The Six Lawful Bases for Processing Personal Data, in Plain English
You keep seeing 'lawful basis' and wondering which one applies to you. Here are the six options in plain English, with a simple way to choose the right one for each thing you do with data.
The short version
- You need a valid lawful basis before you process personal data — there are six to choose from under Article 6, and you should identify, document, and tell people about your choice in your privacy notice.
- No basis is 'better' than another. The right one depends on why you're using the data. The same business will rely on different bases for different activities.
- Consent is often the wrong choice for ordinary business activity. It can be withdrawn at any time and sets a high bar, so for routine work another basis usually fits better.
- Legitimate interests is flexible but not a free pass. You have to do a balancing exercise — a legitimate interests assessment — weighing your interest against the person's rights before you rely on it.
If you run a small business, ‘lawful basis’ is one of those phrases that turns up everywhere in data protection guidance and never quite gets explained. The rule underneath it is simpler than the jargon suggests: before you do anything with someone’s personal data, you need a valid reason that the law recognises, and there are six to choose from. Getting your lawful basis for processing right isn’t about memorising legislation. It’s about matching what you’re doing with data to the option that genuinely fits, then writing it down. This guide walks through all six in plain English and gives you a way to pick.
What ‘lawful basis’ actually means
A lawful basis is the legal reason you’re allowed to use someone’s personal data, and under UK GDPR you must have one in place before you start.
Under the UK GDPR, you can’t process personal data just because it’s useful or convenient. You need to identify a valid lawful basis first. The ICO (the Information Commissioner’s Office, the UK’s data protection regulator) sets out six of them in Article 6, and at least one must apply to each thing you do with data.
Three habits go with this:
- Identify your basis before you process, not after. You can’t collect the data and decide why you were allowed to later.
- Document it. Write down which basis applies to which activity and why. This is part of your accountability duty, and it sits naturally alongside your record of processing activities.
- Tell people. Your privacy notice should say which lawful basis you rely on for each purpose, in language a normal person can follow.
The word ‘processing’ is broad, by the way. It covers collecting, storing, using, sharing, and deleting. Holding a customer list is processing. So is sending an email to it.
The six lawful bases, one by one
There are six lawful bases under Article 6 — consent, contract, legal obligation, vital interests, public task, and legitimate interests — and most small businesses will use three or four of them across different activities.
Here’s each one in plain terms, with an example a small business would recognise.
1. Consent. The person has clearly agreed to you using their data for a specific purpose. Real consent has to be freely given, specific, informed, and unambiguous, which means a clear opt-in, never a pre-ticked box or a buried clause. The catch: the person can withdraw it at any time, and you have to make that as easy as giving it was. Example: a visitor ticks a box to join your newsletter.
2. Contract. You need the data to deliver a contract with the person, or to take steps they’ve asked for before entering one. Example: you take a customer’s name and address to fulfil an order they’ve placed. No order, no contract to perform, so this basis wouldn’t apply.
3. Legal obligation. The law requires you to process the data. This is about obligations set out in law, not contractual ones. Example: keeping financial records to meet HMRC and Companies House requirements, or holding payroll data because employment law says you must.
4. Vital interests. You need to process the data to protect someone’s life. In practice this is rare for an ordinary business and tends to come up only in genuine emergencies. Example: passing a collapsed employee’s medical details to paramedics when they can’t consent themselves. Don’t reach for this one for everyday work.
5. Public task. You’re carrying out a task in the public interest or exercising official authority, and that task has a clear basis in law. This is mostly the territory of public bodies and isn’t usually relevant to a private SME. It’s included for completeness, and so you can rule it out with confidence.
6. Legitimate interests. You have a genuine business reason for the processing, that reason doesn’t override the person’s rights and freedoms, and they’d reasonably expect what you’re doing. This is the most flexible basis, and the one with the most strings attached, which we’ll come back to. Example: keeping basic records of business contacts so you can run the relationship, or sensible security monitoring of your own systems.
NO BASIS IS 'STRONGER'
It's tempting to treat consent as the gold standard, or to assume one basis is safer than the rest. The ICO is explicit that no single lawful basis is better or more important than the others. The 'right' one is simply the one that genuinely fits what you're doing and why. Picking a basis because it sounds the most thorough, rather than because it fits, tends to create more problems than it solves.
Why consent is usually the wrong default
Consent is the right basis when someone is making a genuine free choice, but for ordinary business activity another basis nearly always fits better.
A lot of small businesses reach for consent first, because it feels like the most respectful option. Often it’s the most fragile.
The person can withdraw consent whenever they like, and the moment they do, your basis for that processing disappears. If you’re relying on consent to hold a customer’s order details and they withdraw it halfway through fulfilment, you’ve got a problem you’ve created for yourself. For something you simply have to do to run the business, like delivering an order or keeping tax records, consent is the wrong shape. You don’t actually want the person to be able to switch it off, and pretending the choice is real when it isn’t is its own breach.
Consent is for choices people are genuinely free to make. If you’d carry on processing the data whether they said yes or no, consent was never the honest basis to begin with.
Consent earns its place where there’s a real, free choice: marketing sign-ups, optional features, anything the person can take or leave without losing the core service. Tie it to things you need to do anyway and it stops being meaningful.
Legitimate interests: flexible, but you have to show your working
Legitimate interests is the most adaptable basis, but you can only rely on it after a balancing exercise that weighs your interest against the person’s rights.
Legitimate interests under the UK GDPR is the one businesses lean on most, and it’s worth understanding properly because it asks something of you in return for the flexibility. You can’t just declare it. You have to carry out a balancing exercise, usually called a legitimate interests assessment, or LIA. It’s a short, honest three-part check:
- Purpose. Is there a genuine, specific interest you’re pursuing? ‘Running the business sensibly’ is too vague. ‘Keeping a record of suppliers so we can manage orders’ is real.
- Necessity. Is the processing actually needed to achieve that interest, or could you do it a less intrusive way? If a lighter approach works, use it.
- Balance. Do your interests override the person’s rights and reasonable expectations? Would they be surprised or harmed by what you’re doing? If the answer tips towards them, legitimate interests doesn’t cover it.
Write the assessment down and keep it. It doesn’t need to be long, but it does need to exist. If the ICO ever asks why you relied on legitimate interests, a dated note that shows you thought it through beats a confident answer given on the spot.
A simple way to choose for your business
Pick your basis activity by activity: ask what you’re doing with the data and why, then match it to the basis that genuinely fits.
You don’t choose one lawful basis for the whole business. You choose one for each purpose, and the same business will quite normally use several. Run through what you actually do with personal data and label each one. A few common SME examples:
- Fulfilling an order: contract. You need the customer’s details to deliver what they bought.
- Keeping invoices and tax records: legal obligation. The law requires it, so this isn’t your choice to make and consent would make no sense.
- Sending marketing emails: consent or legitimate interests, depending on the situation. For consumers, electronic marketing rules usually push you towards consent. For existing customers or business-to-business contacts, legitimate interests can apply, but only after you’ve done the balancing exercise and given a clear way to opt out.
- Basic HR and payroll: a mix. Some of it is legal obligation, some is contract, some is legitimate interests, depending on the specific task.
WHEN THE DATA IS EXTRA-SENSITIVE
Some data needs more than an Article 6 basis. Special category data — health, ethnicity, religious or philosophical beliefs, sexual orientation, biometric data used to identify someone, and a few others — needs an additional condition under Article 9 on top of your lawful basis. That's two boxes to tick, not one. If you handle this kind of data, treat it carefully and get advice before you process it. Your GDPR policy starter pack is a good place to record which conditions apply.
The point that catches people out: once you’ve chosen and recorded a basis, you shouldn’t swap it later to suit yourself. The ICO is clear that switching after the fact tends to be unfair to people and breaches the transparency and accountability rules. So spend a little time getting it right the first time. It’s far less effort than unpicking the wrong choice down the line.
Knowing the six lawful bases isn’t the hard part. The skill is the habit: for each thing you do with personal data, pause, ask what you’re doing and why, pick the basis that honestly fits, write it down, and reflect it in your privacy notice. Do that across your handful of real activities and the whole topic stops being abstract. It becomes a short, sensible list you can stand behind.
SecurSentry is launching soon to help UK SMEs work out their lawful basis for each activity, record it properly, and keep their privacy notices honest and up to date. Join the waitlist to be first to know when we open.
This article is general information, not legal or compliance advice. If you handle special category data, or you’re unsure which lawful basis fits a particular activity, seek qualified guidance from a data protection professional or solicitor.