Article 6
Lawfulness of processing
GDPR · Regulation (EU) 2016/679 · Last verified July 2026
Objective
Processing shall be lawful only if and to the extent that at least one of the six legal bases in Article 6(1) applies: consent; contract; legal obligation; vital interests; public task; or legitimate interests (subject to the balancing test and exceptions).
Points of focus
- Identify a lawful basis under Article 6(1)(a)–(f) for each processing purpose
- Document the basis in privacy notices and records of processing (Article 30)
- For legitimate interests, perform and retain a balancing / LIA assessment
- For consent, meet Article 7 conditions (freely given, specific, informed, withdrawable)
- Do not retrofit a different basis mid-stream without transparency and legality review
Implementation notes
For B2B SaaS under GDPR, treat Article 6 as a product and contract design constraint, not a privacy-policy afterthought. Map each purpose — account administration, service delivery, billing, security monitoring, product analytics, and marketing — to a single primary basis and record it in the RoPA and customer-facing notice. Prefer Article 6(1)(b) contract for core service delivery and 6(1)(f) legitimate interests for necessary security and fraud prevention, with a written LIA. Use consent (6(1)(a)) only where you can offer a genuine choice and honor withdrawal without breaking the contract. Align DPAs so customer-as-controller instructions do not assume you are freely choosing purposes for their end-user data. Revisit bases when you launch new tracking or AI features; unlawful processing cannot be cured by security controls alone.
Audit tip: Pick three processing activities (signup, product telemetry, security logs) and show purpose → Article 6 basis → notice text → RoPA row in one packet.
Evidence auditors typically request:
- Records of processing activities listing purpose and Article 6 basis per activity
- Privacy notice / product disclosures naming lawful bases
- Legitimate interests assessments (LIA) for analytics, security logging, or B2B marketing where used
- Consent records and withdrawal flows where consent is the basis
- DPA / customer contract clauses describing controller instructions and purposes
Common gaps
- Defaulting everything to 'consent' in B2B SaaS where contract or legitimate interests fit better
- No LIA on file for legitimate-interests processing
- Privacy notice lists bases that do not match the RoPA
- Switching bases after the fact when consent is withdrawn without legal analysis
Cross-Framework Mapping
| Framework | Requirement | Implementation note |
|---|---|---|
| GDPR | Article 6 | This control |
| ISO 27001 | A.5.34 | Privacy and protection of PII — lawful processing alignment |
| SOC 2 | P4.1, CC2.2 | Privacy criteria / communication of objectives when privacy category in scope |
| HIPAA | 164.502, 164.508 | Uses and disclosures — different legal regime; map carefully for US health data |
Primary sources
- GDPR Article 6: Regulation (EU) 2016/679, Article 6 — Lawfulness of processing