Art. 6 GDPR: The six legal bases are clearly documented and audit-proof
Art. 6 GDPR lists six legal bases. In practice, however, it is not the letter but the documentation that determines whether processing lasts. The article shows how you can select, justify and anchor legal bases in a directory in an audit-proof manner.
Article 6 paragraph 1 GDPR identifies six legal bases on which any processing of personal data must be based: consent, contract, legal obligation, vital interests, public task and legitimate interest. The regulation seems simple, but in practice tests fail less often because of the wording than because of the documentation. During the audit, supervisory authorities such as the Federal Commissioner for Data Protection or the state data protection officers first ask for the list of processing activities in accordance with Art. 30 GDPR and the legal basis stored there. Anyone who enters a blanket statement like "Art. 6 Para. 1 GDPR" here has not formally documented anything and is providing the auditor with a template for follow-up questions.
This article brings order to the six facts, shows the typical pitfalls when it comes to consent and legitimate interest and describes a reliable documentation process. It is aimed at data protection officers, compliance officers and management who expect an internal or external audit in the next twelve months. You will find out which fields the directory must contain at least according to Art. 30 GDPR, when a data protection impact assessment according to Art. 35 GDPR becomes mandatory, how Art. 6 and Art. 9 GDPR overlap with sensitive data, and how the CIVAC Compliance Platform and Officer-as-a-Service link processing activities in such a way that the legal basis is not lost in an Excel table.
Key Takeaways
- Art. 6 Para. 1 GDPR recognises six legal bases, each with its own requirements and obligations to provide evidence to the supervisory authority.
- A legal basis without documented consideration or proof of consent is in fact not a legal basis in the audit.
- The directory according to Art. 30 GDPR is the central storage location in which the choice of legal basis for processing can be permanently verified.
The six legal bases at a glance
Art. 6 Paragraph 1 GDPR lists six alternative circumstances for permission. Letter a regulates the consent of the data subject, letter b the processing for the fulfilment of a contract or for the implementation of pre-contractual measures. Letter c covers legal obligations to which the controller is subject, such as tax, commercial or social law retention obligations. Letter d protects the vital interests of the data subject or another natural person and is rarely used in the human resources area. Letter e addresses public tasks and letter f addresses the legitimate interest of the person responsible or a third party.
The order in the examination is important. The external data protection officer does not choose arbitrarily, but systematically. First, check whether the processing is based on a contract or a legal obligation. Only then do consent or legitimate interest come into consideration. Anyone who chooses to give consent first, even though there is a contract, risks the entire data collection being ineffective if revoked. The European Data Protection Board has expressly confirmed this hierarchy in its guidelines 05/2020 on consent. A legal basis for each processing purpose is mandatory; combined supports are only permitted if each legal basis has its own merits and is documented separately in the directory.
This discipline in selection later determines how stable the processing is in the event of an audit. The overview of the letters used is included as a key figure in the reporting line to management. Anyone who finds that over seventy percent of their processing operations are based on legitimate interest should question internally whether the mandatory data set out in letter c has been systematically overlooked. The opposite finding, that hardly any processing is based on legitimate interest, is also a warning signal: necessary security measures such as log analysis or fraud prevention are probably not clearly supported by law. A distribution of the legal basis across the six letters is realistic and plausible in most medium-sized companies.
Consent according to Art. 6 Para. 1 lit. a GDPR: form, revocation and burden of proof
Consent is the most prominent but also the most fragile fact. Art. 7 GDPR requires that consent be given voluntarily, in an informed manner and unambiguously. The burden of proof lies with the person responsible, not the person concerned. In the audit, a note “User has agreed” is not enough. What is necessary is the wording of the declaration obtained, the time stamp, the technical source (form, cookie banner, double opt-in email) and information about the possibility of revocation in accordance with Art. 7 Para. 3 GDPR. If one of these documents is missing, the legal basis is overturned and the processing becomes retroactively unlawful.
Particular caution applies to employee data. In its ruling of May 8, 2020 (ref. 2 AZR 168/20), the Federal Labour Court made it clear that the voluntary nature of employment relationships in accordance with Article 7 (4) of the GDPR is regularly doubtful. Section 26 (2) BDSG explicitly requires that the voluntary nature of the processing be documented, for example if processing provides the employee with a legal or economic advantage. Anyone who asks employees for consent to publish profile photos on the intranet should therefore document the reason, the benefit and the express information about refusal without consequences.
