# Contract and pre-contractual steps (Article 6(1)(b) GDPR)

The contractual ground for lawful processing under Article 6(1)(b) GDPR: scope, the EU law concept of necessity, distinction from consent and terms of use, the consequences of termination and typical case groups, in particular for online services.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.2-vertrag-und-vorvertragliche-massnahmen
> Sprache: en



Under Article 6(1)(b) GDPR, the processing of personal data is lawful if it is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract. The provision reflects the underlying idea that taking part in contractual dealings regularly presupposes the processing of data as well.

<Callout type="info">
  **Key takeaways**

  * Article 6(1)(b) GDPR supports any processing that is necessary for the **performance of the contract** or for a pre-contractual step taken at the request of the data subject; additional consent is then not required.
  * The requirements are **cumulative**: a valid contract (or a pre-contractual request), the data subject as a party to the contract, and the objective necessity of the specific processing operation.
  * **Necessity** is a concept of EU law: the processing must be objectively indispensable, not merely useful ([CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms/Bundeskartellamt](https://curia.europa.eu/juris/liste.jsf?num=C-252/21\&language=de)).
  * Third-party data, special categories (Article 9 GDPR) and a **change of legal basis** after the contract has ended are not covered by point (b).
  * Service improvement, fraud prevention, behavioral advertising and mere personalization can as a rule **not** be based on point (b) in the online context.
</Callout>

## 1 Overview [#1-overview]

### 1.1 Legal consequence and scope [#11-legal-consequence-and-scope]

Where the requirements of point (b) are met, the provision legitimizes any processing that is necessary for the performance of the contract or for the pre-contractual steps. Additional consent or a balancing of interests is not required. The legal basis covers both contracts between private parties and contractual relationships under public law with the data subject.

### 1.2 Requirements at a glance [#12-requirements-at-a-glance]

The legal basis requires cumulatively:

* a valid contract under civil or public law (or a pre-contractual request),
* that the data subject is itself a party to the contract,
* the objective necessity of the specific processing operation for the performance of the contract (or for the pre-contractual step).

### 1.3 Distinction from consent and terms of use [#13-distinction-from-consent-and-terms-of-use]

Accepting terms of use in the context of a contract does not constitute consent under Article 6(1)(a) GDPR. The two legal bases have different requirements and different legal consequences, in particular as regards the freely given nature of consent, its withdrawal and transparency ([EDPB, Guidelines 2/2019, para. 20](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf)). The controller must communicate clearly from the outset which legal basis it relies on and must state that basis in the information provided under Articles 13 and 14 GDPR. Conversely, where processing is in fact necessary for the performance of the contract, consent is not the appropriate legal basis; an apparently parallel request for consent then creates confusion as to the legal basis and does not satisfy the transparency requirement.

### 1.4 No basis for special categories (Article 9 GDPR) [#14-no-basis-for-special-categories-article-9-gdpr]

Article 9(2) GDPR provides for no exception covering the "performance of a contract". Where the controller processes special categories of personal data (Article 9(1) GDPR), point (b) alone is not sufficient; an additional ground for lawful processing under Article 9(2)(b) to (j) GDPR or explicit consent under Article 9(2)(a) GDPR is required ([EDPB, Guidelines 2/2019, para. 21](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf)).

### 1.5 Embedding in the principles under Article 5 GDPR [#15-embedding-in-the-principles-under-article-5-gdpr]

The legal basis does not dispense with the principles laid down in Article 5 GDPR. In particular, fairness (Article 5(1)(a) GDPR), purpose limitation (Article 5(1)(b) GDPR) and data minimization (Article 5(1)(c) GDPR) must be taken into account when interpreting point (b). The fairness principle requires consideration of the reasonable expectations of the data subject, of any adverse consequences of the processing and of a possible imbalance of power between the parties. Purposes must be specified with sufficient precision; vague formulations such as "improving the user experience", "marketing purposes", "IT security purposes" or "future research" are not sufficient for that ([EDPB, Guidelines 2/2019, para. 16](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf)).

## 2 The contract as the point of reference [#2-the-contract-as-the-point-of-reference]

### 2.1 A valid contract as the basis [#21-a-valid-contract-as-the-basis]

The point of reference is a contract between the controller and the data subject that is valid under the applicable contract law. Validity is governed by national contract law, including the rules on the legal capacity of minors and on unfair terms in consumer contracts (§§ 305 et seq. of the German Civil Code (BGB), transposing Directive 93/13/EEC). The provision is not limited to contracts governed by the law of an EEA Member State.

### 2.2 Contracts under civil law [#22-contracts-under-civil-law]

All valid obligations between the controller and the data subject are covered. The type of contract is irrelevant: contracts of sale, service contracts, contracts for work, loan agreements, tenancy agreements, insurance contracts, employment contracts, treatment contracts and online usage contracts are covered alike.

### 2.3 Quasi-contractual obligations [#23-quasi-contractual-obligations]

Quasi-contractual obligations may also fall under point (b) where they create comparable ties. This concerns in particular the management of another's affairs without a mandate (negotiorum gestio), where an expressly concluded contract is lacking but a statutory obligation exists that gives rise to comparable duties.

### 2.4 Collective bargaining agreements and works agreements [#24-collective-bargaining-agreements-and-works-agreements]

Collective bargaining agreements and works agreements are contentious. They bind the individual employee without that employee being a party to the contract in the narrower sense. In part they are recognized as a "contract" within the meaning of point (b), but predominantly only where the specific processing operation constitutes the necessary implementation of a specific obligation based on a collective bargaining agreement or a works agreement. Otherwise, recourse remains to Article 88 GDPR in conjunction with § 26 of the German Federal Data Protection Act (BDSG) or to points (c) and (f).

### 2.5 Void contracts [#25-void-contracts]

If a contract is void, point (b) is in principle ruled out as a legal basis. For processing operations already carried out, however, point (c) (statutory obligations to unwind the contract) or point (f) (legitimate interest in unwinding the contract) may serve as a basis.

### 2.6 Third-party data [#26-third-party-data]

Article 6(1)(b) GDPR supports only the processing of data of the contracting parties. Where data of third parties are processed, for instance those of relatives of a policyholder, of creditors of the debtor or of relatives of a patient, a separate legal basis is required; as a rule only point (f) comes into consideration.

## 3 Pre-contractual steps [#3-pre-contractual-steps]

### 3.1 The request of the data subject as a statutory requirement [#31-the-request-of-the-data-subject-as-a-statutory-requirement]

The second alternative of point (b) covers processing operations carried out in order to take pre-contractual steps. The requirement is that the step be taken "at the request of the data subject". Approaches made by the controller on its own initiative to the data subject are not covered. Whether a contract is in fact subsequently concluded is irrelevant; what matters is that the request is connected with a possible conclusion of a contract ([EDPB, Guidelines 2/2019, para. 46](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf)).

### 3.2 Typical constellations [#32-typical-constellations]

Covered are, for example, the assessment of creditworthiness in advance of a loan agreement at the request of the potential borrower, obtaining a quote for an insurance contract, or an application by the data subject for a position. Simple availability queries, such as entering a postal code in order to check whether a service is offered in a given region, also fall within this ([EDPB, Guidelines 2/2019, Example 5](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf)). The common feature is that the data subject takes the initiative and therefore has a legitimate interest in prompt handling.

### 3.3 Distinction from advertising measures [#33-distinction-from-advertising-measures]

Advertising intended to initiate new contractual relationships is not a pre-contractual step within the meaning of point (b). At most, it can be justified under point (f) or by consent under point (a).

### 3.4 Distinction from legal obligations [#34-distinction-from-legal-obligations]

Where the data processing is triggered not by the request of the data subject but by a legal obligation of the controller, point (c) is the appropriate legal basis and not point (b). A classic case is the identity verification carried out by banks under anti-money laundering law before an account contract is concluded ([EDPB, Guidelines 2/2019, Example 6](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf)).

## 4 The necessity criterion [#4-the-necessity-criterion]

### 4.1 A concept of EU law [#41-a-concept-of-eu-law]

"Necessary" is an autonomous concept of EU law. It is not exhausted by the question of what the contract formally permits or expressly provides for; rather, it calls for a fact-based assessment of whether the specific processing operation is necessary in relation to the purpose pursued and is to be preferred over less intrusive alternatives. Processing operations that are merely useful for the main performance, or that serve exclusively other business purposes of the controller, do not meet the criterion.

### 4.2 "Objectively indispensable", not merely "useful" [#42-objectively-indispensable-not-merely-useful]

The CJEU requires that the processing be "objectively indispensable" for the performance of the contract. Processing that merely improves or personalizes the service does not meet this criterion ([CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms/Bundeskartellamt, paras. 98 et seq.](https://curia.europa.eu/juris/liste.jsf?num=C-252/21\&language=de)). The benchmark is the performance characteristic of the contract: only processing operations that are directly linked to the main obligation owed or to a necessary ancillary obligation are permissible. In the competition law proceedings concerning Facebook, the German Federal Court of Justice (BGH) emphasized that the performance characteristic of the contract must be construed narrowly in order to protect the data subject against an arbitrary extension of the content of the contract ([BGH, order of 23 June 2020, KVR 69/19, paras. 110 et seq.](https://juris.bundesgerichtshof.de/cgi-bin/rechtsprechung/document.py?Gericht=bgh\&Art=en\&nr=109506)). The drafting of the contract may not extend the criterion at will. A mere reference in the fine print does not render the processing necessary.

### 4.3 Steps of the assessment [#43-steps-of-the-assessment]

In practice, necessity can be assessed along four questions ([EDPB, Guidelines 2/2019, para. 33](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf)):

<Steps>
  <Step>
    **Nature of the service**

    : what service is provided to the data subject and what are its characteristic features?
  </Step>

  <Step>
    **Rationale of the contract**

    : what is its objective and its subject matter, and what have the parties recognizably agreed on?
  </Step>

  <Step>
    **Essential elements**

    : which processing operations belong to the core of the service and which do not?
  </Step>

  <Step>
    **Horizon of expectations**

    : would an average user of the service, aware of how it is marketed and of what it comprises, reasonably expect the intended processing to take place for the performance of the contract?
  </Step>
</Steps>

If the assessment shows that the intended processing goes beyond what is objectively necessary, this does not automatically mean that it is unlawful; the controller must then, however, switch to another legal basis (in particular point (a) or point (f)) and adjust its transparency obligations accordingly.

### 4.4 The perspective of both sides [#44-the-perspective-of-both-sides]

Necessity is not to be assessed solely from the controller's point of view. What matters is whether the main contractual purpose could still be meaningfully achieved without the processing in question, seen from the perspective of a reasonably discerning data subject. That requires a genuine mutual understanding of the purpose of the contract; an objective documented solely internally by the provider is not sufficient for that.

### 4.5 Bundling of several services [#45-bundling-of-several-services]

Where a contract comprises several services or several independent elements of a service that can be performed independently of one another, the requirements of point (b), and in particular necessity, must be assessed separately for each individual service ([CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms/Bundeskartellamt, para. 94](https://curia.europa.eu/juris/liste.jsf?num=C-252/21\&language=de); [EDPB, Guidelines 2/2019, paras. 36 et seq.](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf)). A blanket legitimization of all data processing operations by means of a comprehensive description of services in the terms of use is therefore ruled out. Processing operations that serve solely the controller's broader business model cannot be based on point (b).

### 4.6 Ancillary and follow-up performance [#46-ancillary-and-follow-up-performance]

Point (b) covers not only the main contractual obligation but also ancillary activities that are reasonably foreseeable and necessary in the context of a normal contractual relationship, such as payment processing, reminders in the event of late payment, or the correction of errors and delays in the provision of the service ([EDPB, Guidelines 2/2019, para. 38, Example 3](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf)). The storage of certain data for the duration of a contractual warranty period may also be covered by point (b).

### 4.7 New technologies and changes to the service [#47-new-technologies-and-changes-to-the-service]

Where a new technology is introduced during the term of the contract, or the service is otherwise further developed, necessity must be assessed afresh for every new or modified processing operation. Necessity once affirmed does not continue to apply where the purpose of the processing or the service changes.

