Guide

What Is a Lawful Basis for Processing, and Which One Do I Need?

GDPR gives you six possible lawful bases for processing personal data, not just consent. Here's what all six actually are and how to figure out which one fits a given activity.

Published September 2, 2026·Last updated September 2, 2026

Every single instance of processing personal data under GDPR needs a lawful basis, a specific legal justification from Article 6, and this is one of the most misunderstood parts of the regulation because most people only ever hear about one of the six: consent. Consent gets the most attention because it’s the one visitors actually see, in a cookie banner, but it’s often not even the right basis to rely on for a given activity.

The six lawful bases

  1. Consent — the individual has given clear, affirmative permission for a specific purpose. Must be freely given, specific, informed, and revocable as easily as it was given.
  2. Contract — the processing is necessary to perform a contract with the individual, or to take steps at their request before entering one. Processing a customer’s shipping address to fulfill an order they placed is a contract basis, not consent.
  3. Legal obligation — you’re processing the data because another law requires it, tax record retention, for example.
  4. Vital interests — necessary to protect someone’s life, rarely relevant outside emergency and healthcare contexts.
  5. Public task — processing necessary to perform a task in the public interest or exercise official authority, mostly relevant to public bodies, rarely applicable to private businesses.
  6. Legitimate interests — processing is necessary for a legitimate interest of yours or a third party, and that interest isn’t overridden by the individual’s rights and freedoms. This is the most flexible basis and the most commonly misused.

Consent seems like the safe, obviously-compliant default, but it comes with a real cost: it must be freely given and freely revocable, and processing has to stop the moment someone withdraws it. That’s workable for optional things like marketing emails or analytics cookies. It’s a poor fit for core business processing, if fulfilling a customer’s order legally required consent, and that customer withdrew consent mid-fulfillment, you’d be in an impossible position. That’s exactly why contract, not consent, is the correct basis for that kind of processing, using consent there would actually be a compliance mistake, not an extra-safe choice.

A practical way to pick

Question Likely basis
Is this required to deliver something the person specifically asked for or agreed to buy? Contract
Is this required by a law that applies to you (tax, employment, etc.)? Legal obligation
Is this optional, and would the person reasonably be surprised or object if they knew? Consent
Is this something you need for your own reasonable business purposes, and would the average person expect it, without it being intrusive? Legitimate interests (with a documented balancing test)
Does it involve marketing, non-essential cookies, or advertising? Almost always consent

The single most common lawful-basis decision businesses actually have to make is between consent and legitimate interests, especially for things like basic first-party analytics or business-to-business marketing outreach. We built a dedicated decision framework for exactly this comparison in our consent vs. legitimate interest guide, worth reading once you’ve narrowed it down to those two.

Our recommendation

CookieYes

Whichever basis applies to a given activity, cookie-based tracking specifically almost always needs consent under the separate ePrivacy rules regardless of what GDPR basis you might otherwise rely on. CookieYes is built around getting that specific, most-commonly-needed basis right.

Try CookieYes

You have to document your choice, not just make it

GDPR’s accountability principle means picking a basis isn’t a mental exercise, you need to record which basis applies to which processing activity as part of your Records of Processing Activities. See our ROPA guide for what that documentation actually needs to include.

This guide is educational and not legal advice. Selecting the correct lawful basis for a specific processing activity depends on your facts; consult a privacy attorney before finalizing your basis for any activity you’re unsure about.