Cross-Jurisdictional Global

Lawful Basis Around the World: Consent, Contract, and Everything Between

How processing gets justified across regimes: GDPR's six bases and legitimate interests balancing, PIPL's separate consent, the US opt-out model, LGPD's ten bases, and how to run one basis framework globally.

Regulation

GDPR Article 6 (and Article 9 for special categories), PIPL Article 13, LGPD Articles 7 and 11, APPI's purpose-based model, PIPEDA's consent principle, the US state notice-and-opt-out architecture

Max Penalty

Processing without a valid basis sits in the GDPR's top tier (20 million EUR or 4% of turnover, the theory behind the 1.2 billion EUR Meta transfer fine and the 390 million EUR Meta basis decisions); peers scale similarly

Enforcing Authority

EU/UK DPAs (with the CJEU shaping doctrine), the CAC, ANPD, PPC, OPC, and US state enforcers policing the opt-out layer

Official Source

www.edpb.europa.eu

Executive Summary

  • GDPR-family regimes prohibit processing unless one of an enumerated set of bases applies; the choice is made before processing, documented, disclosed, and hard to change later.
  • Legitimate interests is the GDPR's workhorse and its most litigated basis: a three-part test (purpose, necessity, balancing) that enforcement keeps narrowing, most famously against behavioral advertising.
  • PIPL runs consent-first with no legitimate-interests equivalent and mandatory separate consent for sensitive data, transfers, and disclosures, making it the strictest mainstream permission regime.
  • The US model inverts the question: processing is permitted with notice, and the legal risk lives in the opt-out machinery, sale/share classification, and sensitive-data opt-ins.
  • A global basis framework records, per purpose per jurisdiction, the permission theory and its evidence, because 'why are we allowed to do this' is the first question every regulator asks.

Every privacy regime ultimately answers one question, by what right does this organization process this person’s data, and the answers sort into three families: enumerate the permissible justifications and demand one up front (GDPR and its descendants), regulate the declared purpose and gate expansions with consent (APPI, PIPEDA’s calibrated model), or permit-with-notice and arm the individual with opt-outs (the US states). None of the three is converging into the others, PIPL is doubling down on separate consent, Europe keeps narrowing legitimate interests, and the US keeps building opt-out machinery, so a global program cannot pick one theory and translate it; it must run a basis register that records, per purpose and jurisdiction, which theory applies and what evidence supports it. That register is the program’s constitutional document: when the regulator’s first question arrives, ‘why were you allowed to do this,’ it is the difference between an answer and an improvisation.

Three familiesBasis-first (GDPR, LGPD, PIPL*), purpose-first (APPI, PIPEDA), notice-and-opt-out (US states)
GDPR workhorsesContract necessity (read strictly post-Meta), consent, legitimate interests with a documented LIA
PIPL edgeNo legitimate interests; separate consent for sensitive data, transfers, disclosure, sharing
US edgeSale/share classification, GPC signal honoring, sensitive-data and minors’ opt-ins
Doctrine hubEDPB guidelines

Applying it

See the whole map. The master privacy crosswalk puts basis in context with rights, breach, and transfers.

Wire the consent layer. Cookie consent implementation covers the ePrivacy zone where consent is mandatory regardless of basis.

Handle the automated decisions. ADM opt-outs covers the profiling rights attached to basis choices.

Record it all. Records of processing is where basis decisions live and are produced on request.

Your website’s trackers are basis decisions in production: see what fires before any consent with a free scan.

Frequently Asked Questions

How do the GDPR's six bases actually get chosen in practice?

