Public Interest and Official Authority (Article 6(1)(e) GDPR)
Lawfulness of processing for the performance of a task carried out in the public interest or in the exercise of official authority; requirements for the legal basis under Article 6(3) GDPR and practical examples.
Under Article 6(1)(e) GDPR, processing is lawful where it is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. The provision constitutes the most important legal basis for data processing in the public sector. Public authorities are excluded from point (f) and are referred to point (c) or (e).
Key takeaways
- Point (e) is the central legal basis of the public sector and covers two variants: the task carried out in the public interest and the exercise of official authority that has been vested in the controller.
- Public authorities are excluded from point (f) (Article 6(1), second subparagraph, GDPR) and are referred to point (c) or (e).
- The processing additionally requires a legal basis under Article 6(3) GDPR, which must be clear, precise and proportionate; sweeping general clauses do not suffice.
- Private parties can rely on point (e) only where the task has been assigned to them by a State act of conferral (Beleihung); otherwise only point (f) remains available.
- The data subject enjoys a right to object under Article 21(1) GDPR.
1 Overview
1.1 Legal consequence and structure
Where the conditions of point (e) are met, the provision supports the processing without any need for additional consent. The processing must, however, be based on a legal basis within the meaning of Article 6(3) GDPR and comply with the principles laid down in Article 5 GDPR. The exclusion of public authorities under Article 6(1), second subparagraph, GDPR compels public authorities to rely on point (c) or (e); the general balancing of interests under point (f) is not open to them. Where processing is based on point (e), the data subject enjoys a right to object under Article 21(1), first sentence, GDPR.
1.2 Two variants
Point (e) covers two variants:
- the performance of a task carried out in the public interest, and
- the exercise of official authority vested in the controller.
The first variant covers the entire spectrum of State action serving the common good without having to take the form of an exercise of official powers; the second variant concerns the performance of tasks involving official authority in the narrower sense.
1.3 Act of conferral as a necessary condition
The German Federal Administrative Court (BVerwG) has clarified that private parties can rely on point (e) only where the power has been assigned to them by a State act of conferral (Beleihung) (BVerwG, judgment of 27 March 2019, 6 C 2/18, para. 43). Private parties without such an act of conferral are referred to point (f), even where their activity has a connection with the public interest.
2 Task carried out in the public interest
2.1 Concept
A task is carried out in the public interest where it serves to give effect to public concerns and does not merely pursue commercial or individual interests. The concept is broad; it encompasses the administration providing benefits and services, the administration exercising intrusive powers, regulatory administration and steering administration, as well as services of general interest. It covers tasks corresponding to an objective of general interest recognized by the Union, as well as tasks which national law classifies as being in the public interest. The Court of Justice has, for example, classified the improvement of road safety as a recognized objective of general interest (CJEU, judgment of 22 June 2021, C-439/19, B, para. 108).
2.2 The link to the common good as the core element
What is decisive is the link to the common good. The task must serve public interests; its performance need not necessarily be carried out by a public authority. Bodies governed by public law (universities, professional chambers, broadcasting organizations) and private entities on whom public powers have been conferred may therefore also perform tasks in the public interest.
2.3 Distinction from tasks involving official authority
The distinction between the two variants is not always clear-cut. General administrative activities in the interest of the common good that do not require any official powers fall under the first variant. The second variant, by contrast, presupposes an element of interference or coercion.
3 Exercise of official authority
3.1 Performance of tasks involving official authority
The second variant covers classic activity involving official authority: the police and public order authorities, the tax administration, the judiciary, the public prosecution service, the population registration authorities, the social security authorities. Its hallmark is unilateral intrusive action vis-à-vis the citizen.
3.2 Vesting in the controller
The official authority must be vested in the controller. This means that the task must have passed to the controller by way of a legal provision or an administrative act. Private parties who in fact carry out activities resembling the exercise of official authority without having had public powers conferred on them (private security services, for instance) are not vested with official authority within the meaning of the GDPR.
3.3 Public authorities in judicial proceedings
Where a public authority acts as a party to judicial proceedings, the processing of personal data remains an exercise of official authority within the meaning of point (e). It is immaterial whether the authority appears on an equal footing with the other parties to the proceedings (CJEU, judgment of 8 December 2022, C-180/21, Inspectoratul General pentru Imigrări, para. 87).
4 Requirements for the legal basis
4.1 Legal basis under Article 6(3) GDPR
The specific task and the data processing must be based on a legal basis in Union or Member State law. Article 6(3), second sentence, GDPR permits two routes: either the purpose of the processing is determined in the legal basis itself, or it is necessary for the performance of a task carried out in the public interest.