## 5 Termination and end of the contract [#5-termination-and-end-of-the-contract]

### 5.1 Principle: cessation of the purpose leads to discontinuation [#51-principle-cessation-of-the-purpose-leads-to-discontinuation]

Where the contract ends in full, the purpose of the processing based on point (b) as a rule ceases to exist. The processing must be discontinued; stored data must be erased pursuant to Article 17(1)(a) GDPR. Already when the processing begins, the controller should determine what is to happen when the contract ends and should communicate the storage period transparently.

### 5.2 No "switch" of legal basis [#52-no-switch-of-legal-basis]

A subsequent switch to another legal basis (e.g. point (f)) in order to continue the processing after the contract has ended is in principle impermissible. The data subject provided the data in reliance on the contractual context; relabeling after the event infringes the principle of fairness under Article 5(1)(a) GDPR ([EDPB, Guidelines 2/2019, para. 41](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf)).

### 5.3 Continuing processing on another basis [#53-continuing-processing-on-another-basis]

Steps taken to unwind the contract, such as returns or refunds, are themselves reasonably foreseeable consequences of the contract and can continue to be based on point (b). Beyond that, processing operations remain permissible that rested on their own legal basis from the outset and were communicated transparently, such as retention pursuant to obligations under commercial or tax law (point (c) in conjunction with § 257 of the German Commercial Code (HGB) and § 147 of the German Fiscal Code (AO)) or the defense of legal claims (point (f) in conjunction with Article 17(3)(e) GDPR). Such purposes must be determined before the processing begins and must be disclosed to data subjects in accordance with Articles 13 and 14 GDPR.

## 6 Typical processing operations in the online context that point (b) does not support [#6-typical-processing-operations-in-the-online-context-that-point-b-does-not-support]

In Guidelines 2/2019, the EDPB identified four case groups in which point (b) is regularly not a viable legal basis. The CJEU confirmed this dividing line in the Meta judgment.

### 6.1 Service improvement and new functionalities [#61-service-improvement-and-new-functionalities]

The analysis of usage behavior in order to improve an existing service or to develop new functionalities can as a rule not be based on point (b). The service could also be provided without the processing; the contractual clause permitting such analyses does not replace the necessity assessment. Point (a) or point (f) come into consideration as a legal basis ([EDPB, Guidelines 2/2019, paras. 48 et seq.](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf)).

### 6.2 Fraud and abuse prevention [#62-fraud-and-abuse-prevention]

Monitoring and profiling for the purpose of fraud prevention likewise typically go beyond what is objectively necessary. Necessary measures can, however, regularly be based on point (f); where a legal obligation exists (e.g. to prevent money laundering), point (c) applies ([EDPB, Guidelines 2/2019, para. 50](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf)).

### 6.3 Behavioral online advertising [#63-behavioral-online-advertising]

Behavioral advertising, tracking and profiling for the purpose of ad targeting are not a performance characteristic of the contract, even where the service is financed by advertising. The absolute right to object under Article 21(2) GDPR would be deprived of effect if the provider were able to rely on point (b). In addition, § 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG) requires consent for the storage of, or access to, information on terminal equipment (cookies, tracking pixels, fingerprinting). Lookalike and audience matching aimed at advertising to other persons likewise already fail on the necessity requirement ([EDPB, Guidelines 2/2019, paras. 51 et seq.](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf)).

### 6.4 Personalization of content [#64-personalization-of-content]

The personalization of content is supported by point (b) only where it is an integral part of the service that the parties recognizably took as given. What matters is the nature of the service, the way it is marketed to users, and the question whether the service can be meaningfully provided at all without personalization. Where personalization serves only to retain users or to increase interactivity, objective necessity is lacking; the processing must then be based on another legal basis ([EDPB, Guidelines 2/2019, para. 57](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf)).

<Callout type="warn">
  The line between "integral part" and "merely conducive to user retention" is a narrow one in practice. Anyone seeking to base personalization on point (b) should anchor and market it within the service offering so specifically that the average data subject recognizes it as a core function; otherwise, only point (a) or point (f) with a sound balancing of interests remains.
</Callout>

## 7 Case groups [#7-case-groups]

### 7.1 Banking transactions [#71-banking-transactions]

The processing of identification, account and transaction data is in principle necessary for handling the account contract and for carrying out payment orders. Special statutory requirements, for example under anti-money laundering law, additionally lead to point (c).

