Change of Purpose (Article 6(4) GDPR)
Compatibility test for further processing for new purposes: the function of Article 6(4) GDPR, the criteria of the compatibility test, and the special case of archiving, research, and statistical purposes.
Article 6(4) GDPR governs the conditions under which personal data collected for a specific purpose may also be further processed for another purpose. The provision gives concrete form to the principle of purpose limitation laid down in Article 5(1)(b) GDPR. It is neither an independent legal basis nor an opening clause, but a compatibility test.
Key takeaways
- Article 6(4) GDPR is not a ground for lawful processing in its own right and not an opening clause, but a compatibility test that gives concrete form to the purpose limitation principle of Article 5(1)(b) GDPR.
- Where the data subject has given consent, or where a legal provision within the meaning of Article 23 GDPR applies, the test is dispensed with.
- In the standard case, the compatibility test determines, on the basis of five non-exhaustive criteria (points (a) to (e)), whether the new purpose is compatible with the original one.
- Every instance of further processing necessarily requires its own legal basis under Article 6(1) GDPR; where the purposes are compatible, this may be the same basis that already supported the original collection.
- Archiving, research, and statistical purposes are deemed compatible under Article 5(1)(b) GDPR, provided that the safeguards of Article 89 GDPR are observed.
1 Overview
1.1 Function of the provision
Article 6(4) GDPR answers the question whether a new processing purpose is still compatible with the original purpose of collection. If it is, the original legal basis continues to support the further processing as well. If it is not, the controller must either establish a new legal basis (in particular consent) or refrain from the further processing.
The following diagram gives an overview of the decision logic of Article 6(4) GDPR: first the two exceptions that render the test unnecessary, then the compatibility test as the standard case.
1.2 Legal nature
The provision is itself neither a legal basis for further processing nor an opening clause for national law. It supplements Article 6(1) GDPR and is confined to the compatibility assessment. The German Federal Court of Justice (BGH), by contrast, has construed Article 6(4) GDPR as an opening clause (BGH, order of 24 September 2019, VI ZB 39/18, para. 35); that reading is contested in the literature because it calls into question the exhaustive character of the catalog of grounds for lawful processing in paragraph 1.
1.3 Position within the system
Further processing for another purpose presupposes the following:
- The original processing was lawful (Article 6(1) GDPR),
- The new processing is in turn based on a ground for lawful processing under Article 6(1) GDPR,
- The new purpose is either compatible with the original purpose (in which case the original legal basis continues to apply) or one of the exceptions in the first half-sentence of paragraph 4 applies (consent, specific Member State provision under Article 23 GDPR).
1.4 Purpose limitation as an autonomous concept of Union law
The principle of purpose limitation under Article 5(1)(b) GDPR is not to be equated with the concept used in the German data protection tradition. Whereas earlier German law required every processing step to be strictly tied to the purposes of use determined before or at the time of collection, and allowed for changes of purpose only as an accompanying corrective, Article 5(1)(b) GDPR already operates with a more flexible form of limitation: processing for new purposes that are nevertheless compatible with the original purpose is to be classified as a change of purpose and is not regarded as still being covered by the original purpose. The English language version ("principle of purpose limitation") reflects this conception more clearly.
1.5 A legal basis for the further processing is mandatory
The misleadingly worded second sentence of Recital 50, according to which, where the purposes are compatible, "no legal basis separate from that which allowed the collection of the personal data is required", does not mean that the further processing would be lawful without any legal basis. Every processing operation, including one that changes the purpose, must be based on one of the grounds set out in Article 6(1) GDPR. In many cases this may be the same legal basis that already supported the original collection; the assessment of lawfulness (in particular as regards necessity) must, however, be carried out separately for each individual processing step. Where processing that changes the purpose is based on Article 6(1)(f) GDPR, a comprehensive fresh balancing of interests is required, which must also take into account the interests that were included in the original balancing exercise.
2 Exceptions to the compatibility assessment
2.1 Consent of the data subject
Where the data subject consents to the further processing for a new purpose, the compatibility test is unnecessary. The consent must satisfy the requirements of Articles 4(11) and 7 GDPR; it relates to the new purpose and must be given separately from the original consent.
2.2 Legal provision under Article 23 GDPR
Where the further processing is based on Union or Member State law which constitutes a necessary and proportionate measure in a democratic society to safeguard the objectives referred to in Article 23(1) GDPR, no compatibility test is required either. Typical areas of application are criminal prosecution, national security, defense, and the prevention of serious threats to public security.
3 Compatibility test
3.1 Significance
The compatibility test is the standard case under Article 6(4) GDPR. It determines whether the new purpose is still covered by the original legal basis. The assessment is comprehensive and takes account of all the circumstances of the individual case.
3.2 Non-exhaustive catalog of criteria
Article 6(4) GDPR names five criteria that are to be taken into account "inter alia". The CJEU has refined the assessment to the effect that there must be "a concrete, coherent and sufficiently close link between the purpose for which the data were collected and the further processing of the data", and that it must be ensured that the further processing does not depart from the legitimate expectations of the data subjects as to the further use of their data (CJEU, judgment of 2 March 2023, C-268/21, Norra Stockholm Bygg, para. 32).
