# Legal Obligation (Article 6(1)(c) GDPR)

Legal obligation as a legal basis: the direct link between the obligation and the processing, the controller as the addressee of the obligation, the requirements for the Union or Member State legal basis under Article 6(3) GDPR, and practical examples.

> Quelle: https://www.thomashelbing.com/en/wissen/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.3-rechtliche-verpflichtung
> Sprache: en



Under Article 6(1)(c) GDPR, processing is lawful where it is necessary for compliance with a legal obligation to which the controller is subject. The provision takes account of the fact that numerous statutory obligations, for instance under tax, commercial, social security and labor law, cannot be complied with without the processing of personal data. Point (c) is not itself a legal basis, however, but the gateway to the provision of Union or Member State law that actually legitimizes the processing.

<Callout type="info">
  **Key takeaways**

  * Point (c) requires a **genuine obligation to act**, not a mere permission; a bare authorization does not suffice and points instead to point (e) or (f).
  * The obligation must **relate directly to the processing**: it is not sufficient that the controller can comply with some other obligation only if it incidentally also processes data.
  * The addressee of the obligation must be the **controller itself**; obligations imposed on third parties do not support processing by the controller.
  * The obligation must follow from Union or Member State law, must determine the purpose of the processing and must, under Article 6(3) GDPR, be **clear, precise and proportionate**.
  * The processing remains limited to the **extent necessary** to comply with the obligation; any processing going beyond this, or carried out "as a precaution", requires its own legal basis.
</Callout>

## 1 Overview [#1-overview]

### 1.1 Legal consequence [#11-legal-consequence]

Where a relevant legal obligation exists, it supports the processing necessary for that purpose without any need for additional consent or a balancing of interests. The processing must, however, remain within the limits of the statutory obligation; processing carried out on a stockpiling basis or "as a precaution" that goes beyond the statutory obligation cannot be based on point (c).

### 1.2 Requirements at a glance [#12-requirements-at-a-glance]

The legal basis presupposes:

* a legal obligation in the sense of a concrete obligation to act,
* which relates directly to the processing of data,
* the addressee of the obligation is the controller,
* the obligation is based on Union or Member State law (Article 6(3) GDPR),
* the processing is necessary for compliance with the obligation.

The following diagram shows the assessment in context; only where every stage is passed does point (c) support the processing.

<Mermaid
  chart="flowchart TD
  A[Obligation arising from a legal provision?] -->|no| X[point c does not apply]
  A -->|yes| B[Does the obligation relate directly to the processing?]
  B -->|no, processing merely a factual consequence| F[consider another legal basis, e.g. point f]
  B -->|yes| C[Does the obligation apply to the controller itself?]
  C -->|no| F
  C -->|yes| D[Is the processing necessary to comply with the obligation?]
  D -->|no| F
  D -->|yes| E[point c supports the processing to the extent necessary]"
/>

### 1.3 Direct link to the processing of data [#13-direct-link-to-the-processing-of-data]

The GDPR does not define the term "legal obligation"; what is meant is an obligation arising from a legal provision. The decisive point is that this obligation **relates directly to the processing of data**. The provision must therefore mandate the processing itself and not merely set out a task or an objective that, in practical terms, can be achieved only by processing data.

The relevant test is whether the controller would infringe the statutory obligation (or an order based on statute) if it refrained from carrying out the processing in question. Only in that case is the processing itself the subject matter of the obligation and supported by point (c).

By contrast, it is not sufficient that the controller can comply with some other legal obligation only if it processes personal data at the same time. In that case the processing is not what the law requires, but merely a factual side effect of compliance. It must be based on another legal basis, as a rule on the legitimate interest under [point (f)](/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.6-berechtigte-interessen).

### 1.4 Distinction from a mere authorization [#14-distinction-from-a-mere-authorization]

A legal obligation must be distinguished from a mere authorization. Point (c) requires an obligation, not simply a permission. Where national law affords the controller a margin of discretion, point (c) supports only the processing that is necessary to comply with a binding obligation. Beyond that, recourse must be had to point (e) or (f). In particular, the general principle of ex officio investigation under administrative procedural law is too vague in its substance for a legal obligation within the meaning of point (c) to be derived from it without sector-specific concretization; the relevant basis here is generally point (e). Nor does point (c) cover a transmission merely because the receiving body needs the data in order to perform its tasks.

### 1.5 Distinction from contractual obligations [#15-distinction-from-contractual-obligations]

The German wording is misleading in so far as contracts, too, give rise to "legal obligations". Point (c), however, covers only obligations arising from legal provisions. Processing for the performance of contractual obligations is governed by [point (b)](/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.2-vertrag-und-vorvertragliche-massnahmen), not by point (c). Other language versions express this more clearly, for instance the English ("compliance with a legal obligation") or the French ("respect d'une obligation légale").

