Now onboarding businesses across Leeds & Yorkshire — book a free IT & security review
← All resources

Lawful Basis for Processing Personal Data, Explained

In short

Every time your business uses personal data, UK GDPR says you need a lawful basis — one of six legal reasons. This guide explains all six in plain English, shows how to pick the right one, and clears up the common confusion between consent and legitimate interests. Choosing well now saves headaches later.

Why ‘lawful basis’ matters

Under UK GDPR, you cannot simply use personal data because it is convenient. Every time your business collects, stores, or uses information about a person — a customer, an employee, a supplier contact — you need a lawful basis. That is one of six legal reasons the law recognises for handling personal data.

This sounds technical, but the idea is simple: you should be able to say, in one clear sentence, why you are allowed to use someone’s data. Getting this right is one of the foundations of data protection, and it is far easier to decide up front than to unpick later. If you are new to the wider topic, our GDPR basics for UK small business sets the scene.

The six lawful bases in plain English

UK GDPR gives you six lawful bases. No single one is ‘better’ than the others — the right choice depends on what you are doing and why.

  1. Consent. The person has actively and freely agreed to a specific use of their data, and can withdraw that agreement at any time. Think of a newsletter sign-up.
  2. Contract. You need the data to fulfil a contract with the person, or to take steps they asked for before entering one. For example, using a delivery address to send an order.
  3. Legal obligation. You have to process the data to comply with the law — such as keeping payroll records for HMRC.
  4. Vital interests. You need the data to protect someone’s life. This is rare and mostly relevant in emergencies or healthcare.
  5. Public task. You are carrying out an official function or a task in the public interest, usually as a public body. Most small businesses will not use this one.
  6. Legitimate interests. You have a genuine business reason to use the data, you have checked it does not override the person’s rights and freedoms, and they would reasonably expect it. This is the most flexible basis — and the one that requires the most judgement.

How to pick the right one

The basis should follow the purpose. Ask yourself what you are actually trying to do, then match it to the most natural fit:

  • Selling someone a product or service? Contract usually covers the core activity.
  • Keeping tax, employment or health-and-safety records? Legal obligation.
  • Sending marketing emails to people who have signed up? Consent.
  • Using existing customer details for a closely related, expected purpose — like fraud prevention or basic account administration? Legitimate interests often fits.

A few principles help you choose well:

  • Pick one basis per purpose, and choose before you start. You should not stack several bases as a fallback, and you should not switch later without good reason.
  • Don’t default to consent. Consent feels safe, but it is often the wrong tool. If someone cannot realistically say no — because you need the data to do the job they asked for — then consent is not genuine, and contract or legitimate interests is more honest.
  • Write it down. Record your chosen basis for each activity and explain it in your privacy notice.

If someone cannot realistically say no, then consent is not genuine, and contract or legitimate interests is more honest.

These two cause the most confusion, so they are worth separating clearly.

Consent puts the person in control. They opt in, and they can opt out whenever they like. When they withdraw, you must stop. Consent must be freely given, specific, informed and unambiguous — a pre-ticked box or a buried clause does not count. Consent is the right basis for things people should be able to refuse without losing the core service, such as marketing newsletters.

Legitimate interests gives you more flexibility, but with a condition: you must carry out a short balancing exercise, sometimes called a legitimate interests assessment. It has three parts:

  1. Purpose — is there a genuine, specific benefit to your business or a third party?
  2. Necessity — is using the data a reasonable way to achieve it, with no less intrusive option?
  3. Balance — do the person’s rights and reasonable expectations override your interest?

If the interest is genuine, the processing is necessary, and it does not override people’s rights, legitimate interests is a valid and sensible choice. It suits everyday activities people would expect, like preventing fraud or improving your service.

A useful rule of thumb: if you are doing something people would clearly expect and are unlikely to object to, legitimate interests often fits. If you are doing something people should be able to say no to freely, use consent.

A note on special category data

Some data — health, ethnicity, religious beliefs, sexual orientation, and similar — is treated as special category data. Using it needs both a lawful basis from the six above and an extra condition from a separate list. If you handle this kind of information, take extra care and get advice before you start. Businesses in sensitive sectors, such as healthcare, should treat this as a priority.

Keep it simple and write it down

For most small businesses, this is not as daunting as it sounds. Make a short list of the ways you use personal data, put a lawful basis against each one, and reflect it in your privacy notice. That single page of thinking answers the vast majority of questions the ICO — or a curious customer — might ever ask.

If you would like a hand mapping your data and tightening the security around it, DACROS supports small businesses across Leeds and Yorkshire with practical managed IT and cyber-security. Get in touch and we will keep it in plain English.

Frequently asked questions

Do I need consent for everything I do with personal data?

No. Consent is only one of six lawful bases, and often it is not the best fit. If you are fulfilling an order, meeting a legal duty, or pursuing a reasonable business interest that does not override people's rights, another basis is usually more appropriate. Over-relying on consent creates unnecessary work and risk.

What is the difference between consent and legitimate interests?

Consent means the person has actively agreed and can withdraw at any time. Legitimate interests means you have a genuine reason to use the data, you have checked it does not override the person's rights, and they would reasonably expect it. Consent gives people more control; legitimate interests gives you more flexibility but requires you to do a balancing test.

Can I change my lawful basis later?

You should choose the correct basis before you start processing and document it, because switching afterwards is difficult and can undermine trust. If you told people you relied on consent, you generally cannot quietly move to legitimate interests. Get it right up front and record your reasoning.

Where do I record my lawful basis?

Note it in your record of processing activities and explain it in your privacy notice so people know why you use their data. It does not need to be complicated — a short, clear entry for each activity is enough for most small businesses.

Who writes this

Dacros — led by Jordan Gilbert

Our guides are written and checked by the Dacros team, led by founder Jordan Gilbert. We run the IT and cyber security for UK small businesses — and hold our own systems to the same standard. About Jordan · About Dacros.

Want this handled for you?

Dacros runs the IT and security for UK small businesses. Book a free review and we'll tell you what's worth doing — no jargon, no pressure.