The following overview summarizes the five criteria; the sections that follow examine them in more depth:
| Criterion (Article 6(4) GDPR) | What matters |
|---|---|
| point (a) link between the purposes | How closely the purpose of collection and the purpose of further processing are connected in substance. |
| point (b) context of the collection | The relationship and the relationship of trust between the data subject and the controller, reasonable expectations. |
| point (c) nature of the data | Heightened protection for special categories (Article 9 GDPR) and data relating to criminal offenses (Article 10 GDPR). |
| point (d) possible consequences | The more serious the consequences for the data subject, the stricter the test. |
| point (e) safeguards | Pseudonymization, encryption, and access restrictions can support compatibility. |
3.3 Link between the purposes (point (a))
The question to be examined is how closely the purposes are connected in substance. A link between the purposes suggests itself where both purposes belong to the same context (such as the performance of a contract and a subsequent invoice audit), and is remote where the purposes differ substantially in content (such as contract performance and marketing).
3.4 Context of the collection (point (b))
The context of the original collection is decisive: what was the relationship between the data subject and the controller? What expectations was the data subject reasonably entitled to have? A close relationship of trust (such as that between doctor and patient, or between lawyer and client) raises the requirements for compatibility of purposes.
3.5 Nature of the data (point (c))
Special categories of personal data (Article 9 GDPR) and data relating to criminal convictions (Article 10 GDPR) enjoy heightened protection. Particular restraint is called for when such data are further processed; the compatibility test is regularly applied more strictly.
3.6 Possible consequences (point (d))
The possible consequences of the further processing for the data subject must be taken into account. The more serious the consequences (for example exclusion from benefits, adverse effects on creditworthiness, or public disclosure), the higher the requirements for compatibility.
3.7 Safeguards (point (e))
Measures that mitigate the interference can support compatibility. This applies in particular to pseudonymization, encryption, access restrictions, and organizational measures. Such safeguards may tip the balance in favor of the further processing.
4 Archiving, research, and statistical purposes
4.1 Privileged treatment under Article 5(1)(b) GDPR
Article 5(1)(b), second half-sentence, GDPR classifies further processing for archiving purposes in the public interest, scientific or historical research purposes, or statistical purposes as being, in principle, compatible with the original purposes. That privileged treatment takes effect, however, only in so far as the requirements of Article 89 GDPR are complied with.
4.2 Requirements of Article 89 GDPR
Article 89 GDPR requires appropriate safeguards, in particular data minimization, pseudonymization, and technical and organizational measures. Member States may provide for further derogations from data subject rights in so far as this is necessary for the fulfillment of the privileged purposes.
4.3 Distinction from commercial research
Not every form of "research" is covered by the privileged treatment. The CJEU interprets the concept narrowly; purely commercial market research or product optimization does not fall within it. What is decisive is whether the research is conducted methodically and in accordance with recognized scientific standards.
5 Particular constellations
5.1 Further processing by public authorities
Public authorities cannot rely on point (f) for changes of purpose; they remain confined to points (c) or (e) in conjunction with Article 6(3) GDPR. A change of purpose by a public authority therefore regularly requires an express Member State legal basis.
5.2 Further processing in judicial proceedings
Where a public authority, as a party to judicial proceedings, is ordered to produce documents, this constitutes a change of purpose as compared with the original collection. The CJEU has clarified that such a change of purpose is to be assessed against Article 6(3) and (4) GDPR (CJEU, judgment of 8 December 2022, C-180/21, Inspectoratul General pentru Imigrări, paras. 89 et seq.; CJEU, judgment of 2 March 2023, C-268/21, Norra Stockholm Bygg, paras. 42 et seq.).
5.3 Big data applications and data analytics
Big data evaluations and predictive analytics put the compatibility assessment to the test. Analysis "to obtain new insights" is a new purpose; if that purpose is not already sufficiently specified at the time of the original collection, the further processing fails on the requirement that purposes be specified. Pseudonymization and aggregating techniques are central in these constellations.
In practice, the compatibility test is often not intuitive to apply. It is advisable to document the assessment in writing along the five criteria of Article 6(4) GDPR. If the assessment comes out negative, consent regularly remains the only way out, with all the uncertainties that this entails (freely given nature, withdrawal).
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Legitimate Interests (Article 6(1)(f) GDPR)
Balancing of interests under Article 6(1)(f) GDPR: the three-step test (interest, necessity, balancing), the exclusion of public authorities under Article 6(1), second subparagraph, GDPR, and case groups.
Opening Clauses and National Law (Article 6(2), (3) GDPR)
Scope for Member State regulation under Article 6(1)(c) and (e) GDPR: the structure of the opening clauses, the limits on the national legislature, the German Federal Data Protection Act (BDSG), the data protection acts of the Länder and the TDDDG.