Skip to main content

Have a legal justification — Have a legal justification for your data processing activities

Processing of data is illegal under the GDPR unless you can justify it according to one of six conditions listed in Article 6. There are other provisions related to children and special categories of personal data in Articles 7-11. Review these provisions, choose a lawful basis for processing, and document your rationale. Note that if you choose "consent" as your lawful basis, there are extra obligations, including giving data subjects the ongoing opportunity to revoke consent. If "legitimate interests" is your lawful basis, you must be able to demonstrate you have conducted a privacy impact assessment.

PropertyValue
SectionLawful basis and transparency
Owneroperator

Mapped Controls

ControlTitle
SID-ORG-05Legal, Regulatory, and Contractual Compliance

Source: GDPR Checklist for Data Controllers