GDPR and Legal Bases: Everything You Need to Know About Legal Obligation The **legal obligation** is one of the six legal bases provided by the GDPR that allows organizations to process personal data. Unlike consent or legitimate interest, it applies when processing is necessary to comply with a legal requirement imposed by national or European law. ## What is legal obligation under the GDPR? Legal obligation is defined in **Article 6(1)(c) of the GDPR** as: > "processing is necessary for compliance with a legal obligation to which the controller is subject." This means that the organization does not have a choice: it must process personal data to comply with a specific legal text (law, decree, regulation, European directive, etc.). ### Key characteristics - **Imperative nature**: Processing is imposed by law, not chosen by the organization - **Legal precision**: The obligation must stem from a clear and specific text - **Necessity**: Only data strictly necessary to fulfill the legal obligation may be processed - **Limited purpose**: Data cannot be reused for other purposes ## Concrete examples of legal obligation ### 1. Tax and accounting obligations Organizations must keep accounting records and transmit tax information to tax authorities: - Invoicing and archiving invoices - Annual tax returns - Declarations of payments made to suppliers or employees ### 2. Social obligations In the field of human resources, employers are subject to numerous legal obligations: - Declaration of employees to social security organizations - Payment of social contributions - Keeping payroll records - Declaration of workplace accidents ### 3. Anti-money laundering (AML) obligations Banks and financial institutions must: - Verify the identity of their customers (KYC) - Keep transaction records - Report suspicious transactions to TRACFIN ### 4. Legal retention obligations Certain documents must be kept for a legally defined period: - Accounting documents: 10 years - Employment contracts: 5 years after termination - Patient medical records: 20 years ### 5. Security and prevention obligations Companies are required to declare certain incidents: - Data breaches to the CNIL (within 72 hours) - Professional accidents - Installation of video surveillance with authorization ## Differences with other legal bases | Criterion | Legal obligation | Consent | Legitimate interest | |-----------|------------------|---------|---------------------| | **Choice** | No choice, imposed by law | Free choice of the data subject | Choice of the organization | | **Withdrawal** | Impossible | Possible at any time | Right to object | | **Justification** | Legal text | Active agreement | Balancing of interests | | **Examples** | Tax returns, KYC | Newsletter, cookies | Customer management, fraud prevention | ## Conditions for applying legal obligation ### 1. Existence of a clear legal text The legal obligation must be based on a specific provision of: - A law - A decree - A regulation - A European directive or regulation **⚠️ Important**: An internal policy or contractual agreement is not sufficient to invoke legal obligation. ### 2. Necessity of the processing Only data **strictly necessary** to fulfill the legal obligation may be collected. Any additional data requires another legal basis (consent, legitimate interest, etc.). **Example**: For KYC, a bank must collect identity, address, and profession, but not dietary preferences. ### 3. Transparency toward data subjects Even when processing is based on legal obligation, the organization must inform individuals: - Of the processing and its purpose - Of the legal basis and the specific text imposing the obligation - Of their rights (even if limited) ## Rights of data subjects When processing is based on legal obligation, certain rights are **limited**: | Right | Applicable? | Explanation | |-------|-------------|-------------| | **Right to access** | ✅ Yes | The person can obtain a copy of their data | | **Right to rectification** | ✅ Yes | Inaccurate data can be corrected | | **Right to erasure** | ❌ Limited | Impossible if retention is legally required | | **Right to object** | ❌ No | Processing is mandatory, not optional | | **Right to data portability** | ❌ No | Does not apply to legal obligation | ### Example An employee cannot request the deletion of their payroll records because the employer has a legal obligation to keep them for 5 years. ## Practical mistakes to avoid ### ❌ Error 1: Invoking legal obligation without a legal text Some organizations claim "legal obligation" for processing that is actually optional or based on another basis. **Example**: A company claiming legal obligation to collect customers' dietary preferences for event organization. → This is not a legal obligation but legitimate interest or consent. ### ❌ Error 2: Using legal obligation to avoid obtaining consent Legal obligation cannot be used as a convenient alternative to avoid requesting consent. **Example**: A website claiming legal obligation to install marketing cookies. → This is false, consent is required. ### ❌ Error 3: Collecting excessive data Under the pretext of legal obligation, some organizations collect more data than strictly necessary. **Example**: For KYC, requesting religion or political opinions. → This goes beyond the legal obligation and is