### 7.2 Employment relationships [#72-employment-relationships]

The processing of personal data in the employment relationship is largely governed by Article 88 GDPR in conjunction with § 26 BDSG. Insofar as the data concerned are necessary for the establishment, performance or termination of the employment contract, the processing is also based on point (b).

### 7.3 Debt collection and factoring [#73-debt-collection-and-factoring]

In the case of receivables purchase and debt collection, the main points of dispute concern the passing on of debtor data. Debt collection activity aimed at enforcing a claim against the debtor can be based on point (b) insofar as the claim arises from a contract with the debtor itself; the transmission to third parties (such as credit reference agencies) requires additional legal bases, as a rule point (f).

### 7.4 Marketing and customer retention [#74-marketing-and-customer-retention]

Advertising and customer retention are not a performance characteristic of the contract. Advertising to existing customers can be based on point (f) where the requirements of Article 21 GDPR and of competition law (in particular § 7 of the German Act Against Unfair Competition (UWG)) are complied with. Discount and loyalty programs are in principle to be legitimized under point (b) on account of their core performance promise, insofar as they are consistent with the participation agreement.

### 7.5 Medical treatment [#75-medical-treatment]

The treatment contract (§§ 630a et seq. BGB) supports the processing of data concerning health insofar as such processing is necessary for the treatment. Because of Article 9 GDPR, Article 9(2)(h) GDPR in conjunction with the duties of confidentiality under professional law applies in addition.

### 7.6 Tenancy relationships [#76-tenancy-relationships]

The processing of tenant data for the performance of the tenancy agreement (billing, service charge statements, maintenance) is regularly necessary. Processing going beyond that, such as video surveillance in a multi-family building, is subject to the balancing of interests under point (f) ([CJEU, judgment of 11 December 2019, C-708/18, Asociaţia de Proprietari, paras. 40 et seq.](https://curia.europa.eu/juris/liste.jsf?num=C-708/18\&language=de)).

### 7.7 Online services [#77-online-services]

In the case of online services, particular care must be taken in examining which processing operations belong directly to the service owed under the contract. Under the Meta case law, personalization, behavioral advertising or the cross-service linking of user data cannot be based on point (b) ([CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms/Bundeskartellamt, para. 102](https://curia.europa.eu/juris/liste.jsf?num=C-252/21\&language=de)). The scope of permissible processing must be assessed separately for each individual service element offered.

### 7.8 Mail order business [#78-mail-order-business]

In mail order business, the collection of the delivery address, communication about the shipment as well as the handling of returns and warranty claims are covered by point (b). Where the data subject instead chooses a pick-up point, the processing of the home address is no longer necessary and requires another legal basis ([EDPB, Guidelines 2/2019, Example 1](https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf)). Scoring and creditworthiness checks require a separate legal basis; as a rule only point (f) with a balancing of interests comes into consideration.

### 7.9 Insurance [#79-insurance]

The processing for handling insurance contracts (premium calculation, claims settlement) is covered by point (b). For the processing of data concerning health and for checks for insurance fraud, additional legal bases (Article 9(2)(h) GDPR, point (f)) must be examined.

<Callout type="info">
  Since the CJEU's Meta judgment, point (b) offers considerably less scope for many processing operations in the online context than it did previously. Anyone seeking to rely on the provision must set out specifically why the processing is objectively indispensable for the main performance owed. As soon as the processing serves only the provider's economic interest, only consent or the balancing of interests under point (f) remains.
</Callout>

<Cards>
  <Card title="Legal bases (Article 6 GDPR)" href="/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung" description="Structure and overview." />

  <Card title="Consent" href="/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.1-einwilligung" description="Article 6(1)(a) GDPR." />

  <Card title="Legitimate interests" href="/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.6-berechtigte-interessen" description="Article 6(1)(f) GDPR." />

  <Card title="EDPB Guidelines 2/2019" href="https://www.edpb.europa.eu/sites/default/files/files/file1/edpb_guidelines-art_6-1-b-adopted_after_public_consultation_de_0.pdf" description="EDPB guidelines on Article 6(1)(b) GDPR in the online context." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.