Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Why do privacy laws require both a lawful…
Governance, Ownership & Risk

Why do privacy laws require both a lawful basis and reasonable security controls for personal data processing?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 24, 2026 Domain: Governance, Ownership & Risk

A lawful basis limits when data may be collected or used, while security controls limit how exposed that data becomes once processed. GDPR requires a legal basis and explicit consent in many cases, and both GDPR and CCPA expect reasonable safeguards such as encryption, access controls, and training. Without both, organisations create compliance risk and increase breach impact.

Why lawful basis and security controls are both required

A lawful basis answers the question of whether processing is permitted at all. Security controls answer the separate question of how that permitted processing is protected once personal data exists in a system. Privacy laws require both because lawful collection without safeguards still exposes people, and strong safeguards without a lawful basis still leave the processing itself unlawful.

That separation is important in practice. A company can have a legitimate business purpose, but if it stores the data poorly, over-shares it, or leaves it accessible to too many staff, the legal basis does not reduce the resulting exposure. Conversely, encryption or access control does not cure a collection practice that has no lawful basis or does not meet notice and consent requirements.

The same logic appears in GDPR and related privacy regimes, which expect organisations to justify processing and to protect data appropriately. For the GDPR text itself, the clearest points of reference are the principles and security obligations in EU General Data Protection Regulation (GDPR). For control design, NIST SP 800-53 Rev 5 Security and Privacy Controls maps the kinds of safeguards that make that protection concrete.

How the two duties work together across the data lifecycle

Lawful basis governs the front end of processing: why the data is collected, what purpose it serves, and whether the organisation can continue to use it for that purpose. Security controls govern the whole lifecycle: how the data is stored, transmitted, accessed, backed up, retained, and eventually deleted. The two duties therefore complement each other rather than overlap.

That lifecycle view matters because privacy risk is not limited to the moment of collection. Data that is lawful to process can still become high-risk if it is copied into analytics systems, exported to vendors, retained beyond need, or exposed through weak access control. Good privacy practice therefore treats minimisation, retention, and protection as linked decisions instead of separate compliance checkboxes.

For practitioners, the most useful mental model is simple: lawful basis sets the permission boundary, while security controls set the exposure boundary. If either boundary is missing, the organisation has an avoidable failure mode. You can see the same control logic reflected in NIST Privacy Framework and in implementation-oriented control sets such as CIS Controls v8.

Why privacy laws treat permission and protection as separate obligations

Privacy law is not trying to choose between business utility and data protection. It is trying to ensure that organisations only process personal data when they have a valid reason to do so, and then reduce the harm if that data is misused, leaked, or compromised. That is why the legal basis requirement and the security requirement sit beside each other in the compliance model.

This separation also supports accountability. If an organisation can point to a lawful basis but has no reasonable safeguards, it may still face breach notification duties, regulatory scrutiny, and greater harm to individuals. If it has security controls but no lawful basis, the processing can still be unlawful even if no incident occurs. Privacy compliance therefore depends on both prevention of unlawful use and reduction of likely impact.

In governance terms, this is why mature programs align privacy review with control assurance rather than treating them as separate teams. ISO/IEC 27001:2022 Information Security Management is useful here because it reinforces the discipline of defined controls, ownership, and review around information protection.

Risk and Threat Considerations

When either element is missing, the failure is not just technical. Unlawful processing creates regulatory exposure even if the data is never leaked, while weak security turns otherwise lawful processing into a breach-prone repository of personal data. The combined risk is especially serious when the dataset is sensitive, widely shared, or kept for longer than the original purpose requires.

Failure mechanism: The organisation either processes personal data without a valid legal basis, or it stores and shares validly collected data without adequate safeguards, allowing unauthorised access, disclosure, or misuse.

Impact: The result can be enforcement action, mandatory remediation, loss of trust, and materially greater harm to individuals if the data is exposed or repurposed beyond what privacy law permits.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
GDPRArt. 6 — Lawfulness of ProcessingThe question is about why processing needs a lawful basis.
Art. 32 — Security of ProcessingThe question also asks why reasonable security controls are required.
Recommendation — Document a valid legal basis before collecting or using personal data. Apply appropriate technical and organisational measures to protect personal data.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementPersonal data protection commonly depends on controlling access to systems that process it.
AC-6 — Least PrivilegeReasonable safeguards include limiting who can access personal data.
Recommendation — Rotate and govern authenticators that protect access to personal-data systems. Restrict personal-data access to the minimum necessary privileges.
ISO/IEC 27001:2022A.5.15 — Access controlPrivacy security controls rely on explicit access-control governance.
Recommendation — Define and enforce access rules for personal data processing.

Practitioner Guidance

What to verify: Confirm that every processing activity has both a documented lawful basis and a control set that matches the sensitivity, volume, and use of the data. If the basis changes, or the data starts flowing to new systems or vendors, reassess both the legal and security posture rather than treating the original approval as permanent.

Common mistake: Teams often over-focus on notice or consent and under-specify protection. That is a weak control pattern because it assumes legality alone is enough, when the real test is whether the organisation can justify the processing and defend the data against exposure.

Practitioner takeaway: The strongest privacy posture is built by pairing a valid reason to process with controls that keep the data aligned to that reason throughout its lifecycle.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 24, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org