prohibited. ### ❌ Error 4: Not documenting the legal basis The organization must be able to precisely identify the legal text imposing the obligation. **Solution**: Maintain a table linking each processing operation to the corresponding legal text. ## How to document legal obligation in the register of processing activities? Each processing operation based on legal obligation must be documented in the **register of processing activities** (Article 30 of the GDPR). ### Mandatory information 1. **Purpose of the processing**: "Fulfillment of tax obligations" 2. **Legal basis**: "Legal obligation (Article 6(1)(c) of the GDPR)" 3. **Legal text**: "Articles L.123-22 and L.123-12 of the Commercial Code" 4. **Categories of data**: Only data necessary for the obligation 5. **Retention period**: According to the legal obligation (e.g., 10 years for accounting) ### Concrete example | Element | Detail | |---------|--------| | Processing | Employee payroll management | | Purpose | Fulfillment of social declaration obligations | | Legal basis | Legal obligation (Article 6(1)(c) of the GDPR) | | Legal text | Article L.3243-2 of the Labor Code | | Data collected | Surname, first name, SSN, salary, hours worked | | Retention | 5 years after termination of the employment contract | ## Legal obligation and international transfers When personal data must be transferred outside the European Union to comply with a legal obligation, the organization must: 1. **Verify that the transfer is truly necessary** for fulfilling the obligation 2. **Justify the legal basis of the transfer** (Article 49 of the GDPR) 3. **Inform individuals** about the transfer and associated risks **Example**: A multinational company must transmit employee data to American tax authorities under a tax treaty. This constitutes a legal obligation, but individuals must be informed. ## Legal obligation and sensitive data **Sensitive data** (health, political opinions, religion, etc.) are subject to enhanced protection under Article 9 of the GDPR. However, processing of sensitive data may be authorized if: - It is **necessary to comply with a legal obligation** (Article 9(2)(b)) - A specific text authorizes this processing **Example**: An employer must communicate an employee's health data to occupational medicine services. This is a legal obligation provided by the Labor Code. ## Interaction with other legal bases In some cases, a processing operation may rely on **several legal bases** simultaneously: - **Legal obligation + legitimate interest**: An employer manages payroll (legal obligation) but can also use payroll data for internal statistics (legitimate interest). - **Legal obligation + consent**: A bank collects identity data for KYC (legal obligation) but requests consent to send marketing offers. **⚠️ Important**: The legal basis must be determined separately for each purpose. ## Frequently Asked Questions (FAQ) ### 1. Can I invoke legal obligation for any legal requirement? No. Legal obligation must be imposed by a **clear and specific legal text** (law, regulation, decree). A contractual obligation or internal policy does not suffice. ### 2. Can an individual refuse processing based on legal obligation? No. Legal obligation is imperative. The individual cannot object to this processing, as the organization has no choice but to comply with it. ### 3. What happens if I do not comply with a legal obligation? Non-compliance with a legal obligation can lead to: - Administrative or criminal sanctions by the competent authority (tax authorities, URSSAF, etc.) - GDPR violations if the processing is excessive or poorly documented ### 4. Can I reuse data collected under legal obligation for other purposes? No, unless: - You have another legal basis (consent, legitimate interest) - You obtain the explicit consent of the data subject ### 5. How long should I keep data collected under legal obligation? The retention period is generally specified by the legal text imposing the obligation. If not, apply the principle of proportionality and document your choice. ## Checklist: Correctly applying legal obligation ✅ **Verify that a clear legal text imposes the processing** ✅ **Collect only strictly necessary data** ✅ **Inform individuals of the legal text and their rights** ✅ **Document the legal basis in the register of processing activities** ✅ **Respect the legal retention period** ✅ **Do not reuse data for purposes not covered by the legal obligation** ✅ **Provide a copy of data upon request (right to access)** ✅ **Correct inaccurate data (right to rectification)** ## Conclusion Legal obligation is a **robust legal basis** for processing personal data, as it is imposed by law and cannot be challenged by individuals. However, it must be used **strictly** and **transparently**: - Only invoke legal obligation when a clear legal text requires the processing - Limit data collection to what is strictly necessary - Properly document the legal basis and the legal text - Inform individuals of their (limited) rights Organizations that properly apply legal obligation comply with both the GDPR and sectoral legal obligations, while ensuring optimal protection of personal data. --- **Need help identifying your legal obligations and complying with the GDPR?** Contact our experts for a personalized audit of your processing activities.
The 6 legal bases provided by the GDPR
Compliance with a legal obligation is one of the 6 legal bases provided by the GDPR? :
- Consent,
- Contract, last week's article,
- Legal obligation, this week's article,
- Public interest mission,
- Protection of vital interests,
- Legitimate interest.
As a reminder, choosing your legal basis is mandatory for the processing to be lawful. This choice also determines the rights that data subjects will be able to claim for the processing in question. The rights that can be exercised will not be the same depending on the basis chosen.
To learn more, consult our previous articles and follow us on LinkedIn to be notified as soon as our next articles are published! ??
The legal basis "legal obligation": what is it??
The data controller may choose this legal basis when the implementation of processing is required by applicable law. In other words, the data controller has no choice; they must necessarily carry out the processing to comply with their obligation. It is the legal text that defines the purposes of the processing.
For example, the Labour Code requires employers to maintain a single personnel register. It must contain numerous personal data (surname, first name, nationality, gender, employment, qualifications, etc.). The data controller must maintain this register otherwise they fail to meet their legal obligation and are exposed to criminal sanctions.
Under what conditions should this legal basis be chosen?
The legal obligation must meet four characteristics to be legitimately chosen as a legal basis.
✅ It must be:
- Defined by European law or national law
The obligation upon which the data controller relies must be defined by national law or European Union law. The obligation may, for example, arise from a law, a decree, a European regulation, etc. The national law that establishes the obligation is the law to which the data controller is subject.
Note that a contractual clause cannot be considered a legal obligation. In this case, the legal basis must be reviewed. The data controller will then choose contract as the legal basis. Find our article on this subject by clicking here.
- Imperative
The data controller must be subject to this legal obligation. As explained earlier, they must have no choice but to comply with this obligation. Indeed, they must be compelled to carry out the processing to meet their obligation. The text identified as establishing the obligation must impose the processing on the data controller.
Finally, the legal obligation must provide for the implementation of the processing. The text must not leave the data controller too wide a margin of appreciation. Concretely, the text must set out how the data controller must carry out the processing to meet their obligation.
- Clear and precise
The legal obligation must at a minimum specify the purpose of the processing. The processing must serve one objective, not a cumulation of objectives. This is where the principle of purpose limitation comes into play. To understand the specifics of this principle, find our article on the subject.
- Intended for the data controller, not for the data subjects
The text that establishes the legal obligation must clearly indicate that the obligation concerns the data controller. They must be the only one required to meet this obligation for the legal basis to be chosen. The processing cannot be based on a legal obligation that would be intended for the persons whose data is processed.
For example, the tax administration that processes taxpayers' tax returns cannot base this processing on a legal obligation. The obligation to file tax returns is indeed aimed at individuals, not the entity that processes the returns. This processing is rather based on public interest mission.
If these conditions are not met, the data processing cannot be based on a legal obligation and the data controller must choose another legal basis.
