Data Protection HubIndividual TopicsPrinciples Relating to Processing

Purpose Limitation (Article 5(1)(b) GDPR)

Purpose limitation as a principle of the GDPR: the duty to specify the purpose, the prohibition of incompatible further processing, exceptions for archiving, research and statistical purposes, and the relationship to Article 6(4) GDPR.

Purpose limitation is the "cornerstone of data protection law". It is the reference point for almost all of the other requirements of the GDPR: necessity, information obligations and the legal basis cannot be assessed without a specified purpose.

Key takeaways

  • Purpose limitation has two aspects: specification of the purpose (specified, explicit and legitimate purposes) and the prohibition of incompatible further processing.
  • The purpose must be specified before the processing begins or at the latest when it begins; general labels such as "advertising" or "IT security" are not sufficient.
  • Further processing is permissible only if it is compatible with the context of collection and with the expectations of the data subject (factors: Article 6(4) GDPR).
  • Exceptions to the prohibition of incompatible further processing: consent, statutory authorization and privileged purposes (archiving, research, statistics).
  • An infringement renders the processing unlawful and, as a breach of a basic principle, is subject to administrative fines; it cannot be cured by invoking a new legal basis.

1 Overview

1.1 The two aspects of purpose limitation

Article 5(1)(b), first half-sentence, GDPR breaks the principle down into two aspects:

  • Specification of the purpose: processing may take place only for specified, explicit and legitimate purposes.
  • Prohibition of incompatible further processing: data may not be further processed in a manner that is incompatible with the purpose of collection.

Article 5(1)(b), second half-sentence, GDPR additionally contains a privilege for archiving purposes, scientific or historical research purposes and statistical purposes.

Purpose limitation operates as a structural principle of the GDPR. The purpose of the processing is the fixed point by reference to which the necessity of the data processing, the legal bases under Article 6(1) GDPR, the information obligations under Articles 13 and 14 GDPR as well as the erasure and storage obligations are all aligned. An infringement of purpose limitation renders the processing unlawful; it is moreover subject to administrative fines as a breach of a basic principle.

2 Specification of the purpose

2.1 Specified

The purpose of the processing must be specified, that is, determined before the processing begins or at the latest when it begins. The Charter of Fundamental Rights already prohibits processing for undefined purposes in Article 8(2), first sentence, CFR. The German Federal Constitutional Court (BVerfG) had already objected, in the Census judgment, to the processing of personal data "in reserve" as incompatible with the right to informational self-determination (BVerfG, judgment of 15 December 1983, 1 BvR 209/83 et al., Census, BVerfGE 65, 1).

For the controller, specifying the purpose at the same time performs an alerting and cautionary function. It compels the controller to examine, before collection, which objectives it pursues with the processing, and thus operates as an instrument of self-regulation. The GDPR does not prescribe any particular form; in order to satisfy the accountability obligation under Article 5(2) GDPR, however, the specification should be documented in writing or in a comparably durable form. In practice, the specification is frequently made in the records of processing activities (Article 30(1), second sentence, point (b), GDPR) or in the information provided under Article 13(1)(c) GDPR.

Even where processing is based on a statutory legal basis under Article 6(1)(c) or (e) GDPR, the specification of the purpose remains necessary. Article 6(3), second sentence, GDPR does require the purpose to be determined in the legal basis itself. That statutory purpose is, however, typically framed more broadly than the specific purpose of the processing. The controller must therefore determine, for each specific processing operation, for which of the possible purposes it is actually processing the data.

2.2 Degree of precision of the specification of purpose

How precisely the purpose must be determined depends on the individual case. The more sensitive the data, the more extensive the processing and the more far-reaching the consequences for the data subject, the greater the precision that must be chosen. The GDPR tends toward a rather narrow specification of purpose; Recital 33 GDPR allows a broader specification of purpose only for consent given for research projects.

