Contractual Necessity
Contractual necessity is one of the reasons an organisation is legally allowed to use someone's personal data under the EU GDPR and UK GDPR: it applies when the organisation needs to process that data to carry out a contract with the person, or to take steps the person has asked for before entering into a contract. It does not mean the processing has to be the only possible way to fulfil the contract, but it does have to be genuinely needed rather than merely convenient. This is a distinct legal basis and should not be confused with consent.
Under Article 6 of the EU GDPR (and the corresponding provision of the UK GDPR), contractual necessity is a lawful basis available to a controller where processing is necessary for the performance of a contract to which the data subject is a party, or in order to take steps at the request of the data subject prior to entering into a contract. Per ICO guidance, 'necessary' does not require the processing to be absolutely essential or the only means of performing the contract, but the EDPB indicates the assessment turns on whether the processing is objectively required for the core functions of the contract, evaluated not only from the controller's perspective but also from that of a reasonable data subject entering into it; processing that is merely useful, incidental, or that the controller wishes to bundle in (for example, for service improvement or marketing) generally does not qualify. This basis is legally distinct from consent and from the other Article 6 bases, and selecting it does not by itself guarantee compliance, the controller must still satisfy broader accountability, transparency, and data-minimisation obligations and be able to demonstrate the necessity assessment. Scope note: this entry defines the concept only; it does not address which specific processing activities qualify in a given fact pattern, how contractual necessity interacts with special category data (which requires an additional Article 9 condition), retention periods, cross-border transfer mechanics, or enforcement. Treatment under non-EU/UK regimes such as the CCPA/CPRA or HIPAA differs and does not use this construct.
Why it matters
Choosing the correct lawful basis is a foundational compliance decision under the EU GDPR and UK GDPR, and contractual necessity is frequently over-relied upon because it appears to avoid the operational burden of managing consent. The distinction matters: consent must be freely given and can be withdrawn, whereas contractual necessity applies only where processing is genuinely required to perform a contract with the data subject or to take pre-contractual steps at their request. Mislabelling processing as contractually necessary when it is in fact optional, incidental, or bundled in (for example, for service improvement or marketing) can leave a controller without a valid basis and unable to demonstrate compliance if challenged.
Who it's relevant to
Inside Contractual Necessity
Common questions
Answers to the questions practitioners most commonly ask about Contractual Necessity.