Data Protection HubIndividual TopicsLegal Bases for Processing

Contract and pre-contractual steps (Article 6(1)(b) GDPR)

The contractual ground for lawful processing under Article 6(1)(b) GDPR: scope, the EU law concept of necessity, distinction from consent and terms of use, the consequences of termination and typical case groups, in particular for online services.

Under Article 6(1)(b) GDPR, the processing of personal data is lawful if it is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract. The provision reflects the underlying idea that taking part in contractual dealings regularly presupposes the processing of data as well.

Key takeaways

  • Article 6(1)(b) GDPR supports any processing that is necessary for the performance of the contract or for a pre-contractual step taken at the request of the data subject; additional consent is then not required.
  • The requirements are cumulative: a valid contract (or a pre-contractual request), the data subject as a party to the contract, and the objective necessity of the specific processing operation.
  • Necessity is a concept of EU law: the processing must be objectively indispensable, not merely useful (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms/Bundeskartellamt).
  • Third-party data, special categories (Article 9 GDPR) and a change of legal basis after the contract has ended are not covered by point (b).
  • Service improvement, fraud prevention, behavioral advertising and mere personalization can as a rule not be based on point (b) in the online context.

1 Overview

Where the requirements of point (b) are met, the provision legitimizes any processing that is necessary for the performance of the contract or for the pre-contractual steps. Additional consent or a balancing of interests is not required. The legal basis covers both contracts between private parties and contractual relationships under public law with the data subject.

1.2 Requirements at a glance

The legal basis requires cumulatively:

  • a valid contract under civil or public law (or a pre-contractual request),
  • that the data subject is itself a party to the contract,
  • the objective necessity of the specific processing operation for the performance of the contract (or for the pre-contractual step).

Accepting terms of use in the context of a contract does not constitute consent under Article 6(1)(a) GDPR. The two legal bases have different requirements and different legal consequences, in particular as regards the freely given nature of consent, its withdrawal and transparency (EDPB, Guidelines 2/2019, para. 20). The controller must communicate clearly from the outset which legal basis it relies on and must state that basis in the information provided under Articles 13 and 14 GDPR. Conversely, where processing is in fact necessary for the performance of the contract, consent is not the appropriate legal basis; an apparently parallel request for consent then creates confusion as to the legal basis and does not satisfy the transparency requirement.

1.4 No basis for special categories (Article 9 GDPR)

Article 9(2) GDPR provides for no exception covering the "performance of a contract". Where the controller processes special categories of personal data (Article 9(1) GDPR), point (b) alone is not sufficient; an additional ground for lawful processing under Article 9(2)(b) to (j) GDPR or explicit consent under Article 9(2)(a) GDPR is required (EDPB, Guidelines 2/2019, para. 21).

1.5 Embedding in the principles under Article 5 GDPR

The legal basis does not dispense with the principles laid down in Article 5 GDPR. In particular, fairness (Article 5(1)(a) GDPR), purpose limitation (Article 5(1)(b) GDPR) and data minimization (Article 5(1)(c) GDPR) must be taken into account when interpreting point (b). The fairness principle requires consideration of the reasonable expectations of the data subject, of any adverse consequences of the processing and of a possible imbalance of power between the parties. Purposes must be specified with sufficient precision; vague formulations such as "improving the user experience", "marketing purposes", "IT security purposes" or "future research" are not sufficient for that (EDPB, Guidelines 2/2019, para. 16).

2 The contract as the point of reference

2.1 A valid contract as the basis

The point of reference is a contract between the controller and the data subject that is valid under the applicable contract law. Validity is governed by national contract law, including the rules on the legal capacity of minors and on unfair terms in consumer contracts (§§ 305 et seq. of the German Civil Code (BGB), transposing Directive 93/13/EEC). The provision is not limited to contracts governed by the law of an EEA Member State.

2.2 Contracts under civil law

All valid obligations between the controller and the data subject are covered. The type of contract is irrelevant: contracts of sale, service contracts, contracts for work, loan agreements, tenancy agreements, insurance contracts, employment contracts, treatment contracts and online usage contracts are covered alike.

2.3 Quasi-contractual obligations

Quasi-contractual obligations may also fall under point (b) where they create comparable ties. This concerns in particular the management of another's affairs without a mandate (negotiorum gestio), where an expressly concluded contract is lacking but a statutory obligation exists that gives rise to comparable duties.