The appointment certificate, signed, filed, verifiable. Anyone who collects consent via an identity provider, a CRM or a consent management tool exports the logs at least annually and stores them in an audit-proof manner. The clock starts on awareness. A subsequent subsequent grant of consent does not cure the illegality in the meantime and does not protect against fines in accordance with Art. 83 Para. 5 GDPR. A monthly sample is practically helpful: select three consents obtained from the CRM, request the associated receipts and check for completeness. If this sample fails, the audit also fails.
Contract and pre-contractual measures according to letter b
Art. 6 Para. 1 lit. b GDPR permits processing if it is necessary to fulfil a contract with the data subject or to carry out pre-contractual measures at your request. This is the legal basis of the classic ordering process, reservation and rental agreement. The word “required” is crucial. In Guidelines 02/2019 on online services, the European Data Protection Board emphasised that necessity must be interpreted narrowly. Data that is dispensable for the contract cannot be based on lit. b, but requires an additional legal basis or separate consent.
In concrete terms, this means: A delivery address for sending a package clearly falls under lit. b. This does not include a telephone number that the sender collects solely for marketing purposes. Nor the date of birth, unless proof of age is part of the contract. The separation between contractual and advertising data fields belongs in the directory according to Art. 30 GDPR and in the data protection notice according to Art. 13 GDPR. Anyone who bases comprehensive processing on a blanket basis in the contract risks fines.
The French supervisory authority CNIL imposed a fine of 32 million euros on Amazon France Logistique in 2026, which was based, among other things, on an overstretched interpretation of letter b for employee scanners. Clean documentation for each data field and purpose would have at least greatly limited the dispute. Practice in mail order also shows that data transfer to payment service providers, logistics partners and rating platforms must be based on different letters depending on the constellation. A uniform “fulfilment of contract” clause does not apply to credit checks, newsletters or customer satisfaction surveys. Each of these processing operations must be kept separately in the register and provided with the applicable legal basis.
Legal obligation and public task: letters c and e
Letter c describes processing that the controller must carry out due to a legal obligation. Typical examples are the ten-year retention of accounting documents in accordance with Section 257 of the German Commercial Code (HGB) and Section 147 of the AO, the management of wage accounts in accordance with Section 41 of the Income Tax Act (EStG) or the reporting obligations to social insurance. What is important is that the obligation must follow from a legal norm, not from a recommendation, an industry standard or a corporate directive. An ISO/IEC 27001:2022 specification does not in itself establish a legal basis according to lit. c, but it can provide argumentative help within the scope of the legitimate interest.
Letter e is tailored to public bodies and private actors with public tasks, such as entrusted companies. In the private sector it plays practically no role. The legal obligation must be specifically stated in the list according to Article 30 of the GDPR: “Storage of invoice documents in accordance with Section 147 Paragraph 1 AO, period ten years”. A blanket statement of “legal obligation” does not meet the requirements of the supervisory authorities.
The Compliance Officer should map the commercial, tax and social law retention obligations together with the data protection officer in a deletion matrix. This deletion matrix is maintained as a template in the CIVAC workspace and linked to the directory so that unused retentions automatically fall into the deletion concept. This closes one of the most common audit gaps: retention for too long without a clear obligation. If you cannot derive a deletion period from a specific paragraph, in case of doubt you have processing that needs to be deleted, not saved. This logic reverses the common practice of retaining data as a precautionary measure and forces explicit justification. The deletion matrix thus becomes an active control instrument, not a pure reporting tool.
Legitimate interest according to letter f: the three-stage test
Art. 6 Paragraph 1 Letter f GDPR is the most flexible but also the most demanding legal basis. The European Court of Justice consolidated the three stages of the test in the Fashion ID decision (C-40/17) and most recently in TC Medical Air (C-621/22). First, the controller must have a legitimate interest that is not manifestly unlawful. Secondly, the processing must be necessary to safeguard this interest; a more lenient means must not be available. Thirdly, the fundamental rights and freedoms of the data subject must not outweigh the interests of the controller.
The check must take place before processing and be documented in writing. A delayed consideration in the fine proceedings is not healing. The content of the document includes: description of the interest (e.g. IT security, fraud prevention, direct marketing for existing customers), necessity (which data, which process), balancing with the interests of the person concerned (reasonable expectation, depth of intervention, group of those affected) and result. In its 2026 “Legitimate Interest” guidance, the Data Protection Conference published a structural template that serves as a minimum model.
