SlideShare a Scribd company logo
1 of 12
Legal Basic in GDPR
Legal Basis of GDPR
www.seersco.com
The data controllers should do following before the start of processing of personal data:
• Identify the lawful basis
• Document the lawful basis
If you find that your lawful basis is invalid under GDPR, this will lead to the breach of accountability
and transparency principle.
The choice of lawful basis depends upon:
• Purposes
• The context of processing
Lawful Basis
www.seersco.com
GDPR stipulates six lawful bases.
• Consent
• Contract
• Compliance with a legal obligation
• Vital interest
• Public interest
• Legitimate interest
Consent
www.seersco.com
It means the individual is:
• Agreeing to, and permitting the collection and processing of his/her personal data.
• Consent is a weak basis for processing and organisations would not be able to rely on it quite
often
Consequences of choosing consent as the lawful basis:
• Right to withdraw consent at any time
• The data controller should have to demonstrate that the consent for the processing of
personal data was given by the data subject
Conditions for valid consent:
www.seersco.com
Consent is valid when it is
• Separate from other terms and conditions
• Actively given – no pre-ticked boxes or implied consent
• Granular, and applied to separate processing and purposes
• Verifiable – Organisations must keep audit trail to prove that they had obtained consent and
it was valid
• Easy to withdraw – just as easy as it was to provide
• No imbalance of power – not available to public sector or employer/ employee relationships
Consent of children
www.seersco.com
To provide information society service directly to a child:
• Data processing of a child shall be lawful where the child is at least 16 years old, and his or
her consent is obtained directly.
• Where the child age is below 16 years, processing is lawful only when the consent is given
and processing is authorised by the parents or guardians of the child.
Explicit consent:
• A written consent statement in printed form with signature on an electronically readable
format.
Contract
www.seersco.com
It is applicable when the data controller has a contract with the individual and you need to
process their personal data under contract obligation.
The contract should be between the:
• Data controller
• The data subject
Legal obligation:
www.seersco.com
Organisations can rely on this lawful basis when they are obliged to process the personal data in
order to comply with a common law or statutory obligation.
Organisations should identify:
• The specific legal provision
• An appropriate source of advice or guidance that clearly sets out your obligation
Vital Interest
www.seersco.com
Vital interest:
• Vital interest is the last choice. It is very limited in its scope.
• Organisations are likely to be able to rely on this if they need to process the personal data to
protect someone’s life
Public Interest
www.seersco.com
Public interest:
Data controllers can rely on this lawful basis if they are processing personal data ‘in the exercise of
official authority’.
Official authority includes:
• Public functions
• Powers or
• Specified tasks in the public interest that are stipulated by the law
Legitimate Interest
www.seersco.com
It means the stake that the organisation may have in collecting and processing of personal
data.
They can include:
• Commercial interests
• Individual interests, or
• Broader societal benefits
Legitimate interest is the most flexible lawful basis for processing
If the legitimate interest is chosen as the lawful basis, then there is an extra responsibility
for:
• Considering
• Protecting people’s rights and Interests.
24 Holborn Viaduct,
London
EC1A 2BN
info@seersco.com www.seersco.com

More Related Content

What's hot

Right to be forgotten presentation
Right to be forgotten presentationRight to be forgotten presentation
Right to be forgotten presentation
reporter1120
 

What's hot (20)

Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
Best Practices for Managing Individual Rights under the GDPR [Webinar Slides]
 
Data protection ppt
Data protection pptData protection ppt
Data protection ppt
 
Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysia
 
DPDP Act 2023.pdf
DPDP Act 2023.pdfDPDP Act 2023.pdf
DPDP Act 2023.pdf
 
General Data Protection Regulation
General Data Protection RegulationGeneral Data Protection Regulation
General Data Protection Regulation
 
Urgensi RUU Perlindungan Data Pribadi
Urgensi RUU Perlindungan Data PribadiUrgensi RUU Perlindungan Data Pribadi
Urgensi RUU Perlindungan Data Pribadi
 
GDPR Are you ready for auditing privacy ?
GDPR Are you ready for auditing privacy ?GDPR Are you ready for auditing privacy ?
GDPR Are you ready for auditing privacy ?
 
