GDPR Lawful Basis Selector
Determine appropriate GDPR lawful basis for data processing activities.
Last reviewed by the Radiatus Cloud team
Questionnaire
Going for ISO 27001, SOC 2, HIPAA or GDPR?
Radiatus runs end-to-end compliance & GRC programs.
Determine your GDPR lawful basis
Under the GDPR, every processing of personal data needs a lawful basis, and choosing the right one matters. This tool helps determine the appropriate GDPR lawful basis for a processing activity, so your processing rests on solid ground.
Why the lawful basis is fundamental
The GDPR permits processing personal data only if you have one of six lawful bases, consent, contract, legal obligation, vital interests, public task, or legitimate interests, and the basis must be identified before you process, not after. The choice matters because each carries different obligations and gives individuals different rights, consent can be withdrawn, legitimate interests requires a balancing test. Picking the wrong basis, or relying on consent where another basis fits better, causes real problems. Reasoning through which basis genuinely applies to an activity is a required and consequential step.
A tool, not legal advice
This is a practical aid, not legal advice, and regulations change and vary by circumstance. Confirm your obligations with a qualified professional before relying on any assessment or generated document. It runs entirely in your browser, so nothing you enter is uploaded, which matters when the input describes your compliance posture.
Related tools
- SOC 2 Evidence Readiness — Interactive checklist to gauge your SOC 2 evidence readiness.
- Privacy Policy Checker — Check if your policy covers standard requirements (GDPR/CCPA basics).
- Compliance Req Finder — Find which standards (ISO, SOC2, HIPAA) apply to your industry/region.
- Audit Readiness Planner — Plan your compliance audit timeline (SOC2, ISO) backwards from deadline.
Frequently Asked Questions
What are the GDPR lawful bases?
Consent, contract, legal obligation, vital interests, public task, and legitimate interests. Processing personal data requires one of these to be identified beforehand.
Why does the choice of basis matter?
Because each carries different obligations and gives individuals different rights, consent can be withdrawn, legitimate interests needs a balancing test, so the wrong basis causes problems.
Must the basis be chosen before processing?
Yes. The GDPR requires identifying the lawful basis before processing begins, not justifying it afterward, so it must be reasoned through in advance.
Is consent always the safest basis?
No. Consent can be withdrawn and is not always appropriate; another basis often fits better. The right choice depends on the activity.
Is my input uploaded?
No. The tool runs entirely in your browser.
Privacy & Security
Selection done locally.
About This Tool
This tool runs entirely in your browser. No data is sent to any server, ensuring complete privacy. Simply use the interface above to get started — no registration or login required.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.
Related Tools
SOC 2 Evidence Readiness
ComplianceInteractive checklist to gauge your SOC 2 evidence readiness.
Privacy Policy Checker
ComplianceCheck if your policy covers standard requirements (GDPR/CCPA basics).
Compliance Req Finder
ComplianceFind which standards (ISO, SOC2, HIPAA) apply to your industry/region.