GDPR
Chapter II - Principles

GDPR GDPR-Art.6: Lawfulness of processing

Process personal data only where at least one lawful basis applies: the data subject's consent, necessity for a contract with the data subject or pre-contractual steps at their request, compliance with a legal obligation, protection of vital interests, performance of a public interest task or exercise of official authority, or legitimate interests that are not overridden by the data subject's interests, rights and freedoms. Public authorities cannot rely on legitimate interests for processing carried out in performance of their tasks. Where the basis is legal obligation or public task, that basis must be laid down in Union or Member State law and the purpose must be determined in it. Before processing for a purpose other than the one collected for, without consent or a legal mandate, assess compatibility against the link between the purposes, the context of collection, the nature of the data, the consequences for the data subject and the safeguards in place.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

What else in your programme already covers this

This control maps to 122 controls across 60 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

  • 3.1.1(b) 3.1.1(b) Contract and legal obligation as grounds, with workers fully informed of legally required processing
  • 3.1.1(c) 3.1.1(c) Legitimate interest: a legitimate purpose, a necessary and least intrusive method, a demonstrated balance
  • 4 4 No incompatible further use of monitoring data
  • 5.4.1 5.4.1 Home and remote working: no keystroke, mouse, screen or webcam capture
  • 5.5 5.5 Time and attendance and access control: informed, necessary, and not reused for performance evaluation
  • 5.7(a) 5.7(a) Vehicle tracking: necessary, proportionate, with a private-use opt-out and no evaluation of drivers
  • 5.7.1 5.7.1 Event data recorders and in-cab cameras: only where necessary and proportionate; no continuous recording of drivers
  • 5.8 5.8 Disclosure of employee data to customers only where proportionate
  • PIPL-Art13 Legal Bases for Handling
  • PIPL-Art23 Provision of PI to Third Parties
  • PIPL-Art25 Public Disclosure Prohibited Without Consent
  • PIPL-Art26 Image Collection in Public Places
  • PIPL-Art27 Handling Already-Disclosed PI
  • PIPL-Art35 State Organs Handling for Statutory Duties
  • 3.1.1 3.1.1 Legitimate interest must be real and present, documented by incidents, and reassessed periodically
  • 3.1.3 3.1.3 Balancing is mandatory and made case by case, weighing the intensity of the intrusion
  • 3.1.3.2 3.1.3.2 Reasonable expectations: no cameras where people expect privacy, including most workplaces, washrooms and rest areas
  • 3.2 3.2 Public task: a basis in law, necessity, and national video surveillance rules
  • 4.1 4.1 Disclosing footage to third parties needs its own legal basis and a compatible purpose
  • 4.2 4.2 Disclosure to law enforcement: legal obligation where the law requires it, otherwise legitimate interest on reasonable suspicion
  • s23 s 23 Public bodies further process data for another purpose only on a listed ground
  • s24 s 24 Private bodies reuse data for another purpose only for security, prosecution or legal claims
  • s26-1 s 26(1) sentence 1 Process employee data only where necessary for the employment relationship, on a GDPR legal basis
  • s3 s 3 Public bodies process personal data only where needed for their task or official authority
  • s4-1 s 4(1) Video surveillance of publicly accessible spaces only where necessary for a listed purpose
  • s49 s 49 Further process for another purpose only within s 45 purposes or where a law allows

Canadian PIPEDA · 4 controls

SOC 2 · 4 controls

  • SOC2-P2.1 P2.1 Choice and consent
  • SOC2-P3.1 P3.1 Collecting personal information consistent with objectives
  • SOC2-P4.1 P4.1 Limiting use to identified purposes
  • SOC2-P6.1 P6.1 Disclosure to third parties with consent