## 2 Requirements for the legal basis [#2-requirements-for-the-legal-basis]

### 2.1 Union or Member State law [#21-union-or-member-state-law]

The legal obligation must arise from Union law or from the law of a Member State (Article 6(3), first sentence, GDPR). What matters is not only a formal act of parliament, but any law in the substantive sense. Statutory instruments, municipal by-laws and, in the employment context, the normative part of collective bargaining agreements as well as collective agreements such as works agreements and staff agreements (Article 88 GDPR) are therefore also covered. Whether the rules of professional bodies suffice depends on the constitutional order of the Member State concerned.

Mere administrative instructions, enforcement guidance or circulars and guidelines issued by supervisory authorities are not sufficient. They serve to interpret statutory requirements but do not in themselves establish a legal obligation within the meaning of Article 6(3) GDPR.

Legal provisions of third countries do not give rise to a legal obligation within the meaning of point (c) in the absence of an implementing or adopting act of a Member State (see the example in Section 5.7).

### 2.2 Determination of the purpose of the processing [#22-determination-of-the-purpose-of-the-processing]

The purpose of the processing must be determined in the legal basis itself (Article 6(3), second sentence, GDPR). Unlike under point (e), this determination of the purpose is mandatory under point (c). A legal provision may of course serve as the basis for several processing operations, and not every individual operation needs to be governed by a separate statute. The rules must, however, be so clear and precise that the permissible processing operations are foreseeable for the persons concerned.

### 2.3 Requirements as to specificity [#23-requirements-as-to-specificity]

The legal basis must be formulated in a clear and precise manner. The data subject must be able to discern which processing operations take place for which reasons and which rights and obligations follow from them. The German Federal Administrative Court (BVerwG) has repeatedly emphasized that the German legislature must observe sufficient specificity when giving effect to the opening clause and may not override the requirement of a separate empowering legal basis by way of a comprehensive catch-all provision ([BVerwG, judgment of 27 September 2018, 7 C 5/17, para. 25](https://www.bverwg.de/270918u7c5.17.0); [BVerwG, judgment of 27 March 2019, 6 C 2/18, paras. 45 et seq.](https://www.bverwg.de/270319u6c2.18.0)).

### 2.4 Proportionality [#24-proportionality]

The legal basis must pursue an objective in the public interest and be proportionate to the legitimate aim pursued (Article 6(3), fourth sentence, GDPR). The national legislature is not entitled to blur, by means of general catch-all clauses containing broadly framed balancing tests, the dividing line between the processing powers under points (c) and (e) on the one hand and the general clause in point (f) on the other ([BVerwG, judgment of 27 March 2019, 6 C 2/18, para. 42](https://www.bverwg.de/270319u6c2.18.0)).

### 2.5 Autonomous interpretation of necessity under EU law [#25-autonomous-interpretation-of-necessity-under-eu-law]

Even where the legal obligation stems from Member State law, necessity must be determined autonomously under EU law. The Court of Justice has given substance to this criterion in connection with the Central Register of Foreign Nationals: processing is necessary where it leads to a more efficient application of the underlying legal provisions and no less intrusive means are available ([CJEU, judgment of 16 December 2008, C-524/06, Huber, paras. 52 et seq.](https://curia.europa.eu/juris/liste.jsf?num=C-524/06\&language=de)).

## 3 Legal obligation of the controller [#3-legal-obligation-of-the-controller]

### 3.1 The controller as addressee [#31-the-controller-as-addressee]

The addressee of the legal obligation must be the controller itself. Obligations that apply only to third parties (for example other group companies) do not support processing by the controller. In the case of intra-group processing, careful consideration must therefore be given to which undertaking the statutory obligation applies.

Point (c) does not preclude the use of a processor. For the purposes of determining whether a legal obligation exists, however, regard must always be had to the controller, not to the processor. The processor acts on instructions; the obligation that supports the processing must apply to the controller.

### 3.2 No limitation to obligations under public law [#32-no-limitation-to-obligations-under-public-law]

The obligation may be of a public law or a private law nature, provided that it is rooted in a formal legal provision. Purely contractual obligations, by contrast, are not covered; for these, point (b) is the relevant basis.

### 3.3 Official orders and requests for information [#33-official-orders-and-requests-for-information]

Where a public authority requires the controller to disclose personal data, a careful distinction must be drawn between the authority's power to collect the data and the controller's power to transmit them. The statutory power of an authority to collect data does not in itself confer on the controller receiving the request any power to transmit them. In this respect, point (c) operates as a mirror provision to point (e).

Underlying this is the "double door" model familiar from German constitutional law: the legislature must open both the "door" to the collection of data by the authority and the "door" to the transmission by the controller. An official order therefore supports the transmission only where it is based on a sufficiently specific statutory transmission provision and where the requesting authority has a corresponding power to collect the data.

