What is "Legal Obligation" under the GDPR?

The GDPR's legal obligation lawful basis allows organizations to process personal data when doing so is necessary to comply with an obligation imposed by EU or Member State law. Learn when it applies, why contracts alone are insufficient, and the documentation organizations should maintain.

What is "Legal Obligation" under the GDPR?
Key points: (1) The legal obligation lawful basis applies when processing is necessary to comply with a legal obligation imposed by EU common law or statute. (2) This lawful basis does not apply to obligations arising solely from a contract. (3) Processing must be objectively necessary to satisfy the legal obligation. If the obligation can reasonably be fulfilled without processing the personal data, this lawful basis does not apply. (4) Controllers should document their assessment and be able to demonstrate why the processing is necessary to comply with the legal obligation. (5) Controllers should also be able to identify the applicable legal requirement, or rely on authoritative legal advice or regulatory guidance that clearly establishes the obligation requiring the processing.

This lawful basis only applies where controllers are obliged to process the personal data to comply with EU or Member State law. There need not be a legal obligation specifically requiring the specific processing activity. The point is that the overall purpose must be to comply with a legal obligation which has a sufficiently clear basis in either EU law or Member State common law or statute.

  • Controllers should be able to identify the obligation in question, either by reference to the specific legal provision or by pointing to an appropriate source of advice or guidance that sets it out clearly (e.g. a government website or industry guidance that explains generally applicable legal obligations).
  • Regulatory requirements also qualify as a legal obligation where there is a statutory basis underpinning the regulatory regime and which requires regulated organizations to comply.
Example: An employer needs to process personal data to comply with its legal obligation to disclose employee salary details to HMRC. The employer can point to the HMRC website where the requirements are set out to demonstrate this obligation. In this situation it is not necessary to cite each specific piece of legislation.
Example: A court order may require you to process personal data for a particular purpose and this also qualifies as a legal obligation.

‘Necessary’ does not mean that the processing must be essential for the purposes of performing a contract or taking relevant pre-contractual steps. However, it must be targeted and proportionate. Contractual necessity does not apply if there are other reasonable and less intrusive ways to meet your contractual obligations or take the steps requested. This does not mean that processing which is not necessary is automatically unlawful, but rather that the controller needs to look for a different lawful basis.

Controllers must document the decision that processing is necessary for compliance with a legal obligation, identify an appropriate source for the obligation in question; and include information about the purposes and lawful basis in the privacy notice.

Subscribe to The de la Torre Review

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe