Back to the hub

What are the six lawful bases for processing under GDPR Article 6?

Under Article 6, processing personal data is lawful only if at least one of six legal bases applies: consent, performance of a contract, a legal obligation, vital interests, a public-interest task, or legitimate interests. Most SaaS companies rely on contract, consent, or legitimate interests, and must record which basis covers each activity.

Applies to: Any controller processing personal data under the GDPR, which must identify at least one of the six Article 6 lawful bases for each processing activity before it begins.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Under the GDPR you cannot process personal data simply because you hold it or because it would be convenient. Every activity needs a lawful basis, and it has to be one of six named in Article 6. "We needed it to run the business" is not on the list, so the task is to map what you actually do to the grounds the law recognises.

What are the six lawful bases?

Article 6(1) makes processing lawful only if at least one applies. Consent means the person has agreed to a specific purpose. Contract covers processing necessary to perform an agreement with the person, or to take steps at their request before entering one. Legal obligation covers processing you must do to comply with the law. Vital interests covers protecting someone's life. Public task covers official functions carried out in the public interest. Legitimate interests covers processing needed for interests of yours or a third party, unless the person's rights override them. That final basis does not apply to public authorities acting in their tasks.

Which bases do SaaS companies usually rely on?

Three do most of the work. Contract typically underpins the core service: to give a customer the product they signed up for, you have to process their account data. Consent is the usual basis for marketing emails and for non-essential cookies and similar tracking. Legitimate interests often supports security, fraud prevention, some product analytics, and business-to-business outreach, provided a balancing test shows the person's rights do not override the activity. Legal obligation covers narrower duties such as retaining records for tax. One product routinely uses several bases across its different activities.

Do you have to pick one and record it?

Yes. You should identify the basis for each activity before you process, not reach for one after a complaint arrives. Consent carries extra conditions under Article 7: it must be freely given, specific, informed, and as easy to withdraw as to give. Because moving from one basis to another mid-stream is difficult and looks like an afterthought, the basis for each activity belongs in your record of processing activities and, in plain terms, in your privacy notice. Where a vendor processes data for you, your data processing agreement should reflect the purposes you have set. The basis you pick also gates downstream rights: only consent-based or contract-based automated processing triggers the right to data portability.

What happens if you get it wrong?

Processing with no valid basis is unlawful processing, one of the more serious failures under the regulation and a common enforcement theme that sits in the upper tier of GDPR fines. The fix is rarely dramatic: it is usually a matter of writing down, honestly, which of the six grounds covers each activity and confirming that consent-based processing really has valid consent behind it.

Next step

If you already know the GDPR applies to you, lawful basis is the groundwork the rest of your compliance sits on. The free 2-minute Obligation Scan helps you see which activities need which basis and where consent is doing work it cannot support, then links the record-keeping and vendor steps that follow. The GDPR compliance hub sets out the wider duties.

Compliance checklist

  • List each way you process personal data, from delivering your product to marketing and analytics.
  • Match each activity to one of the six Article 6 bases before you begin processing, not afterwards.
  • For consent, meet the higher bar: a clear, specific, freely given opt-in you can evidence and let people withdraw.
  • For legitimate interests, run and record a balancing test against the person's rights and reasonable expectations.
  • Record the basis for each activity in your record of processing and privacy notice, since switching basis later is difficult.

Sources

Last verified: 2026-08-07

Informational, not legal advice.