[codicts-css-switcher id=”346″]

Global Law Experts Logo
lawful basis uk gdpr

Our Expert in United Kingdom

Public Task vs Legitimate Interests: Choosing the Right Lawful Basis Under the UK GDPR (2026)

By Global Law Experts
– posted 46 minutes ago

Choosing the right lawful basis uk gdpr controllers can rely on has become one of the most consequential, and most misunderstood, decisions facing in-house counsel and data protection officers in 2026. Post-reform activity, fresh guidance signals and heightened enforcement scrutiny have sharpened a long-standing question: when should an organisation rely on Article 6(1)(e) (public task or official authority) rather than Article 6(1)(f) (legitimate interests)? Get it wrong and you expose the business to invalid processing, regulatory challenge and reputational harm; get it right and you build a defensible, documented position that withstands audit.

This guide takes a clear position, gives you a decision framework, and shows you how to record and defend your choice in contracts, records of processing and DPIAs.

Search-intent summary: A decision-focused guide for in-house counsel, DPOs and commercial teams, when to use the public task basis versus legitimate interests, how to document the lawful basis, and how to defend the choice under regulatory scrutiny.

Why this matters now, the UK GDPR 2026 context

Businesses across the UK are frequently uncertain about lawful basis selection, and the confusion is not academic. The lawful basis you choose dictates what processing is permitted, which data subject rights apply in their strongest form, what you must tell individuals in a privacy notice, and how you allocate responsibility in supplier contracts. A weak or poorly evidenced choice is a recognised enforcement angle for the Information Commissioner’s Office. The practical stakes, contract drafting, DPIA obligations and enforcement risk, mean the decision cannot be left to a box-ticking exercise buried in a records of processing spreadsheet.

2026 timeline: what changed and what to watch

The Data (Use and Access) Act 2025 received Royal Assent in June 2025 and forms the current framework for reform to UK data protection law, amending the UK GDPR and the Data Protection Act 2018. Its provisions are being brought into force in stages by secondary legislation. Among other changes, the Act introduces a list of “recognised legitimate interests” for which the balancing test is not required, and clarifies expectations around documentation. The core architecture of Article 6 remains intact: the lawful bases and their essential tests are unchanged. What has shifted is the emphasis. The ICO continues to press organisations to show, not merely assert, that they identified the correct lawful basis and evidenced it before processing began.

Controllers should monitor ICO guidance updates and the commencement of the 2025 Act’s provisions affecting their sector.

Who should read this

This guide is written for the people who make and defend the choice: in-house lawyers, DPOs, compliance officers and commercial teams negotiating data processing agreements. If you are deciding a lawful basis uk gdpr regulators will accept, and then need to document it, this article is for you.

Quick reference, the lawful bases and where public task and legitimate interests sit

Under Article 6 of the UK GDPR, processing is only lawful if at least one basis applies. Before comparing the two bases in focus, it helps to see all six in one place.

The Article 6 lawful bases at a glance

  • Consent (Article 6(1)(a)). The data subject has given clear, specific agreement to processing.
  • Contract (Article 6(1)(b)). Processing is necessary to perform a contract with the data subject, or to take pre-contract steps at their request.
  • Legal obligation (Article 6(1)(c)). Processing is necessary to comply with a legal obligation (other than a contractual one).
  • Vital interests (Article 6(1)(d)). Processing is necessary to protect someone’s life.
  • Public task (Article 6(1)(e)). Processing is necessary to perform a task in the public interest or in the exercise of official authority.
  • Legitimate interests (Article 6(1)(f)). Processing is necessary for the legitimate interests of the controller or a third party, subject to a balancing test.

When bases are mutually exclusive versus overlapping

You should identify a single most appropriate lawful basis for each processing purpose before processing begins, and you cannot generally swap between bases later to fix a problem. Public task and legitimate interests rarely overlap for the same activity: public task turns on a legal mandate, while legitimate interests turns on a commercial or organisational purpose supported by a balancing test. Critically, the UK GDPR provides that legitimate interests (Article 6(1)(f)) does not apply to processing carried out by public authorities in the performance of their tasks. That single point resolves a large proportion of the decisions in practice, and it is why the comparison below matters so much.

