Contact ussales@ventavid.com
VentaVid

Glossary

Our sales with video glossary is here to help you gain an understanding of specific video and marketing terms

Lawful basis

In this article

Lawful basis explained: what it is and how to pick one

A lawful basis is the specific ground under Article 6(1) GDPR that makes an act of processing personal data legal, and every processing purpose needs one identified before the processing starts. There are six of them. They rank equally, and your choice has to be documented and disclosed.

No basis, no processing. That is the whole architecture. The six are not a menu you pick from after the fact to justify something already running, and the regulator's first question in an investigation is usually which one you picked and when.

The six lawful bases in Article 6

  • Consent, Article 6(1)(a): the person has given consent to processing for one or more specific purposes.
  • Contract, 6(1)(b): processing is necessary to perform a contract the person is party to, or to take steps at their request before entering one.
  • Legal obligation, 6(1)(c): processing is necessary to comply with a legal obligation the controller is subject to.
  • Vital interests, 6(1)(d): processing is necessary to protect someone's life.
  • Public task, 6(1)(e): processing is necessary for a task in the public interest or in the exercise of official authority.
  • Legitimate interests, 6(1)(f): processing is necessary for interests pursued by the controller or a third party, except where those are overridden by the interests or fundamental rights of the person.

For insurers

See the damage before you decide

Send one link. Get guided, verified claim video back. No app, no account.

Customer filming damage with her phone

How do you choose the right one?

Start from the purpose, not from the data. Write down what you are trying to achieve, then ask whether the processing is genuinely necessary for that purpose. Necessary does not mean indispensable, but it means more than convenient: if a less intrusive route achieves the same result, the necessity argument weakens.

Then commit. Article 13 requires you to tell people which basis you are relying on, so it goes in the privacy notice and in the record of processing. Switching basis later because the first one became inconvenient is exactly the move regulators treat as evidence that the original choice was never real.

Why consent is usually not the answer for a business process

Article 7(3) gives the person the right to withdraw consent at any time, and withdrawal has to be as easy as giving it. Run that through your process honestly. If your workflow cannot stop cleanly the moment someone withdraws, consent was never the right basis, because the person never had a real choice.

Contract fits when the processing is needed to deliver what the person asked for. Legitimate interests fits a lot of ordinary operational processing, and Recital 47 GDPR says directly that "the processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned." That basis is not free, though. It needs a documented balancing test, and Recital 47 asks whether the person could reasonably expect that processing at the time their data was collected.

Lawful basis explained: a claims example

An insurer asks a policyholder to record video of the damage as part of a remote claim inspection. Processing that footage to assess and settle the claim rests on contract, because it is necessary to perform the policy. The integrity signals logged around the submission, used to decide which files get a second look, sit more naturally on legitimate interests with a written balancing test behind them. Asking for consent to either would be a fiction, because refusing would stall the claim.

Special category data needs a second condition

An Article 6 basis is never enough on its own for the data listed in Article 9, which includes health information. Injury photographs and medical reports in a bodily injury file are special category personal data, so you need an Article 6 basis plus an Article 9(2) condition. Article 9(2)(f), processing necessary for the establishment, exercise or defence of legal claims, is the one that most often carries insurance work. The same layering applies to biometric data used to identify someone.

Where the UK now diverges

The Data (Use and Access) Act 2025 added a seventh ground to the UK GDPR, Article 6(1)(ea), recognised legitimate interests, in force on 5 February 2026. It covers a closed list in Annex 1, including safeguarding national security, public security and defence, responding to an emergency, and certain disclosures to public authorities, and processing on that ground does not need the usual balancing test. The EU GDPR has no equivalent, and the new ground carries its own limits elsewhere in the UK regime, including for automated decision making. Other jurisdictions do not use this model at all: several US state privacy laws run on notice and opt outs rather than on a lawful basis chosen up front. Check the regime that actually applies before assuming your EU analysis carries over.

For insurers

See the damage before you decide

Send one link. Get guided, verified claim video back. No app, no account.

Customer filming damage with her phone

See the damage before you decide

Send one link, get guided, verified claim video back. No app, no account.