Frameworks / GDPR / GDPR-Art.6 GDPR
Chapter II - Principles
GDPR GDPR-Art.6: Lawfulness of processing Process personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, or legitimate interests that are not overridden by the data subject's interests, rights and freedoms. Public authorities cannot rely on legitimate interests for processing carried out in performance of their tasks. Where the basis is legal obligation or public task, that basis must be laid down in Union or Member State law and the purpose must be determined in it. Before processing for a purpose other than the one collected for, without consent or a legal mandate, assess compatibility against the link between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place.
Maintained by Gerard Blokdyk · Verified against the published standard 31 May 2026 · Control text last updated 19 August 2026 What else in your programme already covers this This control maps to 122 controls across 60 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
3.1.1(b) 3.1.1(b) Contract and legal obligation as grounds, with workers fully informed of legally required processing 3.1.1(c) 3.1.1(c) Legitimate interest: a legitimate purpose, a necessary and least intrusive method, a demonstrated balance 4 4 No incompatible further use of monitoring data 5.4.1 5.4.1 Home and remote working: no keystroke, mouse, screen or webcam capture 5.5 5.5 Time and attendance and access control: informed, necessary, and not reused for performance evaluation 5.7(a) 5.7(a) Vehicle tracking: necessary, proportionate, with a private-use opt-out and no evaluation of drivers 5.7.1 5.7.1 Event data recorders and in-cab cameras: only where necessary and proportionate; no continuous recording of drivers 5.8 5.8 Disclosure of employee data to customers only where proportionate PIPL-Art13 Legal Bases for Handling PIPL-Art23 Provision of PI to Third Parties PIPL-Art25 Public Disclosure Prohibited Without Consent PIPL-Art26 Image Collection in Public Places PIPL-Art27 Handling Already-Disclosed PI PIPL-Art35 State Organs Handling for Statutory Duties 3.1.1 3.1.1 Legitimate interest must be real and present, documented by incidents, and reassessed periodically 3.1.3 3.1.3 Balancing is mandatory and made case by case, weighing the intensity of the intrusion 3.1.3.2 3.1.3.2 Reasonable expectations: no cameras where people expect privacy, including most workplaces, washrooms and rest areas 3.2 3.2 Public task: a basis in law, necessity, and national video surveillance rules 4.1 4.1 Disclosing footage to third parties needs its own legal basis and a compatible purpose 4.2 4.2 Disclosure to law enforcement: legal obligation where the law requires it, otherwise legitimate interest on reasonable suspicion s23 s 23 Public bodies further process data for another purpose only on a listed ground s24 s 24 Private bodies reuse data for another purpose only for security, prosecution or legal claims s26-1 s 26(1) sentence 1 Process employee data only where necessary for the employment relationship, on a GDPR legal basis s3 s 3 Public bodies process personal data only where needed for their task or official authority s4-1 s 4(1) Video surveillance of publicly accessible spaces only where necessary for a listed purpose s49 s 49 Further process for another purpose only within s 45 purposes or where a law allows SOC2-P2.1 P2.1 Choice and consent SOC2-P3.1 P3.1 Collecting personal information consistent with objectives SOC2-P4.1 P4.1 Limiting use to identified purposes SOC2-P6.1 P6.1 Disclosure to third parties with consent APPI-A17 Specification of the Purpose of Use APPI-A18 Restriction on Handling Beyond the Purpose of Use APPI-A27 Restriction on Provision to Third Parties MYHR-CUD-1 Authorised collection, use and disclosure only MYHR-CUD-2 Prohibition on unauthorised collection, use and disclosure MYHR-SEC-6 Emergency access controls APP-3 APP 3 - Collection of solicited personal information APP-6 APP 6 - Use or disclosure of personal information APP-7 APP 7 - Direct marketing ePD-Art.13 Unsolicited communications (Article 13) ePD-Art.5 Confidentiality of communications including the Article 5(3) cookie consent rule ePD-Art.9 Location data other than traffic data (Article 9) AUCDR-PS-3 Privacy Safeguard 3 - Seeking to collect CDR data from CDR participants AUCDR-PS-6 Privacy Safeguard 6 - Use or disclosure of CDR data CAYDPA-P1 First Principle - Fair and Lawful Processing CAYDPA-Sch2 Schedule 2 - Conditions for Processing (General Personal Data) CCM-DSP-12 Limitation of Purpose in Personal Data Processing CCM-DSP-15 Limitation of Production Data Use CDR-PS-3 Privacy Safeguard 3: Seeking to Collect CDR Data from CDR Participants CDR-PS-6 Privacy Safeguard 6: Use or Disclosure of CDR Data RDCOC-LAW-01 Lawful Basis for Research RDCOC-SCO-01 Scope of Processing Activities EGY-PDPL-Art.36 Penalty for unauthorised processing EGY-PDPL-Art.6 Lawful bases for processing UAE-PDPL-Art.1_2_3 Scope, definitions and applicability (UAE PDPL Articles 1-3) UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5) 10.1 10.1 No disclosure to third parties without explicit consent, save four cases 5.3 5.3 Compatible further use and avoiding misreading Art. 2-ter(1)-(1-bis) Art. 2-ter(1)-(1-bis) Ground public-task processing in a law, regulation or general administrative act Art. 2-ter(2)-(3) Art. 2-ter(2)-(3) Share or disseminate public-task data only where provided for, and notify the Garante ten days ahead under 1-bis NIST800-PT-2 PT-2 Authority to Process Personally Identifiable Information NIST800-PT-3 PT-3 Personally Identifiable Information Processing Purposes RO-LAW190-002 Processing of National Identification Numbers (CNP) RO-LAW190-005 Workplace Monitoring of Employees CIA-LAW-01 Lawful basis for processing credit information CIA-PSEUDO-04 Pseudonymised credit information processing AL-DPA-3 Lawful Basis for Processing BM-PIPA-6 Conditions for using personal information BA-DPA-6 The Right to Process Without the Data Subject's Consent CCR 7002 Purposes must match reasonable expectations, or consent is needed SD134-3 Lawful Collection CASL-17 Address Harvesting Prohibition CSL-Art41 Lawful Collection of Personal Information - Art. 41 CZ-110-§5 Opravneni ke zpracovani pri plneni pravni povinnosti nebo ukolu (public-task lawful basis) DUAA-P5-LAWFUL Lawful processing and recognised legitimate interests EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox BIK-S7 EU code of conduct for childrens privacy DA-Art.6 Obligations of third-party data recipients (Article 6) DGA-Art.5_6 Conditions for re-use and fees (Articles 5-6) DMA-Art.5 Article 5 self-executing obligations (Article 5) PSD2-Art.94 Data protection (PSD2 Article 94) - GDPR alignment EST-IKS-§14-21 Principles of processing by law enforcement authorities FATF-R.10_11 Customer Due Diligence + Record Keeping (FATF R.10 and R.11) 7.2.2 Identify lawful basis Art. 4(1) Art. 4(1) Install remote-monitoring equipment only for permitted purposes and after a union agreement or labour inspectorate authorisation 47a Art. 47a Set up temporary committees' processing in the instituting decision, and report before dissolution UZB-DPL-02 Consent of the Data Subject ZDPA-01 Lawful Basis and Consent for Processing Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected .
Other controls in Chapter II - Principles You are reading one control. How much of GDPR have you already done? GDPR GDPR-Art.6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.
Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.
Query this from an agent The graph holds this control, the 122 it maps to, and the evidence behind each claim, over MCP and REST.