Executive Summary
Your organization can only process data if one of the 5 following criteria are met:
1. The data subject has given consent for one or more specific purposes;
2. Processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
3. Processing is necessary for compliance with a legal obligation to which your organization is subject;
4. Processing is necessary in order to protect the vital interests of the data subject or of another person;
5. Processing is necessary for the public interest or in the exercise of official authority vested in the controller.
Article Text
1. Processing shall be lawful only if and to the extent that at least one of the following applies:
(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
(b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
(c) processing is necessary for compliance with a legal obligation to which the controller is subject;
(d) processing is necessary in order to protect the vital interests of the data subject or of another natural person;
(e) processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
(f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Quick Wins
Ensure that you inform your partner/employee/customer/vendor what you will use their data for, and for how long. Get written consent, and keep that written consent until the retention period has ended.
Article ID: 283
Created: September 27, 2022
Last Updated: September 27, 2022
Author: Matthew Burdick
Online URL: http://www.compliancewiki.org/article/gdpr-lawfulness-of-processing-summary-283.html