Skip to main content
Category: Legal Basis and Consent

Public Task

Also known as: Public task basis, Article 6(1)(e)
Simply put

Public task is one of the lawful bases an organisation can use to justify processing personal information under the UK GDPR. It generally applies when an organisation needs to handle personal data to perform a task carried out in the public interest or to exercise official authority. This entry covers the concept of the basis itself and does not cover retention rules, cross-border transfer mechanics, or how special category data is additionally handled.

Formal definition

Under the UK GDPR, public task is the lawful basis at Article 6(1)(e) covering processing that is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. According to ICO guidance, it is generally available to any organisation exercising official authority or carrying out a specific task in the public interest, and the underlying task or function may be statutory or established through custom and practice. Public task is one of several lawful bases and should not be conflated with legal obligation (which the ICO indicates typically applies where a controller must process to comply with a legal requirement) or with consent; the appropriate basis depends on the specific processing purpose and context. This definition does not address the corresponding Article 9 condition required when processing special category data, nor does it cover documentation, retention, or enforcement matters, and the treatment described here is scoped to the UK regime and may differ in other jurisdictions.

Why it matters

Public task is one of the six lawful bases available under the UK GDPR, and selecting it correctly is a foundational accountability decision rather than an administrative formality. For public authorities and other bodies exercising official authority or carrying out functions in the public interest, this basis often reflects the reality of why they process personal data more accurately than consent or contract. Choosing the wrong basis can undermine the lawfulness of processing and expose an organisation to challenge, so the basis should be identified before processing begins and aligned to the specific purpose.

A recurring expert-level mistake is treating public task, legal obligation, and consent as interchangeable. According to ICO guidance, where an organisation is legally required to process personal data its lawful basis is likely to be legal obligation, whereas processing carried out in the public interest is more likely to fall under public task. These distinctions matter because different bases carry different implications for how processing must be justified and, in some cases, for the rights available to individuals. No single basis guarantees compliance; appropriateness depends on the specific processing purpose and context.

It is also important not to over-read the scope of this basis. Public task addresses the Article 6 lawful basis only. It does not by itself authorise the processing of special category data, which requires a separate Article 9 condition, and it does not resolve questions of retention, documentation, or cross-border transfers. Relying on public task without addressing these additional requirements leaves significant compliance gaps unaddressed.

Who it's relevant to

Public authorities and government bodies
Organisations exercising official authority or carrying out functions in the public interest are the primary users of this basis. According to ICO guidance, any such organisation can rely on public task where processing is necessary to perform its task, and the underlying function may be statutory or established through custom and practice.
Data protection officers and privacy leads
Those responsible for selecting and documenting lawful bases must distinguish public task from legal obligation and consent, mapping each processing purpose to the most appropriate basis. Accountability requires demonstrable justification for the basis chosen, not merely a stated preference, and this must be settled before processing begins.
Bodies acting on behalf of public authorities
Organisations carrying out a specific task in the public interest may be able to rely on public task even where they are not themselves a traditional public authority. Because availability turns on the role and functions being exercised, such bodies should confirm that the relevant task genuinely applies to their processing.
Compliance and legal reviewers handling sensitive data
Where processing involves special category data, public task alone is insufficient because a separate Article 9 condition is required. Reviewers should ensure that reliance on public task is paired with the additional condition needed, since this entry does not cover how special category data is additionally handled.

Inside Public Task

Public Task as a Lawful Basis
Under the EU GDPR and UK GDPR, public task is one of the lawful bases for processing personal data. It generally applies where processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. Treatment differs in other regimes such as the CCPA and CPRA, which do not use this lawful-basis framework.
Necessity Requirement
Reliance on public task typically requires that the processing be necessary for the relevant function, not merely convenient. If the objective can reasonably be achieved by less intrusive means, the necessity test may not be met.
Basis in Law
The task or authority relied upon generally needs an underpinning in law, whether statute, common law, or another legal source, depending on the jurisdiction. The controller should be able to identify the specific function and its legal foundation.
Controller Accountability
The controller bears responsibility for identifying the applicable lawful basis, documenting the reasoning, and being able to demonstrate it. Accountability under governance frameworks requires demonstrable evidence, not merely a stated intent to rely on public task.
Interaction with Data Subject Rights
The lawful basis chosen affects which data subject rights apply. Where public task is relied upon, certain rights operate differently than under other bases, so the choice of basis has downstream consequences for how requests are handled.

Common questions

Answers to the questions practitioners most commonly ask about Public Task.

