Data Protection HubIndividual TopicsPrinciples Relating to Processing

Lawfulness (Article 5(1)(a) GDPR)

Lawfulness as a principle relating to processing: the need for a legal basis, the relationship to Article 6 GDPR, and the requirement that legal bases be clear and precise.

Under Article 5(1)(a) GDPR, personal data must be processed "lawfully". The principle restates the fundamental rights requirement laid down in Article 8(2), first sentence, of the Charter of Fundamental Rights of the European Union (CFR), under which personal data may be processed only with the consent of the data subject or on some other legitimate basis laid down by law.

Key takeaways

  • Lawfulness requires a legal basis for every processing operation; Article 6(1) GDPR sets out an exhaustive catalog to that effect.
  • Where no applicable legal basis exists, the processing is unlawful on that ground alone ("prohibition subject to permission").
  • The concept is to be understood narrowly: lawfulness means the existence of a legal basis, not compliance with all the other requirements of the GDPR.
  • The legal basis must be clear and precise, so that the processing is foreseeable for the data subject (Recital 41, second sentence, GDPR).
  • The more sensitive the data and the more serious the interference, the higher the requirements as to the specificity of the legal basis.

1 Overview

The principle of lawfulness requires that a legal basis exist for every processing operation. Article 6(1) GDPR gives concrete expression to the principle through an exhaustive catalog of possible legal bases. Where no applicable legal basis exists, the processing is unlawful on that ground alone.

The principle corresponds to what German data protection law has traditionally called a "prohibition subject to permission". It does not presuppose compliance with all the further requirements of the GDPR; other aspects of the processing are covered by the remaining principles in Article 5 GDPR (transparency, data minimization, integrity and confidentiality). A breach of those principles does not automatically render the processing "unlawful" within the meaning of Article 5(1)(a), first alternative, GDPR, but it does constitute a breach of a principle in its own right and is subject to administrative fines.

1.2 A narrow understanding of "lawfulness"

Both Article 8(2) CFR and the scheme of Article 5(1) GDPR support a narrow understanding: lawfulness means the existence of a legal basis, not compliance with all the rules of the GDPR. A broad understanding would mean that any infringement (for example of the information obligations or of data security) would render the processing unlawful as a whole. Such a result cannot be reconciled with the fact that each of the individual principles operates on its own terms.

2.1 Clarity and precision

The legal basis on which a processing operation rests must govern the scope and application of the processing so clearly and precisely that the processing is foreseeable for the data subject. That follows from Recital 41, second sentence, GDPR and corresponds to the requirements that the CJEU has consistently applied to interferences with Articles 7 and 8 CFR (CJEU, judgment of 20 May 2003, C-465/00 and Others, Österreichischer Rundfunk, para. 77; CJEU, judgment of 8 April 2014, C-293/12, C-594/12, Digital Rights Ireland, para. 54).

2.2 Foreseeability for the data subject

Foreseeability is assessed from the objective perspective of the data subject as recipient. The data subject must be able to discern from the legal basis which processing operations are to be expected and on what grounds. The more sensitive the data or the more serious the interference, the higher the requirements to be placed on the specificity of the legal basis.

3 Interaction with the other principles

In substance, the principle of lawfulness is closely connected with the principle of transparency: only where the processing is foreseeable for the data subject can she exercise her rights effectively. At the same time, there is a close link with purpose limitation (Article 5(1)(b) GDPR): the legal basis must always support a specific purpose of processing.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn