Our Expert in United Kingdom
No results available
Choosing the right lawful basis uk gdpr controllers can rely on has become one of the most consequential, and most misunderstood, decisions facing in-house counsel and data protection officers in 2026. Post-reform activity, fresh guidance signals and heightened enforcement scrutiny have sharpened a long-standing question: when should an organisation rely on Article 6(1)(e) (public task or official authority) rather than Article 6(1)(f) (legitimate interests)? Get it wrong and you expose the business to invalid processing, regulatory challenge and reputational harm; get it right and you build a defensible, documented position that withstands audit.
This guide takes a clear position, gives you a decision framework, and shows you how to record and defend your choice in contracts, records of processing and DPIAs.
Search-intent summary: A decision-focused guide for in-house counsel, DPOs and commercial teams, when to use the public task basis versus legitimate interests, how to document the lawful basis, and how to defend the choice under regulatory scrutiny.
Businesses across the UK are frequently uncertain about lawful basis selection, and the confusion is not academic. The lawful basis you choose dictates what processing is permitted, which data subject rights apply in their strongest form, what you must tell individuals in a privacy notice, and how you allocate responsibility in supplier contracts. A weak or poorly evidenced choice is a recognised enforcement angle for the Information Commissioner’s Office. The practical stakes, contract drafting, DPIA obligations and enforcement risk, mean the decision cannot be left to a box-ticking exercise buried in a records of processing spreadsheet.
The Data (Use and Access) Act 2025 received Royal Assent in June 2025 and forms the current framework for reform to UK data protection law, amending the UK GDPR and the Data Protection Act 2018. Its provisions are being brought into force in stages by secondary legislation. Among other changes, the Act introduces a list of “recognised legitimate interests” for which the balancing test is not required, and clarifies expectations around documentation. The core architecture of Article 6 remains intact: the lawful bases and their essential tests are unchanged. What has shifted is the emphasis. The ICO continues to press organisations to show, not merely assert, that they identified the correct lawful basis and evidenced it before processing began.
Controllers should monitor ICO guidance updates and the commencement of the 2025 Act’s provisions affecting their sector.
This guide is written for the people who make and defend the choice: in-house lawyers, DPOs, compliance officers and commercial teams negotiating data processing agreements. If you are deciding a lawful basis uk gdpr regulators will accept, and then need to document it, this article is for you.
Under Article 6 of the UK GDPR, processing is only lawful if at least one basis applies. Before comparing the two bases in focus, it helps to see all six in one place.
You should identify a single most appropriate lawful basis for each processing purpose before processing begins, and you cannot generally swap between bases later to fix a problem. Public task and legitimate interests rarely overlap for the same activity: public task turns on a legal mandate, while legitimate interests turns on a commercial or organisational purpose supported by a balancing test. Critically, the UK GDPR provides that legitimate interests (Article 6(1)(f)) does not apply to processing carried out by public authorities in the performance of their tasks. That single point resolves a large proportion of the decisions in practice, and it is why the comparison below matters so much.
This side-by-side comparison is the analytical heart of the article. Read the table first, then the practitioner commentary that follows.
| Dimension | Article 6(1)(e), public task / official authority | Article 6(1)(f), legitimate interests |
|---|---|---|
| Legal text / basis | Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. | Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party. |
| Typical controllers | Public authorities and bodies exercising statutory or public functions; occasionally private bodies performing delegated public functions. | Private-sector controllers; public authorities cannot rely on it for their public tasks. |
| Availability test | Must be underpinned by domestic law, a statutory power or a public task or function set out in or delegated by law. Narrow scope. | Available where the controller can demonstrate a genuine legitimate interest, necessity and a balancing test in its favour. |
| Legal threshold to rely | Higher: a clear legal power, task or function must exist, and processing must be necessary to perform that public task. | Moderate: necessity to achieve the legitimate interest, plus a balancing test showing the individual’s rights do not override it. |
| Documentation required | Evidence of legal authority or mandate; a record in the ROPA referencing the statutory or legal basis; a DPIA where processing is high-risk. | A legitimate interests assessment (LIA): purpose test, necessity test, balancing test; recorded in the ROPA; often a DPIA where profiling or large-scale processing is involved. |
| DPIA and risk | DPIA likely when processing special category data or delivering large-scale public functions; assess constraints arising from the legal basis. | DPIA often required for high-risk processing (profiling, large-scale). The LIA must be stronger where sensitive data is involved. |
| Contractual / supplier impact | Supplier agreements must acknowledge statutory constraints and may limit subcontracting or require public-sector caveats. | Supplier agreements require clear lawful-basis allocation and commitments to assist with LIAs and data subject rights. |
| Data subject rights | The right to erasure and the right to data portability generally do not apply; the right to object applies. Transparency is vital. | The right to object and the right to erasure apply; portability does not. Balancing outcomes should be documented, with particular attention to direct marketing. |
| Enforcement risk | High scrutiny where public bodies claim a broad public task; the ICO may challenge overreach where there is no clear legal basis. | Scrutiny on weak or poorly documented LIAs; risk of adverse ICO findings and reputational harm if the balancing test is not credible. |
| Examples | A local authority processing for statutory housing allocation; a regulator processing under its statutory remit; a private contractor performing a delegated statutory function. | Marketing to existing customers for cross-sell; fraud prevention by an insurer; a legitimate interest in operating CCTV in an appropriate context. |
| Draft record language | “Processing necessary for [statutory power/function X] under [Act/regulation]. ROPA ref: …” | “Processing necessary for legitimate interest: [purpose]; necessity explanation; balancing outcome: [summary]. LIA ref: …” |
Comparison: public task vs legitimate interests decision framework.