To illustrate, on 16 June 2020, the Data Protection Authority (APD, the Belgian supervisory authority) ruled on a complaint filed by parents of pupils against a school. To conduct a "well-being survey" among pupils, the establishment sent a questionnaire to the children. This document contains personal data of the children and clearly allows them to be identified.
The school based this processing on a legal obligation arising from a Flemish decree "relating to the guidance of pupils in primary education, secondary education and in pupil guidance centres". The guidance of pupils includes here:
- The school career,
- Learning and study,
- Psychological and social functioning,
- Preventive health care.
Parents of pupils filed a complaint, arguing that their consent is required for the school to carry out this data processing. The APD ruled that the legal obligation exists, but does not imply that pupils must answer a questionnaire allowing them to be identified. The decree sets out the purposes of the processing, but does not provide for the personal data of pupils (minors under 13 years old) that must imperatively be processed.
The Belgian supervisory authority concluded that the school acted beyond the means provided for in the text to meet the legal obligation to which it is subject. The legal obligation does not require the school to conduct a questionnaire among pupils. Thus, the legal basis for the processing cannot be based on legal obligation. The legal basis for this processing is consent. This must be obtained from the legal guardians of minor children.
To learn more, consult the decision rendered: https://www.autoriteprotectiondonnees.be/publications/decision-quant-au-fond-n-31-2020.pdf
What consequences for individuals' rights??
Individuals whose data is processed based on a legal obligation will not be able to exercise their right to object, nor their right to data portability. Indeed, since the legal obligation is imperative, the data controller cannot grant a request to object from an individual.
To comply with your obligations, among the information you must provide to individuals (see articles 13 and 14 of the GDPR), inform individuals that they will not be able to exercise these rights in an internal and/or external privacy policy.
# Data Comply One (formerly Mission RGPD) and Legal Bases Data Comply One (formerly Mission RGPD) and legal bases refer to the fundamental legal grounds that justify the processing of personal data under the GDPR. These legal bases are essential pillars that allow organizations to collect, use, and process personal information in compliance with European data protection regulations. ## The Six Legal Bases under GDPR The GDPR establishes six main legal bases for data processing: 1. **Consent**: The data subject has given explicit consent for their data to be processed for one or more specific purposes. 2. **Contract**: Processing is necessary for the performance of a contract to which the data subject is party, or to take steps at the request of the data subject prior to entering into a contract. 3. **Legal obligation**: Processing is necessary for compliance with a legal obligation to which the controller is subject. 4. **Vital interests**: Processing is necessary to protect the vital interests of the data subject or another natural person. 5. **Public interest**: Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller. 6. **Legitimate interests**: Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. ## Data Comply One's Approach to Legal Bases Data Comply One (formerly Mission RGPD) helps organizations identify and document the appropriate legal bases for their data processing activities. This includes: - **Legal basis mapping**: Analyzing each processing activity to determine the most appropriate legal basis - **Documentation**: Maintaining records of processing activities with clearly identified legal bases - **Compliance verification**: Ensuring that the chosen legal basis is properly applied and documented - **Rights management**: Implementing processes to respect data subject rights according to the applicable legal basis ## Importance of Choosing the Right Legal Basis Selecting the appropriate legal basis is crucial because: - It determines the data subject rights that apply - It influences the information that must be provided to data subjects - It affects the organization's obligations regarding data retention and processing limitations - An incorrect legal basis can result in non-compliance and potential sanctions Data Comply One (formerly Mission RGPD) provides tools and expertise to help organizations navigate these requirements and ensure proper application of legal bases in their data processing operations.
Is it difficult for you to know which legal basis to choose? Don't you have the necessary time to dedicate to managing your compliance? Are you lost?
✅ Data Comply One (formerly Mission RGPD) provides you with numerous useful document templates for your compliance. Among these documents, find internal and external privacy policy templates. Download them and adapt them to your company.
Save time with a pre-filled compliant document!
Don't waste any more time, it's so simple!