Data Protection HubIndividual TopicsLegal Bases for Processing

Vital Interests (Article 6(1)(d) GDPR)

Protection of the vital interests of the data subject or of another natural person as a legal basis; subsidiarity and the relationship to the right to self-determination.

Under Article 6(1)(d) GDPR, processing is lawful where it is necessary in order to protect the vital interests of the data subject or of another natural person. The scope of the provision is narrow; it addresses exceptional situations in which life or physical integrity is under threat and the data subject is unable to decide for himself or herself.

Key takeaways

  • Point (d) is an emergency assistance provision for the acute individual case (medical emergencies, rescue operations, humanitarian crises), not a basis for permanent or routine processing operations.
  • Only vital interests in the narrow sense are protected: life, physical integrity, elementary existence; interests of a financial nature do not fall within its scope.
  • The provision is subsidiary: it applies only where the processing manifestly cannot be based on any other legal basis (Recital 46).
  • Where data subjects are capable of deciding for themselves, consent takes precedence; if a data subject who is capable of deciding refuses consent, point (d) is as a rule ruled out.
  • Where data concerning health are involved, Article 9(2)(c) GDPR must additionally be observed as a lex specialis, since it expressly refers to point (d).

1 Overview

Point (d) supports processing that is indispensable in the individual case in order to protect vital interests. What is typically meant are medical emergencies, humanitarian crises, accidents or other situations in which an immediate response is required.

1.2 Interests worthy of protection

Covered are vital interests in the narrow sense: life, physical integrity and elementary conditions of existence. Interests of a financial nature or economic concerns do not fall within its scope. Recital 46 names as examples humanitarian emergencies, such as monitoring epidemics and their spread or humanitarian disasters, in particular in situations of natural and man-made disasters.

"Vital" is not thereby to be equated with "essential to survival". Point (d) does not apply only where there is an acute danger to life; a sufficiently close and weighty connection to physical integrity and health is enough. The provision must, however, be interpreted narrowly (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms/Bundeskartellamt, para. 137). In an individual case, processing may serve both public and vital interests, for instance in the monitoring of epidemics (Recital 46, third sentence). Where data concerning health or other special categories are involved at the same time, Article 9(2)(c) GDPR must be observed as a lex specialis, since it expressly refers to point (d).

1.3 Extension to third parties

The provision protects not only the data subject himself or herself, but also other natural persons. This extension as compared with Data Protection Directive 95/46/EC was added only in the course of the legislative procedure. It covers, for instance, cases in which the disclosure of a relative's data concerning health is indispensable in order to protect other persons.

2 Subsidiarity

Recital 46, second sentence, makes clear that the processing should take place on the basis of another ground for lawful processing "where possible". The processing of personal data should be based on point (d) only where the processing manifestly cannot be based on any other legal basis.

2.2 No systematic safeguarding

Point (d) is not suitable as a basis for systematic processing operations designed to be permanent. For recurring situations, such as civil protection or crisis preparedness, Article 6(1)(c) or (e) GDPR in conjunction with a specific legal basis is the relevant provision. The practical reach of point (d) is confined to acute, unforeseeable individual cases.

3 Relationship to the right to self-determination

3.1 The case of a data subject capable of deciding

Where the data subject is able to decide for himself or herself, the question is whether his or her consent can be obtained. The right to informational self-determination requires restraint in processing without express agreement. Where the data subject is capable of deciding and refuses consent, point (d) is as a rule ruled out, even where the processing appears sensible from the controller's perspective.

3.2 The case of a data subject incapable of deciding

Where the data subject is physically or legally incapable of giving consent, point (d) applies. A typical example is the unconscious patient in the emergency room whose pre-existing conditions, medication and allergies must be processed in order to ensure appropriate medical care.

3.3 Protection of other persons

In the case of the "other natural person" alternative, the protection of third parties is in the foreground. The interests of the data subject (whose data are processed) must yield to the protection of that other person. This concerns, for instance, cases in which genetic information relating to one person must be disclosed in order to protect blood relatives.

4 Necessity

4.1 Standard

The processing must be necessary for the protection of vital interests. It may not extend to data whose processing is dispensable for averting the danger. Under point (d) too, the principle of data minimization applies without restriction.

4.2 Concrete danger

What is required is a concrete, and not merely an abstract, danger. Abstract risk situations or preventive processing operations that could serve the protection of vital interests only indirectly cannot be justified under point (d).

5 Typical categories of cases

5.1 Medical emergency

The unconscious patient is admitted to the emergency room. The processing of existing data concerning health (pre-existing conditions, medication, allergies) is necessary in order to protect his or her life. Because of Article 9 GDPR, Article 9(2)(c) GDPR, which expressly refers to point (d), is also relevant.

5.2 Search and rescue operations

In search and rescue operations, the processing of location data, communications data or data concerning health may be necessary in order to find missing persons or persons in distress. The data processing is confined to what is necessary for the rescue.

5.3 Combating pandemics

In connection with epidemics and pandemics, Recital 46 is of particular importance. However, a careful distinction must be drawn between acute measures in individual cases (point (d)) and systematic processing operations designed to be permanent (point (c) or (e)). Contact tracing or the recording of vaccination data in connection with the coronavirus pandemic are as a rule based on specific statutory bases.

Point (d) is an emergency assistance provision, not a standard provision. Anyone who maintains a processing operation on a permanent basis or carries it out as a matter of routine cannot rely on point (d). The provision is suited exclusively to the acute individual case in which no other legal basis applies and there is no time to obtain consent.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn