CIPP/E Domain 3: European Data Processing – Principles and Lawful Bases
Quick Insights:
The GDPR allows personal data processing only when a valid lawful basis applies. These bases include consent, contractual necessity, legal obligation, public interest or official authority, vital interests, and legitimate interests. Organizations must select the correct basis before processing begins, document their decision, and remain transparent with data subjects.
European data protection law establishes fundamental principles that govern how personal data must be processed. These principles ensure that organizations handle personal data responsibly, respect individuals’ rights, and maintain trust in the digital economy.

The GDPR applies to controllers and processors whose activities fall within its material and territorial scope. Controllers must comply with the GDPR’s requirements and be able to demonstrate that compliance, reflecting the principle of accountability.
The current CIPP/E Body of Knowledge discusses European data-processing principles such as fairness and lawfulness, purpose limitation, proportionality, accuracy, storage limitation, and integrity and confidentiality. Under Article 5 of the GDPR, the formal principles are lawfulness, fairness and transparency, purpose limitation, data minimization, storage limitation, accuracy, integrity and confidentiality, and accountability.
This article focuses primarily on the lawful processing criteria covered under Domain-2.
Lawful Bases for Processing Personal Data
Organizations cannot lawfully process personal data unless at least one lawful basis applies. Article 6 of the GDPR provides an exhaustive list of six lawful bases:
Consent
Consent is one of the six lawful bases available under Article 6 of the GDPR. It is appropriate only when individuals have genuine choice and control over the processing. Valid consent must include:
- Freely given: Individuals must have a real choice without pressure
- Specific: Consent must relate to clearly defined purposes
- Informed: Individuals must understand how their data will be used
- Unambiguous: Consent must be expressed through a clear and affirmative action
Controllers must be able to demonstrate that consent was obtained. Individuals have the right to withdraw their consent at any time, and the process must be as simple as providing consent. Withdrawal does not make processing carried out before the withdrawal unlawful.
Consent should not be bundled into general terms or made a condition of receiving a service where the additional processing is unnecessary for that service. Misleading choices and deceptive design patterns may also prevent consent from being freely given, informed, or unambiguous.
Contractual Necessity
Processing may be lawful when it is essential to fulfill a contract with the individual or to take requested steps before entering into that contract.
Examples:
- Processing customer details to deliver an online purchase
- Using personal data to manage a subscription service
- Processing payment information to fulfill a transaction
Contractual necessity must be interpreted strictly. It is not enough for processing to be useful, convenient or included in contractual terms. The controller should be able to demonstrate that the contract’s essential purpose cannot reasonably be achieved without the processing.
Legal Obligation
Processing may also be required to comply with a legal obligation imposed on the controller.
Examples:
- Tax reporting obligations
- Employment law requirements
- Regulatory compliance obligations
The obligation must be established in EU or Member State law. Internal policies, ordinary contractual commitments or general business preferences do not by themselves qualify as legal obligations under Article 6(1)(c).
Vital Interests
Processing may occur when it is necessary to protect someone’s vital interests, typically in situations involving life or death.
Examples:
- Emergency medical treatment when a patient cannot provide consent
- Sharing medical information to protect someone’s life during an emergency
This lawful basis is rarely used and generally applies only in urgent situations.
Public Interest or Official Authority
Processing may be lawful when it is necessary to perform a task carried out in the public interest or to exercise official authority.
Examples may include:
- Administering statutory public benefits
- Issuing licenses or permits
- Maintaining official records
- Conducting legally mandated public-health monitoring
This basis is frequently used by public authorities, although another organization may rely on it where it has been entrusted by law with an appropriate public task.
Legitimate Interests
A controller or third party may rely on legitimate interests where three cumulative conditions are satisfied:
- A lawful, genuine and clearly defined legitimate interest exists.
- The processing is necessary to pursue that interest.
- The individual’s interests, rights and freedoms do not override it.
Possible legitimate interests may include:
- Fraud prevention
- Network security monitoring
- Internal administrative purposes
However, an activity is not automatically lawful merely because it benefits the organization.
Controllers should document the purpose, necessity and balancing assessment and explain the legitimate interest transparently to data subjects. The nature of the data, impact on individuals, reasonable expectations, available safeguards and involvement of children should be considered.
Public authorities cannot rely on legitimate interests when processing personal data in the performance of their official tasks.
The EDPB’s draft Guidelines 1/2024 provide further discussion of the three-stage assessment, but the EDPB currently lists them as a public-consultation version rather than final guidelines.
Processing Special Categories of Personal Data
Article 9 generally prohibits processing personal data revealing racial or ethnic origin, trade-union membership, genetic data, political opinions, religious or philosophical beliefs, qualifying biometric identification data, health information, or information concerning a person’s sex life or sexual orientation.
To process this data lawfully, the controller generally needs both:
- A lawful basis under Article 6
- An applicable exception under Article 9(2)
Exceptions may include explicit consent, employment and social-protection law, vital interests, legal claims, substantial public interest, healthcare, public health, or qualifying research and statistical purposes. Additional safeguards and Member State conditions may also apply.
To be continued with this domain: GDPR Information Provision Obligations
The next part of Domain III covers transparency, privacy notices, and the information controllers must provide under the GDPR.
Conclusion
Understanding lawful processing is essential for GDPR compliance. Organizations should avoid selecting a lawful basis simply because it appears convenient. Instead, they must assess whether the processing is necessary, proportionate, and supported by the GDPR. Proper documentation, transparency, and regular reviews help demonstrate accountability and protect individuals’ rights.
CIPP/E Certification Training with InfosecTrain
Enroll in InfosecTrain’s CIPP European Privacy Training to build a strong understanding of data subject rights under the GDPR. Led by experienced instructors, this course equips you with practical insights and essential knowledge to navigate privacy regulations confidently and prepare effectively for CIPP/E certification. Enhance your data protection skills with expert guidance and real-world scenarios.
TRAINING CALENDAR of Upcoming Batches For CIPP/E Training
| Start Date | End Date | Start - End Time | Batch Type | Training Mode | Batch Status | |
|---|---|---|---|---|---|---|
| 07-Sep-2026 | 22-Sep-2026 | 20:00 - 22:00 IST | Weekday | Online | [ Close ] | |
| 10-Oct-2026 | 25-Oct-2026 | 09:00 - 13:00 IST | Weekend | Online | [ Open ] | |
| 16-Nov-2026 | 01-Dec-2026 | 20:00 - 22:00 IST | Weekday | Online | [ Open ] | |
| 05-Dec-2026 | 20-Dec-2026 | 09:00 - 13:00 IST | Weekend | Online | [ Open ] |
Frequently Asked Questions
What are the six lawful bases under the GDPR?
The six lawful bases are consent, contract, legal obligation, public interest or official authority, vital interests, and legitimate interests.
Is consent always required to process personal data?
No. Consent is only one lawful basis. Another basis may be more appropriate depending on the purpose and circumstances of the processing.
Can consent be withdrawn?
Yes. Individuals can withdraw consent at any time, and withdrawing it must be as easy as giving it.
When can contractual necessity be used?
It can be used when processing is genuinely required to perform a contract or take requested steps before entering into one.
What is a legitimate interests assessment?
It is an assessment that identifies the legitimate interest, checks whether processing is necessary, and balances that interest against individuals’ rights and freedoms.