It follows at the same time that point (c) does not call for "blind obedience". The controller remains responsible for the processing under data protection law (Article 5(1)(a) and Article 24 GDPR). It is entitled, and in cases of doubt may be obliged, to examine the legal justification put forward by the requesting body; where the conditions of the empowering provision are manifestly absent, it may refuse to provide the information.

## 4 Necessity [#4-necessity]

### 4.1 Standard [#41-standard]

The processing must be necessary for compliance with the statutory obligation. It may not extend to data that go beyond the statutory purpose and must be limited to the extent required in order to comply with the obligation. Where a provision requires only that identity be established, for instance, it is not necessary also to collect details of bank accounts or of a person's reliability.

### 4.2 Limits imposed by the principle of data minimization [#42-limits-imposed-by-the-principle-of-data-minimization]

Point (c) does not dispense with the principle of [data minimization](/docs/dsgvo-hub/einzelthemen/grundsaetze-der-verarbeitung/1.3.3.5-datenminimierung) (Article 5(1)(c) GDPR). Where the statutory obligation can be complied with without processing particular data, the processing is precisely not necessary.

## 5 Practical examples [#5-practical-examples]

### 5.1 Commercial and tax law [#51-commercial-and-tax-law]

The retention of accounting records, commercial letters and annual financial statements under §§ 238 and 257 of the German Commercial Code (HGB) and § 147 of the German Fiscal Code (AO) supports the processing of the personal data they contain. This covers, in particular, invoices containing customer and supplier data, payroll records and employment contracts. These recording and retention obligations under commercial, trade, tax and social security law are among the classic cases falling under point (c).

### 5.2 Social security and labor law [#52-social-security-and-labor-law]

Reporting obligations towards social security institutions (§§ 28a et seq. and § 99 of the German Social Code (SGB), Book IV), the withholding and remittance of wage tax (§§ 41 et seq. of the German Income Tax Act (EStG)) and documentation obligations under occupational health and safety law call for the processing of employee data. The obligation to carry out company integration management (§ 167(2) SGB IX) likewise constitutes a legal obligation within the meaning of point (c) and includes the disclosure of the essential data to an employee representative body to be involved in the process, where the data subject agrees ([BAG, judgment of 17 April 2019, 7 AZR 292/17, para. 41](https://www.bundesarbeitsgericht.de/entscheidung/7-azr-292-17/)). In addition, obligations may arise from the reporting of employee inventions to the German Patent and Trade Mark Office under the combined operation of the German Employee Inventions Act (ArbnErfG) and the German Patent Act (PatG).

Conversely, general statutory duties of cooperation on the part of the data subject, for instance under §§ 60 et seq. of the German Social Code, Book I (SGB I), do not in themselves establish a legal obligation of the controller within the meaning of point (c).

### 5.3 Anti-money laundering, procurement and anti-corruption law [#53-anti-money-laundering-procurement-and-anti-corruption-law]

The German Money Laundering Act (§§ 10 et seq. GwG) requires financial institutions and other obliged entities to comply with obligations relating to identification, the assessment of suspicions and reporting. The associated processing of data is supported by point (c), in part overlaid by Article 9(2) GDPR where special categories of data are processed. Supervisory instructions or circulars in the banking and insurance sectors, by contrast, are not sufficient; they merely interpret the statutory requirements.

The mandatory suitability assessments under public procurement law likewise entail the processing of personal data, which may be based on point (c) where the statutory rules are sufficiently clear. Obtaining consent is inadvisable in these mandatory situations, because consent would be freely revocable and would not support the processing required by law.

### 5.4 Documentation of working time [#54-documentation-of-working-time]

The Court of Justice has inferred from Article 31(2) of the Charter of Fundamental Rights of the European Union and from the directives on working time that the Member States must require employers to set up a system enabling the duration of time worked each day by each worker to be measured ([CJEU, judgment of 14 May 2019, C-55/18, CCOO, para. 60](https://curia.europa.eu/juris/liste.jsf?num=C-55/18\&language=de)). The resulting processing of data is to be based on point (c). A corresponding obligation to grant access to the working time records may also exist vis-à-vis the competent enforcement authority.

### 5.5 Tachographs and driving times [#55-tachographs-and-driving-times]

The obligation to use tachographs under Regulation (EC) No 561/2006 applies to employees who are required to observe driving times and rest periods. No such obligation exists for all other employees; monitoring carried out "as a precaution" finds no basis in point (c). Nor does the recording obligation cover the collection of the distance driven or of the precise location.

