Skip to main content
Category: Privacy & Data Protection

Lawful Basis

Also known as: Legal Basis for Processing, Lawful Basis for Processing
Simply put

A lawful basis is the legal justification an organization must have before it processes personal data under the EU General Data Protection Regulation (GDPR). The GDPR sets out six available lawful bases, and an organization typically needs to identify at least one that applies to a given processing activity. Which basis is chosen can affect the rights individuals are able to exercise over their data.

Formal definition

Under Article 6(1) of the GDPR, a lawful basis is the legal ground required for the lawful processing of personal data. The evidence identifies six available bases within Article 6(1): consent, contract, legal obligation, vital interests, public task, and (as commonly noted in GDPR practice) legitimate interests, though the sixth basis is not fully enumerated in the provided evidence. A valid lawful basis must be established for a given processing operation, and the basis selected directly affects which data subject rights apply to that processing. This entry addresses the GDPR framework specifically; the term's scope, and the applicability and interpretation of individual bases, may differ under other data protection regimes and is out of scope here.

Why it matters

Under the GDPR, processing personal data without a valid lawful basis is not permitted, which makes the identification of an appropriate basis a foundational compliance step rather than an administrative formality. Organizations that deploy AI systems trained on or operating over personal data typically need to establish which of the GDPR's six lawful bases applies to each processing activity, since the absence of a valid basis can render the processing unlawful under the regulation.

The choice of lawful basis carries consequences beyond initial compliance. As commonly noted in GDPR practice, the basis selected directly affects which data subject rights an individual is able to exercise over their data. For example, the rights available to an individual can differ depending on whether processing relies on consent, contract, legal obligation, or another basis. This means the decision is not interchangeable: selecting one basis over another shapes the downstream obligations an organization owes to the people whose data it processes.

This entry addresses lawful basis specifically within the GDPR framework. The concept, the number of available bases, and their interpretation may differ under other data protection regimes, and those regimes are out of scope here. Practitioners should not assume that a lawful basis analysis performed for GDPR purposes transfers directly to non-EU jurisdictions.

Who it's relevant to

Privacy and Data Protection Officers
DPOs and privacy specialists are typically responsible for determining and documenting which lawful basis applies to each processing activity involving personal data. Because the chosen basis affects the data subject rights that apply, they must map bases to processing operations carefully rather than defaulting to a single justification across the organization.
AI and Data Science Teams
Teams building or operating AI systems that process personal data need to work with privacy functions to confirm a valid lawful basis exists for training, inference, and related processing. Establishing the basis is a prerequisite for lawful processing under the GDPR, and it cannot be treated as an afterthought once a system is in production.
Legal and Compliance Professionals
Legal and compliance staff advise on which of the six Article 6(1) bases is appropriate for a given purpose—for example, identifying where "legal obligation" is the correct basis—and on the downstream rights implications of that choice. They should note that this analysis is scoped to the GDPR and may not carry over to other data protection regimes.
Auditors and Governance Reviewers
Those reviewing an organization's data protection posture assess whether a valid lawful basis has been identified and documented for processing activities. Because the selected basis governs which individual rights apply, auditors examine not only that a basis exists but that it is appropriate to the specific processing operation.

Inside Lawful Basis

Legal ground for processing
The specific justification an organization relies on to make personal data processing lawful. Under the EU General Data Protection Regulation (GDPR), which issues this concept as binding law within its jurisdiction, several lawful bases are commonly recognized, including consent, contract, legal obligation, vital interests, public task, and legitimate interests. The applicable set and terminology may differ in other jurisdictions.
Purpose specification
A lawful basis is typically tied to a defined processing purpose. The basis is generally assessed against the specific purpose for which data is used, so a single dataset may require different bases for different uses. Repurposing data for AI training may not be covered by the basis established for the original collection.
Documentation and accountability
In many data protection frameworks, controllers are expected to identify and record the lawful basis before processing begins and to be able to demonstrate it. This links to broader AI governance obligations around record-keeping and demonstrable accountability, though it is distinct from model risk management, which concerns the measurement and control of risks arising from the model itself.
Balancing and necessity assessment
Certain bases, such as legitimate interests as commonly defined under GDPR, require a necessity and balancing test weighing the organization's interests against the rights and interests of data subjects. The precise requirements are jurisdiction- and basis-specific.
Data subject rights linkage
The chosen lawful basis can affect which rights individuals may exercise (for example, rights relating to erasure, objection, or withdrawal of consent). The relationship between basis and rights varies by framework and by the specific basis selected.

