Compliance, Standards and Contracts
Lawful Basis for Processing Personal Data: Six Bases Explained
Before your business touches a single piece of personal information, UK GDPR asks one question: why are you allowed to? Picking a lawful basis for processing data is not paperwork you can skip. Article 6 of the UK GDPR says every use of personal data must rest on one of a small set of legal grounds, and if none of them fits, the processing is simply unlawful. This guide explains the six bases in plain terms, when each one applies, and the new seventh basis added in 2026.
For a small business the stakes are practical, not abstract. Get the basis right and you can point to it if the Information Commissioner’s Office (ICO) or a customer ever asks. Get it wrong, most often by leaning on consent when a different basis fits better, and you create work and risk for yourself later.
What “processing” actually means
Processing is deliberately broad. It covers collecting, storing, using, sharing, altering and deleting personal data, whether on a computer or in a structured paper file. If you hold a customer list, run payroll, keep CCTV, or email marketing to a mailing list, you are processing personal data and you need a lawful basis for each purpose.
Two points that trip people up:
- One basis per purpose, not per business. The basis you rely on to process a staff member’s data for payroll is different from the one you use to email them company news. Map each distinct purpose to its own basis.
- You should decide the basis before you start, and you cannot casually swap to a different one later just because the first became inconvenient.
The six lawful bases under Article 6
Article 6(1) of the UK GDPR sets out six lawful bases. No single one is “better” than the others. The right choice depends on your relationship with the person and why you need their data.
1. Consent
The person has given clear, specific, freely given permission for a particular use. Consent must be a positive opt-in (no pre-ticked boxes), and the person must be able to withdraw it as easily as they gave it. Because it can be taken back at any time, consent is often the weakest basis for ongoing processing. Reserve it for things like optional marketing where the person genuinely has a free choice.
2. Contract
Processing is necessary to deliver a contract the person is party to, or to take steps they asked for before entering one. Taking a delivery address to fulfil an order, or setting up an account someone signed up for, sits here. “Necessary” is the key word: it must be genuinely needed to perform the contract, not merely useful.
3. Legal obligation
Processing is necessary to comply with the law (not counting contractual obligations). Keeping payroll records for HMRC, or retaining certain financial data for the statutory period, falls under this. You should be able to point to the specific legal requirement.
4. Vital interests
Processing is necessary to protect someone’s life. This is a narrow, emergency basis, for example passing a collapsed customer’s medical details to paramedics. Most businesses rarely rely on it.
5. Public task
Processing is necessary to perform a task in the public interest or under official authority set out in law. This is mainly for public authorities and bodies exercising official functions, so most private companies will not use it.
6. Legitimate interests
Processing is necessary for your own (or a third party’s) legitimate interests, provided those interests are not overridden by the individual’s rights and freedoms. This is the most flexible basis and often the most appropriate for common business activities such as fraud prevention, network security, or contacting existing customers about similar products. It comes with a catch: you must carry out and record a three-part legitimate interests assessment (identify the interest, show the processing is necessary, and balance it against the person’s rights).
The ICO’s guide to lawful basis walks through each of these in full and offers an interactive tool to help you choose.
The new seventh basis: recognised legitimate interest (2026)
There is now a further option. The Data (Use and Access) Act 2025 inserted a seventh lawful basis, recognised legitimate interest, which came into force on 5 February 2026, with ICO guidance published in March 2026.
It is deliberately narrow. It applies only to a closed list of public-interest purposes set out in Annex 1 of the UK GDPR, such as safeguarding, crime prevention, and responding to emergencies. Its one practical advantage over ordinary legitimate interests is that you do not need to complete the balancing test, because Parliament has already decided the balance is appropriate. You must still tell people you are relying on it and name the specific condition. For most everyday commercial processing, the original six bases (especially legitimate interests) remain the ones you will use. The ICO covers the detail on its recognised legitimate interest page.
Special category data needs more
If you handle sensitive information (health, ethnicity, religion, sexual orientation, biometric or genetic data, political or trade union membership), an Article 6 basis alone is not enough. You also need a separate Article 9 condition on top. Our guide to the eight principles of data protection sets out the wider rules that apply once you have chosen a basis.
How to get this right in practice
- List your processing purposes. Payroll, marketing, order fulfilment, CCTV, and so on, each as a separate line.
- Assign one basis to each. Ask what your real relationship with the person is: did they consent, is it a contract, does the law require it, or is it a legitimate interest?
- Document it. Record your choices in your record of processing activities, and write a legitimate interests assessment for anything relying on basis six.
- Reflect it in your privacy notice. People have the right to know which basis you rely on for each purpose.
Choosing carefully now saves you from unpicking the wrong basis later. If a customer withdraws marketing consent, you should not lose the right to keep their order records, because those two purposes should never have shared one basis in the first place.
Frequently asked questions
What is a lawful basis for processing data? It is the legal ground under Article 6 of the UK GDPR that permits you to use personal data. There are six core bases (consent, contract, legal obligation, vital interests, public task and legitimate interests), plus a narrow seventh, recognised legitimate interest, added in 2026. Every processing purpose must rely on at least one.
Do I need a lawful basis for every use of personal data? Yes. Each distinct purpose needs its own lawful basis. The basis you use for payroll differs from the one you use for marketing, even though it is the same person’s data.
Is consent always the safest lawful basis? No. Consent can be withdrawn at any time and must be freely given, which makes it fragile for ongoing processing. For many business activities, contract, legal obligation or legitimate interests is a stronger and more appropriate choice.
What is the difference between legitimate interests and recognised legitimate interest? Ordinary legitimate interests (basis six) can cover a wide range of purposes but requires you to complete and record a balancing test. Recognised legitimate interest applies only to a fixed list of public-interest purposes in Annex 1 and skips the balancing test, because the law has already decided it is justified.
What happens if I process data without a lawful basis? The processing is unlawful, breaching a core principle of the UK GDPR. This can lead to complaints, ICO enforcement action, and potential fines, as well as claims for compensation from affected individuals.
Can I change the lawful basis after I start processing? You should decide the basis before processing begins and not switch without good reason. If circumstances genuinely change, you must have a valid new basis, tell the individuals affected, and update your records and privacy notice.