Comparison: Public task versus legitimate interests, the lawful basis uk gdpr decision centrepiece

This side-by-side comparison is the analytical heart of the article. Read the table first, then the practitioner commentary that follows.

Dimension Article 6(1)(e), public task / official authority Article 6(1)(f), legitimate interests
Legal text / basis Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party.
Typical controllers Public authorities and bodies exercising statutory or public functions; occasionally private bodies performing delegated public functions. Private-sector controllers; public authorities cannot rely on it for their public tasks.
Availability test Must be underpinned by domestic law, a statutory power or a public task or function set out in or delegated by law. Narrow scope. Available where the controller can demonstrate a genuine legitimate interest, necessity and a balancing test in its favour.
Legal threshold to rely Higher: a clear legal power, task or function must exist, and processing must be necessary to perform that public task. Moderate: necessity to achieve the legitimate interest, plus a balancing test showing the individual’s rights do not override it.
Documentation required Evidence of legal authority or mandate; a record in the ROPA referencing the statutory or legal basis; a DPIA where processing is high-risk. A legitimate interests assessment (LIA): purpose test, necessity test, balancing test; recorded in the ROPA; often a DPIA where profiling or large-scale processing is involved.
DPIA and risk DPIA likely when processing special category data or delivering large-scale public functions; assess constraints arising from the legal basis. DPIA often required for high-risk processing (profiling, large-scale). The LIA must be stronger where sensitive data is involved.
Contractual / supplier impact Supplier agreements must acknowledge statutory constraints and may limit subcontracting or require public-sector caveats. Supplier agreements require clear lawful-basis allocation and commitments to assist with LIAs and data subject rights.
Data subject rights The right to erasure and the right to data portability generally do not apply; the right to object applies. Transparency is vital. The right to object and the right to erasure apply; portability does not. Balancing outcomes should be documented, with particular attention to direct marketing.
Enforcement risk High scrutiny where public bodies claim a broad public task; the ICO may challenge overreach where there is no clear legal basis. Scrutiny on weak or poorly documented LIAs; risk of adverse ICO findings and reputational harm if the balancing test is not credible.
Examples A local authority processing for statutory housing allocation; a regulator processing under its statutory remit; a private contractor performing a delegated statutory function. Marketing to existing customers for cross-sell; fraud prevention by an insurer; a legitimate interest in operating CCTV in an appropriate context.
Draft record language “Processing necessary for [statutory power/function X] under [Act/regulation]. ROPA ref: …” “Processing necessary for legitimate interest: [purpose]; necessity explanation; balancing outcome: [summary]. LIA ref: …”

Comparison: public task vs legitimate interests decision framework.

Practitioner commentary, reading the table in practice

Three rows in this table cause most of the real-world difficulty, and they deserve unpacking.

Necessity is a genuine test, not a formality. Under both bases, processing must be necessary to achieve the stated purpose, meaning there is no reasonable, less intrusive way to achieve the same outcome. “Necessary” does not mean essential in an absolute sense, but it does mean more than merely useful or convenient. A controller who can achieve its purpose without processing the personal data, or by processing less of it, will struggle to rely on either basis. This is where many legitimate interests assessments fail: the purpose is legitimate and the balance may favour the controller, but the processing is broader than it needs to be.

Delegation to private contractors is possible but narrow. A private company can rely on Article 6(1)(e) where it is exercising a function that has a clear basis in law, including a public function genuinely delegated to it. Consider a local authority that outsources part of a statutory service to an IT provider. The authority relies on public task for the underlying processing. The IT provider, as a processor acting on the authority’s instructions, does not need its own lawful basis for that instructed processing, but if the contractor is itself a controller performing a delegated function set out in law, it can rely on public task only to the extent that legal basis reaches.

