Organisations should map each collection or processing purpose to one lawful basis before they begin using the data. GDPR does not require consent in every case, but it does require a valid legal ground that matches the activity. Teams should document the basis, check it against the purpose, and make sure the chosen basis can be defended if regulators review the processing.
How to determine the lawful basis before collection
The lawful basis decision comes first because it shapes what you may collect, why you may collect it, and how you must explain the processing. The practical test is simple: define the exact purpose, identify the minimum data needed, and choose the basis that fits that purpose rather than forcing every activity into consent.
For example, a payroll record, a customer account, and a marketing newsletter can involve different bases even when they use the same personal data set. Organisations should avoid mixing purposes inside one collection step, because the legal basis has to match the specific processing activity, not the broad business relationship.
What a defensible lawful basis assessment should cover
A defensible assessment starts with purpose limitation. Document the processing purpose in business terms, then translate it into the legal basis that best fits the actual relationship between the organisation and the data subject. That means deciding whether the processing is needed for a contract, a legal obligation, legitimate interests, vital interests, public task, or consent.
The chosen basis should also be stable enough for the lifecycle of the processing. If the activity depends on consent, the organisation must be able to withdraw that consent without breaking unrelated processing. If the activity depends on legitimate interests, the balancing assessment should show why the organisation’s need is not overridden by the individual’s rights and expectations.
Where the processing is more sensitive, the assessment should be tighter. GDPR expects the legal ground to align with the activity, and it also ties that decision to broader principles such as fairness, minimisation, and accountability. That is why the basis should be recorded before collection begins, not reconstructed after the fact.
How to operationalise the decision across systems and records
The lawful basis should be part of the intake and design process, not a legal afterthought. Collection forms, onboarding flows, APIs, and internal workflows should each carry the approved purpose and basis so teams do not silently repurpose data later. If the same dataset supports multiple activities, each activity needs its own basis and its own record of why it applies.
That record should be easy to audit. Teams should be able to show the purpose, the selected basis, the rationale, any notices presented to the individual, and any restrictions on reuse. The operational goal is consistency: the privacy notice, the data map, and the retention rules should all point to the same legal story.
For organisations handling identity or account data, NHIMG’s Identity Data Privacy and Consent Guide is a useful companion because it shows how consent, minimisation, and retention decisions affect lawful collection and downstream use.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | EU General Data Protection Regulation | Lawful basis selection is a core GDPR requirement for processing personal data. |
| Recommendation — Map each purpose to a valid Article 6 basis before collection and keep the rationale documented. | ||
| ISO/IEC 27001:2022 | A.5.34 — Privacy and protection of PII | Lawful-basis decisions are part of governing personal data handling and accountability. |
| Recommendation — Define privacy governance so collection, notice, and retention align with a documented legal basis. | ||
| NIST SP 800-53 Rev 5 | AR-2 — Privacy Impact and Risk Assessment | Selecting a lawful basis requires evaluating privacy impact before processing starts. |
| AP-1 — Authority to Process Personally Identifiable Information | Processing personal data needs an approved authority and clear purpose, not ad hoc collection. | |
| AU-2 — Audit Events | Documenting the chosen lawful basis creates traceability for later review and challenge. | |
| Recommendation — Perform a privacy assessment before collection to confirm the legal ground fits the processing purpose. Authorize each personal-data collection purpose explicitly and tie it to the right legal authority. Log the lawful basis decision and keep evidence that supports it for audit and review. | ||
Practitioner Guidance
What to verify: Confirm that every collection purpose has one documented lawful basis before any personal data is gathered. If the team cannot explain why that basis fits the purpose in plain language, the decision is not ready for production use.
Decision rule: If the processing can be delivered without relying on the individual’s permission, do not default to consent just because it is familiar. Choose the basis that best matches the actual legal and operational relationship, then make the notice and records match that choice.
What practitioners underestimate: The hardest failures usually come from purpose drift, not from the initial choice. A basis that was defensible at collection can become weak if the data is later reused for a different objective without a fresh assessment.
Practitioner takeaway: The lawful basis is a design decision, not a paperwork exercise, and the organisation’s strongest position is the one it can explain, document, and keep consistent as the processing evolves.
Related resources from NHI Mgmt Group
- Why do organisations need data protection assessments before launching high-risk processing activities?
- Why do organisations need a clear legal basis before processing personal information?
- What breaks when organisations do not tie personal data to a clear processing basis?
- How should organisations prepare for CTDPA compliance before collecting or processing consumer data?