APPI · 3 controls

  • APPI-A17 Specification of the Purpose of Use
  • APPI-A18 Restriction on Handling Beyond the Purpose of Use
  • APPI-A27 Restriction on Provision to Third Parties
  • MYHR-CUD-1 Authorised collection, use and disclosure only
  • MYHR-CUD-2 Prohibition on unauthorised collection, use and disclosure
  • MYHR-SEC-6 Emergency access controls
  • APP-3 APP 3 - Collection of solicited personal information
  • APP-6 APP 6 - Use or disclosure of personal information
  • APP-7 APP 7 - Direct marketing
  • ePD-Art.13 Unsolicited communications (Article 13)
  • ePD-Art.5 Confidentiality of communications including the Article 5(3) cookie consent rule
  • ePD-Art.9 Location data other than traffic data (Article 9)
  • AUCDR-PS-3 Privacy Safeguard 3 - Seeking to collect CDR data from CDR participants
  • AUCDR-PS-6 Privacy Safeguard 6 - Use or disclosure of CDR data
  • CAYDPA-P1 First Principle - Fair and Lawful Processing
  • CAYDPA-Sch2 Schedule 2 - Conditions for Processing (General Personal Data)
  • CCM-DSP-12 Limitation of Purpose in Personal Data Processing
  • CCM-DSP-15 Limitation of Production Data Use
  • CDR-PS-3 Privacy Safeguard 3: Seeking to Collect CDR Data from CDR Participants
  • CDR-PS-6 Privacy Safeguard 6: Use or Disclosure of CDR Data
  • RDCOC-LAW-01 Lawful Basis for Research
  • RDCOC-SCO-01 Scope of Processing Activities
  • EGY-PDPL-Art.36 Penalty for unauthorised processing
  • EGY-PDPL-Art.6 Lawful bases for processing
  • UAE-PDPL-Art.1_2_3 Scope, definitions and applicability (UAE PDPL Articles 1-3)
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)
  • 10.1 10.1 No disclosure to third parties without explicit consent, save four cases
  • 5.3 5.3 Compatible further use and avoiding misreading
  • Art. 2-ter(1)-(1-bis) Art. 2-ter(1)-(1-bis) Ground public-task processing in a law, regulation or general administrative act
  • Art. 2-ter(2)-(3) Art. 2-ter(2)-(3) Share or disseminate public-task data only where provided for, and notify the Garante ten days ahead under 1-bis

NIST SP 800-53 Rev 5 · 2 controls

  • NIST800-PT-2 PT-2 Authority to Process Personally Identifiable Information
  • NIST800-PT-3 PT-3 Personally Identifiable Information Processing Purposes
  • RO-LAW190-002 Processing of National Identification Numbers (CNP)
  • RO-LAW190-005 Workplace Monitoring of Employees
  • CIA-LAW-01 Lawful basis for processing credit information
  • CIA-PSEUDO-04 Pseudonymised credit information processing
  • AL-DPA-3 Lawful Basis for Processing
  • BM-PIPA-6 Conditions for using personal information
  • BA-DPA-6 The Right to Process Without the Data Subject's Consent

CCPA/CPRA · 1 control

  • CCR 7002 Purposes must match reasonable expectations, or consent is needed
  • SD134-3 Lawful Collection
  • CASL-17 Address Harvesting Prohibition
  • CSL-Art41 Lawful Collection of Personal Information - Art. 41
  • CZ-110-§5 Opravneni ke zpracovani pri plneni pravni povinnosti nebo ukolu (public-task lawful basis)

DORA · 1 control

  • DUAA-P5-LAWFUL Lawful processing and recognised legitimate interests

EU AI Act · 1 control

  • EUAI-Art.59 Further processing of personal data for developing certain AI systems in the public interest in the AI regulatory sandbox
  • BIK-S7 EU code of conduct for childrens privacy

EU Data Act · 1 control

  • DA-Art.6 Obligations of third-party data recipients (Article 6)
  • DGA-Art.5_6 Conditions for re-use and fees (Articles 5-6)
  • DMA-Art.5 Article 5 self-executing obligations (Article 5)
  • PSD2-Art.94 Data protection (PSD2 Article 94) - GDPR alignment
  • FATF-R.10_11 Customer Due Diligence + Record Keeping (FATF R.10 and R.11)

ISO 27701:2019 · 1 control

  • 7.2.2 Identify lawful basis
  • Art. 4(1) Art. 4(1) Install remote-monitoring equipment only for permitted purposes and after a union agreement or labour inspectorate authorisation
  • 47a Art. 47a Set up temporary committees' processing in the instituting decision, and report before dissolution
  • UZB-DPL-02 Consent of the Data Subject
  • ZDPA-01 Lawful Basis and Consent for Processing

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Chapter II - Principles

You are reading one control. How much of GDPR have you already done?

GDPR GDPR-Art.6 is one control. If you already hold one of the frameworks below, a reviewed crosswalk already says how much of GDPR your existing evidence covers. Hold ISO 27701:2019 and 21 of 41 GDPR controls already carry evidence.

Each report names every control your existing framework evidences, every one it does not, the reasoning behind each claim, and the claims that were argued against and rejected. 0 were rejected on the ISO 27701:2019 pair alone.

Query this from an agent

The graph holds this control, the 122 it maps to, and the evidence behind each claim, over MCP and REST.