Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› How should organisations determine the lawful basis before…
Governance, Ownership & Risk

How should organisations determine the lawful basis before collecting personal data for processing activities?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 29, 2026 Domain: Governance, Ownership & Risk

Organisations should map each collection or processing purpose to one lawful basis before they begin using the data. GDPR does not require consent in every case, but it does require a valid legal ground that matches the activity. Teams should document the basis, check it against the purpose, and make sure the chosen basis can be defended if regulators review the processing.

How to determine the lawful basis before collection

The lawful basis decision comes first because it shapes what you may collect, why you may collect it, and how you must explain the processing. The practical test is simple: define the exact purpose, identify the minimum data needed, and choose the basis that fits that purpose rather than forcing every activity into consent.

For example, a payroll record, a customer account, and a marketing newsletter can involve different bases even when they use the same personal data set. Organisations should avoid mixing purposes inside one collection step, because the legal basis has to match the specific processing activity, not the broad business relationship.

What a defensible lawful basis assessment should cover

A defensible assessment starts with purpose limitation. Document the processing purpose in business terms, then translate it into the legal basis that best fits the actual relationship between the organisation and the data subject. That means deciding whether the processing is needed for a contract, a legal obligation, legitimate interests, vital interests, public task, or consent.

The chosen basis should also be stable enough for the lifecycle of the processing. If the activity depends on consent, the organisation must be able to withdraw that consent without breaking unrelated processing. If the activity depends on legitimate interests, the balancing assessment should show why the organisation’s need is not overridden by the individual’s rights and expectations.

Where the processing is more sensitive, the assessment should be tighter. GDPR expects the legal ground to align with the activity, and it also ties that decision to broader principles such as fairness, minimisation, and accountability. That is why the basis should be recorded before collection begins, not reconstructed after the fact.

How to operationalise the decision across systems and records

The lawful basis should be part of the intake and design process, not a legal afterthought. Collection forms, onboarding flows, APIs, and internal workflows should each carry the approved purpose and basis so teams do not silently repurpose data later. If the same dataset supports multiple activities, each activity needs its own basis and its own record of why it applies.

That record should be easy to audit. Teams should be able to show the purpose, the selected basis, the rationale, any notices presented to the individual, and any restrictions on reuse. The operational goal is consistency: the privacy notice, the data map, and the retention rules should all point to the same legal story.

For organisations handling identity or account data, NHIMG’s Identity Data Privacy and Consent Guide is a useful companion because it shows how consent, minimisation, and retention decisions affect lawful collection and downstream use.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPREU General Data Protection RegulationLawful basis selection is a core GDPR requirement for processing personal data.
Recommendation — Map each purpose to a valid Article 6 basis before collection and keep the rationale documented.
ISO/IEC 27001:2022A.5.34 — Privacy and protection of PIILawful-basis decisions are part of governing personal data handling and accountability.
Recommendation — Define privacy governance so collection, notice, and retention align with a documented legal basis.
NIST SP 800-53 Rev 5AR-2 — Privacy Impact and Risk AssessmentSelecting a lawful basis requires evaluating privacy impact before processing starts.
AP-1 — Authority to Process Personally Identifiable InformationProcessing personal data needs an approved authority and clear purpose, not ad hoc collection.
AU-2 — Audit EventsDocumenting the chosen lawful basis creates traceability for later review and challenge.
Recommendation — Perform a privacy assessment before collection to confirm the legal ground fits the processing purpose. Authorize each personal-data collection purpose explicitly and tie it to the right legal authority. Log the lawful basis decision and keep evidence that supports it for audit and review.

Practitioner Guidance

What to verify: Confirm that every collection purpose has one documented lawful basis before any personal data is gathered. If the team cannot explain why that basis fits the purpose in plain language, the decision is not ready for production use.

Decision rule: If the processing can be delivered without relying on the individual’s permission, do not default to consent just because it is familiar. Choose the basis that best matches the actual legal and operational relationship, then make the notice and records match that choice.

What practitioners underestimate: The hardest failures usually come from purpose drift, not from the initial choice. A basis that was defensible at collection can become weak if the data is later reused for a different objective without a fresh assessment.

Practitioner takeaway: The lawful basis is a design decision, not a paperwork exercise, and the organisation’s strongest position is the one it can explain, document, and keep consistent as the processing evolves.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 29, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org