You need one of the six grounds in Article 6(1) for every purpose you process personal data for, you have to pick it before you start, and you cannot quietly change it later because the first one stopped being convenient. Most teams know the list. What they lack is a procedure for choosing, which is why the same handful of processing activities get labelled "legitimate interest" by default and nobody can explain why.
This article covers when the choice actually happens, what each of the six is genuinely for, the order to work through them, what rules a basis out, and where your decision has to show up afterwards.
You Pick Per Purpose, Before You Process
The unit of decision is the purpose, not the company and not the dataset. The same customer email address might be processed under contract to deliver the service, under legal obligation to keep an invoice record, and under legitimate interests to send a product-change notice. Three purposes, three bases, one field in one table.
The timing matters as much as the choice. Article 5(1)(a) requires processing to be lawful, and Article 5(2) requires you to demonstrate it. A basis identified after a complaint arrives is not a basis, it is a justification — and the difference is visible to anyone reading the dates on your documentation.
The harder constraint is that you cannot swap. Regulators are consistent that you should not switch basis part-way through unless there is a genuine reason, because the rights attached to each basis differ. Erasure is close to absolute against consent and qualified against contract. Portability applies to consent and contract and not to legitimate interests. Telling someone their data was processed under consent, then relying on legitimate interests when they withdraw, retrospectively changes what rights they had. That is the specific thing not to do.
What Each Of The Six Is Actually For
Consent, 6(1)(a). The person has genuinely agreed. Powerful where there is real choice, fragile everywhere else, and heavy to administer because it must be as easy to withdraw as to give.
Contract, 6(1)(b). Processing necessary to perform a contract with the person, or to take pre-contractual steps at their request. "Necessary" is doing the work: it covers delivering the service they signed up for, not everything you would like to do with the resulting data.
Legal obligation, 6(1)(c). A statutory duty, not a contractual one and not a commercial norm. Tax record retention qualifies; a customer's security questionnaire does not.
Vital interests, 6(1)(d). Life-or-death situations. Almost never relevant to a B2B SaaS and worth knowing mainly so you can rule it out quickly.
Public task, 6(1)(e). Official authority or a task in the public interest. Not available to most private companies.
Legitimate interests, 6(1)(f). Your interest or a third party's, balanced against the person's rights. The most flexible and the most demanding, because it requires a documented three-part assessment. How that assessment works — the purpose, necessity and balancing tests, and the documentation each requires — is a subject in its own right and this article does not repeat it.
The Order To Work Through Them
Work top-down and stop at the first that genuinely fits.
Is it legally required? If a statute compels the processing, 6(1)(c) is the answer and there is nothing to weigh. This is the smallest category and the easiest to confirm.
Is it necessary to deliver what they asked for? If the person cannot receive the service without it, 6(1)(b) applies and you are done. Test it honestly: could you deliver the product without this processing? If yes, it is not necessary, whatever its business value.
Would a reasonable person expect it, and can I justify it? That is 6(1)(f) territory, and it needs the assessment before you rely on it, not after.
Does the person have a genuine free choice? Only then is consent appropriate. Consent chosen because it feels safest is usually the worst option available — it is the most easily invalidated and the most operationally expensive.
The order matters because working bottom-up produces the classic failure: reaching for consent, discovering it cannot be freely given in your context, and then retrofitting legitimate interests to a process already built around a checkbox.
What Rules A Basis Out
Several constraints remove options before you get to weigh them.
Special category data. Article 9(1) prohibits processing health, biometric, racial, political, religious, trade union, genetic and sex life data unless an Article 9(2) condition also applies. You need a lawful basis under Article 6 and a condition under Article 9. Legitimate interests is not one of the Article 9(2) conditions.
Public authorities cannot rely on legitimate interests for processing carried out in the performance of their tasks.
Children and information society services. Where you rely on consent for a service offered directly to a child, Article 8 adds a parental consent requirement below an age that varies by Member State — which is a real constraint on choosing consent, not a detail.