2.4 Collective bargaining agreements and works agreements

Collective bargaining agreements and works agreements are contentious. They bind the individual employee without that employee being a party to the contract in the narrower sense. In part they are recognized as a "contract" within the meaning of point (b), but predominantly only where the specific processing operation constitutes the necessary implementation of a specific obligation based on a collective bargaining agreement or a works agreement. Otherwise, recourse remains to Article 88 GDPR in conjunction with § 26 of the German Federal Data Protection Act (BDSG) or to points (c) and (f).

2.5 Void contracts

If a contract is void, point (b) is in principle ruled out as a legal basis. For processing operations already carried out, however, point (c) (statutory obligations to unwind the contract) or point (f) (legitimate interest in unwinding the contract) may serve as a basis.

2.6 Third-party data

Article 6(1)(b) GDPR supports only the processing of data of the contracting parties. Where data of third parties are processed, for instance those of relatives of a policyholder, of creditors of the debtor or of relatives of a patient, a separate legal basis is required; as a rule only point (f) comes into consideration.

3 Pre-contractual steps

3.1 The request of the data subject as a statutory requirement

The second alternative of point (b) covers processing operations carried out in order to take pre-contractual steps. The requirement is that the step be taken "at the request of the data subject". Approaches made by the controller on its own initiative to the data subject are not covered. Whether a contract is in fact subsequently concluded is irrelevant; what matters is that the request is connected with a possible conclusion of a contract (EDPB, Guidelines 2/2019, para. 46).

3.2 Typical constellations

Covered are, for example, the assessment of creditworthiness in advance of a loan agreement at the request of the potential borrower, obtaining a quote for an insurance contract, or an application by the data subject for a position. Simple availability queries, such as entering a postal code in order to check whether a service is offered in a given region, also fall within this (EDPB, Guidelines 2/2019, Example 5). The common feature is that the data subject takes the initiative and therefore has a legitimate interest in prompt handling.

3.3 Distinction from advertising measures

Advertising intended to initiate new contractual relationships is not a pre-contractual step within the meaning of point (b). At most, it can be justified under point (f) or by consent under point (a).

Where the data processing is triggered not by the request of the data subject but by a legal obligation of the controller, point (c) is the appropriate legal basis and not point (b). A classic case is the identity verification carried out by banks under anti-money laundering law before an account contract is concluded (EDPB, Guidelines 2/2019, Example 6).

4 The necessity criterion

4.1 A concept of EU law

"Necessary" is an autonomous concept of EU law. It is not exhausted by the question of what the contract formally permits or expressly provides for; rather, it calls for a fact-based assessment of whether the specific processing operation is necessary in relation to the purpose pursued and is to be preferred over less intrusive alternatives. Processing operations that are merely useful for the main performance, or that serve exclusively other business purposes of the controller, do not meet the criterion.

4.2 "Objectively indispensable", not merely "useful"

The CJEU requires that the processing be "objectively indispensable" for the performance of the contract. Processing that merely improves or personalizes the service does not meet this criterion (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms/Bundeskartellamt, paras. 98 et seq.). The benchmark is the performance characteristic of the contract: only processing operations that are directly linked to the main obligation owed or to a necessary ancillary obligation are permissible. In the competition law proceedings concerning Facebook, the German Federal Court of Justice (BGH) emphasized that the performance characteristic of the contract must be construed narrowly in order to protect the data subject against an arbitrary extension of the content of the contract (BGH, order of 23 June 2020, KVR 69/19, paras. 110 et seq.). The drafting of the contract may not extend the criterion at will. A mere reference in the fine print does not render the processing necessary.

4.3 Steps of the assessment

In practice, necessity can be assessed along four questions (EDPB, Guidelines 2/2019, para. 33):

Nature of the service: what service is provided to the data subject and what are its characteristic features?
Rationale of the contract: what is its objective and its subject matter, and what have the parties recognizably agreed on?
Essential elements: which processing operations belong to the core of the service and which do not?
Horizon of expectations: would an average user of the service, aware of how it is marketed and of what it comprises, reasonably expect the intended processing to take place for the performance of the contract?

If the assessment shows that the intended processing goes beyond what is objectively necessary, this does not automatically mean that it is unlawful; the controller must then, however, switch to another legal basis (in particular point (a) or point (f)) and adjust its transparency obligations accordingly.

4.4 The perspective of both sides

Necessity is not to be assessed solely from the controller's point of view. What matters is whether the main contractual purpose could still be meaningfully achieved without the processing in question, seen from the perspective of a reasonably discerning data subject. That requires a genuine mutual understanding of the purpose of the contract; an objective documented solely internally by the provider is not sufficient for that.

