Join our Newsletter — 33% off our NHI Course

Article 6 Of GDPR

Article 6 is the GDPR provision that sets out the lawful grounds for processing personal data. It is the core legal test for whether collection or use is permitted. If no valid basis applies, the processing is unlawful even if the data is useful or operationally convenient.

What Article 6 Does in GDPR

Article 6 is the legal gate that decides whether personal data processing has a lawful basis. It sits upstream of most GDPR analysis: if the organisation cannot point to a valid basis, the processing is unlawful even if the use case is useful, efficient, or common.

That makes Article 6 less about a single control and more about legal authority for processing. It is the provision that connects an operational activity, such as onboarding, fraud prevention, HR administration, or service delivery, to a recognised lawful ground.

For privacy and identity programmes, this matters because lawful basis is not the same as permission, notice, or contractual language. A system can have user expectations, internal approval, or business need and still fail Article 6 if the chosen basis does not fit the actual processing purpose.

The Six Lawful Bases in Practice

Article 6 provides six lawful bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. The right basis depends on the exact purpose of processing, the controller’s role, and the surrounding legal context.

  • Consent is appropriate only when it is freely given, specific, informed, and withdrawable.
  • Contract covers processing necessary to perform or prepare a contract with the data subject.
  • Legal obligation applies when another law requires the processing.
  • Vital interests is narrow and used for urgent protection of life or physical safety.
  • Public task applies to official authority or public-interest functions.
  • Legitimate interests requires a real organisational interest that is not overridden by the individual’s rights and freedoms.

In practice, the basis should be chosen for the specific activity, not selected once and reused everywhere. Article 6 is often where organisations discover that a single programme may need different lawful bases for different processing steps, such as service delivery, fraud monitoring, and retention.

Why Article 6 Is the Core Legality Test

Article 6 is the first checkpoint in GDPR compliance because it decides whether processing has a lawful foundation at all. If no basis applies, later safeguards such as minimisation, retention limits, or access controls do not make the processing lawful on their own.

This is why Article 6 is often read alongside other GDPR duties. The GDPR itself ties lawful basis to core principles, and Article 6 works in tandem with transparency, purpose limitation, and storage limitation. In other words, lawful basis answers “may we process this data?”, while the rest of GDPR answers “how must we do it?”.

For practitioners, the practical consequence is that business convenience is not a fallback basis. Teams need a defensible legal theory for each processing purpose, especially where the same dataset supports multiple operational uses.

How Article 6 Shapes Governance and Control Decisions

Article 6 forces organisations to document why each processing activity exists and who approved that reasoning. That makes it a governance requirement, not just a legal citation, because the lawful basis should be traceable across policies, notices, records of processing, and change management.

It also affects control design. If a use case depends on legitimate interests, the organisation needs to show balancing of interests and constrain processing accordingly. If it depends on consent, the system must support withdrawal without breaking unrelated services. If it depends on contract, the processing scope should stay tightly aligned to what is actually necessary.

When identity security control mapping is being built, Article 6 is the legal layer that explains why access to personal data exists in the first place. Identity data privacy and consent guidance becomes especially relevant where consent, retention, and delegated access interact with personal data handling.

Risk and Threat Considerations

Article 6 failures create legal and operational exposure because unlawful processing can invalidate an otherwise sound security design, trigger remediation work, and undermine trust in the data programme. A common risk is basis drift, where a team starts with one lawful basis but later expands use beyond what that basis can support.

Failure mechanism: The organisation either selects the wrong basis, applies one basis to multiple purposes without review, or cannot evidence why the chosen basis fits the actual processing.

Impact: Processing may become unlawful, notices and records may be inaccurate, downstream sharing or retention may need to stop, and supervisory or contractual scrutiny may increase.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

Framework Control / Reference Relevance
GDPR Article 6 — Lawfulness of Processing Defines the lawful bases that make personal data processing permissible under GDPR.
Recommendation — Map each processing purpose to a valid lawful basis and stop processing that lacks one.
ISO/IEC 27001:2022 A.5.34 — Privacy and protection of PII Supports governance of personal data handling where lawful processing decisions must be controlled.
Recommendation — Document lawful basis decisions within your privacy and PII governance records.
NIST SP 800-53 Rev 5 AR-1 — Governance and Privacy Program Covers privacy governance processes that require authorized, documented personal-data processing decisions.
AP-1 — Privacy Program Plan Establishes the program structure used to manage lawful processing obligations and accountability.
PM-25 — Privacy Impact Assessments Supports assessing whether processing purposes have a lawful basis and proportional privacy impact.
Recommendation — Require documented approval for each personal-data processing purpose before collection or use. Include lawful-basis management in the privacy program plan and review process. Perform privacy impact assessments when processing changes could alter the lawful basis.

Practitioner Guidance

Governance implication: Treat Article 6 as a live control point, not a one-time legal checkbox. The lawful basis should be recorded at the processing-purpose level, reviewed when the use case changes, and kept consistent with notices, contracts, and retention rules.

What to watch for: The strongest warning sign is a programme that cannot explain why it needs the data, which basis supports each purpose, and whether the basis still fits after scope changes. That usually indicates the legal reasoning is lagging behind the operational reality.

Practitioner takeaway: If the team cannot defend the basis in plain language, the processing design is probably ahead of the governance model.