Anyone who uses legitimate interest as a catch-all for everything that doesn’t fit anywhere else will be noticed in the audit. The auditor calls, the evidence is ready. as soon as the assessment is made in a template that is linked to the processing in the directory. In practice, it has proven useful to check the balance every twelve months, especially if quantities, data fields or recipient groups have changed. Versioning with the date, author and reason for the change belongs in every workspace that deserves this name. Anyone who carries out the assessment exclusively in a Word file will lose track of the current status by the third update at the latest.
Sensitive data: Art. 6 GDPR meets Art. 9 GDPR
Art. 6 GDPR is the basic fact. If special categories of personal data are processed, such as health data, biometric data, trade union membership or data on ethnic origin, Art. 9 GDPR applies. In this case, the person responsible needs both a legal basis according to Art. 6 and an additional exception according to Art. 9 Para. 2 GDPR. Both must be fulfilled; one does not replace the other. This double check is often overlooked in practice, especially in operational integration management and HR software.
Examples: When maintaining a disease register by the company doctor, Art. 6 Para. 1 lit. c GDPR in conjunction with Section 26 BDSG provides the legal basis. In addition, Article 9 Paragraph 2 Letter b or Letter h GDPR is required. If biometric data is processed for access control, the legitimate interest pursuant to Article 6 (1) (f) GDPR is not sufficient. Express consent must be obtained in accordance with Article 9 Paragraph 2 Letter a of the GDPR or another narrow exception must be met.
In the past three years, the German supervisory authorities have repeatedly imposed fines of between 50,000 and 1.8 million euros for failure to carry out this double check. The company medical area receives its own mask in the CIVAC workspace, which enforces both legal bases before processing is released. This is not a technical chicanery, but a direct implementation of the double structure of Articles 6 and 9 GDPR. Anyone who licences the workspace will receive the mask prepared. Anyone who uses Officer-as-a-Service gets it including maintenance and regular updates to new DSK resolutions. The separation between the data protection officer and the company doctor in accordance with Section 78 SGB
Change of legal basis and information obligations
A legal basis may generally not be exchanged during ongoing proceedings if the purpose does not change. The European Data Protection Board made this clear in its guidelines 03/2019: Anyone who initially bases processing on consent and then switches to legitimate interest after its revocation circumvents the protection concept of Article 7 GDPR. A change is only permitted if the original choice of legal basis was objectively wrong, this is documented and the persons affected are informed.
Changes to the legal basis trigger the information obligations under Articles 13 and 14 GDPR again. The data protection notice must be updated so that the new legal basis is visible, ideally with an active notice to data subjects if the change is material. The change is documented in the directory in accordance with Art. 30 GDPR with the date, reason and new justification. Anyone who uses versioning will have an easier time in the audit.
The CIVAC platform records every change to processing with a time stamp and author in a change log that cannot be removed from the workspace. Audit-proof, documented, Art. 30-proof. This versioning does not replace the legal review, but it makes it comprehensible. If you cannot or do not want to carry out the check yourself, you can licence the workspace for the internal representatives or have the representatives appointed by CIVAC. Both paths lead to the same result: a documented, understandable and, in case of doubt, defensible legal basis for processing. Versioning also applies to changes in purpose, which must be checked separately in accordance with Art. 6 Para. 4 GDPR. A change of purpose requires a separate compatibility check and, if necessary, a new legal basis.
Legal basis and data protection impact assessment
The legal basis is closely related to the data protection impact assessment in accordance with Art. 35 GDPR. If processing is likely to pose a high risk to the rights and freedoms of natural persons, a DPIA must be carried out. The German Data Protection Conference has published a list of such processing operations, the so-called must list according to Article 35 (4) GDPR. This includes, among other things, extensive employee data processing, profiling with legal consequences, biometric identification and the use of AI-supported applicant filters.
The DPIA not only examines the legal basis, but also proportionality. A legal basis formally exists, but the processing may still be disproportionate. In this case, Art. 36 GDPR requires prior consultation with the supervisory authority. In practice, the DPIA is often only written after the project is productive. This is both illegal and operationally risky because a subsequent correction triggers additional costs and loss of trust.