Three rows in this table cause most of the real-world difficulty, and they deserve unpacking.
Necessity is a genuine test, not a formality. Under both bases, processing must be necessary to achieve the stated purpose, meaning there is no reasonable, less intrusive way to achieve the same outcome. “Necessary” does not mean essential in an absolute sense, but it does mean more than merely useful or convenient. A controller who can achieve its purpose without processing the personal data, or by processing less of it, will struggle to rely on either basis. This is where many legitimate interests assessments fail: the purpose is legitimate and the balance may favour the controller, but the processing is broader than it needs to be.
Delegation to private contractors is possible but narrow. A private company can rely on Article 6(1)(e) where it is exercising a function that has a clear basis in law, including a public function genuinely delegated to it. Consider a local authority that outsources part of a statutory service to an IT provider. The authority relies on public task for the underlying processing. The IT provider, as a processor acting on the authority’s instructions, does not need its own lawful basis for that instructed processing, but if the contractor is itself a controller performing a delegated function set out in law, it can rely on public task only to the extent that legal basis reaches.
Where the contractor wants to use the same data for its own commercial purposes, that is a separate processing operation requiring its own basis, and public task will not stretch to cover it.
The commercial controller almost always lands on legitimate interests. Take a retailer marketing complementary products to existing customers. There is no statutory mandate, the purpose is a legitimate commercial one, and, provided a robust LIA shows customers would reasonably expect the marketing and their rights are not overridden, legitimate interests is the appropriate basis. The retailer must still honour the right to object and comply with the direct marketing rules (including the requirements of the Privacy and Electronic Communications Regulations 2003 for electronic marketing), but the analysis is fundamentally different from a public body’s.
Use this stepwise process to reach a defensible lawful basis uk gdpr choice, and record your reasoning as you go.
State the specific processing purpose in plain terms, and identify whether the controller is a public authority, a body exercising a public function, or a private organisation. This single classification narrows the field immediately: if you are a public authority processing to perform your tasks, legitimate interests is off the table for that activity.
Look for a clear legal basis that authorises the processing. Ask:
If you can evidence a genuine legal basis, Article 6(1)(e) is likely the correct basis. If you cannot point to a specific power or function set out in law, do not stretch the concept, move to legitimate interests.
Where you rely on legitimate interests, run a three-part legitimate interests assessment. First, the purpose test: identify the legitimate interest and confirm it is real and specific. Second, the necessity test: confirm the processing is a reasonable and proportionate way to achieve that interest, with no less intrusive alternative. Third, the balancing test: weigh your interest against the individual’s interests, rights and freedoms, taking account of their reasonable expectations and any impact on them. Document the outcome. A credible LIA is the single most important artefact you can produce to defend a legitimate interests decision.
Assess whether the processing is likely to result in a high risk to individuals. Large-scale profiling, systematic monitoring, or processing special category data will typically trigger a mandatory DPIA regardless of the lawful basis. A DPIA lawful basis analysis should record the chosen basis, the risks identified and the mitigations applied. Where the DPIA reveals residual high risk that cannot be reduced, consult the ICO before proceeding.
Choose Article 6(1)(e) when all of the following are true:
Choose legitimate interests when all of the following are true:
The ability to document lawful basis decisions is now central to defensibility. Regulators expect to see evidence created before processing began, not reconstructed after a complaint.
