment has a clear baseline to compare against.
Before reusing cookie-derived data for a new purpose, run and record a structured compatibility assessment addressing the GDPR factors, including the link between purposes, the context, the nature of the data, potential consequences, and available safeguards.
Where the original processing relied on consent, treat new purposes such as advertising or profiling as generally requiring separate, specific consent rather than relying on a compatibility analysis alone.
Keep the ePrivacy and GDPR analyses separate in your records, confirming both that valid consent (or an applicable exemption) covers storage or access on the device and that any further processing satisfies purpose limitation.
Apply safeguards such as pseudonymisation or encryption where feasible, as these can be relevant factors in a compatibility assessment, while recognising they support but do not guarantee a compatible outcome.
Confirm the geographic and legal scope before relying on any conclusion, since purpose compatibility is a GDPR concept whose application may differ from opt-out oriented frameworks such as certain US state privacy laws, and seek legal judgment where interpretations are contested.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.