Fast Track Bootcamps
 Crafted For Career-Ready Skills

CIPP/E Domain 3: European Data Processing – Principles and Lawful Bases

Quick Insights:

The GDPR allows personal data processing only when a valid lawful basis applies. These bases include consent, contractual necessity, legal obligation, public interest or official authority, vital interests, and legitimate interests. Organizations must select the correct basis before processing begins, document their decision, and remain transparent with data subjects.

European data protection law establishes fundamental principles that govern how personal data must be processed. These principles ensure that organizations handle personal data responsibly, respect individuals’ rights, and maintain trust in the digital economy.

CIPP/E Domain 3: European Data Processing — Principles and Lawful Bases

The GDPR applies to controllers and processors whose activities fall within its material and territorial scope. Controllers must comply with the GDPR’s requirements and be able to demonstrate that compliance, reflecting the principle of accountability.

The current CIPP/E Body of Knowledge discusses European data-processing principles such as fairness and lawfulness, purpose limitation, proportionality, accuracy, storage limitation, and integrity and confidentiality. Under Article 5 of the GDPR, the formal principles are lawfulness, fairness and transparency, purpose limitation, data minimization, storage limitation, accuracy, integrity and confidentiality, and accountability.

This article focuses primarily on the lawful processing criteria covered under Domain-2.

Lawful Bases for Processing Personal Data

Organizations cannot lawfully process personal data unless at least one lawful basis applies. Article 6 of the GDPR provides an exhaustive list of six lawful bases:

Consent

Consent is one of the six lawful bases available under Article 6 of the GDPR. It is appropriate only when individuals have genuine choice and control over the processing. Valid consent must include:

  • Freely given: Individuals must have a real choice without pressure
  • Specific: Consent must relate to clearly defined purposes
  • Informed: Individuals must understand how their data will be used
  • Unambiguous: Consent must be expressed through a clear and affirmative action

Controllers must be able to demonstrate that consent was obtained. Individuals have the right to withdraw their consent at any time, and the process must be as simple as providing consent. Withdrawal does not make processing carried out before the withdrawal unlawful.

Consent should not be bundled into general terms or made a condition of receiving a service where the additional processing is unnecessary for that service. Misleading choices and deceptive design patterns may also prevent consent from being freely given, informed, or unambiguous.

Contractual Necessity

Processing may be lawful when it is essential to fulfill a contract with the individual or to take requested steps before entering into that contract.

Examples:

  • Processing customer details to deliver an online purchase
  • Using personal data to manage a subscription service
  • Processing payment information to fulfill a transaction

Contractual necessity must be interpreted strictly. It is not enough for processing to be useful, convenient or included in contractual terms. The controller should be able to demonstrate that the contract’s essential purpose cannot reasonably be achieved without the processing.

Legal Obligation

Processing may also be required to comply with a legal obligation imposed on the controller.

Examples:

  • Tax reporting obligations
  • Employment law requirements
  • Regulatory compliance obligations

The obligation must be established in EU or Member State law. Internal policies, ordinary contractual commitments or general business preferences do not by themselves qualify as legal obligations under Article 6(1)(c).

Vital Interests

Processing may occur when it is necessary to protect someone’s vital interests, typically in situations involving life or death.

Examples:

  • Emergency medical treatment when a patient cannot provide consent
  • Sharing medical information to protect someone’s life during an emergency

This lawful basis is rarely used and generally applies only in urgent situations.

Public Interest or Official Authority

Processing may be lawful when it is necessary to perform a task carried out in the public interest or to exercise official authority.

Examples may include:

  • Administering statutory public benefits
  • Issuing licenses or permits
  • Maintaining official records
  • Conducting legally mandated public-health monitoring

This basis is frequently used by public authorities, although another organization may rely on it where it has been entrusted by law with an appropriate public task.

Legitimate Interests

A controller or third party may rely on legitimate interests where three cumulative conditions are satisfied:

  • A lawful, genuine and clearly defined legitimate interest exists.
  • The processing is necessary to pursue that interest.
  • The individual’s interests, rights and freedoms do not override it.

Possible legitimate interests may include:

  • Fraud prevention
  • Network security monitoring
  • Internal administrative purposes

However, an activity is not automatically lawful merely because it benefits the organization.

Controllers should document the purpose, necessity and balancing assessment and explain the legitimate interest transparently to data subjects. The nature of the data, impact on individuals, reasonable expectations, available safeguards and involvement of children should be considered.

Public authorities cannot rely on legitimate interests when processing personal data in the performance of their official tasks.

The EDPB’s draft Guidelines 1/2024 provide further discussion of the three-stage assessment, but the EDPB currently lists them as a public-consultation version rather than final guidelines.

Processing Special Categories of Personal Data

Article 9 generally prohibits processing personal data revealing racial or ethnic origin, trade-union membership, genetic data, political opinions, religious or philosophical beliefs, qualifying biometric identification data, health information, or information concerning a person’s sex life or sexual orientation.

To process this data lawfully, the controller generally needs both:

  • A lawful basis under Article 6
  • An applicable exception under Article 9(2)

Exceptions may include explicit consent, employment and social-protection law, vital interests, legal claims, substantial public interest, healthcare, public health, or qualifying research and statistical purposes. Additional safeguards and Member State conditions may also apply.

To be continued with this domain: GDPR Information Provision Obligations

The next part of Domain III covers transparency, privacy notices, and the information controllers must provide under the GDPR.

Conclusion

Understanding lawful processing is essential for GDPR compliance. Organizations should avoid selecting a lawful basis simply because it appears convenient. Instead, they must assess whether the processing is necessary, proportionate, and supported by the GDPR. Proper documentation, transparency, and regular reviews help demonstrate accountability and protect individuals’ rights.

CIPP/E Certification Training with InfosecTrain

Enroll in InfosecTrain’s CIPP European Privacy Training to build a strong understanding of data subject rights under the GDPR. Led by experienced instructors, this course equips you with practical insights and essential knowledge to navigate privacy regulations confidently and prepare effectively for CIPP/E certification. Enhance your data protection skills with expert guidance and real-world scenarios.

Cipp

TRAINING CALENDAR of Upcoming Batches For CIPP/E Training

Start Date End Date Start - End Time Batch Type Training Mode Batch Status
07-Sep-2026 22-Sep-2026 20:00 - 22:00 IST Weekday Online [ Close ]
10-Oct-2026 25-Oct-2026 09:00 - 13:00 IST Weekend Online [ Open ]
16-Nov-2026 01-Dec-2026 20:00 - 22:00 IST Weekday Online [ Open ]
05-Dec-2026 20-Dec-2026 09:00 - 13:00 IST Weekend Online [ Open ]

Frequently Asked Questions

What are the six lawful bases under the GDPR?

The six lawful bases are consent, contract, legal obligation, public interest or official authority, vital interests, and legitimate interests.

Is consent always required to process personal data?

No. Consent is only one lawful basis. Another basis may be more appropriate depending on the purpose and circumstances of the processing.

Can consent be withdrawn?

Yes. Individuals can withdraw consent at any time, and withdrawing it must be as easy as giving it.

When can contractual necessity be used?

It can be used when processing is genuinely required to perform a contract or take requested steps before entering into one.

What is a legitimate interests assessment?

It is an assessment that identifies the legitimate interest, checks whether processing is necessary, and balances that interest against individuals’ rights and freedoms.

Operationalizing-DPDPA-Enforcement-Readiness-Auditable-Compliance
TOP