Your record of processing activities should, for each purpose, capture:
A concise LIA record might read: “Legitimate interest: retaining transaction records to prevent and detect fraud. Necessity: processing is necessary because fraud cannot be detected without analysing transaction patterns, and no less intrusive method achieves comparable results. Balancing outcome: customers reasonably expect fraud prevention, the data used is limited to what is required, and no significant adverse impact on individuals was identified; the interest is not overridden. LIA ref: LIA-2026-014.” Adapt the purpose, necessity reasoning and balancing conclusion to your facts, do not reuse boilerplate.
Transparency is not optional. Your privacy notice should name the lawful basis and give a short justification. For legitimate interests, tell individuals what the interest is. For public task, name the function and, where appropriate, the legal power. Example: “We process this information to perform our statutory functions under [Act]” or “We rely on our legitimate interest in [purpose]; you have the right to object.”
Data processing agreements are where lawful-basis decisions either hold together or fall apart. The controller is responsible for identifying the lawful basis, but the processor must support it operationally.
For a legitimate interests context: “The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller’s obligations to respond to data subject requests and to complete legitimate interests assessments relating to the Services.”
For a public task context: “The Processor acknowledges that the Controller processes personal data in the exercise of statutory functions and shall not process the personal data for any purpose beyond the documented instructions of the Controller, nor engage any subprocessor without the Controller’s prior written or general written authorisation.”
These are starting points, legal review and tailoring to the specific arrangement are needed before use.
Understanding how the ICO and courts approach lawful-basis disputes helps you build a defensible position from the outset.
The most common triggers for regulatory challenge are a legitimate interests assessment that reads as a formality rather than genuine analysis, a public authority stretching public task beyond its legal remit, and a mismatch between the lawful basis stated in the privacy notice and the basis actually recorded internally. Avoid these by completing your LIA or evidencing your statutory power before processing, keeping records consistent across your ROPA and privacy notice, and revisiting the analysis when the processing changes.
Individuals can bring claims where processing without a valid lawful basis has caused them damage, and compensation in UK data protection claims is assessed on the facts of the harm rather than a fixed tariff. Following the Supreme Court’s decision in Lloyd v Google (2021), claimants generally need to demonstrate material damage or distress rather than relying on “loss of control” alone. In a supplier context, an invalid lawful basis can cascade into contractual disputes over indemnities and liability caps. The practical mitigation is a clear audit trail: a documented decision, a defensible LIA or statutory citation, and contractual allocation of responsibility that reflects who actually decided the purpose and means of processing.
Where the stakes are high, a formal legal opinion on the lawful basis is a sensible investment.
Your lawful basis choice sits alongside, but does not replace, the rules on international transfers.
Having a valid lawful basis for processing does not authorise a transfer of personal data outside the UK. A separate transfer mechanism, such as the UK’s International Data Transfer Agreement (IDTA), the UK Addendum to the EU standard contractual clauses, binding corporate rules, or reliance on UK adequacy regulations, must be in place. Supplier agreements should identify the transfer mechanism, require the processor to flag any onward transfers, and commit the processor to maintaining the safeguards.
To operationalise a defensible lawful basis uk gdpr position across the organisation, phase the work:
Lawful-basis decisions are fact-specific, and the difference between public task and legitimate interests can turn on the precise wording of a statutory power or the credibility of a balancing test. If you need tailored advice, you can find a data protection lawyer in the UK through the Global Law Experts directory, and review the Data Privacy, United Kingdom practice area for related guidance. Focus on finding counsel with genuine data protection and commercial technology experience.
Selecting the correct lawful basis uk gdpr controllers can defend is not a matter of preference, it follows from who you are and what authorises the processing. If you are exercising a genuine public function with a clear basis in law, rely on Article 6(1)(e) and cite the power. If you are a commercial controller pursuing a legitimate purpose without a statutory mandate, rely on legitimate interests and stand it up with a credible, documented LIA. In every case, the choice is only as strong as the evidence behind it: record it in your ROPA, reflect it in your privacy notice, allocate it correctly in supplier contracts, and DPIA it where risk demands.
Do that consistently, and your lawful basis will withstand the scrutiny that 2026 has made inevitable.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Nigel Miller at Fox Williams LLP, a member of the Global Law Experts network.
posted 11 minutes ago
posted 34 minutes ago
posted 57 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message