Skip to main content
Category: Legal Basis and Consent

Contractual Necessity

Also known as: Contract (lawful basis), Performance of a contract, Necessary for the performance of a contract
Simply put

Contractual necessity is one of the reasons an organisation is legally allowed to use someone's personal data under the EU GDPR and UK GDPR: it applies when the organisation needs to process that data to carry out a contract with the person, or to take steps the person has asked for before entering into a contract. It does not mean the processing has to be the only possible way to fulfil the contract, but it does have to be genuinely needed rather than merely convenient. This is a distinct legal basis and should not be confused with consent.

Formal definition

Under Article 6 of the EU GDPR (and the corresponding provision of the UK GDPR), contractual necessity is a lawful basis available to a controller where processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract. Per ICO guidance, 'necessary' does not require the processing to be absolutely essential or the only means of performing the contract, but the EDPB indicates the assessment turns on whether the processing is objectively required for the core functions of the contract, evaluated not only from the controller's perspective but also from that of a reasonable data subject entering into it; processing that is merely useful, incidental, or that the controller wishes to bundle in (for example, for service improvement or marketing) generally does not qualify. This basis is legally distinct from consent and from the other Article 6 bases, and selecting it does not by itself guarantee compliance, the controller must still satisfy broader accountability, transparency, and data-minimisation obligations and be able to demonstrate the necessity assessment. Scope note: this entry defines the concept only; it does not address which specific processing activities qualify in a given fact pattern, how contractual necessity interacts with special category data (which requires an additional Article 9 condition), retention periods, cross-border transfer mechanics, or enforcement. Treatment under non-EU/UK regimes such as the CCPA/CPRA or HIPAA differs and does not use this construct.

Why it matters

Choosing the correct lawful basis is a foundational compliance decision under the EU GDPR and UK GDPR, and contractual necessity is frequently over-relied upon because it appears to avoid the operational burden of managing consent. The distinction matters: consent must be freely given and can be withdrawn, whereas contractual necessity applies only where processing is genuinely required to perform a contract with the data subject or to take pre-contractual steps at their request. Mislabelling processing as contractually necessary when it is in fact optional, incidental, or bundled in (for example, for service improvement or marketing) can leave a controller without a valid basis and unable to demonstrate compliance if challenged.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads are typically responsible for advising on lawful basis selection and ensuring that contractual necessity is not applied to processing that is merely convenient. They should ensure the necessity assessment is documented and defensible, and that activities such as marketing or service improvement are mapped to an appropriate alternative basis rather than folded into the contract.
Legal and Contracts Teams
Legal teams drafting customer, employment, or supplier contracts influence what processing can later be justified as necessary for performance. They should be aware that bundling optional processing into a contract does not extend the contractual necessity basis to cover it, and that the assessment is judged from a reasonable data subject's perspective, not solely the controller's.
Privacy Engineers and Product Teams
Those designing data flows and features need to distinguish processing that is objectively required for core contract functions from processing that is optional or incidental. This distinction affects which basis governs each processing activity and may require separate handling, consent flows, or data-minimisation controls for functions that fall outside contractual necessity.
Compliance and Governance Officers
Compliance and information governance leads oversee the accountability evidence that supports lawful basis decisions. They should confirm that reliance on contractual necessity is recorded, periodically reviewed, and reflected accurately in transparency notices, recognising that stated intent alone does not satisfy the accountability principle.

Inside Contractual Necessity

Lawful basis under the EU GDPR
Contractual necessity is one of the lawful bases for processing personal data recognized under the EU GDPR (and mirrored in the UK GDPR). It permits processing where it is necessary for the performance of a contract to which the data subject is a party, or to take steps at the data subject's request prior to entering into a contract. It is distinct from, and should not be conflated with, consent as a lawful basis.
Necessity test
The basis applies only where the processing is genuinely necessary to deliver the contracted service or product, not merely useful, convenient, or commercially desirable. Processing that could reasonably be achieved by less intrusive means generally falls outside this basis and may require a different lawful basis.
Party to the contract
The data subject must be a party to the contract, or the processing must relate to pre-contractual steps taken at the data subject's request. Processing of personal data relating to third parties who are not parties to the contract generally cannot rely on this basis.
Pre-contractual steps
The basis extends to processing needed to take steps at the data subject's request before a contract is concluded, such as providing a quote or assessing an application initiated by the individual, as distinct from unsolicited processing by the controller.
Controller accountability
The data controller determining the purposes and means of processing bears responsibility for identifying and being able to demonstrate the appropriate lawful basis, including why contractual necessity applies. A processor acting on the controller's instructions does not itself select the lawful basis.

