SecurSentry
← All notes
UK GDPR

The Six Lawful Bases for Processing Personal Data, in Plain English

You keep seeing 'lawful basis' and wondering which one applies to you. Here are the six options in plain English, with a simple way to choose the right one for each thing you do with data.

The short version

If you run a small business, ‘lawful basis’ is one of those phrases that turns up everywhere in data protection guidance and never quite gets explained. The rule underneath it is simpler than the jargon suggests: before you do anything with someone’s personal data, you need a valid reason that the law recognises, and there are six to choose from. Getting your lawful basis for processing right isn’t about memorising legislation. It’s about matching what you’re doing with data to the option that genuinely fits, then writing it down. This guide walks through all six in plain English and gives you a way to pick.

What ‘lawful basis’ actually means

A lawful basis is the legal reason you’re allowed to use someone’s personal data, and under UK GDPR you must have one in place before you start.

Under the UK GDPR, you can’t process personal data just because it’s useful or convenient. You need to identify a valid lawful basis first. The ICO (the Information Commissioner’s Office, the UK’s data protection regulator) sets out six of them in Article 6, and at least one must apply to each thing you do with data.

Three habits go with this:

The word ‘processing’ is broad, by the way. It covers collecting, storing, using, sharing, and deleting. Holding a customer list is processing. So is sending an email to it.

The six lawful bases, one by one

There are six lawful bases under Article 6 — consent, contract, legal obligation, vital interests, public task, and legitimate interests — and most small businesses will use three or four of them across different activities.

Here’s each one in plain terms, with an example a small business would recognise.

1. Consent. The person has clearly agreed to you using their data for a specific purpose. Real consent has to be freely given, specific, informed, and unambiguous, which means a clear opt-in, never a pre-ticked box or a buried clause. The catch: the person can withdraw it at any time, and you have to make that as easy as giving it was. Example: a visitor ticks a box to join your newsletter.

2. Contract. You need the data to deliver a contract with the person, or to take steps they’ve asked for before entering one. Example: you take a customer’s name and address to fulfil an order they’ve placed. No order, no contract to perform, so this basis wouldn’t apply.

3. Legal obligation. The law requires you to process the data. This is about obligations set out in law, not contractual ones. Example: keeping financial records to meet HMRC and Companies House requirements, or holding payroll data because employment law says you must.

4. Vital interests. You need to process the data to protect someone’s life. In practice this is rare for an ordinary business and tends to come up only in genuine emergencies. Example: passing a collapsed employee’s medical details to paramedics when they can’t consent themselves. Don’t reach for this one for everyday work.

5. Public task. You’re carrying out a task in the public interest or exercising official authority, and that task has a clear basis in law. This is mostly the territory of public bodies and isn’t usually relevant to a private SME. It’s included for completeness, and so you can rule it out with confidence.

6. Legitimate interests. You have a genuine business reason for the processing, that reason doesn’t override the person’s rights and freedoms, and they’d reasonably expect what you’re doing. This is the most flexible basis, and the one with the most strings attached, which we’ll come back to. Example: keeping basic records of business contacts so you can run the relationship, or sensible security monitoring of your own systems.

NO BASIS IS 'STRONGER'

It's tempting to treat consent as the gold standard, or to assume one basis is safer than the rest. The ICO is explicit that no single lawful basis is better or more important than the others. The 'right' one is simply the one that genuinely fits what you're doing and why. Picking a basis because it sounds the most thorough, rather than because it fits, tends to create more problems than it solves.

Consent is the right basis when someone is making a genuine free choice, but for ordinary business activity another basis nearly always fits better.

A lot of small businesses reach for consent first, because it feels like the most respectful option. Often it’s the most fragile.

The person can withdraw consent whenever they like, and the moment they do, your basis for that processing disappears. If you’re relying on consent to hold a customer’s order details and they withdraw it halfway through fulfilment, you’ve got a problem you’ve created for yourself. For something you simply have to do to run the business, like delivering an order or keeping tax records, consent is the wrong shape. You don’t actually want the person to be able to switch it off, and pretending the choice is real when it isn’t is its own breach.

Consent is for choices people are genuinely free to make. If you’d carry on processing the data whether they said yes or no, consent was never the honest basis to begin with.

Consent earns its place where there’s a real, free choice: marketing sign-ups, optional features, anything the person can take or leave without losing the core service. Tie it to things you need to do anyway and it stops being meaningful.

Legitimate interests: flexible, but you have to show your working

Legitimate interests is the most adaptable basis, but you can only rely on it after a balancing exercise that weighs your interest against the person’s rights.

Legitimate interests under the UK GDPR is the one businesses lean on most, and it’s worth understanding properly because it asks something of you in return for the flexibility. You can’t just declare it. You have to carry out a balancing exercise, usually called a legitimate interests assessment, or LIA. It’s a short, honest three-part check:

  1. Purpose. Is there a genuine, specific interest you’re pursuing? ‘Running the business sensibly’ is too vague. ‘Keeping a record of suppliers so we can manage orders’ is real.
  2. Necessity. Is the processing actually needed to achieve that interest, or could you do it a less intrusive way? If a lighter approach works, use it.
  3. Balance. Do your interests override the person’s rights and reasonable expectations? Would they be surprised or harmed by what you’re doing? If the answer tips towards them, legitimate interests doesn’t cover it.

Write the assessment down and keep it. It doesn’t need to be long, but it does need to exist. If the ICO ever asks why you relied on legitimate interests, a dated note that shows you thought it through beats a confident answer given on the spot.

A simple way to choose for your business

Pick your basis activity by activity: ask what you’re doing with the data and why, then match it to the basis that genuinely fits.

You don’t choose one lawful basis for the whole business. You choose one for each purpose, and the same business will quite normally use several. Run through what you actually do with personal data and label each one. A few common SME examples:

WHEN THE DATA IS EXTRA-SENSITIVE

Some data needs more than an Article 6 basis. Special category data — health, ethnicity, religious or philosophical beliefs, sexual orientation, biometric data used to identify someone, and a few others — needs an additional condition under Article 9 on top of your lawful basis. That's two boxes to tick, not one. If you handle this kind of data, treat it carefully and get advice before you process it. Your GDPR policy starter pack is a good place to record which conditions apply.

The point that catches people out: once you’ve chosen and recorded a basis, you shouldn’t swap it later to suit yourself. The ICO is clear that switching after the fact tends to be unfair to people and breaches the transparency and accountability rules. So spend a little time getting it right the first time. It’s far less effort than unpicking the wrong choice down the line.

Knowing the six lawful bases isn’t the hard part. The skill is the habit: for each thing you do with personal data, pause, ask what you’re doing and why, pick the basis that honestly fits, write it down, and reflect it in your privacy notice. Do that across your handful of real activities and the whole topic stops being abstract. It becomes a short, sensible list you can stand behind.

SecurSentry is launching soon to help UK SMEs work out their lawful basis for each activity, record it properly, and keep their privacy notices honest and up to date. Join the waitlist to be first to know when we open.


This article is general information, not legal or compliance advice. If you handle special category data, or you’re unsure which lawful basis fits a particular activity, seek qualified guidance from a data protection professional or solicitor.

Frequently asked questions

What are the six lawful bases for processing under UK GDPR?

Article 6 of the UK GDPR sets out six lawful bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. You must have at least one valid basis in place before you process personal data, and you should record which one you're relying on for each purpose.

Is consent the best lawful basis to rely on?

No. The ICO is clear that no single basis is better or more important than the others — the right one depends on your purpose. Consent is often the wrong choice for ordinary business activity because it can be withdrawn at any time and must be freely given, specific, informed, and unambiguous. For routine work, contract, legal obligation, or legitimate interests usually fits better.

Can I change my lawful basis later if the first one turns out to be wrong?

You should not plan to. The ICO says that if you pick the wrong basis it can be difficult to swap to another one later, because switching after the fact is likely to be unfair to people and to breach the accountability and transparency rules. Choose your basis carefully before you start processing, and document why you picked it.

Does special category data need anything extra?

Yes. Special category data — things like health, ethnicity, religious beliefs, or sexual orientation — needs an additional condition for processing under Article 9, on top of your Article 6 lawful basis. So if you handle this kind of data you have two things to get right, not one. If you're unsure, take advice before you process it.

Written by The SecurSentry Team

We write plain-English notes on security and compliance for small businesses — the things we wish someone had explained to us. Read more notes →

More from the blog

UK GDPR

Does a Small Business Need a Data Protection Officer (DPO)?

29 Jul 2026 · 9 min
UK GDPR

Data Retention for Small Businesses: How Long to Keep Personal Data

25 Jul 2026 · 8 min
UK GDPR

What a Record of Processing Activities (ROPA) Is, and How to Build One

19 Jul 2026 · 7 min

Be first to know when we launch.

Leave your email and we'll let you know the moment SecurSentry is ready. One email — no newsletters, no spam.

Just one email, at launch. We never share your data. Privacy policy.

You're on the list — we'll be in touch at launch.