Can a private company rely on the public task lawful basis?
Generally no, not by default. Under the EU GDPR and UK GDPR, the public task basis is oriented toward the performance of a task carried out in the public interest or in the exercise of official authority. It is typically available to public authorities and to private bodies only where they have been specifically vested with such a task or authority by law. A private company acting in its ordinary commercial capacity would usually need to consider another lawful basis, such as legitimate interests or contract. Whether a particular private body qualifies depends on the underlying legal framework in the relevant jurisdiction, and this entry does not resolve that assessment for any specific organisation.
Is public task just another name for consent or a substitute for it?
No. Public task is a distinct lawful basis and should not be conflated with consent. Consent requires a freely given, specific, informed, and unambiguous indication of the data subject's wishes, whereas public task rests on the existence of a relevant public interest task or official authority grounded in law rather than on the individual's agreement. Relying on public task does not require obtaining consent, and choosing one basis has different consequences for data subject rights and for the conditions that must be met. Selecting the appropriate basis depends on context and should be documented; this entry does not cover how to choose between bases in a given scenario.
What legal foundation should we identify before relying on public task?
In most cases you should identify the specific law, statutory function, or grant of official authority that establishes the task being performed. Under the EU GDPR and UK GDPR framing, this basis generally needs to be grounded in a legal basis under applicable law rather than asserted informally. Documenting the source of the task and the authority it confers supports the accountability expectation that reliance on a basis be demonstrable with evidence, not merely stated. This entry does not specify which statutes apply to any particular body or sector.
How does relying on public task affect the rights available to data subjects?
The lawful basis chosen influences which data subject rights apply and how they operate. Where public task is the basis, certain rights, such as the right to erasure or the applicability of the right to object, can operate differently than they would under other bases. Because the interaction between lawful basis and individual rights is nuanced and jurisdiction-dependent, you should assess each right against the specific processing rather than assume a uniform outcome. This entry does not enumerate the precise rights treatment for public task or provide article-level detail.
What should we record to demonstrate accountability when using public task?
You should generally be able to evidence the task or authority being relied upon, its legal source, and the reasoning connecting the processing to that task. Accountability under governance and data protection frameworks requires demonstrable evidence rather than stated intent, so documentation of the basis determination is typically expected. This may sit alongside records of processing activities, but those records are an obligation in their own right and are not the same thing as a data inventory tool. This entry does not prescribe a specific documentation format or retention period.
Do we still need to consider other obligations such as a DPIA when relying on public task?
Yes, selecting a lawful basis does not by itself discharge other obligations. A data protection impact assessment is not automatically required in every case; it is generally triggered by the nature and risk of the processing rather than by the choice of public task as a basis, so it must be assessed on its own criteria. Transparency, purpose limitation, data minimisation, and security expectations continue to apply independently of the basis chosen. This entry does not cover cross-border transfer mechanics, retention rules, or enforcement consequences.

Common misconceptions

Public task is essentially the same as consent, so an organisation can switch to it if consent is refused or withdrawn.
Public task is a distinct lawful basis and should not be conflated with consent. The lawful basis should be identified before processing and not swapped opportunistically. Consent and public task carry different obligations and different implications for data subject rights.
Any public sector body can automatically rely on public task for all of its processing.
Public task is not a blanket authorisation. It applies to specific processing that is necessary for a task in the public interest or exercise of official authority, and it generally needs a basis in law. Some public sector processing may require a different lawful basis, and private organisations may also perform qualifying public functions in some cases.
Relying on public task removes the need to consider necessity or to document the decision.
The necessity test still applies, and the controller must be able to demonstrate the basis and its legal underpinning. Selecting public task without documented justification does not satisfy accountability expectations.

Best practices

Identify and document the specific task, function, or official authority being relied upon, together with its underpinning in law, before processing begins.
Apply the necessity test rigorously and record why less intrusive alternatives are not reasonably available for achieving the objective.
Retain demonstrable evidence of the lawful basis decision so that accountability can be shown to a regulator or reviewer, rather than relying on stated intent.
Do not switch to public task as a fallback when consent is refused or withdrawn; confirm the correct basis at the outset and apply it consistently.
Map how the choice of public task affects applicable data subject rights and ensure request-handling processes reflect those differences.
Scope reliance narrowly to the qualifying processing activities and seek legal review where the legal underpinning or applicability is uncertain, noting that treatment differs across jurisdictions and regimes such as the CCPA and CPRA.