Data Protection HubIndividual TopicsLegal Bases for Processing

Legal Bases for Processing (Article 6 GDPR)

Overview of Article 6 GDPR: prohibition subject to permission, the exhaustive catalog of grounds for lawful processing, the necessity principle, and the relationship to the opening clauses and to the purpose limitation principle.

Article 6 GDPR is the central authorizing provision of European data protection law. Any processing of personal data, whether carried out by public or non-public bodies, is lawful only if it can be based on one of the grounds for lawful processing listed in Article 6(1) GDPR. The provision implements the fundamental rights requirement laid down in Article 8(2) of the Charter of Fundamental Rights of the European Union (CFR), according to which personal data must be processed on the basis of consent or of some other legitimate basis laid down by law.

Key takeaways

  • Prohibition subject to permission: any processing is unlawful for as long as it cannot be based on one of the grounds for lawful processing set out in Article 6(1) GDPR.
  • The catalog is exhaustive: there is one consent-based legal basis (point (a)) and five statutory ones (points (b) to (f)); national law, too, cannot create additional grounds.
  • The legal basis applies cumulatively alongside the principles of Article 5 GDPR and, in the case of special categories, alongside Article 9 GDPR.
  • Apart from consent, every ground for lawful processing is subject to the narrowly construed requirement of necessity (the limits of what is strictly necessary).
  • Where a legal basis is lacking, administrative fines under Article 83(5) GDPR as well as claims for erasure and compensation by the data subject may follow.

1 Overview

If none of the legal bases in Article 6(1) GDPR is present, the processing is unlawful. In addition to the legal basis, the principles of Article 5 GDPR must be complied with at the same time; both assessments apply cumulatively alongside one another (CJEU, judgment of 4 May 2023, C-60/22). A single legal basis suffices; by using the wording "at least one", Article 6(1), first subparagraph, GDPR makes it expressly clear that processing may be based on several legal bases at the same time.

The catalog in Article 6(1) GDPR is exhaustive and conclusive (CJEU, judgment of 1 August 2022, C-184/20, Vyriausioji tarnybinės etikos komisija, para. 67; CJEU, judgment of 30 March 2023, C-34/21, Hauptpersonalrat der Lehrerinnen und Lehrer, para. 70). Outside this catalog no further legal bases exist; national law, too, cannot create additional grounds for lawful processing.

1.2 The catalog of grounds for lawful processing

Article 6(1) GDPR distinguishes between a consent-based legal basis (point (a)) and five statutory grounds for lawful processing (points (b) to (f)). In substance, the statutory grounds largely correspond to their predecessors in Article 7 of Directive 95/46/EC; the case law on that Directive therefore remains transferable to a large extent.

1.3 Prohibition subject to permission

The regulatory model underlying Article 6 GDPR is traditionally described as a "prohibition subject to permission": the processing of personal data is prohibited in principle and permissible only where a statutory or consent-based ground for lawful processing applies. This model is safeguarded in fundamental rights terms by Article 8(2), first sentence, CFR; in principle, individuals are to remain masters of their own data.

The model has occasionally attracted criticism, which at its core advocates a "risk-based regulatory approach" that would regulate processing operations with varying degrees of strictness depending on their risk potential. The GDPR, however, already follows that approach without abandoning the principle of prohibition: it differentiates according to sensitive categories of data (Article 9 GDPR), takes risks into account within the grounds for lawful processing (in particular under Article 6(1)(f) GDPR) and requires a data protection impact assessment where risks are high (Article 35 GDPR).

1.4 The necessity principle

With the exception of consent (point (a)), all grounds for lawful processing are subject to the requirement of necessity. Recital 39 GDPR specifies this criterion to the effect that personal data may be processed only if the purpose of the processing could not reasonably be fulfilled by other means.

The CJEU construes necessity narrowly. The processing must remain within the "limits of what is strictly necessary" (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms/Bundeskartellamt, para. 106); it is not already permissible merely because it is "useful" or "expedient" for the processing purpose. This narrow interpretation applies to all statutory grounds for lawful processing under Article 6(1) GDPR.

2 Structure and composition of the provision

2.1 Paragraph 1: the grounds for lawful processing

Paragraph 1 forms the heart of Article 6 GDPR. The second subparagraph excludes public authorities from the scope of point (f): public authorities acting in the performance of their tasks cannot rely on the general balancing of interests but must base their processing on point (c) or point (e) in conjunction with Article 6(3) GDPR.

2.2 Paragraph 2: opening clause with a clarifying function

Paragraph 2 gives the Member States the option of adopting more specific provisions, or of maintaining existing ones, within the scope of points (c) and (e). It essentially serves a clarifying function; the actual regulatory competence follows from paragraph 3.

Paragraph 3 constitutes the basis of competence for Member State rules in the area of points (c) and (e). The legal basis must be laid down by the Union or by the Member State, pursue a specific purpose, be in the public interest and be proportionate (fourth sentence). Member States may in particular lay down requirements as to the types of data, the categories of data subjects, purpose limitation, storage periods and procedures. They cannot create new grounds for lawful processing outside the exhaustive catalog in paragraph 1.

