What Is a Lawful Basis? Seven UK GDPR Routes Explained
What is a lawful basis under UK GDPR? Compare all seven routes, avoid treating consent as the default, and record the basis that fits each purpose.

A customer questionnaire asks for the lawful basis behind each use of personal data. The empty field can make the term sound like a code that a privacy specialist supplies. It is a practical decision instead: the organisation identifies why it needs the information, then selects the legal ground that fits that purpose before the processing starts 1,2.
Quick Answer. A lawful basis under UK law is one of seven routes: consent, contract, legal obligation, vital interests, public task, legitimate interests or recognised legitimate interest for five pre-approved public-interest conditions. Choose before processing, document necessity and any balancing, and explain the purpose and basis to people 1,2,6,7.
Seven routes, not seven labels
UK GDPR Article 6, as amended by the Data (Use and Access) Act 2025, provides seven lawful-basis routes: consent, contract, legal obligation, vital interests, public task, legitimate interests and recognised legitimate interest for five pre-approved public-interest conditions. The routes are not seven descriptions for the same idea, and no single basis is the safest answer for every organisation 1,2,6,7.
| Lawful basis | Plain-language test | Ordinary example |
|---|---|---|
| Consent | The person has a genuine choice and gives valid permission for this specific use. | Optional email updates requested through an unticked sign-up box, subject to PECR where relevant 3,5. |
| Contract | The processing is necessary to perform a contract with the person or take requested steps before entering it. | Using a delivery address to send goods that the customer bought 1,2. |
| Legal obligation | UK law requires the organisation to process the information. | Keeping information that a binding legal duty requires, with the duty identified in the record. |
| Vital interests | Processing is necessary to protect someone's life. | Sharing critical information during a genuine life-or-death emergency. |
| Public task | Processing is necessary for an official function or task in the public interest that has a basis in law. | A public body carrying out a statutory function. |
| Legitimate interests | A legitimate purpose requires the processing, and the person's interests and rights do not override it. | Proportionate fraud prevention after a written purpose, necessity and balancing assessment 4. |
| Recognised legitimate interest | Processing is necessary for one of five pre-approved public-interest conditions; no balancing test applies. | A qualifying public-interest use recorded against the relevant recognised condition and necessity test 6,7. |
The table is a starting point, not a menu of convenient wording. “We have an interest in it” does not complete the legitimate-interests test. “Our contract mentions data” does not make every later use necessary for that contract. Each basis has boundaries that must match what actually happens.
Purpose comes before the answer
Start with a sentence that describes the purpose without legal vocabulary. “We use the address to deliver the order” is specific enough to test. “Customer administration” is not: it could hide delivery, marketing, fraud prevention and debt recovery, each of which may need separate analysis.
Necessity is the discipline shared by several bases. The organisation should ask whether it can achieve the stated purpose through a less intrusive, reasonably available method. A useful system does not become necessary merely because the business has already bought it. The ICO advises organisations to determine and document their basis before processing, then tell people the basis and purpose in the privacy information 2.
A single customer platform can support several purposes without having one blanket basis. Delivery details may be necessary for a contract. Proportionate fraud checks may rest on legitimate interests after a balancing assessment. Optional marketing may need a different analysis under UK GDPR and PECR. Split the record by purpose first; attaching every basis to the whole platform as a precaution hides the decision instead of defending it.
Consent and legitimate interests are not synonyms
Consent is not a courtesy word for data collection. It is a basis with demanding conditions: the person needs a real choice, the request must be specific and informed, and a clear positive action must express the decision. Consent can be withdrawn. Once it is withdrawn, future processing that depended on that consent must stop, while the lawfulness of processing completed before withdrawal is unaffected 1,3.
That makes consent unsuitable when the organisation would proceed regardless of the answer. An employer normally cannot describe essential payroll processing as optional consent. A seller cannot ask whether it may use the delivery address, then refuse to fulfil an existing order when the customer says no. Contract or legal obligation may fit those purposes more honestly, depending on the facts 2,3.
Legitimate interests also requires more than preference. The ICO structures the assessment around purpose, necessity and balancing: identify the legitimate purpose, test whether the processing is necessary, then decide whether the person's interests or fundamental rights override the organisation's interest 4. That distinction matters. The written assessment should describe the expected benefit, the people affected, the information used, the likely impact and the safeguards that reduce it.
Recognised legitimate interest is a separate seventh basis, not a shorter version of ordinary legitimate interests. It applies only where processing is necessary for one of five pre-approved public-interest conditions. The balancing test is removed for that narrow route, but necessity remains. It is not an exemption: transparency duties, individual rights and the other data-protection principles continue to apply 6,7.
Ordinary direct marketing does not move automatically into the recognised route. Where standard legitimate interests is appropriate, the organisation still completes the purpose, necessity and balancing test. A UK GDPR lawful basis also does not switch off the Privacy and Electronic Communications Regulations, so the communication channel and audience may still require consent under PECR 4,5,7.
Sensitive data needs another condition
Article 6 is only the first layer when the information receives extra protection. Special-category data, such as health information, needs an Article 6 basis and a separate Article 9 condition. Personal data relating to criminal convictions and offences is governed by Article 10 and the applicable UK safeguards 1,2.
Those additional conditions do not replace the lawful basis. A health provider cannot record an Article 9 condition and leave the Article 6 field empty. Nor does ordinary consent automatically become the explicit consent condition that Article 9 may require. The two questions should appear separately in the processing record.
The basis changes the rights around the processing
The lawful basis can affect which individual rights apply. The right to data portability, for example, is tied to specified processing based on consent or contract, while the right to object has particular relevance to public task and legitimate interests 1,2. This is another reason the basis must reflect reality: the choice shapes how the organisation answers a request later.
A basis does not remove the other UK GDPR principles. Information must still be used fairly, transparently and for defined purposes; kept accurate and no longer than necessary; secured appropriately; and supported by evidence of accountability 1. A technically available basis cannot rescue an excessive collection or a misleading notice.
Turn the basis into a usable record
A small business does not need a legal essay for every activity. It does need enough evidence for another person to understand and repeat the decision. The record should connect the real purpose to the chosen basis, the necessity test and any supporting assessment.
| Record field | What to write | Weak substitute to avoid |
|---|---|---|
| Purpose | The concrete outcome, such as delivering an order | “Business operations” |
| People and data | Whose information is used and which fields matter | “Customer data” |
| Basis | One of the seven lawful-basis routes that fits this purpose | A list of all seven |
| Necessity | Why the purpose cannot reasonably be achieved with less data | “The system requires it” |
| Extra condition | Article 9 condition or Article 10 safeguard where applicable | Leaving the second layer implicit |
| Supporting evidence | Consent record, contract analysis, legal duty or legitimate-interests assessment | A template with no facts |
| Privacy information | Where the purpose and basis are explained to the person | A notice that says only “we comply with GDPR” |
Review the entry when the purpose, data, people, technology or relationship changes. A genuinely new purpose may need a new basis. A later edit cannot turn earlier unlawful processing into lawful processing, so the useful control is a decision made before launch, not a label repaired after a complaint 2.
The immediate task is modest: choose one real processing activity, write its purpose in one sentence and test the seven bases against the facts. If the answer is consent, verify that “no” is genuinely possible. If it is standard legitimate interests, complete the three-part assessment. If recognised legitimate interest may apply, identify the pre-approved condition and prove necessity. If sensitive or criminal-offence data is involved, record the second legal condition separately.
Last updated: 26 August 2026.
Frequently Asked Questions
What is a lawful basis under UK GDPR?
Is consent the safest lawful basis?
Can we choose legitimate interests because it is convenient?
Can one system use more than one lawful basis?
Do special-category data need a lawful basis too?
Can a lawful basis be changed after processing starts?
Sources
- 1.UK GDPR (retained) — legislation.gov.uk · 2026
- 2.A guide to lawful basis — Information Commissioner's Office · 2026
- 3.Consent — Information Commissioner's Office · 2026
- 4.Legitimate interests — Information Commissioner's Office · 2026
- 5.Guide to the Privacy and Electronic Communications Regulations — Information Commissioner's Office · 2026
- 6.Data (Use and Access) Act 2025 — legislation.gov.uk · 2026
- 7.Recognised legitimate interest — Information Commissioner's Office · 2026
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.