### 5.6 Marketing: documenting consent to telephone marketing [#56-marketing-documenting-consent-to-telephone-marketing]

Anyone engaging in telephone marketing must document the explicit consent obtained beforehand and retain the record for five years (§ 7a of the German Act Against Unfair Competition (UWG)). This statutory documentation and retention obligation supports the associated processing via point (c), even where the advertiser would delete the data for data protection reasons in the absence of the obligation.

### 5.7 Legal obligations under third-country law [#57-legal-obligations-under-third-country-law]

Obligations under the law of third countries do not establish a legal obligation within the meaning of point (c) in the absence of an implementing or adopting act of a Member State. This applies, for example, to the requirements of the US Sarbanes-Oxley Act. In such situations, processing may at most be considered on the basis of the legitimate interest under [point (f)](/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.6-berechtigte-interessen) or, in the employment context, under Article 88 GDPR.

### 5.8 Insolvency administration [#58-insolvency-administration]

The insolvency administrator is required to preserve and realize the insolvency estate as effectively as possible, including by asserting the debtor's claims. That obligation does not, however, release the administrator from the general requirements of data protection law, even where compliance with them diminishes the estate. The legal obligation therefore supports only the processing necessary to perform the task, within the limits imposed by data protection law.

### 5.9 Duties of cooperation towards courts and public authorities [#59-duties-of-cooperation-towards-courts-and-public-authorities]

Where courts, in the course of their ex officio investigation, request files or documents from public authorities (§ 86(1) and § 99(1) of the German Code of Administrative Court Procedure (VwGO)), point (c) supports the transmission in so far as the obligation to produce the documents extends. In parallel, point (e) may be relevant for the performance of the judicial task itself ([CJEU, judgment of 8 December 2022, C-180/21, Inspectoratul General pentru Imigrări, paras. 83 et seq.](https://curia.europa.eu/juris/liste.jsf?num=C-180/21\&language=de)). Where a public authority responds to a request for information under press law, this can be assessed under point (c) or (e) only if there is a sufficiently specific empowering provision; where no such provision exists, the case law falls back on the substantive requirements of point (f) ([BVerwG, judgment of 27 September 2018, 7 C 5/17, paras. 24 et seq.](https://www.bverwg.de/270918u7c5.17.0)).

### 5.10 Information provided to law enforcement and security authorities [#510-information-provided-to-law-enforcement-and-security-authorities]

Where security authorities require undertakings to hand over customer data, sector-specific legal provisions are needed both for the collection by the authority and for the transmission by the undertaking (for instance the obligations of telecommunications providers to provide information under the German Telecommunications Act (TKG)). In particular, a mere need for information on the part of an authority does not justify the blanket retention of data for the purpose of combating crime ([CJEU, judgment of 8 April 2014, C-293/12 and others, Digital Rights Ireland](https://curia.europa.eu/juris/liste.jsf?num=C-293/12\&language=de)).

<Callout type="info">
  In practice, careful consideration must be given under point (c) to where the legal obligation ends. Any processing that goes beyond it requires its own legal basis. This also applies to "voluntary" accompanying measures by which the controller seeks to make compliance with statutory obligations easier for itself.
</Callout>

<Cards>
  <Card title="Legal Bases (Article 6 GDPR)" href="/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung" description="Structure and overview." />

  <Card title="Legitimate Interests" href="/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.6-berechtigte-interessen" description="Article 6(1)(f) GDPR." />

  <Card title="Public Interest and Official Authority" href="/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.5-oeffentliches-interesse-und-oeffentliche-gewalt" description="Article 6(1)(e) GDPR." />

  <Card title="Opening Clauses and National Law" href="/docs/dsgvo-hub/einzelthemen/rechtsgrundlagen-der-verarbeitung/1.3.2.8-oeffnungsklauseln-und-nationales-recht" description="Article 6(2) and (3) GDPR." />
</Cards>


---

## About the author

This article was written by [Dr. Thomas Helbing, specialist lawyer for IT law in Munich](https://www.thomashelbing.com/en).

Since 2020 and continuously through today (2026), Handelsblatt has [recognized](https://www.thomashelbing.com/en#auszeichnungen) Dr. Helbing as one of **"Germany's Best Lawyers"** in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the **leading lawyers for data protection and IT law** and is listed among the **top 100 lawyers in Germany (2024/25)**. Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has **many years of advisory experience in data protection and IT law** and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His [professional background](https://www.thomashelbing.com/en#stationen) covers the **full spectrum of IT and technology law practice**. He began his career at a major international law firm, then gained **in-house experience at a DAX-listed company**, and is himself an **entrepreneur and founder of several digital ventures**. He also has **hands-on programming experience**, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his [clients](https://www.thomashelbing.com/en#referenzen) have included **technology companies and SaaS providers**, leading **German research institutions** and a **systemically important German bank**. His advisory focus lies in particular on **GDPR compliance, the data economy, SaaS, AI regulation and IT contract law**.