Where the contractor wants to use the same data for its own commercial purposes, that is a separate processing operation requiring its own basis, and public task will not stretch to cover it.

The commercial controller almost always lands on legitimate interests. Take a retailer marketing complementary products to existing customers. There is no statutory mandate, the purpose is a legitimate commercial one, and, provided a robust LIA shows customers would reasonably expect the marketing and their rights are not overridden, legitimate interests is the appropriate basis. The retailer must still honour the right to object and comply with the direct marketing rules (including the requirements of the Privacy and Electronic Communications Regulations 2003 for electronic marketing), but the analysis is fundamentally different from a public body’s.

How to decide, a step-by-step decision tree

Use this stepwise process to reach a defensible lawful basis uk gdpr choice, and record your reasoning as you go.

Step 1: Identify the purpose and the controller type

State the specific processing purpose in plain terms, and identify whether the controller is a public authority, a body exercising a public function, or a private organisation. This single classification narrows the field immediately: if you are a public authority processing to perform your tasks, legitimate interests is off the table for that activity.

Step 2: Check for statutory or legal authority

Look for a clear legal basis that authorises the processing. Ask:

  • Is there a statute, regulation or statutory instrument that requires or empowers this activity?
  • Is the task set out in law, or clearly delegated by law to your organisation?
  • Can you cite the specific provision, not just a general public-interest sentiment?
  • Is the processing necessary to perform that task, rather than an optional add-on?

If you can evidence a genuine legal basis, Article 6(1)(e) is likely the correct basis. If you cannot point to a specific power or function set out in law, do not stretch the concept, move to legitimate interests.

Step 3: Necessity and proportionality, the LIA methodology

Where you rely on legitimate interests, run a three-part legitimate interests assessment. First, the purpose test: identify the legitimate interest and confirm it is real and specific. Second, the necessity test: confirm the processing is a reasonable and proportionate way to achieve that interest, with no less intrusive alternative. Third, the balancing test: weigh your interest against the individual’s interests, rights and freedoms, taking account of their reasonable expectations and any impact on them. Document the outcome. A credible LIA is the single most important artefact you can produce to defend a legitimate interests decision.

Step 4: DPIA trigger and mitigation

Assess whether the processing is likely to result in a high risk to individuals. Large-scale profiling, systematic monitoring, or processing special category data will typically trigger a mandatory DPIA regardless of the lawful basis. A DPIA lawful basis analysis should record the chosen basis, the risks identified and the mitigations applied. Where the DPIA reveals residual high risk that cannot be reduced, consult the ICO before proceeding.

The decision framework, take a position

Choose Article 6(1)(e) when all of the following are true:

  • The controller is exercising a public function or official authority; and
  • The processing has a clear basis in domestic law, a statutory power or a task or function set out in law; and
  • The processing is necessary, not merely convenient, to perform that public task; and
  • Supplier arrangements are constrained by, and consistent with, the legal limits.

Choose legitimate interests when all of the following are true:

  • The controller is a private entity (or a public body acting outside its public tasks where legitimate interests is genuinely appropriate); and
  • There is no clear statutory or legal basis for the processing as a public task; and
  • The processing is necessary to achieve a legitimate commercial or organisational purpose; and
  • A robust LIA and balancing test support the conclusion; and
  • A DPIA and contractual protections address the residual risks.

Documentation, records and DPIAs, what to record

The ability to document lawful basis decisions is now central to defensibility. Regulators expect to see evidence created before processing began, not reconstructed after a complaint.

ROPA entry checklist

Your record of processing activities should, for each purpose, capture:

  • The specific processing purpose, in plain language.
  • The lawful basis relied on, and, for public task, the exact statutory power or function cited.
  • For legitimate interests, a reference to the completed LIA.
  • The categories of data and data subjects, and any special category condition where relevant.
  • Retention periods and the reasoning behind them.
  • Whether a DPIA was carried out, with a cross-reference.

