Article 6: Lawfulness of processingAI-relevant
Praxikon tracks Article 6 (Lawfulness of processing) under the GDPR, alongside the EU AI Act, citing the source for every statement.
What does Article 6 govern?
Article 6 determines when the processing of personal data is lawful. Paragraph 1 lists six legal bases, at least one of which must apply: consent (a), performance of a contract (b), a legal obligation (c), vital interests (d), a task in the public interest or official authority (e) and legitimate interests (f). Public authorities may not rely on legitimate interests in the performance of their tasks (paragraph 1, last subparagraph). Paragraphs 2 and 3 require that bases (c) and (e) are laid down in Union or Member State law and allow Member States to specify them further. Paragraph 4 gives the factors for assessing whether data may be used for a purpose other than the one for which they were collected.
Key term: Legal basis: one of the six conditions in paragraph 1 that makes processing lawful; without a legal basis, processing is not permitted
Directly affects:controllerprocessordata subjectmember state
Praxikon’s reading of the text and the recitals; the official text below prevails.
AI Act intersection
A valid legal basis is required for processing personal data in AI training data. AI Act Art. 10 indirectly references this GDPR requirement.
Official text
Source: EUR-Lex, Regulation (EU) 2016/679. Official text, reproduced without modification.
What does this mean for you?
Controller
Before each processing operation, decide which legal basis in paragraph 1 you rely on and record it. If you choose legitimate interests (paragraph 1(f)), you must weigh your interest against the interests and fundamental rights of the data subject, with extra weight where a child is involved; recital 47 names the reasonable expectations of the data subject as the yardstick. If you want to use data for a new purpose, for example to train an AI model, you run the compatibility test of paragraph 4, unless you have fresh consent or a legal provision that allows it.
Processor
The legal basis belongs to the controller; as a processor you cannot choose a legal basis yourself. If you use the data for a purpose of your own, you are no longer a processor for that part and need your own legal basis under paragraph 1.
Data Protection Officer
Check that a legal basis is recorded for every processing operation and that it fits the situation: recital 43 warns that consent is not a valid basis where there is a clear imbalance, for example between a public authority and a citizen. Guard the compatibility test of paragraph 4 whenever someone proposes using data for a different purpose.
Data Subject
An organisation may process your data only if one of the six legal bases in paragraph 1 applies. If it relies on legitimate interests, your interests and fundamental rights must not override that interest (paragraph 1(f)). When data are used for another purpose, recital 50 says the organisation must inform you about that purpose and about your rights, including the right to object.
Compliance checklist
Related recitals
In order for processing to be lawful, personal data should be processed on the basis of the consent of the data subject concerned or some other legitimate basis, laid down by law, either in this Regul...
(41)Where this Regulation refers to a legal basis or a legislative measure, this does not necessarily require a legislative act adopted by a parliament, without prejudice to requirements pursuant to the c...
(42)Where processing is based on the data subject's consent, the controller should be able to demonstrate that the data subject has given consent to the processing operation. In particular in the context ...
(43)In order to ensure that consent is freely given, consent should not provide a valid legal ground for the processing of personal data in a specific case where there is a clear imbalance between the dat...
(44)Processing should be lawful where it is necessary in the context of a contract or the intention to enter into a contract....
(45)Where processing is carried out in accordance with a legal obligation to which the controller is subject or where processing is necessary for the performance of a task carried out in the public intere...
(46)The processing of personal data should also be regarded to be lawful where it is necessary to protect an interest which is essential for the life of the data subject or that of another natural person....
(47)The legitimate interests of a controller, including those of a controller to which the personal data may be disclosed, or of a third party, may provide a legal basis for processing, provided that the ...
(48)Controllers that are part of a group of undertakings or institutions affiliated to a central body may have a legitimate interest in transmitting personal data within the group of undertakings for inte...
(49)The processing of personal data to the extent strictly necessary and proportionate for the purposes of ensuring network and information security, i.e. the ability of a network or an information system...
(50)The processing of personal data for purposes other than those for which the personal data were initially collected should be allowed only where the processing is compatible with the purposes for which...