Article 6 offers six: consent, contract necessity, legal obligation, vital interests, public task, and legitimate interests, and the practical selection logic is narrower than the list suggests. Contract necessity (6(1)(b)) covers processing objectively required to deliver the service the person signed up for, account management, fulfillment, payment, and the CJEU and EDPB read 'necessity' strictly: the Meta decisions (Irish DPC, January 2023, 390 million EUR combined) rejected contract as a basis for behavioral advertising inside social-media terms, establishing that burying a processing purpose in the contract does not make it contractually necessary. Legal obligation (6(1)(c)) covers tax records, AML checks, employment-law retention, mechanical where it applies. Vital interests and public task are narrow (emergencies; public authorities). That leaves the real decision for everything else, consent versus legitimate interests. Consent (6(1)(a), standard set by Articles 4(11) and 7): required where law says so (ePrivacy for cookies and marketing to individuals), where the processing is intrusive enough that balancing would fail, and where special categories need Article 9(2)(a) explicit consent; its costs are operational (capture, records, withdrawal propagation) and structural (withdrawal must be honored, and consent invalid if bundled or coerced). Legitimate interests (6(1)(f)): the flexible basis for fraud prevention, security, B2B marketing, analytics, and intra-group administration, but it carries the three-part test, identify the interest, prove necessity (no less intrusive means), and balance against the individual's interests and reasonable expectations, documented in a legitimate interests assessment (LIA), and it triggers the Article 21 objection right. The selection discipline that survives audits: one basis per purpose chosen before launch, recorded in the RoPA with reasoning, disclosed in the notice, and never swapped retroactively when the first theory fails, basis-shopping after the fact is an aggravating factor the DPAs explicitly call out.

Why is legitimate interests so contested, and where are its current boundaries?

Because it is the basis where the controller grades its own homework, the LIA is self-administered balancing, so enforcement has concentrated on policing its edges. The settled boundaries: behavioral advertising cannot rest on legitimate interests at scale, the trajectory ran from the DPAs' rejection of contract (Meta 2023) to the Irish DPC and EDPB's position and the CJEU's 2024 judgment in the Dutch tennis-association case (KNLTB), which confirmed commercial interests can qualify as legitimate but still require genuine necessity and balancing, while Meta's own pivot to consent for EU personalized ads marks the industry's concession; cookies and device access were never eligible (ePrivacy requires consent regardless of GDPR basis); and special categories cannot ride on it at all (Article 9 has no legitimate-interests gate). The still-live zones: AI training on scraped or first-party data (the Irish DPC's engagement with Meta over Llama training, and EDPB Opinion 28/2024 on AI models, accept legitimate interests as arguable while demanding real necessity analysis, safeguards, and opt-out mechanics); fraud and security (broadly accepted, recital 47 and 49 territory); B2B and postal marketing (accepted with easy objection); employee monitoring (heavily fact-dependent, with proportionality doctrine doing the work). What a defensible LIA looks like: the interest named concretely (not 'business purposes'), alternatives considered and rejected with reasons, the data minimized to the purpose, the individual's reasonable expectations analyzed honestly (would they be surprised?), safeguards enumerated (pseudonymization, retention limits, opt-outs), and a conclusion someone signed and dated. The tell of an indefensible one: written after the processing started, by the team that wanted the answer yes. UK note: the Data (Use and Access) Act 2025 introduced 'recognised legitimate interests' for enumerated purposes (crime prevention, safeguarding, emergencies), removing the balancing test for those narrow cases, a UK-EU divergence to track in dual-market programs.

How does PIPL's consent architecture differ from the GDPR's?

PIPL looks GDPR-shaped and is stricter in three structural ways. Fewer alternative bases: Article 13 permits processing on consent, contract or HR-management necessity, legal duties, public health emergencies, news reporting in the public interest, already-disclosed data within reason, and a catch-all for other legal provisions, but there is no legitimate-interests equivalent, so the flexible residual basis European programs lean on simply does not exist, and purposes that ride on LI in Europe (analytics, fraud models beyond legal mandates, product improvement) generally need consent in China. Separate consent (单独同意): for sensitive personal information (Article 29), cross-border transfers (Article 39), public disclosure (Article 25), provision to other handlers (Article 23), and image collection beyond public-security purposes, consent must be obtained separately, a distinct, specific consent action for that act, not a clause inside general terms, and Chinese court decisions and CAC enforcement have invalidated bundled consent under exactly this doctrine; implementation means dedicated consent moments in product flows, which is why PIPL localization is a UX project, not a policy edit. Sensitivity defined by risk, not list: sensitive personal information is anything whose leakage or misuse could easily harm dignity or personal/property safety, explicitly including biometrics, religion, specific identity, medical health, financial accounts, location tracking, and all data of minors under 14, broader in reach than Article 9's closed list (financial accounts and location are not GDPR special categories), and carrying its own necessity, protection-measure, and notification duties beyond the separate consent. Add the practical overlays, consent for transfer does not replace the transfer mechanism itself (CAC assessment, Chinese SCC filing, or certification), and withdrawal must be as convenient as granting (Article 15), and the design consequence is clear: a global consent platform needs a PIPL mode with distinct consent objects per act, not a translated GDPR banner.

