Lawful basis for processing personal data in practice

Latest Comments

No comments to show.
SME decision-maker and cybersecurity consultant reviewing a digital data governance dashboard with subtle compliance and record-keeping visuals

Key takeaways

  • Start with the business purpose, then choose the lawful basis that genuinely fits that purpose.
  • Do not use consent by default, because it is only suitable when people can freely agree and later withdraw.
  • Document each lawful basis decision in a simple register and review it when the activity changes.
  • Special category data needs extra care, so check whether you need both a lawful basis and an additional condition.

What lawful basis means in plain English

If your business handles personal data, you need a clear reason for doing so. That reason is called a lawful basis. In practice, it is the foundation that lets you collect, use, store, and share personal data for a specific purpose.

For many SMEs, this is not just a paperwork issue. If you choose the wrong basis, you can create avoidable risk. That can lead to poor customer trust, extra admin, delays to projects, and more work if someone later asks why you collected their data in the first place.

Think of lawful basis as the business justification for the activity. It should match what you are actually doing, not what feels easiest to write down.

Why you need a lawful basis before you process personal data

You should know your lawful basis before you start a processing activity, not after. That applies whether you are collecting customer contact details, storing employee records, running payroll, sending marketing emails, or using CCTV.

The key point is simple: you should not process personal data just because it might be useful. You need a reason that fits the purpose and the context.

How this differs from consent, privacy notices, and internal policy

These things are related, but they are not the same.

  • Lawful basis is the legal reason you are allowed to process the data.
  • Consent is only one possible lawful basis, and it is not suitable for every situation.
  • A privacy notice tells people what you do with their data.
  • Internal policy tells your staff how to handle data inside the business.

A privacy notice does not give you permission to process data. A policy does not replace a lawful basis. And consent is not a shortcut for avoiding a proper decision.

The six lawful bases and when SMEs typically use them

There are six lawful bases. You only need to use the one, or ones, that genuinely fit the activity. For many SMEs, the most common are contract, legal obligation, and legitimate interests.

Consent, contract, legal obligation, vital interests, public task, and legitimate interests

  • Consent means the person has clearly agreed to the processing.
  • Contract means the processing is needed to enter into or perform a contract with the person.
  • Legal obligation means you must process the data to comply with the law.
  • Vital interests means the processing is needed to protect someone’s life.
  • Public task applies where you are carrying out a task in the public interest or under official authority.
  • Legitimate interests means your business has a real and proper reason to process the data, and that reason is not overridden by the person’s rights and interests.

Simple business examples for each lawful basis

  • Consent: a customer signs up to receive optional marketing emails.
  • Contract: you use a delivery address to send goods a customer has ordered.
  • Legal obligation: you keep payroll records for tax and employment purposes.
  • Vital interests: a workplace emergency where you share medical information to protect someone’s life.
  • Public task: usually not relevant to most SMEs, but may apply to some organisations delivering public services.
  • Legitimate interests: you monitor your website for fraud, protect your systems, or contact existing customers about similar services where the balance is fair.

If you are unsure how a processing activity fits into your wider data protection approach, it can help to review it alongside your overall controls. Our guide to GDPR principles explained for SMEs is a useful companion piece, because lawful basis works best when it sits within a broader, sensible approach to data handling.

How to choose the right lawful basis for a specific activity

Start with the purpose, not the label. Ask what you are trying to achieve, who the data relates to, and whether the activity is necessary. Then choose the lawful basis that best matches that purpose.

Start with the purpose of the processing

For example, if you need to process a customer’s address to deliver an order, contract is usually the natural fit. If you need to keep employee records because the law requires it, legal obligation is likely the right basis. If you want to send marketing to existing customers, legitimate interests or consent may be possible depending on the exact circumstances, but you should not assume consent is always safest.

Ask yourself three practical questions:

  • Why are we processing this data?
  • Would the activity still make sense if we removed the data?
  • Is there a better lawful basis than the one we first thought of?

What to do when more than one lawful basis seems possible

Sometimes more than one basis could apply. That is normal. The important thing is to choose the one that best reflects the real purpose and document why.

Do not pick several bases just to cover every possibility. That can create confusion later, especially if the activity changes. It is better to be specific and consistent.

If the purpose changes, review the lawful basis again. A basis that was correct for one activity may not be right for another.

Consent is often overused because it feels straightforward. In reality, it can be one of the hardest bases to manage well. If you use consent, you must be able to show that it was freely given, specific, informed, and unambiguous.

What valid consent needs to look like

Good consent is clear and active. People should understand what they are agreeing to, and they should be able to say no without being penalised.

For consent to work properly, it should usually be:

  • Separate from other terms and conditions.
  • Easy to understand in plain language.
  • Easy to withdraw later.
  • Linked to a specific purpose.

If someone must agree in order to receive a service that does not actually need that data, the consent may not be valid. That creates risk, because the business may think it has permission when it does not.

Common situations where consent is the wrong choice

Consent is often the wrong choice where the processing is needed to deliver a service, meet a legal requirement, or run the business in a normal way. For example, you do not usually need consent to process payroll, fulfil an order, or keep basic customer records for contract management.

It is also a poor fit where there is an imbalance of power, such as some employment situations. In those cases, people may not feel free to refuse.

As a rule, do not use consent just because it seems safer. Use it only when it genuinely fits the activity and you can manage it properly.

Using legitimate interests safely

For many SMEs, legitimate interests is one of the most useful lawful bases. It can support sensible business activities such as fraud prevention, network security, internal administration, and some forms of direct marketing. But it is not a blank cheque.