4.5 Bundling of several services

Where a contract comprises several services or several independent elements of a service that can be performed independently of one another, the requirements of point (b), and in particular necessity, must be assessed separately for each individual service (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms/Bundeskartellamt, para. 94; EDPB, Guidelines 2/2019, paras. 36 et seq.). A blanket legitimization of all data processing operations by means of a comprehensive description of services in the terms of use is therefore ruled out. Processing operations that serve solely the controller's broader business model cannot be based on point (b).

4.6 Ancillary and follow-up performance

Point (b) covers not only the main contractual obligation but also ancillary activities that are reasonably foreseeable and necessary in the context of a normal contractual relationship, such as payment processing, reminders in the event of late payment, or the correction of errors and delays in the provision of the service (EDPB, Guidelines 2/2019, para. 38, Example 3). The storage of certain data for the duration of a contractual warranty period may also be covered by point (b).

4.7 New technologies and changes to the service

Where a new technology is introduced during the term of the contract, or the service is otherwise further developed, necessity must be assessed afresh for every new or modified processing operation. Necessity once affirmed does not continue to apply where the purpose of the processing or the service changes.

5 Termination and end of the contract

5.1 Principle: cessation of the purpose leads to discontinuation

Where the contract ends in full, the purpose of the processing based on point (b) as a rule ceases to exist. The processing must be discontinued; stored data must be erased pursuant to Article 17(1)(a) GDPR. Already when the processing begins, the controller should determine what is to happen when the contract ends and should communicate the storage period transparently.

A subsequent switch to another legal basis (e.g. point (f)) in order to continue the processing after the contract has ended is in principle impermissible. The data subject provided the data in reliance on the contractual context; relabeling after the event infringes the principle of fairness under Article 5(1)(a) GDPR (EDPB, Guidelines 2/2019, para. 41).

5.3 Continuing processing on another basis

Steps taken to unwind the contract, such as returns or refunds, are themselves reasonably foreseeable consequences of the contract and can continue to be based on point (b). Beyond that, processing operations remain permissible that rested on their own legal basis from the outset and were communicated transparently, such as retention pursuant to obligations under commercial or tax law (point (c) in conjunction with § 257 of the German Commercial Code (HGB) and § 147 of the German Fiscal Code (AO)) or the defense of legal claims (point (f) in conjunction with Article 17(3)(e) GDPR). Such purposes must be determined before the processing begins and must be disclosed to data subjects in accordance with Articles 13 and 14 GDPR.

6 Typical processing operations in the online context that point (b) does not support

In Guidelines 2/2019, the EDPB identified four case groups in which point (b) is regularly not a viable legal basis. The CJEU confirmed this dividing line in the Meta judgment.

6.1 Service improvement and new functionalities

The analysis of usage behavior in order to improve an existing service or to develop new functionalities can as a rule not be based on point (b). The service could also be provided without the processing; the contractual clause permitting such analyses does not replace the necessity assessment. Point (a) or point (f) come into consideration as a legal basis (EDPB, Guidelines 2/2019, paras. 48 et seq.).

6.2 Fraud and abuse prevention

Monitoring and profiling for the purpose of fraud prevention likewise typically go beyond what is objectively necessary. Necessary measures can, however, regularly be based on point (f); where a legal obligation exists (e.g. to prevent money laundering), point (c) applies (EDPB, Guidelines 2/2019, para. 50).

6.3 Behavioral online advertising

Behavioral advertising, tracking and profiling for the purpose of ad targeting are not a performance characteristic of the contract, even where the service is financed by advertising. The absolute right to object under Article 21(2) GDPR would be deprived of effect if the provider were able to rely on point (b). In addition, § 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG) requires consent for the storage of, or access to, information on terminal equipment (cookies, tracking pixels, fingerprinting). Lookalike and audience matching aimed at advertising to other persons likewise already fail on the necessity requirement (EDPB, Guidelines 2/2019, paras. 51 et seq.).

6.4 Personalization of content

The personalization of content is supported by point (b) only where it is an integral part of the service that the parties recognizably took as given. What matters is the nature of the service, the way it is marketed to users, and the question whether the service can be meaningfully provided at all without personalization. Where personalization serves only to retain users or to increase interactivity, objective necessity is lacking; the processing must then be based on another legal basis (EDPB, Guidelines 2/2019, para. 57).

The line between "integral part" and "merely conducive to user retention" is a narrow one in practice. Anyone seeking to base personalization on point (b) should anchor and market it within the service offering so specifically that the average data subject recognizes it as a core function; otherwise, only point (a) or point (f) with a sound balancing of interests remains.