4.2 Specificity
The legal basis must be clear and precise. The data subject must be able to discern which processing operations take place on the basis of the provision. According to the case law of the German Federal Administrative Court, sweeping general clauses (general provisions assigning tasks without conferring a concrete power, for instance) do not suffice (BVerwG, judgment of 27 September 2018, 7 C 5/17, para. 26).
4.3 Proportionality
The legal basis must be proportionate to the objective pursued (Article 6(3), fourth sentence, GDPR) and must not restrict the right to the protection of personal data disproportionately.
4.4 Prohibition on supplementing the provision by balancing tests
The German Federal Administrative Court has made clear that the national legislature may not "supplement" the necessity requirement under point (e) by means of general balancing-of-interests clauses. The statutory basis must itself set out the framework of the processing; transposing the balancing of interests into the statutory criteria of a public law ground for lawful processing is impermissible (BVerwG, judgment of 27 March 2019, 6 C 2/18, para. 42).
5 Necessity
5.1 Autonomous standard under EU law
Under point (e), too, necessity must be determined autonomously under EU law. The Court of Justice has given substance to this standard in the proceedings concerning the Central Register of Foreign Nationals: processing is necessary where it leads to a more efficient application of the underlying legal provisions and no less intrusive means are available (CJEU, judgment of 16 December 2008, C-524/06, Huber, paras. 52 et seq.).
5.2 Strict scrutiny in the case of particularly serious interferences
In the case of particularly serious interferences (publication of personal data on the internet or processing of special categories of data, for instance), the Court of Justice requires strict scrutiny of necessity. The processing must be limited to what is strictly necessary (CJEU, judgment of 1 August 2022, C-184/20, Vyriausioji tarnybinės etikos komisija, paras. 97 et seq.).
6 Practical examples
6.1 Police and public order authorities
Data processing by the police and public order authorities in the field of safeguarding against and preventing threats to public security (but not in the field of criminal prosecution and the execution of criminal penalties, which under Article 2(2)(d) GDPR falls within the scope of Directive (EU) 2016/680) is typically supported by point (e) and given concrete form by specific police and public order statutes.
6.2 Social security authorities
The processing of data concerning benefit recipients (unemployment benefit II, social assistance, pensions, housing benefit) rests on point (e) and is given concrete form by the sector-specific provisions of the German Social Code (SGB).
6.3 Tax and revenue administration
Data processing by the tax administration is a classic exercise of official authority. It finds its legal basis in the German Fiscal Code (§§ 29b et seq. AO) and in individual tax statutes.
6.4 Population registration
Registration law (the German Federal Registration Act and the registration acts of the Länder) supports the data processing carried out by the registration authorities and at the same time governs transmission to other public authorities and, under certain conditions, to private parties as well.
6.5 Video surveillance by public bodies
Video surveillance of publicly accessible spaces by public bodies finds its legal basis in § 4(1), first sentence, no. 1 of the German Federal Data Protection Act (BDSG) in conjunction with point (e) GDPR, in so far as it is necessary for the performance of the relevant tasks. Specific requirements laid down in road traffic legislation apply to traffic surveillance.
6.6 Broadcasting organizations
The public service broadcasting organizations act in the public interest (Article 5(1), second sentence, of the German Basic Law (GG); Interstate Broadcasting Treaty). The processing of editorial data falls under the media privilege (Article 85 GDPR in conjunction with the statutes of the Länder and the interstate treaties), while the remaining processing falls under point (e).
6.7 Performance of judicial tasks
Data processing in judicial proceedings (ex officio investigation, the keeping of files, the publication of decisions) is based on point (e). In so far as it concerns the principle of ex officio investigation, the relevant procedural codes apply (§ 86 of the German Code of Administrative Court Procedure (VwGO), § 244 of the German Code of Criminal Procedure (StPO), § 139 of the German Code of Civil Procedure (ZPO)).
Point (e) is the workhorse provision of the public sector. In practice it must always be viewed in conjunction with the relevant sector-specific law. Anyone who argues, without a sector-specific statutory basis, that an operation is "in the public interest" runs the risk that the processing will fail for want of a sufficiently specific legal basis.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Vital Interests (Article 6(1)(d) GDPR)
Protection of the vital interests of the data subject or of another natural person as a legal basis; subsidiarity and the relationship to the right to self-determination.
Legitimate Interests (Article 6(1)(f) GDPR)
Balancing of interests under Article 6(1)(f) GDPR: the three-step test (interest, necessity, balancing), the exclusion of public authorities under Article 6(1), second subparagraph, GDPR, and case groups.