Anyone who uses a platform like CIVAC links the DPIA template directly to the processing in the directory and forces the review as an approval step. The 490 audit templates in the workspace also cover the DPIA and contain the test points required by DSK Short Paper No. 5. The connection between legal basis, DPIA and directory is the core of proper GDPR compliance. Others run compliance like a filing cabinet. We run it like software. The platform stores the DPIA in the EU data residence and allows external auditors to be invited with time-limited read access. A completely completed DPIA document is not located in a Sharepoint folder, but rather directly in the processing to which it relates. This structural proximity shortens access to the crucial evidence in the audit from half an hour to just a few clicks. Anyone who lets the examiner search for more than ten minutes has already lost.
From reading to organised indexing: a concrete next step
Anyone who has read the article up to this point knows the six legal bases, the pitfalls when it comes to consent and legitimate interest, the double structure for special data and the connection to the DPIA. The next step is not another white paper, but an orderly inventory. What processing are you currently carrying out? What legal basis is included in the directory? How old is the last update? When was the last time a consideration of legitimate interest was documented?
CIVAC works as a compliance platform and officer-as-a-service. The platform maintains the directory in accordance with Art. 30 GDPR, the templates for declarations of consent, the three-stage check for legitimate interest and the DPIA in a common workspace with an EU data residence. Licence the workspace for your internal representatives, or have our representatives order it. In the Officer-as-a-Service variant, our external data protection officers take over the appointment certificate, the reporting line to the management and the maintenance of the directory, usually within two working days of placing the order.
Turn reading into a mandate. A short email to info@civac.de with the industry, number of employees and existing data protection status is enough for the first appointment. If you prefer to use the contact form, you can find it linked via the FAQ page. What you don't get: a generic advice offer. What you get: concrete feedback about what gaps there are in your directory and how they can be closed in the next thirty days. Verifiable, documented, with appointment certificate if you choose the external variant. If you don't want to book the first appointment straight away, you can request a checklist in advance with which your department can begin the inventory itself.
FAQ
Do I need a separate legal basis for each processing according to Art. 6 GDPR?
Yes. Each processing activity with an independent purpose requires its own legal basis. If the same data is processed for multiple purposes, a legal basis must be checked for each purpose and entered in the list in accordance with Art. 30 GDPR. A general basis based on Article 6 Para. 1 GDPR without specifying the letters is not sufficient in the audit and regularly leads to complaints from the supervisory authority.
Can I switch the consent to legitimate interest if the user revokes?
No. The European Data Protection Board made it clear in guidelines 03/2019 that a subsequent change of the legal basis is inadmissible. With the revocation of consent, the lawfulness of the processing ends. The data must be deleted or anonymized unless there is another independent obligation to retain it, such as a commercial law deadline in accordance with Section 257 of the German Commercial Code (HGB), and is documented in the directory.
Is Art. 6 GDPR sufficient as a legal basis for health data?
No. Health data is one of the special categories according to Art. 9 Para. 1 GDPR. Those responsible need both a legal basis according to Art. 6 and an additional exception according to Art. 9 Para. 2 GDPR. If one of the two is missing, the processing is unlawful and can be punished with a fine of up to 20 million euros or four percent of group sales.
How do I correctly document a consideration of legitimate interest?
The three-stage test is carried out in writing: designation of the legitimate interest, necessity of the processing and balancing it with the fundamental rights of the data subject. The Data Protection Conference has published a structural template that serves as a minimum template. The consideration is linked to the processing in the directory in accordance with Art. 30 GDPR, versioned in the event of changes and checked at least annually.
Does the legal basis have to be stated in the data protection information?
Yes. Art. 13 Para. 1 lit. c GDPR requires the legal basis for data collection to be stated. In the case of a legitimate interest, the specific interest pursued must also be specified, not just the abstract norm. A change in the legal basis triggers the update of the information and, if necessary, the active information of those affected, for example in the event of significant changes in purpose in accordance with Art. 6 Para. 4 GDPR.
During the audit, who checks whether my legal basis is valid?
During an audit by the supervisory authority, the clerks first check the list in accordance with Art. 30 GDPR and randomly check the documents provided. In the case of an internal audit, the data protection officer takes care of this. CIVAC offers the templates, the workspace and, if desired, an external data protection officer who takes over the review as an officer-as-a-service and answers questions directly.
Sounds like a lot of work?
Officer duties, deadlines, paperwork — that's exactly what we take off your hands. Say hello and we'll show you how.
Turn this into a mandate.
Let us carry the operational weight. External officer, templates and documentation in one workspace. No obligation.