7 Case groups

7.1 Banking transactions

The processing of identification, account and transaction data is in principle necessary for handling the account contract and for carrying out payment orders. Special statutory requirements, for example under anti-money laundering law, additionally lead to point (c).

7.2 Employment relationships

The processing of personal data in the employment relationship is largely governed by Article 88 GDPR in conjunction with § 26 BDSG. Insofar as the data concerned are necessary for the establishment, performance or termination of the employment contract, the processing is also based on point (b).

7.3 Debt collection and factoring

In the case of receivables purchase and debt collection, the main points of dispute concern the passing on of debtor data. Debt collection activity aimed at enforcing a claim against the debtor can be based on point (b) insofar as the claim arises from a contract with the debtor itself; the transmission to third parties (such as credit reference agencies) requires additional legal bases, as a rule point (f).

7.4 Marketing and customer retention

Advertising and customer retention are not a performance characteristic of the contract. Advertising to existing customers can be based on point (f) where the requirements of Article 21 GDPR and of competition law (in particular § 7 of the German Act Against Unfair Competition (UWG)) are complied with. Discount and loyalty programs are in principle to be legitimized under point (b) on account of their core performance promise, insofar as they are consistent with the participation agreement.

7.5 Medical treatment

The treatment contract (§§ 630a et seq. BGB) supports the processing of data concerning health insofar as such processing is necessary for the treatment. Because of Article 9 GDPR, Article 9(2)(h) GDPR in conjunction with the duties of confidentiality under professional law applies in addition.

7.6 Tenancy relationships

The processing of tenant data for the performance of the tenancy agreement (billing, service charge statements, maintenance) is regularly necessary. Processing going beyond that, such as video surveillance in a multi-family building, is subject to the balancing of interests under point (f) (CJEU, judgment of 11 December 2019, C-708/18, Asociaţia de Proprietari, paras. 40 et seq.).

7.7 Online services

In the case of online services, particular care must be taken in examining which processing operations belong directly to the service owed under the contract. Under the Meta case law, personalization, behavioral advertising or the cross-service linking of user data cannot be based on point (b) (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms/Bundeskartellamt, para. 102). The scope of permissible processing must be assessed separately for each individual service element offered.

7.8 Mail order business

In mail order business, the collection of the delivery address, communication about the shipment as well as the handling of returns and warranty claims are covered by point (b). Where the data subject instead chooses a pick-up point, the processing of the home address is no longer necessary and requires another legal basis (EDPB, Guidelines 2/2019, Example 1). Scoring and creditworthiness checks require a separate legal basis; as a rule only point (f) with a balancing of interests comes into consideration.

7.9 Insurance

The processing for handling insurance contracts (premium calculation, claims settlement) is covered by point (b). For the processing of data concerning health and for checks for insurance fraud, additional legal bases (Article 9(2)(h) GDPR, point (f)) must be examined.

Since the CJEU's Meta judgment, point (b) offers considerably less scope for many processing operations in the online context than it did previously. Anyone seeking to rely on the provision must set out specifically why the processing is objectively indispensable for the main performance owed. As soon as the processing serves only the provider's economic interest, only consent or the balancing of interests under point (f) remains.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn

On this page

1 Overview1.1 Legal consequence and scope1.2 Requirements at a glance1.3 Distinction from consent and terms of use1.4 No basis for special categories (Article 9 GDPR)1.5 Embedding in the principles under Article 5 GDPR2 The contract as the point of reference2.1 A valid contract as the basis2.2 Contracts under civil law2.3 Quasi-contractual obligations2.4 Collective bargaining agreements and works agreements2.5 Void contracts2.6 Third-party data3 Pre-contractual steps3.1 The request of the data subject as a statutory requirement3.2 Typical constellations3.3 Distinction from advertising measures3.4 Distinction from legal obligations4 The necessity criterion4.1 A concept of EU law4.2 "Objectively indispensable", not merely "useful"4.3 Steps of the assessment4.4 The perspective of both sides4.5 Bundling of several services4.6 Ancillary and follow-up performance4.7 New technologies and changes to the service5 Termination and end of the contract5.1 Principle: cessation of the purpose leads to discontinuation5.2 No "switch" of legal basis5.3 Continuing processing on another basis6 Typical processing operations in the online context that point (b) does not support6.1 Service improvement and new functionalities6.2 Fraud and abuse prevention6.3 Behavioral online advertising6.4 Personalization of content7 Case groups7.1 Banking transactions7.2 Employment relationships7.3 Debt collection and factoring7.4 Marketing and customer retention7.5 Medical treatment7.6 Tenancy relationships7.7 Online services7.8 Mail order business7.9 Insurance