TL;DR, Quick Answer
6 min readGDPR Article 6 provides six legal bases: consent, contract, legal obligation, vital interests, public task, and legitimate interests. Pick the basis that genuinely fits the purpose before processing begins.
Only one thing makes processing lawful, and the GDPR six legal bases processing personal data set out the whole menu: consent, contract, legal obligation, vital interests, public task and legitimate interests.
Under the GDPR, processing personal data is lawful only if at least one legal basis applies. The six legal bases are listed in GDPR Article 6: consent, contract, legal obligation, vital interests, public task, and legitimate interests.
Choosing a legal basis is not a paperwork exercise. It affects transparency wording, user rights, withdrawal options, objection rights, and whether the processing is defensible at all.
1. Consent
Consent applies when a person freely gives a specific, informed, and unambiguous indication of agreement. It must be as easy to withdraw as it is to give. Pre-ticked boxes, silence, inactivity, and bundled consent do not work.
Use consent when people have a real choice, such as optional marketing emails or non-essential cookies. Do not use consent when the person has no practical alternative, such as an employee being asked to consent to core HR processing.
For cookies and tracking, remember that ePrivacy consent may be required even before GDPR legal basis analysis. If analytics cookies are optional, they generally need prior consent in Europe unless a narrow exemption applies.
- Optional marketing emails
- Non-essential cookies with a genuine alternative
- An employee asked to consent to core HR processing
- Pre-ticked boxes, silence, or bundled consent

2. Contract
Contract applies when processing is necessary to perform a contract with the person or to take requested steps before entering into a contract.
Examples:
- Processing a shipping address to deliver an order.
- Creating an account so a user can access a paid service.
- Processing payment details for a subscription.
It does not cover processing that is merely useful to the business. Behavioral advertising is not necessary to deliver a SaaS account. Product analytics may support the service, but it usually needs a separate analysis.
3. Legal Obligation
Legal obligation applies when EU or member-state law requires the processing. Examples include tax records, employment law obligations, accounting retention, sanctions screening in some contexts, or responding to lawful regulatory requests.
The obligation must come from law, not a contract or internal policy. If a vendor contract says you must collect certain marketing data, that is not a GDPR legal obligation.
4. Vital Interests
Vital interests applies when processing is necessary to protect someone's life. It is narrow and rare in normal business operations.
Examples might include emergency medical information or crisis response. It is usually not relevant to website analytics, marketing, or SaaS onboarding.
5. Public Task
Public task applies when processing is necessary for a task carried out in the public interest or under official authority. It is mainly used by public bodies or private organizations exercising official functions under law.
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
Most private companies cannot use public task for routine commercial processing.
6. Legitimate Interests
Legitimate interests can apply when the controller or a third party has a legitimate interest, the processing is necessary for that interest, and the person's rights and freedoms do not override it.
This requires a balancing test. A typical legitimate interests assessment asks:
- What is the legitimate interest?
- Is the processing necessary for that interest?
- What is the impact on individuals?
- What safeguards reduce that impact?
- Can people reasonably expect this processing?
- Can they object easily?
Potential examples include fraud prevention, network security, basic B2B prospecting, or limited first-party analytics in some contexts. But legitimate interests is not a magic phrase for tracking. Cross-site advertising, invasive profiling, sensitive inference, and unexpected data sharing are much harder to justify.
Legal Bases and Individual Rights
The legal basis changes the rights available:
| Legal basis | Practical consequence |
|---|---|
| Consent | User can withdraw consent |
| Contract | Processing must be necessary for the contract |
| Legal obligation | Deletion may be limited by retention laws |
| Vital interests | Narrow emergency use |
| Public task | Objection rights may apply |
| Legitimate interests | User has a right to object |
You must tell people the legal basis in your privacy notice.
Analytics Examples
Cookie-based Google Analytics
A typical GA4 web setup uses cookies to distinguish users and sessions, as Google explains in its GA4 cookie documentation. In Europe, this usually raises ePrivacy consent questions before the analytics cookie is set. GDPR legal basis then depends on the processing design, vendor terms, transfers, and whether advertising features are enabled.
Cookieless aggregate analytics
A cookieless tool that avoids identifiers, IP storage, fingerprinting, advertising reuse, and personal event payloads reduces or avoids personal-data processing depending on implementation. Even then, the organization should document the purpose, data categories, retention, and vendor role.
Product analytics inside an account
Authenticated product analytics processes account-level personal data. Contract can cover events necessary to provide the service, while legitimate interests can cover security or product improvement. Sensitive or optional uses need consent or a different basis.
Common Mistakes
- Choosing consent because it sounds safest, then making the service unusable if consent is refused.
- Using contract for processing that is only useful for marketing.
- Using legitimate interests without a balancing test.
- Forgetting ePrivacy rules for cookies and device storage.
- Changing purposes later without reassessing compatibility.
- Failing to update the privacy notice when tools change.
The right legal basis is the one that honestly fits the processing. If no basis fits, the answer is not creative wording. The answer is to stop or redesign the processing.
Document the Choice
For each processing purpose, record the chosen basis and one sentence explaining why it fits. This is especially important for analytics, marketing, and AI features, where teams inherit assumptions from old tools. A short record is easier to maintain than a long memo nobody updates.

