Get Demo
↑

GDPR Lawful Basis for Processing (Article 6): The Six Bases

Article 6(1)(a–f) sets six lawful bases — consent, contract, legal obligation, vital interests, public task.

Published: September 2026 Compliance · GDPR 8–12 min read

Every processing activity needs at least one lawful basis under Article 6(1)(a–f). Consent is only one of six options. Getting the basis wrong — or failing to document it — is a classic enforcement theme.

Related: GDPR hub · Principles · Privacy notice · CSA.

Locked count: Six lawful bases in Article 6(1)(a–f). Special-category data (Art 9) and criminal-offence data (Art 10) need additional conditions beyond Article 6.

The Six Bases (Article 6(1))

Basis
When it typically fits
Watch-outs
(a) Consent
Optional marketing, cookies beyond necessity
Must be freely given, specific, informed, unambiguous; easy withdrawal
(b) Contract
Delivering a paid SaaS service the user requested
Only what is necessary for the contract
(c) Legal obligation
Tax, employment, AML retention
Cite the specific legal duty
(d) Vital interests
Life-or-death emergencies
Rare in ordinary B2B processing
(e) Public task
Public authorities / official authority
Usually not for private SaaS vendors
(f) Legitimate interests
Security logging, fraud prevention, some B2B analytics
Document LIA; respect Art 21 objection rights

Legitimate Interests in Practice

Security monitoring and SIEM retention often rely on legitimate interests when carefully scoped — see GDPR and SIEM logs. Always balance necessity against data-subject impact and keep the Legitimate Interests Assessment (LIA) with your RoPA.

How CyberSilo Helps

Document Every Basis Before You Scale Processing

Map products and vendors to Article 6(1)(a–f) so privacy notices and RoPA rows stay consistent.

Frequently Asked Questions

How many lawful bases does GDPR have?

Six under Article 6(1)(a–f): consent, contract, legal obligation, vital interests, public task, and legitimate interests.

Is consent always required?

No. Consent is one basis. Contract and legitimate interests are common for SaaS and security processing when conditions are met.

What is a Legitimate Interests Assessment?

A documented three-part test (purpose, necessity, balancing) used when relying on Article 6(1)(f).

GDPR hub · Principles · Consent & cookies · RoPA · CSA

📰 More from CyberSilo

Latest Articles

Stay ahead of evolving cyber threats with our expert insights

✅ Link copied!