Common questions

Answers to the questions practitioners most commonly ask about Lawful Basis.

Does having a lawful basis for processing personal data mean an AI system is automatically compliant?
No. Establishing a lawful basis addresses only one requirement for processing personal data under data protection regimes such as the EU/UK GDPR. It does not, on its own, satisfy other obligations that may apply, such as transparency, purpose limitation, data minimization, security, data subject rights, or any separate AI-specific governance requirements. A lawful basis is typically necessary but not sufficient, and treating it as a blanket compliance conclusion is a common error.
Is consent always the strongest or preferred lawful basis to rely on?
Not necessarily. In many data protection frameworks, consent is one of several possible lawful bases and is not inherently superior to others such as contract, legal obligation, or legitimate interests. Consent carries its own conditions—typically that it be freely given, specific, informed, and withdrawable—which can make it fragile or impractical for certain processing. The appropriate basis depends on the context and purpose of the processing, and defaulting to consent can be a pitfall where another basis is more suitable and defensible.
How should a team document its selected lawful basis for a given processing activity?
As commonly practiced, the lawful basis is identified and recorded before processing begins, tied to a specific, defined purpose, and captured in records of processing activities or equivalent documentation. Where legitimate interests is relied on, organizations often document a balancing assessment. The documentation should make clear which basis applies to which purpose, since a single system may involve multiple processing activities with different bases. This entry does not prescribe a mandatory template, as requirements vary by jurisdiction and regulator.
Can one lawful basis cover an entire AI system, or should it be assessed per activity?
Lawful basis is typically assessed at the level of a specific processing purpose rather than for a system as a whole. An AI system may involve distinct activities—such as training on historical data, deploying for inference, or retaining outputs—that can call for different bases. Assigning a single basis to a complex system risks obscuring purposes that do not fit that basis. Practitioners commonly map processing activities and evaluate each against candidate bases.
What happens if the purpose of processing changes after a lawful basis was established?
A change in purpose can affect whether the original lawful basis still applies. In many frameworks, further processing must be compatible with the original purpose or supported by an appropriate basis for the new purpose. Where reliance was on consent for a specific purpose, using the data for a materially different purpose may require reassessment. Because compatibility and re-basing rules vary by jurisdiction, teams generally revisit the lawful basis when purposes evolve rather than assuming it carries over.
How does lawful basis interact with an organization's AI governance and model risk processes?
Lawful basis is primarily a data protection concept, but it commonly intersects with AI governance and model risk management where those processes review data used in models. Governance structures may assign accountability for confirming that a valid basis exists before data is used, and model risk processes may treat the absence or fragility of a basis as a risk to be identified and managed. These functions overlap without being interchangeable: satisfying data protection requirements does not replace governance or risk controls, and vice versa.

Common misconceptions

Obtaining consent is always the safest or default lawful basis.
Consent is one of several bases and is not inherently superior. In many frameworks consent must meet strict conditions (such as being freely given, specific, and withdrawable), and it may be inappropriate or impractical for some AI use cases. Another basis, such as legitimate interests or contract, may be more suitable depending on the purpose and jurisdiction.
Having a lawful basis to collect data automatically permits using it to train or operate AI models.
A lawful basis is typically assessed against a specific purpose. Using data collected for one purpose to train an AI system can constitute a new purpose that may require its own basis or a compatibility assessment. This is a common area where practitioners err.
Establishing a lawful basis is purely a legal formality separate from AI governance and risk work.
Identifying and documenting a lawful basis intersects with AI governance obligations such as accountability and record-keeping, though it does not by itself address model risk. It reduces certain legal and compliance risks but does not eliminate them, and it is distinct from model risk management activities.

Best practices

Identify and document the lawful basis for each specific processing purpose before processing begins, rather than applying a single basis across all AI-related uses.
Assess separately whether data collected for an original purpose can lawfully be repurposed for model training or operation, and document that determination.
Where relying on a basis that requires a necessity and balancing assessment, such as legitimate interests as commonly defined, complete and retain that assessment.
Confirm which jurisdiction's rules apply, since lawful basis requirements and terminology differ across frameworks and should not be treated as universal or interchangeable.
Map the chosen lawful basis to the data subject rights it triggers, so downstream processes can support requests such as objection or withdrawal of consent where applicable.
Coordinate lawful basis documentation with broader AI governance records without conflating it with model risk management, treating it as a risk-reducing control rather than one that eliminates legal risk.