Sample LIA wording

A concise LIA record might read: “Legitimate interest: retaining transaction records to prevent and detect fraud. Necessity: processing is necessary because fraud cannot be detected without analysing transaction patterns, and no less intrusive method achieves comparable results. Balancing outcome: customers reasonably expect fraud prevention, the data used is limited to what is required, and no significant adverse impact on individuals was identified; the interest is not overridden. LIA ref: LIA-2026-014.” Adapt the purpose, necessity reasoning and balancing conclusion to your facts, do not reuse boilerplate.

Privacy notice language

Transparency is not optional. Your privacy notice should name the lawful basis and give a short justification. For legitimate interests, tell individuals what the interest is. For public task, name the function and, where appropriate, the legal power. Example: “We process this information to perform our statutory functions under [Act]” or “We rely on our legitimate interest in [purpose]; you have the right to object.”

Contracting and supplier agreements, drafting practicalities

Data processing agreements are where lawful-basis decisions either hold together or fall apart. The controller is responsible for identifying the lawful basis, but the processor must support it operationally.

Controller and processor clause checklist

  • Allocate responsibility clearly: the controller determines the lawful basis; the processor acts only on documented instructions.
  • Require the processor to assist with data subject rights requests, LIAs and DPIAs.
  • Address subprocessing authorisations, especially where a public task basis constrains onward disclosure.
  • Include audit and information rights so the controller can evidence compliance.
  • Deal with transfers and the mechanism relied on.
  • Include the mandatory processor terms required by Article 28 of the UK GDPR.

Clause examples to adapt

For a legitimate interests context: “The Processor shall, taking into account the nature of the processing, assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Controller’s obligations to respond to data subject requests and to complete legitimate interests assessments relating to the Services.”

For a public task context: “The Processor acknowledges that the Controller processes personal data in the exercise of statutory functions and shall not process the personal data for any purpose beyond the documented instructions of the Controller, nor engage any subprocessor without the Controller’s prior written or general written authorisation.”

These are starting points, legal review and tailoring to the specific arrangement are needed before use.

Enforcement risk, litigation and compensation

Understanding how the ICO and courts approach lawful-basis disputes helps you build a defensible position from the outset.

ICO red flags and how to avoid them

The most common triggers for regulatory challenge are a legitimate interests assessment that reads as a formality rather than genuine analysis, a public authority stretching public task beyond its legal remit, and a mismatch between the lawful basis stated in the privacy notice and the basis actually recorded internally. Avoid these by completing your LIA or evidencing your statutory power before processing, keeping records consistent across your ROPA and privacy notice, and revisiting the analysis when the processing changes.

Litigation scenarios and indemnity considerations

Individuals can bring claims where processing without a valid lawful basis has caused them damage, and compensation in UK data protection claims is assessed on the facts of the harm rather than a fixed tariff. Following the Supreme Court’s decision in Lloyd v Google (2021), claimants generally need to demonstrate material damage or distress rather than relying on “loss of control” alone. In a supplier context, an invalid lawful basis can cascade into contractual disputes over indemnities and liability caps. The practical mitigation is a clear audit trail: a documented decision, a defensible LIA or statutory citation, and contractual allocation of responsibility that reflects who actually decided the purpose and means of processing.

Where the stakes are high, a formal legal opinion on the lawful basis is a sensible investment.

Cross-border transfers and the interplay with lawful basis

Your lawful basis choice sits alongside, but does not replace, the rules on international transfers.

Supplier obligations for transfers

Having a valid lawful basis for processing does not authorise a transfer of personal data outside the UK. A separate transfer mechanism, such as the UK’s International Data Transfer Agreement (IDTA), the UK Addendum to the EU standard contractual clauses, binding corporate rules, or reliance on UK adequacy regulations, must be in place. Supplier agreements should identify the transfer mechanism, require the processor to flag any onward transfers, and commit the processor to maintaining the safeguards.

Practical checklist

  • Confirm the lawful basis for the underlying processing first.
  • Identify every transfer and its destination.
  • Select and document the transfer mechanism for each.
  • Record the necessity of the transfer alongside the necessity of the processing.

