Skip to content
Law Society of Scotland
Search
Find a Solicitor
Contact us
About us
Sign in
Search
Find a Solicitor
Contact us
About us
Sign in
  • For members

    • For members

    • CPD & Training

    • Membership and fees

    • Rules and guidance

    • Regulation and compliance

    • Journal

    • Business support

    • Career growth

    • Member benefits

    • Professional support

    • Lawscot Wellbeing

    • Lawscot Sustainability

  • News and events

    • News and events

    • Law Society news

    • Blogs & opinions

    • CPD & Training

    • Events

  • Qualifying and education

    • Qualifying and education

    • Qualifying as a Scottish solicitor

    • Career support and advice

    • Our work with schools

    • Lawscot Foundation

    • Funding your education

    • Social mobility

  • Research and policy

    • Research and policy

    • Research

    • Influencing the law and policy

    • Equality and diversity

    • Our international work

    • Legal Services Review

    • Meet the Policy team

  • For the public

    • For the public

    • What solicitors can do for you

    • Making a complaint

    • Client protection

    • Find a Solicitor

    • Frequently asked questions

    • Your Scottish solicitor

  • About us

    • About us

    • Contact us

    • Who we are

    • Our strategy, reports and plans

    • Help and advice

    • Our standards

    • Work with us

    • Our logo and branding

    • Equality and diversity

  1. Home
  2. News and events
  3. Law Society news
  4. GDPR – What is a legal basis and why does it matter?

GDPR – What is a legal basis and why does it matter?

13th November 2017 | Professional support | Data protection

Carolyn Thurston Smith, policy executive at the Law Society of Scotland, explains the legal bases in article 6 of the General Data Protection Regulation (GDPR).

Article 6 of the GDPR sets out legal bases for processing of personal data. Data processing is only lawful if the controller has a legal basis for the particular processing activity taking place, so it may be lawful for the controller to use a particular set of data for one purpose but unlawful to use that same data in a different context.

Understanding Article 6 is key to understanding how the GDPR affects you.

What are the legal bases which can be used?

The possible grounds for processing are:

  • Consent
  • Performance of a contract to which the data subject is party, or to take steps prior to entering into a contract at the request of the data subject
  • Compliance with a legal obligation which the controller is bound to comply with
  • Protection of the vital interests of the data subject or another natural person
  • Performance of a task carried out in the public interest or in the exercise of official authority vested in the controller
  • Legitimate interests pursued by the controller or a third party

For the last of these there is an exception where the interests in question are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child. This basis also has restrictions on its use in the public sector.

Where the basis for processing is a legal obligation, or a task carried out in the public interest, or exercise of official authority, then the parameters will be determined by EU law or domestic law of the relevant member state.

What happens if the controller wants to process existing data for a new or different purpose?

In some cases a controller may wish to use data they hold already for a different purpose from the one for which it was originally collected.This is permitted in certain circumstances. Where the controller seeks to rely on a basis other than consent, or on EU or Member State law, the controller has to consider whether this other purpose is compatible with the original purpose, taking into account the following factors:

  • Any link between the original purpose and purposes of the intended further processing
  • The context in which the personal data was collected and relationship between the data subject and the data controller
  • The nature of the data
  • Possible consequences of further processing

As a rough rule of thumb, if the data subject would be surprised by the different purpose then it is probably incompatible.

These rules apply to all types of organisation from law firms and other businesses to public authorities. A particular processing action may be lawful on the basis of more than one of the conditions for processing outlined above. The most important thing is to consider that whatever processing you’re carrying out, you must have identified at least one legal basis to support that action.

GDPR blog

Tim Musson, Convener of the Law Society of Scotland’s Privacy Law Committee, explains why the General Data Protection Regulation (GDPR) is all-important for law firms.

GDPR Personal data breaches

Anna Drozd, policy adviser on professional issues at our Brussels Office, explains what personal data breaches are and how to report them under the GDPR.

GDPR changes to consent

Domhnall Dods, regulatory solicitor and GDPR expert at Towerhouse and member of the Law Society’s Privacy Law Committee, explains the changes to rules around consent in the General Data Protection Regulation (GDPR).

GDPR data protection officers

Dr Kenneth Meechan, member of the Law Society of Scotland’s Privacy Law Committee, explains the new rules on data protection officers and sets out some important tasks which all law firms should consider.

GDPR

Our guide to data protection from the perspective of a legal practice

Read more about GDPR
Add To Favorites

Additional

Categories

  • New lawyers
  • Law Society news
  • Regulation
  • Research and policy
  • Legal aid
  • Professional support
  • Wellbeing
  • Business support
  • Equality and diversity
  • International
  • In-house lawyers
  • Schools
  • For the public
  • Videos
  • Fraud alerts
  • Career growth
  • Member benefits
  • Law and technology
  • Professional skills courses
  • Aberdeen
  • Edinburgh
  • Glasgow
  • Perth
  • Inverness
  • Commercial skills for young professionals
  • Roadshow
  • CPD event
  • Working in-house
  • Public Policy Committee
  • Roadshows
  • careers
  • property (non-commercial)
  • licensing
  • Journal online news
  • Sustainability
  • Policy committees

News Archive

  • 2025
  • 2024
  • 2023
  • 2022
  • 2021
  • 2020
  • 2019
  • 2018
  • 2017
  • 2016
  • 2015
  • 2014
  • 2013

Related articles

  • Law Society members reach new career heights
  • New partnership bolsters Law Society sustainability commitment
  • Spring celebrations for newly accredited Law Society members
  • Celebrations at first banking and finance paralegal accreditation
Law Society of Scotland
Atria One, 144 Morrison Street
Edinburgh
EH3 8EX
If you’re looking for a solicitor, visit FindaSolicitor.scot
T: +44(0) 131 226 7411
E: lawscot@lawscot.org.uk
About us
  • Contact us
  • Who we are
  • Strategy reports plans
  • Help and advice
  • Our standards
  • Work with us
Useful links
  • Find a Solicitor
  • Sign in
  • CPD & Training
  • Rules and guidance
  • Website terms and conditions
Law Society of Scotland | © 2025
Made by Gecko Agency Limited