
Lawful Basis and Legitimate Interests
Choosing a lawful basis is the first decision in any UK GDPR compliance analysis, and the choice constrains everything the controller can do with the data afterwards. Article 6(1) of the UK GDPR contains seven conditions. Most commercial processing is justified by performance of a contract. Where it is not, a controller turns to legitimate interests, and to consent only as a last resort. The seventh condition, Article 6(1)(ea), recognised legitimate interests, was inserted on 5 February 2026 by the Data (Use and Access) Act 2025, and removes the balancing test for a closed list of five purposes.
The seven conditions in Article 6(1)
At least one of the seven conditions in Article 6(1) must be satisfied before data processing begins, and the controller must identify which one and document it. That follows from the accountability principle in Article 5(2) rather than from Article 6 itself.
The first place to start is performance of contractual obligations. Article 6(1)(b) requires that the processing be objectively necessary for performance of a contract with the data subject, not merely convenient or commercially sensible, but where it is satisfied the controller has no balancing exercise to document, no withdrawal to administer, and a description of the processing the data subject already understands. Legal obligation under Article 6(1)(c) requires a basis laid down in domestic law, whether by statute directly or by regulations under section 16 of the Data Protection Act 2018; a contractual obligation between private parties is not enough. Vital interests under Article 6(1)(d) is an emergency provision. Public task under Article 6(1)(e) is the route for most public sector processing, and its wording was widened on 5 February 2026.
Where the processing is not necessary for the contract, the two that matter most commercially are recognised legitimate interests at Article 6(1)(ea) and legitimate interests at Article 6(1)(f). Neither is available to a public authority processing in the performance of its tasks.
Consent under Article 6(1)(a) comes last, and except for a narrow set of circumstances where it is required should be the last resort for most businesses processing personal data, as there are conditions on how it is obtained (see below) and it can always be withdrawn.
The five recognised legitimate interests in Annex 1
There are five recognised legitimate interests, and they are set out in Annex 1 to the UK GDPR rather than in the Act. Article 6(5) is the gateway: processing is necessary for the purposes of a recognised legitimate interest only if it meets a condition in Annex 1. Annex 1 was inserted on 5 February 2026 by Schedule 4 to the Data (Use and Access) Act 2025.
The conditions are at Annex 1 paragraphs 1, 2, 3, 5 and 6. Paragraph 1 covers disclosure to a person who states that they need the data for public task processing with a legal basis satisfying Article 6(3). Paragraph 2 covers national security, public security and defence. Paragraph 3 covers responding to an emergency, with paragraph 4 defining emergency by reference to Part 2 of the Civil Contingencies Act 2004. Paragraph 5 covers detecting, investigating or preventing crime, or apprehending or prosecuting offenders. Paragraph 6 covers safeguarding a vulnerable individual.
The numbering is not contiguous because paragraphs 4, 7 and 8 are definitions rather than conditions. Crime is paragraph 5, not 4, and safeguarding is paragraph 6, not 5. Public health, scientific research and statistical purposes are not among them.
The most commercially useful of the five is paragraph 5. Fraud is a crime, so anti-fraud processing that is genuinely necessary for detecting, investigating or preventing it can rest on Article 6(1)(ea) with no balancing test. The boundary is necessity for the criminal purpose. Commercial loss reduction, credit scoring and general risk appetite fall outside paragraph 5 and remain Article 6(1)(f) questions.
When the balancing test still applies
Only the balancing test falls away, and only where an Annex 1 condition applies. Necessity does not. Article 6(1)(ea) requires that the processing be necessary for the purposes of a recognised legitimate interest, and each Annex 1 condition is drafted so that it is met only where the processing is necessary for the purpose that condition describes. A controller relying on Article 6(1)(ea) must still identify the paragraph and evidence necessity against it.
