Article 6 of the GDPR sets out various legal bases for processing data. Consent isn't the only deciding factor — other legal bases apply too, such as contract performance, balancing of interests, and legal obligations. Companies must observe the applicable rules to comply with data protection law. heyData provides support through legally compliant solutions and consultation to help you meet your data protection obligations.
Article 6 of the GDPR – Lawfulness of the
Companies, authorities, and institutions that process personal data are required to review the lawfulness of any planned processing under Article 6 of the General Data Protection Regulation (GDPR). Even before the European General Data Protection Regulation came into force, the "prohibition subject to authorization" principle was already regulated by the German Federal Data Protection Act, and even then, handling personal data was fundamentally prohibited unless permitted. To process personal data, a controller must be able to demonstrate a so-called legal basis. If a company, authority, or institution intends to process personal data, it must determine which legal basis applies and whether the processing is thereby permitted under Art. 6 GDPR. In principle, a distinction must be made between different categories of personal data — if special categories of personal data are involved, Article 9 of the GDPR must also be observed. For most companies in manufacturing or services, these special categories can be disregarded. If special categories of personal data are processed, it's advisable to contact heyData's data protection experts to review all legal aspects in detail.
Consent – Often an Unnecessary Legal Basis
In everyday practice, companies often point to a required consent to justify continuing a cooperation. When consent is insisted upon, this is often because the content of Article 6 GDPR is unfamiliar, and insisting on consent stems from a lack of knowledge of the legal situation. Looking at Article 6, you'll find further, often more suitable, legal bases that permit the processing of personal data — an existing contractual relationship, for example. Since consent is listed as a possible legal basis right at the start of Article 6 GDPR, it's unsurprising that the article is often interpreted to mean that consent as a legal basis is unavoidable and must be treated as a prerequisite. The other options are frequently overlooked in everyday practice.
The Order of Legal Bases Under Article 6 of the GDPR
To assess the legal bases under Art. 6, it makes sense to review the lawfulness of processing personal data in a specific order.
Work through the points listed below — the review is complete as soon as one of the points applies.
- Protection of vital interests (Art. 6(1)(d))
- Performance of a task in the public interest (Art. 6(2)(e))
- Legal/statutory obligation (Art. 6(1)(c))
- Contractual relationship with the data subject (Art. 6(1)(b))
- Balancing of interests (Art. 6(1)(f))
- Consent (Art. 6(1)(a))
When assessing a legal basis, the points should be reviewed in this order. The first two points rarely apply in everyday practice, but must be considered for the sake of completeness.
Protection of Vital Interests
The protection of vital interests, addressed in Article 6(1)(d) of the GDPR, covers situations where a person's life is acutely at risk. In such cases, all reasonable measures may be taken to protect that person. This basis rarely applies to companies and authorities, but should still be kept in mind.
Performance of a Task in the Public Interest
Looking at Article 6(1)(e) of the GDPR, most companies will notice that this description often doesn't apply to their own situation. This basis targets controllers entrusted with a task carried out in the public interest or in the exercise of official authority — the police service, for example. In individual cases, however, Article 6(1)(e) can also apply to a service business, such as car repair shops that carry out a sovereign task by performing emissions inspections.
Legal/Statutory Obligation
For companies, authorities, and institutions, Article 6(1)(c) often applies, since it covers legal obligations that cannot be fulfilled without processing personal data.
Examples include the following situations:
- As an employer, you're required under statutory reporting obligations to register a new employee with their health insurance provider. In this case, the personal data may be used for that specific processing purpose. The same applies to processing the information required for tax and social security contributions.
- Employers are required to comply with the legal requirements on maximum working hours, as set out in the Working Hours Act. To meet these requirements, employees' working hours must be recorded and thus processed.
- To curb money laundering and rule out income from illegal sources, companies with certain responsibilities relating to financial transactions are given a legal basis for processing — insurers and banks in particular.
- Employers are also legally required to pay employees for their work and document the payment. To transfer wages correctly, the money must be sent to a known account — the Minimum Wage Act must also be observed here. To make payment, the employer may request the employee's bank details and document their working hours.
Contractual Relationships With a Data Subject
To perform a contract or support entering into a contract, processing data and information is often necessary and therefore permitted. The term "contract" shouldn't be assessed solely under national or EU law. In this context, the term "contract" also applies when two parties reach an agreement — even verbally. Scheduling an appointment is one example of such an agreement.
To rely on the term "contract" as a legal basis, the data subject must be a party to the contract. When referring to "pre-contractual measures," an initiative by the data subject must have been recorded. A merely presumed interest doesn't constitute a legal basis and therefore doesn't apply to advertising.
The following processes often fall under the contractual justification, meaning consent isn't required:
- During a job application process, the data submitted may be processed. The selection process falls under "pre-contractual measures."
- Within an employment relationship, the employer may collect working hours to perform the contract. The working hours may also be used to calculate and pay the employee's wages.
- When a private individual contacts a company, their contact details may be received and used. Personal data is often provided in online shopping, and the contact details and banking information received may be used to carry out the corresponding service and delivery.
Balancing of Interests
To rely on a balancing of interests as a legal basis, several factors should be assessed and considered:
- The data subject's interest must be clearly identifiable, and the processing of data must be in the controller's interest. It must be evident that both sides pursue the same objective.
- If a data subject can reasonably expect data processing to take place and is informed about it, this constitutes a legal basis.
It's important that the controller has implemented strong protective measures. To accurately assess a balancing of interests, it's a good idea to contact heyData's experts for a precise evaluation.
Consent
Consent is often unnecessary and often not advisable either, since it can be withdrawn at any time. Controllers should keep the following points in mind:
- Consent must never be coerced.
- Consent must serve a specific purpose. It must be given voluntarily, and the data subject must be informed of their right to withdraw it. Any subsequent withdrawal must also be processed promptly.
- The controller must be able to demonstrate that valid consent was obtained.
- No processing may take place without consent.
- Processing must not be tied to other measures unless this is necessary.
Conclusion
Article 6 of the General Data Protection Regulation (GDPR) sets out the lawfulness of processing personal data. Several legal bases can apply to data processing — not just consent. These legal bases should be reviewed in a specific order, starting with the protection of vital interests and the performance of tasks in the public interest, followed by legal obligations, contractual relationships, a balancing of interests, and finally consent. Using consent isn't always necessary and it can be withdrawn. It's important that consent is given voluntarily, serves a specific purpose, and can be withdrawn. Alternatively, other legal bases such as legal obligations, contractual relationships, or a balancing of interests can be used. If you have questions about the lawfulness of data processing, it's advisable to consult data protection experts. By observing the applicable legal bases, companies and institutions can ensure they comply with data protection law.
FAQ
Why is Article 6 GDPR so central to data processing?
Why is Article 6 GDPR so central to data processing?
Article 6 forms the foundation of European data protection law. It enshrines the principle of prohibition subject to permission: processing personal data is generally prohibited unless the company can rely on at least one of the six legal bases defined in Article 6. Without such a legal basis, the processing is unlawful.
What are the 6 legal bases permitted under Article 6 GDPR?
What are the 6 legal bases permitted under Article 6 GDPR?
Data processing is only lawful if one of the following 6 conditions is met:
- Consent (Art. 6(1)(a)): The data subject has given their consent freely and in an informed manner.
- Performance of a contract (Art. 6(1)(b)): Processing is necessary for the performance of a contract or pre-contractual measures.
- Legal obligation (Art. 6(1)(c)): The company must fulfill legal obligations (e.g., tax retention periods).
- Vital interests (Art. 6(1)(d)): Protection of the life or health of the data subject or another person.
- Public interest (Art. 6(1)(e)): Performance of a task carried out in the public interest or in the exercise of official authority.
- Legitimate interest (Art. 6(1)(f)): Processing is necessary to protect the company's legitimate interests, provided these are not overridden by the interests of the data subjects.
When can a company rely on "legitimate interest" (Art. 6(1)(f))?
When can a company rely on "legitimate interest" (Art. 6(1)(f))?
Relying on legitimate interest always requires a three-step assessment:
- Interest: Does the company have a legal, economic, or non-material interest (e.g., direct marketing, IT security)?
- Necessity: Is the processing necessary to achieve this goal, or are there less intrusive means?
- Balancing of interests: Do the fundamental rights and freedoms of the data subject outweigh the company's interest? If the data subject's interests prevail, this legal basis cannot be used.
Can companies simply switch the legal basis during ongoing processing?
Can companies simply switch the legal basis during ongoing processing?
No. The appropriate legal basis must be determined, documented, and communicated to the data subject in the privacy policy before processing begins. Switching afterwards (e.g., from withdrawn consent to legitimate interest) is generally not permitted and constitutes a data protection violation.