Common questions

Answers to the questions practitioners most commonly ask about Contractual Necessity.

Does contractual necessity mean I can process any data I want as long as there is a contract with the individual?
No. Contractual necessity is limited to processing that is objectively required to perform the specific contract with the data subject, or to take steps at their request before entering into it. It does not license processing that is merely useful, commercially convenient, or that a controller has bundled into the contract. Processing that goes beyond what the contract genuinely requires needs a separate lawful basis. Whether a particular processing activity is truly necessary is fact-specific and depends on the nature of the contract and the jurisdiction; this entry does not resolve those assessments for any given case.
Is contractual necessity just another way of relying on consent?
No. Contractual necessity and consent are distinct lawful bases and should not be conflated. Consent requires a freely given, specific, informed, and unambiguous indication that can generally be withdrawn, whereas contractual necessity rests on an objective test of whether the processing is required to perform the contract. Because they are separate bases, the associated data subject rights and the controller's obligations can differ. Choosing to rely on contractual necessity does not create a consent relationship, and a controller should not present a lawful basis to individuals as if it were consent when it is not.
How should a controller document that it is relying on contractual necessity?
A controller should generally be able to identify the specific contract or pre-contractual request, articulate why the processing is objectively necessary to perform it, and retain that reasoning as demonstrable evidence rather than a stated intent. Under accountability-oriented frameworks, this analysis typically supports records of processing activities and internal policy documentation. This entry does not prescribe a particular template or specify retention periods, which depend on the applicable regime and organizational context.
What happens to data processed under contractual necessity once the contract ends?
The end of a contract does not automatically make continued processing lawful. Once the processing is no longer necessary to perform the contract, the original basis generally no longer applies, and any further retention or use typically requires a separate lawful basis, such as a legal obligation to retain records. Determining applicable retention obligations and their duration is outside the scope of this entry and must be assessed against the relevant jurisdiction and sector rules.
Can a data processor rely on contractual necessity as its lawful basis?
The lawful basis for processing is generally identified by the controller, which determines the purposes and means, while a processor acts on the controller's documented instructions under its processing agreement. A processor's contract with the controller is not the same as the controller's lawful basis toward the data subject. Controllers and processors bear distinct obligations, and this entry does not cover the full allocation of those responsibilities between them.
Does contractual necessity apply when processing special category or sensitive data?
Contractual necessity as a general lawful basis does not by itself authorize processing of special category or sensitive data, which is typically subject to additional conditions and heightened requirements. A controller generally needs to satisfy both a lawful basis and a separate applicable condition for such data. The specific conditions, their availability, and how they differ across regimes are outside the scope of this entry.

Common misconceptions

Contractual necessity covers any processing mentioned or bundled within a contract's terms.
The basis is limited to processing that is objectively necessary to perform the specific contract or to take pre-contractual steps at the data subject's request. Including a processing activity in contract wording does not by itself make it necessary; activities such as marketing or profiling that are not required to deliver the contracted service typically need a separate lawful basis.
Contractual necessity and consent are interchangeable ways to justify the same processing.
They are distinct lawful bases under the EU GDPR with different conditions and consequences. Relying on contractual necessity where processing is not genuinely necessary, or treating consent as a fallback for the same activity, can undermine the validity of the basis. The appropriate basis depends on the specific processing and context, and no single basis guarantees overall compliance.
Contractual necessity works the same way across all privacy regimes.
This basis is a feature of the EU GDPR and the UK GDPR. Other frameworks such as the CCPA and CPRA, HIPAA, ISO/IEC 27701, and the NIST Privacy Framework do not use the same lawful-basis structure, and treatment differs. Claims about contractual necessity should be scoped to the GDPR context rather than assumed to be universal.

Best practices

Document a specific necessity assessment for each processing activity relying on this basis, recording why the processing is genuinely required to perform the contract or a requested pre-contractual step rather than merely convenient.
Separate processing that is truly necessary for contract performance from ancillary activities such as marketing, analytics, or profiling, and identify a distinct appropriate lawful basis for those ancillary activities.
Confirm that the data subject is a party to the contract, or that processing relates to steps taken at their request, before relying on this basis, and use an alternative basis for processing concerning non-parties.
Ensure the controller retains demonstrable evidence supporting the choice of contractual necessity, since accountability under the GDPR requires being able to show the basis, not merely to assert it.
Review reliance on contractual necessity when the scope of the contract or the processing changes, and reassess whether a different lawful basis has become more appropriate.
Confirm the scope of this basis with qualified legal advice for cross-jurisdictional processing, as this entry does not address non-GDPR regimes, cross-border transfer mechanics, retention rules, or enforcement consequences.