When legitimate interests can work for an SME

Legitimate interests can work where your business has a real need, the processing is necessary, and the impact on the individual is limited or can be managed. It is often a good fit for activities that help you run the business securely and efficiently.

Examples may include:

  • Detecting suspicious account activity.
  • Keeping records to manage customer relationships.
  • Protecting staff, premises, and systems.
  • Using limited data for internal reporting and service improvement.

If you are also thinking about whether a more formal assessment is needed for a higher-risk activity, our article on data protection impact assessments explained for UK SMEs may help. A lawful basis decision and a risk assessment are different things, but they often inform each other.

What a simple balancing check should cover

Before relying on legitimate interests, carry out a simple balancing check. You do not need a long report for every activity, but you should be able to explain your thinking.

Cover these points:

  • What is the business interest?
  • Why is the processing necessary?
  • What data is involved?
  • What is the likely impact on the person?
  • What safeguards reduce that impact?
  • Would the person reasonably expect this processing?

If the activity feels intrusive, unexpected, or hard to justify, legitimate interests may not be the right basis.

Special category data and extra care

Some personal data needs extra care because it is more sensitive. This includes information about health, race, religion, political views, trade union membership, sex life, sexual orientation, and biometric or genetic data in certain circumstances.

What special category data is

Special category data is not just another type of personal data. It can create greater harm if mishandled, so you should be more cautious about whether you really need it, who can see it, and how long you keep it.

Why you may need both a lawful basis and an additional condition

For special category data, a lawful basis alone is not enough. You usually also need an additional condition that allows you to process that type of data.

That means you should not stop at asking, “What is our lawful basis?” You should also ask, “Do we have a separate reason that covers the sensitive nature of the data?”

In practice, this is where many SMEs need to slow down and check the detail. If you are processing health information for employee absence management, for example, the business purpose may be straightforward, but the sensitivity of the data means you need to be more careful about access, retention, and justification.

Documenting your decision

Good documentation makes decisions easier to defend internally and easier to review later. It also stops the business from relying on memory, which is where many data protection problems start.

What to record in a lawful basis register

A simple lawful basis register does not need to be complicated. For each processing activity, record:

  • The purpose of the processing.
  • The type of personal data involved.
  • The lawful basis chosen.
  • Why that basis was selected.
  • Whether special category data is involved.
  • Any key safeguards or restrictions.
  • Who owns the activity and reviews it.

This can sit alongside your wider records of processing. The point is to make the decision visible and easy to revisit.

How to keep the record practical and easy to maintain

Keep it short enough that people will actually use it. A long, theoretical document is less useful than a concise record that is updated when the business changes.

Review the record when you launch a new service, change a supplier, start a new marketing campaign, introduce a new system, or begin collecting a new type of data. If the activity changes, the lawful basis may need to change too.

That same discipline helps with wider data handling decisions, including retention and disposal. If you are improving your overall data lifecycle controls, our guide to secure decommissioning and data destruction practices for UK SMEs can support the practical side of keeping data only as long as needed.

Common mistakes SMEs make

Most lawful basis mistakes are not caused by bad intent. They usually happen because the business is moving quickly and the data decision was not given enough attention.

Using consent because it feels safest

This is one of the most common errors. Consent feels familiar, but it is not always the safest option. If the business later cannot prove that consent was valid, it may have to stop the activity or rework the process.

In many cases, contract or legitimate interests is a better fit and is easier to manage over time.

Changing lawful basis later without reviewing the original purpose

Another common issue is changing the lawful basis after the fact because the original choice no longer seems convenient. That is risky if the purpose has not been reviewed properly.

If the purpose has changed, document the new purpose and reassess the basis. If the purpose has not changed, think carefully before switching just to make the paperwork easier.

A simple checklist for reviewing your processing activities

Use this checklist whenever you start a new activity or change an existing one.

Questions to ask before starting a new activity

  • What is the business purpose?
  • Do we really need this data?
  • Which lawful basis best fits the purpose?
  • Would the person reasonably expect this processing?
  • Are we handling any special category data?
  • Do we need extra safeguards or a more detailed review?
  • Have we recorded the decision clearly?

Questions to revisit when the purpose or data changes

  • Has the purpose changed?
  • Are we collecting more data than before?
  • Have we added a new supplier or system?
  • Would the original lawful basis still make sense?
  • Do staff know what has changed?
  • Does the privacy notice still match reality?

If you want to strengthen the wider control environment around these decisions, it can help to look at the operational side as well as the legal basis. Our article on technical and organisational measures under GDPR is useful for turning policy into day-to-day practice.

Bringing it together

For SMEs, the best approach is usually simple: define the purpose, choose the lawful basis that genuinely fits, record the decision, and review it when the activity changes. That keeps the business practical, reduces confusion, and makes it easier to explain your approach to staff, customers, and suppliers.

If you are not sure whether a particular processing activity is set up in the right way, or if you want help reviewing your records and decision-making, a short conversation can save time later. Speak to a consultant if you would like pragmatic support tailored to your business.

Frequently asked questions

What are the six lawful bases for processing personal data?

The six lawful bases are consent, contract, legal obligation, vital interests, public task, and legitimate interests.

What is considered a legal basis for processing personal data?

A legal basis is the reason your organisation is allowed to process personal data for a specific purpose. The right basis depends on what you are doing, such as fulfilling a contract, meeting a legal duty, or relying on legitimate interests.

What is an example of lawful processing of personal data?

Using a customer’s address to deliver goods they ordered is a common example of lawful processing, because the data is needed to perform the contract.

Tags:

Comments are closed