Legal-Basis Record Checklist
For each analytics purpose, write down the legal basis and why it fits: public website audience measurement, marketing pixels, product telemetry, fraud prevention, account analytics, and support diagnostics each need a different analysis. Do not reuse one basis for the whole stack.
Also check ePrivacy rules before tags run. Even when GDPR legitimate interests may be arguable for limited analytics, device storage, cookies, pixels, SDKs, or similar access may still require consent unless a narrow exemption applies in the relevant jurisdiction.
Frequently Asked Questions
Can legitimate interests replace consent for website cookies?
Legitimate interests can support some processing, but ePrivacy rules sit apart from the GDPR and usually require consent before an optional cookie is set. A narrow exemption covers strictly necessary cookies, but analytics and advertising cookies rarely qualify. Settle the ePrivacy question first, then pick the GDPR basis for what happens after.
Flowsery
Start Your 14-Day Free Trial
Real-time dashboard
Goal tracking
Cookie-free tracking
What happens if no legal basis fits the processing?
The processing has to stop or be redesigned. Careful wording in the privacy notice does not create a legal basis that was never there.
Can an employer use consent for core HR processing?
Rarely, because an employee asked to consent to core HR processing has no practical alternative to giving it. GDPR does not treat that as a free choice, so employers usually rely on contract or legal obligation instead.
Does contract cover behavioral advertising inside a SaaS product?
No, because behavioral advertising is not necessary to deliver the account someone paid for. Contract only covers what the agreement needs, like shipping an order or granting access to a paid service, so advertising needs its own basis such as consent or legitimate interests.
Is legitimate interests a safe default for tracking?
Legitimate interests is not a shortcut for tracking. Cross-site advertising, invasive profiling, sensitive inference, and unexpected data sharing are hard to justify under the balancing test, and each still needs a documented look at necessity, impact, and safeguards.
What does a legitimate interests balancing test actually check?
A legitimate interests balancing test asks whether the interest is real and whether the processing is necessary for it. It also weighs the impact on people and whether they can reasonably expect it or object easily. Fraud prevention, network security, and basic B2B prospecting can pass this test, but only with the assessment done and written down.
Can a private company rely on public task as its legal basis?
Most private companies cannot use public task for routine commercial processing, since it is meant for bodies exercising official functions under law. A private business handling orders or subscriptions should look at contract or legitimate interests instead.
How does the legal basis change what a privacy notice has to say?
The privacy notice must name the legal basis for each purpose, and that basis decides which rights to describe. Consent needs a withdrawal option, legitimate interests needs an objection right, and legal obligation needs an explanation of retention limits.
Does switching to cookieless analytics remove the need for a GDPR assessment?
Not automatically. A cookieless tool that avoids identifiers, IP storage, fingerprinting, and personal event payloads reduces or avoids personal-data processing depending on how it is implemented, but the organization still has to document the purpose, data categories, retention, and vendor role.
Why can't one legal basis cover the whole analytics stack?
Different analytics purposes carry different risks and expectations. Public website audience measurement, marketing pixels, product telemetry, fraud prevention, account analytics, and support diagnostics each need their own analysis, so reusing one basis for everything skips the assessment each purpose actually needs.
Was This Article Helpful?
Let us know what you think!
See us more often in Google
One click marks Flowsery as a preferred source, so our articles sit higher in your Top Stories, AI Mode, and AI Overviews.
Before you go...
Flowsery
Revenue-first analytics for your website
Track every visitor, source, and conversion in real time. Simple, powerful, and cookie-free.
Real-time dashboard
Goal tracking
Cookie-free tracking
Related Articles
Explained Clearly - Data Tracking Consent
Valid data tracking consent has to be freely given, specific, informed and easy to withdraw. The banner patterns that quietly invalidate all of it.


Key Insights - GDPR Summary Principles
The 7 principles of GDPR shape everything from lawful processing to storage limits. This guide explains what each principle means in practice.


Key Insights - Employee Survey GDPR Data Processing Agreement
Every SaaS tool touching personal data needs a data processing agreement. The Article 28 clauses, subprocessor traps, and a vendor review checklist.

