Guides

A Practical Guide to GDPR Legal Bases Explained

Taras Shynkarenko
Taras Shynkarenko
•Updated: •6 min read
A Practical Guide to GDPR Legal Bases ExplainedA Practical Guide to GDPR Legal Bases Explained

TL;DR, Quick Answer

6 min read

GDPR Article 6 provides six legal bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Pick the basis that genuinely fits the purpose before processing begins.

Only one thing makes processing lawful, and the GDPR six legal bases processing personal data set out the whole menu: consent, contract, legal obligation, vital interests, public task and legitimate interests.

Under the GDPR, processing personal data is lawful only if at least one legal basis applies. The six legal bases are listed in GDPR Article 6: consent, contract, legal obligation, vital interests, public task, and legitimate interests.

Choosing a legal basis is not a paperwork exercise. It affects transparency wording, user rights, withdrawal options, objection rights, and whether the processing is defensible at all.

Consent applies when a person freely gives a specific, informed, and unambiguous indication of agreement. It must be as easy to withdraw as it is to give. Pre-ticked boxes, silence, inactivity, and bundled consent do not work.

Use consent when people have a real choice, such as optional marketing emails or non-essential cookies. Do not use consent when the person has no practical alternative, such as an employee being asked to consent to core HR processing.

For cookies and tracking, remember that ePrivacy consent may be required even before GDPR legal basis analysis. If analytics cookies are optional, they generally need prior consent in Europe unless a narrow exemption applies.

When consent holds up
Real choice exists
  • Optional marketing emails
  • Non-essential cookies with a genuine alternative
No real choice
  • An employee asked to consent to core HR processing
  • Pre-ticked boxes, silence, or bundled consent
Consent only works when withdrawal is as easy as giving it.

A courier handing over a package at someone's door, the kind of delivery that only needs an address under a contract basis.

2. Contract

Contract applies when processing is necessary to perform a contract with the person or to take requested steps before entering into a contract.

Examples:

  • Processing a shipping address to deliver an order.
  • Creating an account so a user can access a paid service.
  • Processing payment details for a subscription.

It does not cover processing that is merely useful to the business. Behavioral advertising is not necessary to deliver a SaaS account. Product analytics may support the service, but it usually needs a separate analysis.

Legal obligation applies when EU or member-state law requires the processing. Examples include tax records, employment law obligations, accounting retention, sanctions screening in some contexts, or responding to lawful regulatory requests.

The obligation must come from law, not a contract or internal policy. If a vendor contract says you must collect certain marketing data, that is not a GDPR legal obligation.

4. Vital Interests

Vital interests applies when processing is necessary to protect someone's life. It is narrow and rare in normal business operations.

Examples might include emergency medical information or crisis response. It is usually not relevant to website analytics, marketing, or SaaS onboarding.

5. Public Task

Public task applies when processing is necessary for a task carried out in the public interest or under official authority. It is mainly used by public bodies or private organizations exercising official functions under law.

Flowsery
Flowsery

Start Your 14-Day Free Trial

Real-time dashboard

Goal tracking

Cookie-free tracking

Most private companies cannot use public task for routine commercial processing.

6. Legitimate Interests

Legitimate interests can apply when the controller or a third party has a legitimate interest, the processing is necessary for that interest, and the person's rights and freedoms do not override it.

This requires a balancing test. A typical legitimate interests assessment asks:

  1. What is the legitimate interest?
  2. Is the processing necessary for that interest?
  3. What is the impact on individuals?
  4. What safeguards reduce that impact?
  5. Can people reasonably expect this processing?
  6. Can they object easily?

Potential examples include fraud prevention, network security, basic B2B prospecting, or limited first-party analytics in some contexts. But legitimate interests is not a magic phrase for tracking. Cross-site advertising, invasive profiling, sensitive inference, and unexpected data sharing are much harder to justify.

The legal basis changes the rights available:

Legal basisPractical consequence
ConsentUser can withdraw consent
ContractProcessing must be necessary for the contract
Legal obligationDeletion may be limited by retention laws
Vital interestsNarrow emergency use
Public taskObjection rights may apply
Legitimate interestsUser has a right to object

You must tell people the legal basis in your privacy notice.

Analytics Examples

A typical GA4 web setup uses cookies to distinguish users and sessions, as Google explains in its GA4 cookie documentation. In Europe, this usually raises ePrivacy consent questions before the analytics cookie is set. GDPR legal basis then depends on the processing design, vendor terms, transfers, and whether advertising features are enabled.

Cookieless aggregate analytics

A cookieless tool that avoids identifiers, IP storage, fingerprinting, advertising reuse, and personal event payloads reduces or avoids personal-data processing depending on implementation. Even then, the organization should document the purpose, data categories, retention, and vendor role.

Product analytics inside an account

Authenticated product analytics processes account-level personal data. Contract can cover events necessary to provide the service, while legitimate interests can cover security or product improvement. Sensitive or optional uses need consent or a different basis.

Common Mistakes

  • Choosing consent because it sounds safest, then making the service unusable if consent is refused.
  • Using contract for processing that is only useful for marketing.
  • Using legitimate interests without a balancing test.
  • Forgetting ePrivacy rules for cookies and device storage.
  • Changing purposes later without reassessing compatibility.
  • Failing to update the privacy notice when tools change.

The right legal basis is the one that honestly fits the processing. If no basis fits, the answer is not creative wording. The answer is to stop or redesign the processing.

How a bad basis compounds
1
Consent chosen for comfort. It feels safest, so the service breaks the moment someone declines it.
2
Purpose changes. Nobody checks whether the basis still fits the new purpose.
3
Tools change, wording doesn't. The privacy notice stops matching what actually happens.
4
Assumptions get inherited. Teams pick up the old choice instead of a documented reason.
A one-sentence record for each purpose keeps assumptions from becoming permanent.

Document the Choice

For each processing purpose, record the chosen basis and one sentence explaining why it fits. This is especially important for analytics, marketing, and AI features, where teams inherit assumptions from old tools. A short record is easier to maintain than a long memo nobody updates.

Someone writing on a clipboard at a desk, matching the practice of recording one legal basis per processing purpose.

For each analytics purpose, write down the legal basis and why it fits: public website audience measurement, marketing pixels, product telemetry, fraud prevention, account analytics, and support diagnostics each need a different analysis. Do not reuse one basis for the whole stack.

Also check ePrivacy rules before tags run. Even when GDPR legitimate interests may be arguable for limited analytics, device storage, cookies, pixels, SDKs, or similar access may still require consent unless a narrow exemption applies in the relevant jurisdiction.

Frequently Asked Questions

Legitimate interests can support some processing, but ePrivacy rules sit apart from the GDPR and usually require consent before an optional cookie is set. A narrow exemption covers strictly necessary cookies, but analytics and advertising cookies rarely qualify. Settle the ePrivacy question first, then pick the GDPR basis for what happens after.

Flowsery
Flowsery

Start Your 14-Day Free Trial

Real-time dashboard

Goal tracking

Cookie-free tracking

The processing has to stop or be redesigned. Careful wording in the privacy notice does not create a legal basis that was never there.

Rarely, because an employee asked to consent to core HR processing has no practical alternative to giving it. GDPR does not treat that as a free choice, so employers usually rely on contract or legal obligation instead.

Does contract cover behavioral advertising inside a SaaS product?

No, because behavioral advertising is not necessary to deliver the account someone paid for. Contract only covers what the agreement needs, like shipping an order or granting access to a paid service, so advertising needs its own basis such as consent or legitimate interests.

Is legitimate interests a safe default for tracking?

Legitimate interests is not a shortcut for tracking. Cross-site advertising, invasive profiling, sensitive inference, and unexpected data sharing are hard to justify under the balancing test, and each still needs a documented look at necessity, impact, and safeguards.

What does a legitimate interests balancing test actually check?

A legitimate interests balancing test asks whether the interest is real and whether the processing is necessary for it. It also weighs the impact on people and whether they can reasonably expect it or object easily. Fraud prevention, network security, and basic B2B prospecting can pass this test, but only with the assessment done and written down.

Most private companies cannot use public task for routine commercial processing, since it is meant for bodies exercising official functions under law. A private business handling orders or subscriptions should look at contract or legitimate interests instead.

The privacy notice must name the legal basis for each purpose, and that basis decides which rights to describe. Consent needs a withdrawal option, legitimate interests needs an objection right, and legal obligation needs an explanation of retention limits.

Does switching to cookieless analytics remove the need for a GDPR assessment?

Not automatically. A cookieless tool that avoids identifiers, IP storage, fingerprinting, and personal event payloads reduces or avoids personal-data processing depending on how it is implemented, but the organization still has to document the purpose, data categories, retention, and vendor role.

Different analytics purposes carry different risks and expectations. Public website audience measurement, marketing pixels, product telemetry, fraud prevention, account analytics, and support diagnostics each need their own analysis, so reusing one basis for everything skips the assessment each purpose actually needs.

Was This Article Helpful?

Let us know what you think!

See us more often in Google

One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.

Before you go...

Flowsery

Flowsery

Revenue-first analytics for your website

Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.

Real-time dashboard

Goal tracking

Cookie-free tracking

Related Articles