Cross-references
Frequently asked questions
Connections
What connects to Article 6 GDPR
Themes where this returns
The counterpart in the other law
Case law
- EU Court of Justice in KNLTB: a purely commercial interest can be a legitimate interest
2024-10-04 · final, Hof van Justitie van de Europese Unie
- Noord-Nederland District Court upholds DPA fine for village livestream, reduces it to 375 euros
2025-01-09 · status not established, Rechtbank Noord-Nederland
- Council of State: 600,000 euro fine for wifi tracking in Enschede stays annulled
2026-07-29 · final, Raad van State, Afdeling bestuursrechtspraak
- Mousse: asking for Mr or Ms when selling a train ticket is not necessary
2025-01-09 · final, Hof van Justitie van de EU (Eerste kamer), Mousse tegen Commission nationale de l'informatique et des libertés (CNIL) en SNCF Connect
- Overijssel District Court revokes DPA fine for wifi tracking in Enschede
2024-02-02 · final, Rechtbank Overijssel
- Interim relief judge: DPA must redact fine amount when giving an enforcement decision to complainants
2024-05-31 · status not established, Rechtbank Den Haag, voorzieningenrechter (kort geding, team handel)
- Meta v Bundeskartellamt: competition authority may find a GDPR breach, strict conditions for legal bases behind personalised advertising
2023-07-04 · final, Hof van Justitie van de EU (Grote kamer), Meta Platforms Inc., Meta Platforms Ireland Ltd en Facebook Deutschland GmbH tegen Bundeskartellamt
Guidelines
- Opinion 28/2024 on certain data protection aspects related to the processing of personal data in the context of AI models
2024-12-17 · final, European Data Protection Board (EDPB)
- Guidelines 03/2026 on web scraping in the context of generative AI
2026-07-07 · under consultation, European Data Protection Board (EDPB)
- Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR (legitimate interest)
2024-10-08 · adopted, European Data Protection Board (EDPB)
- Guidelines 05/2020 on consent under Regulation 2016/679
2020-05-04 · final, European Data Protection Board (EDPB)
- Dutch DPA (AP) publishes position paper on the Digital Omnibus and the AI Omnibus
2026-01-13 · final, Autoriteit Persoonsgegevens
- Guidelines 01/2025 on Pseudonymisation
2025-01-16 · adopted, European Data Protection Board (EDPB)
- Guidelines 1/2026 on processing of personal data for scientific research purposes
2026-04-15 · adopted, European Data Protection Board (EDPB)
- EDPB and EDPS adopt Joint Opinion 2/2026 on the Digital Omnibus
2026-02-10 · final, European Data Protection Board en European Data Protection Supervisor
Enforcement and fines8 of 9
- Dutch DPA and tennis federation KNLTB end litigation: fine cut from 525,000 to at most 250,000 euros
2025-10-18 · status not established, Autoriteit Persoonsgegevens
- 600,000 euro fine for AS Watson (Kruidvat) over tracking cookies without consent
2024-05-02 · annulled, Autoriteit Persoonsgegevens
- 500 euro fine and penalty order for Stichting Oud Lemmer over webcam livestream
2021-07-09 · status not established, Autoriteit Persoonsgegevens
- DPA cuts Kruidvat fine to 50,000 euros on objection
2025-05-27 · status not established, Autoriteit Persoonsgegevens
- Ten municipalities fined a total of 250,000 euros for unlawful files on Muslim residents
2026-02-03 · final, Autoriteit Persoonsgegevens
- Experian Netherlands fined 2.7 million euros for credit scoring without legal basis or information
2025-10-16 · final, Autoriteit Persoonsgegevens
- Coolblue fined 40,000 euros on objection for cookies without consent
2024-12-23 · status not established, Autoriteit Persoonsgegevens
- Formal warning to the Dutch Minister of Education, Culture and Science not to put the CABR war archive online and searchable
2024-11-26 · final, Autoriteit Persoonsgegevens
Legislation in motion
- Proposal: exception for biometric verification under the data subject's sole control (Article 9(2)(l) GDPR)
2025-11-19 · proposal, Europese Commissie
- Proposal: legitimate interest for development and operation of AI (new Article 88c GDPR)
2025-11-19 · proposal, Europese Commissie
- Council: Irish Presidency continues with a revised compromise, Antici Group 11 September 2026
2026-09-11 · under negotiation, Raad van de Europese Unie, Iers voorzitterschap
- Proposal: cookie rules move from ePrivacy to the GDPR, with new exceptions and a six-month rule (new Article 88a GDPR and Article 5(3) ePrivacy)
2025-11-19 · under negotiation, Europese Commissie
- Proposal: definition of scientific research, purpose limitation and information duty for research (Article 4(38), 5(1)(b) and 13(5) GDPR)
2025-11-19 · under negotiation, Europese Commissie