2.4 Paragraph 4: change of purpose

Paragraph 4 gives concrete form to the purpose limitation principle set out in Article 5(1)(b) GDPR for cases of further processing. The provision is neither an independent legal basis nor an opening clause; it lays down a non-exhaustive catalog of criteria against which the compatibility of a new processing purpose with the original collection purpose can be measured.

3 Relationship to other provisions of the GDPR

3.1 Relationship to Article 5 GDPR

The grounds for lawful processing in Article 6 GDPR give concrete form to the principle of lawfulness laid down in Article 5(1)(a) GDPR. The remaining principles of Article 5 GDPR (purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality) apply irrespective of the applicable legal basis and must be complied with in addition.

3.2 Relationship to Article 9 GDPR

For the processing of special categories of personal data (Article 9(1) GDPR), Article 6(1) GDPR alone does not suffice. In addition, one of the exceptions in Article 9(2) GDPR must apply. The CJEU has made clear that both provisions must be examined cumulatively (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms/Bundeskartellamt, para. 90).

Where a data set is processed as a whole and contains both sensitive and non-sensitive data, and the data cannot be separated at the time of collection, the lawfulness of the processing as a whole is governed by Article 9(2) GDPR as soon as the data set contains at least one item of sensitive data (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms/Bundeskartellamt, para. 89).

3.3 Relationship to the opening clauses

The opening clauses in Article 6(2) and (3), Article 23 and Articles 85 et seq. GDPR allow for special Member State rules. They do not alter the structure of the catalog of grounds in Article 6(1) GDPR: national special provisions must themselves connect to one of the six grounds for lawful processing (CJEU, judgment of 30 March 2023, C-34/21, Hauptpersonalrat der Lehrerinnen und Lehrer, para. 70).

4.1 Permissibility in principle

By using the wording "at least one", Article 6(1), first subparagraph, GDPR makes it expressly clear that processing may be based cumulatively on several grounds for lawful processing. This concerns in particular constellations in which the processing pursues different purposes and each purpose requires its own legal basis. Obtaining consent does not preclude recourse to other legal bases where consent is refused or withdrawn (Article 17(1)(b) GDPR).

4.2 Limits of cumulation

Basing a processing operation on several legal bases must not undermine the respective requirements. In particular, the stricter requirements applicable to consent (Article 7 GDPR), or the requirement of a direct link to the content of the contract under point (b), must not be circumvented by relying in the alternative on point (f). In contractual constellations it must therefore be examined as a matter of priority whether consent or point (b) carries the processing; point (f) comes into consideration only where the processing cannot be accommodated there.

4.3 Clarity for the data subject

The EDPB points out that it must be examined precisely which legal basis applies in the specific individual case, because the legal bases are subject to different requirements and have different consequences for the rights of data subjects. No confusion may arise on the part of the data subject as to which legal basis is being relied upon (EDPB, Guidelines 2/2019 on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services, paras. 17 et seq.).

For the storage of credit card data by online retailers for the sole purpose of facilitating future purchases, consent is the only possible legal basis; point (b) does not support such processing (EDPB, Recommendations 02/2021, para. 10).

5 Lawfulness requirements and the consequences of unlawfulness

If none of the grounds in Article 6(1), first subparagraph, GDPR is present, the processing is unlawful. Infringements of Article 6 GDPR are subject, under Article 83(5)(a) GDPR, to administrative fines of up to EUR 20 million or 4 % of the total worldwide annual turnover. Data subjects may bring civil proceedings for an injunction against further processing; the lawfulness provisions of Article 6(1) GDPR are, in particular, capable of constituting a protective statute within the meaning of § 823(2) of the German Civil Code (BGB). In addition, rights to erasure under Article 17 GDPR and claims for compensation under Article 82 GDPR apply, the latter being subject to an autonomous interpretation under Union law.

5.2 Interrelations of unlawfulness within the processing sequence

More difficult to assess are the consequences that an unlawful partial act has for subsequent processing steps. Article 6 GDPR neither prescribes a continuous "chain of lawfulness" nor are the individual processing steps to be entirely decoupled from one another. The assessment calls for a differentiated balancing based on the function of the infringed element of the provision, the gravity of the infringement and the data subject's need for protection. In certain constellations the notion of a "cure" may carry weight; in the case of systematic infringements, the deterrence rationale prevails.

5.3 Practical consequence: video recordings from unlawful video surveillance

Video recordings originating from private video surveillance that is not covered by Article 6(1)(f) GDPR may nevertheless be admissible as evidence in criminal proceedings despite the unlawfulness of their collection (German Federal Court of Justice (BGH), order of 18 August 2020, 5 StR 175/20). Admissibility depends, in the individual case, on a balancing between the interest in an effective administration of criminal justice and the protection of the data subject's fundamental rights.

5.4 Information obligations as an independent duty

The lawfulness of further processing for a changed purpose does not depend on all transparency and information obligations (Article 13(3), Article 14(4) GDPR) having been complied with. An infringement of the information obligations triggers independent sanctions and claims for compensation, but does not necessarily render the further processing unlawful.

Individual processing operations can often be based on several grounds for lawful processing. This is permissible under Article 6(1), first subparagraph, GDPR; the controller must, however, actually identify the legal basis applicable in each case, because the information obligations (Article 13(1)(c) GDPR) and the rights of data subjects (e.g. Article 21 GDPR) depend on it.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn