No history yet

Complex Lawful Bases

Beyond the Basics of Lawful Processing

You already know that every act of processing personal data requires a valid lawful basis under GDPR Article 6. But for the CIPP/EU exam, simply listing the six bases isn't enough. You need to master the strategic decisions behind choosing the right basis and defending that choice, especially when several options seem plausible.

This involves navigating nuanced legal tests and understanding the high stakes of processing special category data. We'll focus on the complexities of Legitimate Interest, Contractual Necessity, and the strict requirements for processing sensitive information under Article 9. Getting this right is the difference between simple compliance and a defensible data protection strategy.

The Legitimate Interest Three-Part Test

Article 6(1)(f), Legitimate Interest, is the most flexible lawful basis, but it's not a free pass. It cannot be used by public authorities in the performance of their tasks. For private organizations, relying on it requires passing a mandatory three-part test. You must document this assessment to demonstrate accountability.

  1. Purpose Test: Is there a legitimate interest behind the processing?
  2. Necessity Test: Is the processing necessary for that purpose?
  3. Balancing Test: Do the individual’s interests, rights, or freedoms override the legitimate interest?

The purpose must be lawful, specific, and a real, present interest. Examples include fraud prevention, ensuring network and information security, or direct marketing. The necessity test is strict; if you can reasonably achieve the same goal with less intrusive data processing, this test fails. Finally, the balancing test requires you to weigh your interests against the individual's. Consider the nature of the data, the individual’s reasonable expectations, and the potential impact of the processing. Recent have added important clarifications, especially regarding the balancing test in complex situations like profiling.

Contract vs. Legitimate Interest

Distinguishing between processing that is necessary for a contract (Article 6(1)(b)) and processing done for a legitimate interest (Article 6(1)(f)) is a common exam scenario, especially for online services.

The key word is "necessity." For Article 6(1)(b) to apply, the processing must be objectively necessary to perform the contract. If the service could still be provided without that specific processing, it isn't necessary. This also applies to steps taken at the request of the individual before entering into a contract, like generating a price quote based on user-provided details. However, this pre-contractual scope is narrow. It doesn't cover speculative processing, like creating a user profile before they've even requested a service.

For example, an e-commerce site processing a customer's address to ship a product is a clear case of contractual necessity. However, using their purchase history to show them personalized ads is not. The primary service (delivery) is possible without the advertising. The advertising would need to be justified under a different basis, likely Legitimate Interest or Consent.

Article 9 and Explicit Consent

Processing special categories of personal data, such as health information, political opinions, or racial or ethnic origin, is prohibited by default under Article 9. To proceed, you need both a valid lawful basis under Article 6 and a specific exception under Article 9. The most common exception is (Article 9(2)(a)).

For any consent to be valid under GDPR, it must be freely given, specific, informed, and an unambiguous indication of the individual’s wishes. When relying on consent, you must make it easy for individuals to withdraw it at any time. The process to withdraw consent must be as simple as the process to give it. Upon withdrawal, you must stop processing for that purpose, unless another lawful basis applies.

Criteria for Valid ConsentDescription
Freely GivenThe individual must have a real choice; no negative consequences for refusal.
SpecificConsent must be for a specific, granular purpose. No blanket consent.
InformedYou must explain the controller's identity, the purpose of processing, and the types of data collected.
UnambiguousRequires a clear affirmative action. Silence or pre-ticked boxes are not valid.

Mastering these nuances is critical. The IAPP exam will test your ability to apply these tests to real-world scenarios, forcing you to choose and justify the most appropriate lawful basis. Focus on the reasoning behind the rules, not just the rules themselves.

Quiz Questions 1/5

An organization wishes to rely on legitimate interest as its lawful basis for processing personal data under GDPR Article 6(1)(f). What are the three essential components of the mandatory assessment it must conduct and document?

Quiz Questions 2/5

An e-commerce company requires a user's shipping address to deliver a purchased product. To improve its marketing, the company also analyzes the user's browsing history on its site to create a personalized advertising profile. What are the most appropriate lawful bases for these two separate processing activities?