General labels such as "advertising", "improvement of performance" or "IT security" are not sufficient. They do not enable the data subject to understand the specific processing operations and therefore run counter to the principle of transparency and to purpose limitation (Article 29 Working Party, WP 203, Opinion 03/2013 on purpose limitation, of 2 April 2013, p. 16).

2.3 Explicit

The criterion "explicit" ("eindeutig" in German, "explicites" in French) has, alongside the clarity of the purpose, a communicative dimension: the purpose is to be communicated to the data subject. The specification of purpose therefore serves not only to bind the controller internally but at the same time to ensure transparency and foreseeability from the perspective of the data subject.

2.4 Legitimate

"Legitimate" is to be understood more broadly than "lawful" within the meaning of Article 6(1) GDPR. What matters is not whether a legal basis for the processing exists, but whether the purpose is consistent with the legal order as a whole. Purposes that the legal order condemns (such as the targeted discrimination against particular groups of persons on racist grounds) are not legitimate. In practice this is a coarse filter; it only bites in cases of blatant infringements.

3 Prohibition of incompatible further processing

3.1 Double negation and flexibility

Article 5(1)(b), first half-sentence, GDPR prohibits further processing for purposes that are "incompatible" with the original purposes of collection. The Union legislature deliberately opted for this double negation instead of requiring express compatibility. That affords the controller a certain margin: in case of doubt, the further processing is not prohibited. Recital 50, first and sixth sentences, GDPR nevertheless describe the positive case of compatibility, which shows that the controller cannot decide entirely freely.

3.2 Reference to the context of collection

Compatibility is to be measured against the context of collection and against the expectations of the data subject at that point in time. Article 6(4) GDPR lists the factors to be taken into account (any link between the purposes, the context in which the data were collected, the nature of the data, the possible consequences, and the existence of appropriate safeguards). What is additionally decisive is whether the data subject had to reasonably expect the further processing at the time of collection. The more the thrust of the purpose shifts, the less compatibility can be assumed.

3.3 The "manner" of the processing

Article 5(1)(b), first half-sentence, GDPR refers not only to the purpose of the further processing but to the "manner" of the processing. Even where the purpose continues to exist, further processing may be unlawful if material circumstances (such as the technical conditions or the range of recipients) have changed since collection and the processing thereby appears in a different light to the data subject.

3.4 Exceptions to the prohibition of incompatible further processing

Consent: where the data subject has consented to the further processing (Article 6(4) GDPR), that person is no longer in need of protection. The precondition is that the consent is sufficiently specific and clearly indicates the purpose of the further processing.
Statutory authorization: a provision of Union or national law which is a necessary and proportionate measure to safeguard one of the objectives referred to in Article 23(1) GDPR may permit incompatible further processing (Article 6(4) GDPR). In Germany, §§ 23 and 24 of the Federal Data Protection Act (BDSG) are of particular importance.
Privileged purposes: under Article 5(1)(b), second half-sentence, GDPR, compatibility is deemed to exist for archiving purposes in the public interest, for scientific or historical research purposes and for statistical purposes.

The privilege under Article 5(1)(b), second half-sentence, GDPR is to be construed narrowly. It does not exempt the controller from the requirements of Article 89(1) GDPR as to technical and organizational measures, and it does not entirely exclude the rights to object under Article 21 GDPR. Whether the further processing additionally requires a legal basis under Article 6(1) GDPR is disputed in the legal literature.

Where the further processing is incompatible with the purpose of collection, it is unlawful. The controller cannot cure the incompatibility by falling back on a new legal basis under Article 6(1) GDPR; the only remaining option is a fresh collection for the other purpose. Otherwise the principle of purpose limitation would be deprived of any effect and the specific requirements of Article 6(4) in conjunction with Article 23(1) GDPR would be circumvented.

4 Change of purpose as an information obligation

A change of purpose that is compatible with the purpose of collection is permissible, but the controller must inform the data subject of the change (Article 13(3) and Article 14(4) GDPR). The information obligation mitigates the difficulty that every change of purpose entails for the data subject's control over their data.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn