Under the UK GDPR, organisations must have a valid legal reason before processing personal data. There are now seven lawful bases, including recognised legitimate interest. Choosing the right basis matters because it affects transparency, individual rights, accountability, and whether the processing is lawful in the first place.
Under the UK GDPR, organisations must identify a valid lawful basis before processing personal data. There are now seven lawful bases: consent, contract, legal obligation, vital interests, public task, recognised legitimate interest, and legitimate interests. The right basis depends on the purpose and circumstances of the processing, not simply what feels easiest to use.
Main rule
You need a lawful basis before processing personal data
Seven bases
Including recognised legitimate interest as a separate lawful basis
Why it matters
The basis affects rights, notices, records, and accountability
A lawful basis is not something to choose after the processing has already started. It should be identified before personal data is collected, used, shared, stored, or otherwise processed. Organisations should be clear about which basis applies from the start and be able to demonstrate why it fits the particular purpose.
The lawful basis should match the real purpose of the processing. It should not be selected later simply to justify a decision that has already been made.
A single organisation may rely on different lawful bases for different activities, such as payroll, marketing, customer support, legal compliance, or security.
Lawful basis decisions should be recorded as part of wider compliance governance, including privacy information, data mapping, and records of processing where applicable.
This is closely connected to accountability and transparency, because organisations must be able to explain what they are doing and why.
Article 6 of the UK GDPR now contains seven lawful bases for processing personal data. Each has a different purpose, and there is no automatic hierarchy between them. The correct basis is the one that genuinely fits the processing activity and its circumstances.
Consent may apply where the individual has a genuine choice and gives a clear, informed, specific and unambiguous indication that they agree to the processing.
Contract may apply where the processing is necessary to perform a contract with the individual, or to take requested steps before entering into a contract.
Legal obligation may apply where processing is necessary for the organisation to comply with a legal duty that applies to it.
Vital interests generally applies where processing is necessary to protect someone's life and is usually relevant only in limited circumstances.
Public task may apply where processing is necessary to perform a task in the public interest or exercise an official function that has a clear basis in law.
This basis applies only where processing is necessary for one of the pre-approved public-interest purposes set out in law, including certain crime prevention, safeguarding, emergency, security, defence, and public-task disclosure situations.
Legitimate interests may apply where there is a genuine legitimate interest, the processing is necessary, and the individual's interests, rights and freedoms do not override it.
The correct lawful basis depends on the specific purpose and context of the processing. No one basis is automatically better or safer than another, and organisations should consider whether one of the more specific bases clearly applies before turning to broader options such as consent or legitimate interests.
Contract, legal obligation, vital interests and public task each apply to particular circumstances. Recognised legitimate interest is also purpose-specific and can only be used where the processing falls within one of its pre-approved statutory conditions and is necessary for that purpose.
Recognised legitimate interest is separate from legitimate interests. The recognised basis does not require the usual balancing test because the relevant public-interest purposes have been pre-approved in law. Ordinary legitimate interests remains broader, but requires the organisation to consider whether the individual's rights and interests override the legitimate interest.
Start by asking what you are doing, why you are doing it, and whether the processing is genuinely necessary. If a specific or pre-approved purpose applies, consider that basis first. Otherwise, assess whether another basis such as consent or legitimate interests properly reflects the relationship, expectations, risks, and degree of control involved.
Lawful basis mistakes usually happen when organisations choose a basis too quickly, treat consent as the default, confuse similar bases, or fail to connect the decision to their privacy information and records.
Consent is not automatically the strongest or most appropriate basis. If people cannot genuinely refuse or withdraw without detriment, another lawful basis may better reflect the processing.
Recognised legitimate interest is not simply another name for legitimate interests. It is a separate lawful basis restricted to specific pre-approved public-interest purposes and has its own requirements.
Different processing purposes may need different lawful bases. Treating all personal-data use as one broad activity can result in inaccurate records and unclear privacy information.
A lawful basis under Article 6 is not always enough. If special category data or criminal offence data is involved, additional conditions or requirements may also need to be identified.
Lawful basis decisions should be specific, documented, and reflected in privacy information. They should also be reviewed when processing changes, especially where organisations introduce new data, purposes, sharing arrangements, or technologies.
The easiest way to understand lawful basis is to apply it to everyday processing activities. These examples are simplified, and the correct basis will always depend on the particular purpose and circumstances.
Payroll processing may involve legal obligation, contract, or different bases for different elements, depending on the particular requirement being met.
Marketing may involve consent or legitimate interests under UK GDPR, while PECR can impose additional rules depending on the communication and recipient. See Direct Marketing and GDPR for more detail.
Processing that is objectively necessary to fulfil a customer's order may often rely on contract, while related analytics, marketing, or other secondary purposes may require a different basis.
Some proportionate security monitoring may rely on legitimate interests, depending on the purpose, necessity of the monitoring, people's reasonable expectations, and its impact on them.
Recognised legitimate interest may be relevant where processing is necessary to prevent, detect, or investigate crime, including fraud. If the organisation is under a legal duty to process or disclose the information, legal obligation may instead be the more appropriate basis.
Recognised legitimate interest may apply where processing is necessary to safeguard a child or an adult who meets the relevant definition of being at risk, although other lawful bases may be more appropriate depending on the organisation and its duties.
If the lawful basis is wrong, the rest of the compliance structure can weaken around it. That can affect transparency, individual rights, retention, records, accountability, and whether the processing is lawful at all. The correct approach is to start with the purpose, identify the basis that genuinely fits, and document the reasoning.
This article is based on current ICO guidance on the seven lawful bases under the UK GDPR and the changes introduced by the Data (Use and Access) Act 2025. It also connects to more detailed TGS guidance on recognised legitimate interests, consent, legitimate interests, transparency, and accountability.
Use the glossary for clear explanations of key GDPR concepts, or download the checklist if you want a practical starting point for reviewing lawful bases, privacy information, data handling, records, and wider accountability across your organisation.
We use cookies and similar technologies to make our website work and to provide optional features such as live chat.
Some cookies are strictly necessary for the website to function. Optional cookies support tools such as live chat and will only be used if you choose to allow them.
We also use privacy-friendly, cookieless website analytics to understand aggregated website usage. This does not use cookies or track you across websites.
You can choose to accept all cookies, reject non-essential cookies, or manage your preferences.