What is "Public Task" under the GDPR?

The GDPR's public task lawful basis permits processing when it is necessary to perform a task in the public interest or exercise official authority established by law. Learn who can rely on this basis, its legal requirements, the necessity test, and the documentation controllers should maintain.

What is "Public Task" under the GDPR?
Key points: (1) The public task lawful basis applies when processing is necessary to perform a task in the public interest or exercise official authority established by law. (2) This lawful basis is most commonly used by public authorities, but it may also apply to private organizations that perform public functions or exercise official powers. (3) The task, function, or power must have a clear basis in EU statute or common law. A specific statutory power to process personal data is not required, but the underlying legal authority must exist. (4) Processing must be objectively necessary. If the task can reasonably be carried out in a less intrusive way, this lawful basis does not apply. (5) Controllers should document their assessment, identify the relevant public task or official authority, and be able to demonstrate the legal basis supporting the processing.

Any organization that exercises official authority or carries out a specific task in the public interest may use this lawful basis.

This lawful basis can apply to controllers that are either:

  • carrying out a specific task in the public interest which is laid down by law; or
  • exercising official authority (for example, a public body’s tasks, functions, duties or powers) which is laid down by law.

What does "laid down by law" mean?

GDPR requires that the relevant task or function has a clear basis in EU or Member State law. This will most often be in the form of statutes. Controllers do not need specific legal authority for the particular processing activity as long as the overall purpose is to perform a public interest task or exercise official authority, and that overall task or authority has a sufficiently clear basis in law. GDPR is also clear that public authorities can not rely on legitimate interests for processing carried out in performance of their tasks.

The focus is on the nature of the function, not the nature of the organization. However, private sector organizations should be able to consider legitimate interests as an alternative.

Example: Private water companies are likely to be able to rely on the public task basis even if they do not fall within the definition of a public authority. This is because they are considered to be carrying out functions of public administration and therefore exercise special legal powers to carry out utility services in the public interest.

Where an organization is exercising official authority, it does not need to perform a separate public interest balancing test. However, it must still be able to demonstrate that the processing is objectively necessary for the exercise of that authority.

What does "necessary" mean?

‘Necessary’ means that the processing must be a targeted and proportionate way of achieving the purpose. If there is another reasonable and less intrusive way to achieve the same result this lawful basis does not apply.

Controllers must document their decision that processing is necessary to perform a task in the public interest or exercise official authority; identify the relevant task or authority and its basis in common law or statute; and include basic information about the purposes and lawful basis in the privacy notice.

Subscribe to The de la Torre Review

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe