Skip to content
compliancebase
GDPRChapter II — Lawfulness of processing

Article 6

Lawfulness of processing

GDPR · Regulation (EU) 2016/679 · Last verified July 2026

Objective

Processing shall be lawful only if and to the extent that at least one of the six legal bases in Article 6(1) applies: consent; contract; legal obligation; vital interests; public task; or legitimate interests (subject to the balancing test and exceptions).

Points of focus

  • Identify a lawful basis under Article 6(1)(a)–(f) for each processing purpose
  • Document the basis in privacy notices and records of processing (Article 30)
  • For legitimate interests, perform and retain a balancing / LIA assessment
  • For consent, meet Article 7 conditions (freely given, specific, informed, withdrawable)
  • Do not retrofit a different basis mid-stream without transparency and legality review

Implementation notes

For B2B SaaS under GDPR, treat Article 6 as a product and contract design constraint, not a privacy-policy afterthought. Map each purpose — account administration, service delivery, billing, security monitoring, product analytics, and marketing — to a single primary basis and record it in the RoPA and customer-facing notice. Prefer Article 6(1)(b) contract for core service delivery and 6(1)(f) legitimate interests for necessary security and fraud prevention, with a written LIA. Use consent (6(1)(a)) only where you can offer a genuine choice and honor withdrawal without breaking the contract. Align DPAs so customer-as-controller instructions do not assume you are freely choosing purposes for their end-user data. Revisit bases when you launch new tracking or AI features; unlawful processing cannot be cured by security controls alone.

Audit tip: Pick three processing activities (signup, product telemetry, security logs) and show purpose → Article 6 basis → notice text → RoPA row in one packet.

Evidence auditors typically request:

  • Records of processing activities listing purpose and Article 6 basis per activity
  • Privacy notice / product disclosures naming lawful bases
  • Legitimate interests assessments (LIA) for analytics, security logging, or B2B marketing where used
  • Consent records and withdrawal flows where consent is the basis
  • DPA / customer contract clauses describing controller instructions and purposes

Common gaps

  • Defaulting everything to 'consent' in B2B SaaS where contract or legitimate interests fit better
  • No LIA on file for legitimate-interests processing
  • Privacy notice lists bases that do not match the RoPA
  • Switching bases after the fact when consent is withdrawn without legal analysis

Cross-Framework Mapping

FrameworkRequirementImplementation note
GDPRArticle 6This control
ISO 27001A.5.34Privacy and protection of PII — lawful processing alignment
SOC 2P4.1, CC2.2Privacy criteria / communication of objectives when privacy category in scope
HIPAA164.502, 164.508Uses and disclosures — different legal regime; map carefully for US health data

Primary sources

Frequently Asked Questions

Usually no. Consent must be freely given — problematic when processing is required to deliver the paid service. Contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f)) are more typical for core B2B SaaS operations; reserve consent for optional uses.

A documented balancing test: identify the interest, show necessity, and weigh impacts on data subjects' rights, including mitigations. Keep the LIA with your RoPA; supervisors and customers may ask for it.

The controller determines purposes and means, including the Article 6 basis for their processing. As processor you follow documented instructions (Article 28) and should not invent secondary purposes for customer personal data.

SOC 2 Security alone does not prove lawful basis. If the privacy Trust Services category is in scope, related privacy criteria may touch notice and choice, but GDPR Article 6 remains a legal obligation assessed under data-protection law.

Changing basis is legally sensitive — especially abandoning consent after collection. Update notices, RoPA, and legal analysis first; do not silently swap bases to avoid consent withdrawal.

Framework versions referenced in this page:

  • GDPRRegulation (EU) 2016/679

Last verified: July 2026 · Primary sources linked above