Practical checklist and a 30-60-90 day action plan

To operationalise a defensible lawful basis uk gdpr position across the organisation, phase the work:

  • Immediate. Map current processing purposes and record the lawful basis claimed for each; flag any that lack evidence.
  • By 30 days. Run or refresh LIAs for legitimate interests activities and confirm statutory powers for public task activities; trigger DPIAs where high risk is identified.
  • By 60 days. Update data processing agreements, privacy notices and the ROPA so they are consistent with the recorded basis.
  • By 90 days. Report to the board on residual risk, embed the decision process into new-project governance, and train relevant teams.

Getting legal help

Lawful-basis decisions are fact-specific, and the difference between public task and legitimate interests can turn on the precise wording of a statutory power or the credibility of a balancing test. If you need tailored advice, you can find a data protection lawyer in the UK through the Global Law Experts directory, and review the Data Privacy, United Kingdom practice area for related guidance. Focus on finding counsel with genuine data protection and commercial technology experience.

Conclusion

Selecting the correct lawful basis uk gdpr controllers can defend is not a matter of preference, it follows from who you are and what authorises the processing. If you are exercising a genuine public function with a clear basis in law, rely on Article 6(1)(e) and cite the power. If you are a commercial controller pursuing a legitimate purpose without a statutory mandate, rely on legitimate interests and stand it up with a credible, documented LIA. In every case, the choice is only as strong as the evidence behind it: record it in your ROPA, reflect it in your privacy notice, allocate it correctly in supplier contracts, and DPIA it where risk demands.

Do that consistently, and your lawful basis will withstand the scrutiny that 2026 has made inevitable.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Nigel Miller at Fox Williams LLP, a member of the Global Law Experts network.

Sources

  1. Information Commissioner’s Office, A guide to lawful basis
  2. Information Commissioner’s Office, Legitimate interests
  3. Information Commissioner’s Office, Public task
  4. Legislation.gov.uk, Data Protection Act 2018
  5. Legislation.gov.uk, UK GDPR (retained Regulation (EU) 2016/679)
  6. Legislation.gov.uk, Data (Use and Access) Act 2025
  7. The Law Society, Data protection guidance

FAQs

Is Article 6(1)(e) the same as a public task basis?
Yes. Article 6(1)(e) covers processing necessary for a task carried out in the public interest or in the exercise of official authority vested in the controller. It requires an underpinning of statutory or legal basis, and public authorities cannot rely on legitimate interests for processing carried out to perform their tasks.
Only in narrow circumstances, where the company is exercising a task or function that has a clear basis in law, such as a contractor performing a delegated statutory function, and the processing is necessary for that function. It cannot use public task to justify processing for its own commercial purposes.
Use legitimate interests when there is no statutory mandate, the processing is necessary for a legitimate commercial or organisational purpose, and a documented LIA shows the individual’s rights and freedoms do not override that interest. This is the default lawful basis uk gdpr private-sector controllers rely on for activities like fraud prevention and customer marketing.
Not automatically. A DPIA is required where the processing is likely to result in a high risk to individuals, for example, large-scale profiling or processing of special category data. Many high-risk legitimate interests scenarios will trigger a DPIA, so assess the risk in every case.
Record the basis in your ROPA with supporting evidence, either the statutory power for public task or a reference to the completed LIA. Include lawful-basis allocation and assistance obligations in your data processing agreements, and add clear privacy-notice wording that names the basis and gives a short justification.
The Data (Use and Access) Act 2025 introduces clarifications, including a list of “recognised legitimate interests” and reinforced documentation expectations, but the core lawful-basis principles under Article 6 remain unchanged. Provisions are commencing in stages, so monitor ICO updates and take specific legal advice on how the changes affect your sector.

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Public Task vs Legitimate Interests: Choosing the Right Lawful Basis Under the UK GDPR (2026)

Send welcome message

Custom Message