Right to be forgotten presentation
Right to be forgotten presentationRight to be forgotten presentation
Right to be forgotten presentation
 
What about GDPR?
What about GDPR?What about GDPR?
What about GDPR?
 
GDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection RegulationGDPR Basics - General Data Protection Regulation
GDPR Basics - General Data Protection Regulation
 
PDPA 2010 at office (HairulHafiz)
PDPA 2010 at office (HairulHafiz)PDPA 2010 at office (HairulHafiz)
PDPA 2010 at office (HairulHafiz)
 
2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa compliance2019 04-17 10 steps to ccpa compliance
2019 04-17 10 steps to ccpa compliance
 
Personal Data Protection in Malaysia
Personal Data Protection in MalaysiaPersonal Data Protection in Malaysia
Personal Data Protection in Malaysia
 
Unit 6 Privacy and Data Protection 8 hr
Unit 6  Privacy and Data Protection 8 hrUnit 6  Privacy and Data Protection 8 hr
Unit 6 Privacy and Data Protection 8 hr
 
Overview on data privacy
Overview on data privacy Overview on data privacy
Overview on data privacy
 
GDPR
GDPRGDPR
GDPR
 
Data Protection (Download for slideshow)
Data Protection (Download for slideshow)Data Protection (Download for slideshow)
Data Protection (Download for slideshow)
 
Fundamentals of Information Systems Security Chapter 10
Fundamentals of Information Systems Security Chapter 10Fundamentals of Information Systems Security Chapter 10
Fundamentals of Information Systems Security Chapter 10
 
GDPR for Dummies
GDPR for DummiesGDPR for Dummies
GDPR for Dummies
 
Ley de Protección de Datos Personales 29733 y su Reglamento (primera edición)
Ley de Protección de Datos Personales 29733 y su Reglamento (primera edición)Ley de Protección de Datos Personales 29733 y su Reglamento (primera edición)
Ley de Protección de Datos Personales 29733 y su Reglamento (primera edición)
 

Similar to Legal Basis in GDPR

Cognizant_Candidate_Privacy_Notice.pdfmmmmmahh:uulkhsgghkmnhgd
Cognizant_Candidate_Privacy_Notice.pdfmmmmmahh:uulkhsgghkmnhgdCognizant_Candidate_Privacy_Notice.pdfmmmmmahh:uulkhsgghkmnhgd
Cognizant_Candidate_Privacy_Notice.pdfmmmmmahh:uulkhsgghkmnhgd
SandhyaSandy678561
 

Similar to Legal Basis in GDPR (20)

Public sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, ExeterPublic sector breakfast club - October 2017, Exeter
Public sector breakfast club - October 2017, Exeter
 
Reddico GDPR Presentation
Reddico GDPR PresentationReddico GDPR Presentation
Reddico GDPR Presentation
 
How to Turn GDPR into a Competitive Advantage
How to Turn GDPR into a Competitive AdvantageHow to Turn GDPR into a Competitive Advantage
How to Turn GDPR into a Competitive Advantage
 
B2: Fundraising in an age of GDPR
B2: Fundraising in an age of GDPRB2: Fundraising in an age of GDPR
B2: Fundraising in an age of GDPR
 
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIADR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
DR. OLIVER MASSMANN - PRIVACY LAWS IN ASIA
 
Principles of Data Protection
Principles of Data ProtectionPrinciples of Data Protection
Principles of Data Protection
 
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
GDPR Breakfast Briefing for Business Owners, IT Directors, HR Directors & Ops...
 
European GDPR for Good Technology Collective (GTC)
European GDPR for Good Technology Collective (GTC)European GDPR for Good Technology Collective (GTC)
European GDPR for Good Technology Collective (GTC)
 
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...What does the GDPR mean for charity communicators? | Scotland Networking Grou...
What does the GDPR mean for charity communicators? | Scotland Networking Grou...
 
GDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business AdvisorsGDPR Breakfast Briefing for Business Advisors
GDPR Breakfast Briefing for Business Advisors
 
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPRData Privacy and Data Protection: Rotary’s Compliance with GDPR
Data Privacy and Data Protection: Rotary’s Compliance with GDPR
 
Cognizant_Candidate_Privacy_Notice.pdfmmmmmahh:uulkhsgghkmnhgd
Cognizant_Candidate_Privacy_Notice.pdfmmmmmahh:uulkhsgghkmnhgdCognizant_Candidate_Privacy_Notice.pdfmmmmmahh:uulkhsgghkmnhgd
Cognizant_Candidate_Privacy_Notice.pdfmmmmmahh:uulkhsgghkmnhgd
 
The Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A PresentationThe Protection of Personal Information Act: A Presentation
The Protection of Personal Information Act: A Presentation
 
How to get your business GDPR ready
How to get your business GDPR readyHow to get your business GDPR ready
How to get your business GDPR ready
 
Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)Getting to grips with General Data Protection Regulation (GDPR)
Getting to grips with General Data Protection Regulation (GDPR)
 
GDPR Summary
GDPR SummaryGDPR Summary
GDPR Summary
 
LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...
LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...
LAWYER IN VIETNAM DR OLIVER MASSMANN NEW DRAFT DECREE ON PERSONAL DATA PROTEC...
 
Opportunity or burden
Opportunity or burdenOpportunity or burden
Opportunity or burden
 
GDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To PrepareGDPR is Coming, Five Things You Can Do Now To Prepare
GDPR is Coming, Five Things You Can Do Now To Prepare
 
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
GDPR Breakfast Briefing - For Business Owners, HR Directors, Marketing Direct...
 

Recently uploaded

一比一原版西澳大学毕业证学位证书
 一比一原版西澳大学毕业证学位证书 一比一原版西澳大学毕业证学位证书
一比一原版西澳大学毕业证学位证书
SS A
 
PowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptxPowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptx
ca2or2tx
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
RRR Chambers
 
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
 
Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Call Girls In Delhi Whatsup 9873940964 Enjoy Unlimited Pleasure
 
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxAudience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
MollyBrown86
 
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
mayurchatre90
 

Recently uploaded (20)

WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Nangli Wazidpur Sector 135 ( Noida)
 
一比一原版西澳大学毕业证学位证书
 一比一原版西澳大学毕业证学位证书 一比一原版西澳大学毕业证学位证书
一比一原版西澳大学毕业证学位证书
 
PowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptxPowerPoint - Legal Citation Form 1 - Case Law.pptx
PowerPoint - Legal Citation Form 1 - Case Law.pptx
 
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptxKEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
KEY NOTE- IBC(INSOLVENCY & BANKRUPTCY CODE) DESIGN- PPT.pptx
 
pnp FIRST-RESPONDER-IN-CRIME-SCENEs.pptx
pnp FIRST-RESPONDER-IN-CRIME-SCENEs.pptxpnp FIRST-RESPONDER-IN-CRIME-SCENEs.pptx
pnp FIRST-RESPONDER-IN-CRIME-SCENEs.pptx
 
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdfBPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
BPA GROUP 7 - DARIO VS. MISON REPORTING.pdf
 
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptxCOPYRIGHTS - PPT 01.12.2023 part- 2.pptx
COPYRIGHTS - PPT 01.12.2023 part- 2.pptx
 
Transferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptxTransferable and Non-Transferable Property.pptx
Transferable and Non-Transferable Property.pptx
 
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No AdvanceRohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
Rohini Sector 25 Call Girls Delhi 9999965857 @Sabina Saikh No Advance
 
Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
Russian Call Girls Rohini Sector 7 💓 Delhi 9999965857 @Sabina Modi VVIP MODEL...
 
Relationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdfRelationship Between International Law and Municipal Law MIR.pdf
Relationship Between International Law and Municipal Law MIR.pdf
 
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxxAudience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
Audience profile - SF.pptxxxxxxxxxxxxxxxxxxxxxxxxxxx
 
Introduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusionIntroduction to Corruption, definition, types, impact and conclusion
Introduction to Corruption, definition, types, impact and conclusion
 
LITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULELITERAL RULE OF INTERPRETATION - PRIMARY RULE
LITERAL RULE OF INTERPRETATION - PRIMARY RULE
 
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptxIBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
IBC (Insolvency and Bankruptcy Code 2016)-IOD - PPT.pptx
 
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
Negotiable Instruments Act 1881.UNDERSTAND THE LAW OF 1881
 
Chp 1- Contract and its kinds-business law .ppt
Chp 1- Contract and its kinds-business law .pptChp 1- Contract and its kinds-business law .ppt
Chp 1- Contract and its kinds-business law .ppt
 
THE FACTORIES ACT,1948 (2).pptx labour
THE FACTORIES ACT,1948 (2).pptx   labourTHE FACTORIES ACT,1948 (2).pptx   labour
THE FACTORIES ACT,1948 (2).pptx labour
 
Essentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmmEssentials of a Valid Transfer.pptxmmmmmm
Essentials of a Valid Transfer.pptxmmmmmm
 
Human Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptxHuman Rights_FilippoLuciani diritti umani.pptx
Human Rights_FilippoLuciani diritti umani.pptx
 

Legal Basis in GDPR

  • 2. Legal Basis of GDPR www.seersco.com The data controllers should do following before the start of processing of personal data: • Identify the lawful basis • Document the lawful basis If you find that your lawful basis is invalid under GDPR, this will lead to the breach of accountability and transparency principle. The choice of lawful basis depends upon: • Purposes • The context of processing
  • 3. Lawful Basis www.seersco.com GDPR stipulates six lawful bases. • Consent • Contract • Compliance with a legal obligation • Vital interest • Public interest • Legitimate interest
  • 4. Consent www.seersco.com It means the individual is: • Agreeing to, and permitting the collection and processing of his/her personal data. • Consent is a weak basis for processing and organisations would not be able to rely on it quite often Consequences of choosing consent as the lawful basis: • Right to withdraw consent at any time • The data controller should have to demonstrate that the consent for the processing of personal data was given by the data subject
  • 5. Conditions for valid consent: www.seersco.com Consent is valid when it is • Separate from other terms and conditions • Actively given – no pre-ticked boxes or implied consent • Granular, and applied to separate processing and purposes • Verifiable – Organisations must keep audit trail to prove that they had obtained consent and it was valid • Easy to withdraw – just as easy as it was to provide • No imbalance of power – not available to public sector or employer/ employee relationships
  • 6. Consent of children www.seersco.com To provide information society service directly to a child: • Data processing of a child shall be lawful where the child is at least 16 years old, and his or her consent is obtained directly. • Where the child age is below 16 years, processing is lawful only when the consent is given and processing is authorised by the parents or guardians of the child. Explicit consent: • A written consent statement in printed form with signature on an electronically readable format.
  • 7. Contract www.seersco.com It is applicable when the data controller has a contract with the individual and you need to process their personal data under contract obligation. The contract should be between the: • Data controller • The data subject
  • 8. Legal obligation: www.seersco.com Organisations can rely on this lawful basis when they are obliged to process the personal data in order to comply with a common law or statutory obligation. Organisations should identify: • The specific legal provision • An appropriate source of advice or guidance that clearly sets out your obligation
  • 9. Vital Interest www.seersco.com Vital interest: • Vital interest is the last choice. It is very limited in its scope. • Organisations are likely to be able to rely on this if they need to process the personal data to protect someone’s life
  • 10. Public Interest www.seersco.com Public interest: Data controllers can rely on this lawful basis if they are processing personal data ‘in the exercise of official authority’. Official authority includes: • Public functions • Powers or • Specified tasks in the public interest that are stipulated by the law
  • 11. Legitimate Interest www.seersco.com It means the stake that the organisation may have in collecting and processing of personal data. They can include: • Commercial interests • Individual interests, or • Broader societal benefits Legitimate interest is the most flexible lawful basis for processing If the legitimate interest is chosen as the lawful basis, then there is an extra responsibility for: • Considering • Protecting people’s rights and Interests.
  • 12. 24 Holborn Viaduct, London EC1A 2BN info@seersco.com www.seersco.com