Direct marketing. Whatever basis you pick, Article 21(2) gives an unqualified right to object, with no balancing available to you at that point.
And separately from all of this, storing or reading information on someone's device carries its own consent requirement under the ePrivacy rules. Whether product analytics needs consent is the clearest worked example of two regimes producing two different answers to what looks like one question.
Where Your Decision Has To Show Up
Choosing is half the work. The other half is that the choice is visible in three places, and inconsistency between them is what gets noticed.
Your privacy information has to state it: Articles 13(1)(c) and 14(1)(c) require the purposes and the legal basis. Where you rely on legitimate interests, a separate provision — Article 13(1)(d) for data collected from the person, Article 14(2)(b) where it was not — requires you to name the interests themselves.
Your record of processing activities should carry it per activity, which is what makes it possible to answer a rights request correctly rather than generously.
Your assessments — the legitimate interests assessment, the consent records — are the evidence that the decision was made rather than assumed.
The place this most often falls apart is data you did not collect directly. When personal data arrives from a third party or a public source rather than the person, the basis question is identical but the paper trail is thinner, and there is a separate obligation to tell people you hold it.
Common Mistakes With Lawful Bases
Picking one basis for the whole company. A basis attaches to a purpose. An organisation that says "we rely on legitimate interests" has not made a decision, it has skipped one, and it will not survive the first question about a specific processing activity.
Treating consent as the safe default. Consent is the most easily invalidated basis and creates the most ongoing work. Where the person has no real choice, consent is not merely weak — it is invalid, and the processing it was supposed to support has no basis at all.
Stretching contract necessity. Article 6(1)(b) covers what is necessary to deliver the service. Product analytics, marketing, enrichment and scoring are not necessary to deliver it, however normal they are, and accepting terms of service is not consent to them.
Switching basis when the first one becomes inconvenient. Moving from consent to legitimate interests when someone withdraws retrospectively changes their rights. If a basis was wrong, fix it deliberately and tell people; do not quietly substitute.
Documenting the conclusion but not the reasoning. "Legitimate interests" written in a cell is not an assessment. What matters is why the other bases did not fit and what was weighed — because that is what you will be asked for.
FAQ
Can I rely on more than one lawful basis for the same processing?
You should identify the single most appropriate basis for each purpose rather than listing several as a hedge. Naming a fallback suggests the primary one might not hold, and it makes your privacy information ambiguous about which rights apply. Where a genuinely different purpose exists, that is a separate entry with its own basis.
Does legitimate interests mean I do not have to tell anyone?
No. Transparency is independent of your basis. You must state that you rely on legitimate interests and describe what those interests are, and people retain the right to object. What legitimate interests removes is the need to ask permission first, not the need to be open about it.
What if I realise the basis we have been using is wrong?
Fix it deliberately. Work out the correct basis, assess whether the processing was lawful in the interim, correct your privacy information and your records, and consider whether people need to be told. The failure mode is silently updating a spreadsheet and hoping nobody compares versions.
Is "we've always done it this way" ever a legitimate interest?
No. Longevity is not an interest — it is an explanation of how the processing started. A legitimate interest has to be a specific, current, articulable purpose that you could state to the person concerned. If the honest answer is that nobody remembers why the processing exists, that is a signal to stop it rather than to justify it.
Closing Thought
The reason lawful basis feels harder than it is comes down to a mismatch in how the question is usually asked. Teams want to know which basis is best, as though the six were options on a menu with different levels of protection. They are not. They are descriptions of six different situations, and in almost every case the facts have already decided which one you are in. The work is not choosing well — it is looking honestly at what you are doing and naming it accurately, which is uncomfortable precisely when the honest name is "we would like to do this and nobody asked."
Once decided, the basis has to stay visible in your privacy information, your record and your assessments. ComplyDog hosts a compliance portal on your own domain covering your DPA, subprocessor list, data subject request handling and security page, which is where the outward-facing half of this ends up. It does not choose your bases or write your assessments — those are judgements about your own processing, and they are the part that has to come first.