Outside the five conditions, the three-part assessment under Article 6(1)(f) applies as before: identify the interest pursued, show that the processing is necessary rather than merely useful, and balance the interest against the data subject’s interests, rights and freedoms, giving particular weight where the data subject is a child. Article 6(11), also new on 5 February 2026, names three examples of processing that may be necessary for a legitimate interest: direct marketing, intra-group transmission for internal administrative purposes, and ensuring the security of network and information systems. These are examples, not deemed lawful bases. They do not remove the balancing test and they do not displace PECR.
| Question | Article 6(1)(ea) recognised legitimate interests | Article 6(1)(f) legitimate interests |
|---|---|---|
| Balancing test | Not required | Required, and must be documented |
| Necessity | Required twice: under Article 6(1)(ea) and again within the Annex 1 condition relied on | Required |
| Scope | Closed list of five Annex 1 conditions | Open, subject to the balance |
| Right to object | Applies, Article 21(1) | Applies, Article 21(1) |
| Solely automated significant decisions | Barred by Article 22B(4) | Available, subject to Articles 22A to 22D |
| Public authorities in their public tasks | Not available | Not available |
Article 22B(4) bars a significant decision taken solely by automated processing where the controller relies, entirely or partly, on Article 6(1)(ea). That is a hard bar, not a safeguards requirement. A controller building automated decisioning cannot found it on a recognised legitimate interest, even in part.
Why consent is the route of last resort
Consent is the basis to use once the others have been exhausted, not the basis to start from. It is a poor foundation for anything a business intends to keep doing, for four reasons.
The conditions for obtaining it are strict. Article 4(11) requires a freely given, specific, informed and unambiguous indication by a statement or clear affirmative action, and Article 7 puts the burden of proving all of that on the controller. Where the conditions are not met the controller has no lawful basis at all, not a weaker one, and the processing is unlawful from the start.
It can be withdrawn at any time. Article 7(3) requires that withdrawal be as easy as giving consent, so a processing operation built on consent is one the data subject can switch off. That is the point of consent and not a defect in it, but it makes consent unsuitable for processing the business needs to be able to rely on.
It is the hardest basis to build on later. Article 8A(4) restricts reuse most tightly where the data was collected on consent, so a controller that took consent and later needs the data for a different purpose will in most cases have to go back and ask again.
And it carries an evidential burden for as long as the processing continues. The controller must be able to show, records in hand, that each data subject gave consent meeting all four criteria, at the time and for the purpose relied on.
None of this makes consent wrong. Where processing is genuinely optional, where the ePrivacy rules require it, or where explicit consent is the only available Article 9(2) condition, consent is the right answer and the only answer. The error is taking it first because it feels like the safe choice.
Reuse for a new purpose under Article 8A
Reusing data for a new purpose is now governed by Article 8A, which replaced Article 6(4) on 5 February 2026. Article 8A(2) sets out the factors: any link between the original and the new purpose, the context of collection including the relationship between data subject and controller, the nature of the processing including whether it involves special category or criminal offence data, the possible consequences for data subjects, and the existence of safeguards such as encryption or pseudonymisation.
Article 8A(4) restricts reuse most tightly where the data was collected on consent. In that case further processing is compatible only where the data subject consents to the new purpose, or the processing is to demonstrate compliance with Article 5(1), or it falls within the Annex 2 or public-interest routes and the controller cannot reasonably be expected to obtain consent. Data collected on consent is therefore materially harder to repurpose than data collected on another basis.
Special category data: Article 9(2) and Schedule 1
An Article 6 basis is necessary but not sufficient. Processing of special category data also requires a condition in Article 9(2), and for most of those conditions a further condition in Schedule 1 to the Data Protection Act 2018. The substantial public interest conditions are in Part 2 of that Schedule, and most of them require an appropriate policy document under paragraph 5, which cross-refers to paragraph 39 in Part 4.
For regulated firms the conditions relied on in practice are usually paragraph 10, preventing, investigating or detecting unlawful acts, and paragraph 12, regulatory requirements relating to unlawful acts and dishonesty. Paragraph 14, headed preventing fraud, is narrower than that heading: it requires disclosure by a member of, or under arrangements made by, an anti-fraud organisation within section 68 of the Serious Crime Act 2007, so it does not cover a firm’s own internal anti-fraud processing.
The right to object under Article 21
The right to object applies whichever of the three bases the controller relies on. Article 21(1) was amended on 5 February 2026 to add point (ea), so the right to object on grounds relating to the data subject’s particular situation now covers processing under Article 6(1)(e), (ea) and (f) alike. On objection the controller must stop unless it demonstrates compelling legitimate grounds overriding the data subject’s interests, rights and freedoms, or the processing is for the establishment, exercise or defence of legal claims. Reliance on a recognised legitimate interest is not an answer to an objection.
Where the processing is for direct marketing, Article 21(2) and (3) give an absolute right: no balancing, no compelling grounds, and the processing must stop.