How do LGPD, APPI, PIPEDA, and the other mixed regimes handle basis?

LGPD (Brazil): the most GDPR-like, with ten bases in Article 7, the GDPR's six plus credit protection, health protection by professionals, research by study bodies, and judicial/arbitral exercise of rights, and a legitimate-interests basis with its own balancing requirement (Article 10) and ANPD guidance following European doctrine; sensitive data (Article 11) runs a narrower list of gates with no legitimate-interests option, and children's data (following the 2023-2024 ANPD interpretation) processed on best-interests analysis rather than the earlier consent-only reading. APPI (Japan): structurally different, not basis-enumeration but purpose-regulation: personal information may be collected and used within a purpose of use that must be specified and disclosed, with consent required for exceeding it, for providing data to third parties (subject to the opt-out filing route for non-sensitive data, narrowed by amendments after the recruit-scandal era), and for sensitive categories ('special care-required information'); the compliance discipline is purpose hygiene, defining purposes tightly and re-consenting on expansion, rather than basis selection. PIPEDA (Canada): consent is the cardinal principle but with a doctrine of implied consent calibrated to sensitivity and reasonable expectations (express consent for sensitive data or unexpected uses, implied for obvious transactional processing), guided by the OPC's meaningful-consent guidelines and the overarching 'appropriate purposes' reasonableness limit in section 5(3); Quebec's Law 25 tightens all of this provincially with express-consent rules and sensitive-information handling closer to European practice. Korea's PIPA: consent-centered with enumerated exceptions, historically strict, with 2023 amendments adding flexibility (including for contract performance) while raising penalties toward turnover-based fines. India's DPDP Act: consent or enumerated 'legitimate uses' (voluntary provision, state functions, emergencies, employment purposes), with consent managed through registered consent managers once the rules operationalize. The composite lesson: outside the GDPR family the permission question is answered by purpose discipline plus calibrated consent, and the global program's basis register needs a column for these theories, not a forced mapping onto Article 6.

How does the US notice-and-opt-out model work, and where is consent creeping in?

The baseline: US state privacy laws permit processing of personal information subject to accurate notice, purpose limitation duties (the CPRA added a GDPR-flavored 'reasonably necessary and proportionate' standard), and consumer opt-out rights, of sale (broadly defined in California to include valuable-consideration exchanges that catch routine adtech), of sharing for cross-context behavioral advertising, of targeted advertising (the Virginia/Colorado formulation), and of profiling in furtherance of significant decisions; the enforcement action lives in whether the opt-outs actually work, the Sephora settlement (California AG, 2022) established that ignoring Global Privacy Control signals is a violation, GPC honoring is now mandatory in California, Colorado, and a growing list of states, and CPPA and multi-state sweeps keep testing links, signals, and downstream propagation. Where opt-in consent is entering the US model: sensitive data (Virginia, Colorado, Connecticut, and most post-2021 states require opt-in consent for processing sensitive categories, a real GDPR-ward move, while California handles the same categories through its limit-use right); minors (COPPA's verifiable parental consent under 13, strengthened by the 2025 rule amendments; state laws requiring consent for teens' targeted advertising, and the age-appropriate design codes extending duties to under-18s); biometrics (Illinois BIPA's written-release regime, with its private right of action and the Rogers/White Castle-era per-scan exposure that drove the 2024 amendment capping accrual, plus Texas and Washington's My Health My Data with its own consent architecture for health data); and dark-pattern doctrine (consent obtained through manipulative interfaces is statutorily invalid under CPRA and Colorado rules, converging with the EDPB's position from the other direction). Design consequence for global systems: the US layer is not 'GDPR lite' but a different machine, flow classification (is this a sale/share?), signal ingestion (GPC), state-by-state sensitive-data consent gates, and minors' flows, running beside the European basis engine, keyed by user jurisdiction, with Washington's My Health My Data and Illinois BIPA as the private-litigation tripwires that make misclassification expensive.

Regulatory Crosswalk

GDPR Articles 6 and 9PIPL Article 13LGPD Articles 7 and 11PIPEDACCPA/CPRA

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.