Legal Obligation
In data protection, a legal obligation is one of the reasons an organization is permitted to use personal data under the EU GDPR: the organization processes the data because a law requires it to. This differs from processing based on a person's consent, because the organization must carry out the activity regardless of whether the individual agrees. More broadly in law, a legal obligation is simply a duty to do or not do something, which can arise from legislation or other sources.
Under the EU GDPR, 'compliance with a legal obligation to which the controller is subject' is one of the six lawful bases for processing personal data. This basis is available to the controller, not the processor, and generally applies where a binding legal requirement compels the processing; it should not be conflated with consent or with the other lawful bases, and reliance on it typically requires that the obligation derive from a law rather than from a contractual term alone. As a general legal concept, an obligation is a duty to act or refrain from acting, which may be created voluntarily or imposed; a statutory obligation specifically arises from legislation independent of any contract. This entry defines the term and its role as a lawful basis only. It does not address which specific obligations qualify, how the basis interacts with retention or cross-border transfer requirements, documentation obligations such as records of processing activities, or how equivalent concepts are treated under the UK GDPR, the CCPA and CPRA, HIPAA, or other regimes, where treatment may differ. Confirming that a given legal obligation validly supports processing in a specific case requires jurisdiction- and context-specific legal analysis.
Why it matters
Choosing the correct lawful basis is a foundational compliance decision under the EU GDPR, and legal obligation is frequently misapplied. Organizations sometimes reach for it as a convenient justification when the activity is actually driven by a contract term or by their own business preference rather than by a binding requirement in law. As the evidence indicates, a statutory obligation arises from legislation independent of any contract, so a duty that exists only because two parties agreed to it in a contract does not generally qualify as a legal obligation for this purpose. Getting this distinction wrong can leave processing without a valid basis, which undermines the accountability that governance frameworks require organizations to be able to demonstrate with evidence.
The legal obligation basis also matters because it changes the individual's position. When processing rests on this basis rather than on consent, the activity proceeds regardless of whether the person agrees, and certain data subject rights that hinge on consent operate differently. Treating consent and legal obligation as interchangeable is a common expert-level error that can produce misleading privacy notices and unworkable rights-handling processes. Because this entry defines the concept and its role only, it does not resolve whether any specific obligation validly supports a given processing activity; that determination requires jurisdiction- and context-specific legal analysis.
Who it's relevant to
Inside Legal Obligation
Common questions
Answers to the questions practitioners most commonly ask about Legal Obligation.