Why the choice of lawful basis matters commercially
The basis chosen at the outset determines what the business can lawfully do with the data for as long as it holds it. A controller relying on contract has no balancing exercise to document and no withdrawal right to manage. A controller relying on Article 6(1)(f) must document the balancing exercise and must stop on a valid objection unless it can show compelling legitimate grounds. A controller relying on Article 6(1)(ea) escapes the balancing exercise but cannot automate a significant decision at all. A controller relying on consent must honour withdrawal at any time, must satisfy Article 8A(4) before reusing the data, and carries the evidential burden throughout.
Viewpoint
The advice I give clients on this is consistent and it rarely changes with the facts. Work down the conditions in order of durability, not in the order Article 6(1) prints them. Ask first whether the processing is necessary for performance of the contract the customer has actually entered into. If it is not, ask whether the processing is necessary for a legitimate interest, and whether one of the five Annex 1 conditions removes the balancing exercise. Use consent only when nothing else fits.
Consent is attractive to businesses because it looks like permission, and permission feels safer than judgement. It is the opposite. A legitimate interests assessment is a piece of work done once and recorded; consent is an obligation that runs for the life of the processing, can be revoked by the data subject at any moment, and makes the data harder to use for anything else. A business that builds its core processing on consent has given away control of it.
The recognised legitimate interests introduced by the DUAA do not change that hierarchy. They are narrow, and four of the five are of no use to a commercial controller at all. The one that matters, crime at Annex 1 paragraph 5, is genuinely useful for anti-fraud work and is worth identifying properly rather than defaulting to a balancing exercise that was never needed.
Frequently asked questions about lawful basis
Which lawful basis should I choose first?
Performance of a contract under Article 6(1)(b), where the processing is objectively necessary for it. Failing that, legitimate interests under Article 6(1)(f), or a recognised legitimate interest under Article 6(1)(ea) where one of the five Annex 1 conditions applies. Consent is the route of last resort, for processing that is genuinely optional or where the ePrivacy rules or Article 9(2) leave no alternative.
Why is consent a poor basis for routine processing?
Because the conditions for obtaining it are strict and the burden of proving them sits on the controller under Article 7, because it can be withdrawn at any time and withdrawal must be as easy as giving it, because Article 8A(4) makes consent-collected data the hardest to reuse for a new purpose, and because the evidential burden runs for as long as the processing does.
Can I rely on recognised legitimate interests for fraud prevention?
Yes, under Annex 1 paragraph 5, provided the processing is necessary for detecting, investigating or preventing crime. The controller must record which paragraph it relies on and the evidence of necessity: the absence of a balancing test does not remove the accountability obligation in Article 5(2).
Can a public authority use legitimate interests?
Not for processing carried out in the performance of its tasks. The closing words of Article 6(1) exclude both point (ea) and point (f) for that processing. A public authority acting outside its public tasks, for example in managing its own premises, is in a different position.
Do I need a legitimate interests assessment in writing?
Article 6(1)(f) does not say so in terms, but the accountability principle in Article 5(2) requires a controller to demonstrate compliance, and a balancing exercise that was never recorded is very hard to demonstrate after the event. Where an Annex 1 condition applies instead, record which paragraph is relied on and the evidence of necessity.
Can I switch lawful basis if a data subject complains?
Article 6 contains no express prohibition, but the Information Commissioner’s position is that a controller should not switch after the event, and the original identification and its documentation are what accountability will be tested against. The controller identifies and documents the basis before processing begins, as Article 5(2) requires.
Does the DUAA change how consent is assessed?
Not directly, but the Court of Appeal did. In RTM v Bonne Terre Ltd [2026] EWCA Civ 488 the court held that consent is assessed objectively, and that the individual data subject’s vulnerability or impaired autonomy is neither necessary nor relevant to whether consent was given. The analysis rests on the design of the consent mechanism and the structural character of the relationship.
Can Annex 1 change?
Yes. Under Article 6(6) the Secretary of State may amend Annex 1 by regulations subject to the affirmative resolution procedure, though the five original conditions cannot be removed that way, and a new condition may be added only where it is necessary to safeguard an objective listed in Article 23(1)(c) to (j). Treat the list as live and check it before relying on it.
Discuss your matter
Related Data Protection pages
The choice of lawful basis runs through UK GDPR Compliance, AI and Automated Decision-Making, Data Protection Impact Assessments, PECR and ePrivacy and UK/EU Data Protection Divergence. For the wider framework see Data Protection.
