Governance & Compliance · Data artifact
Lawful Basis Record
Data artifactGovernance & ComplianceSafety, Security & GovernanceVariation point (abstract)arc:LawfulBasisRecord
An abstract documented justification establishing which of GDPR's six lawful bases authorizes a specific personal-data processing purpose.
Responsibility. Justifies each processing purpose under an appropriate lawful basis.
Also known as: Lawful basis for processing, Legal basis
Variants
| Variant | When to choose |
|---|---|
| Consent Basis | Choose when processing is genuinely optional and not necessary for the service (e.g., marketing, optional research participation, analytics cookies); avoid when withdrawal would disrupt ongoing operations such as longitudinal research. |
| Contract Basis | Choose when processing is genuinely necessary, not merely convenient, for contract performance (e.g., shipping address and payment for a purchase, employee bank details, treatment as healthcare service delivery). |
| Legal Obligation Basis | Choose when a specific statute mandates the processing (e.g., tax record retention, workplace safety documentation, medical record retention); vague references to 'legal compliance' are insufficient. |
| Legitimate Interests Basis | Choose when an organizational or third-party interest (e.g., fraud prevention, medical research with safeguards, behavioural analytics) does not override individual rights and consent would be operationally fragile. |
| Public Task Basis | Choose for governmental functions, public health initiatives or publicly funded research exercising official authority, identifying the specific public interest or legal provision. |
| Vital Interests Basis | Choose only narrowly, where failure to process could result in serious harm or death (e.g., treating an unconscious patient, child protection). |
Relationships
is read by dependency
is audited by assurance
Design guidance
- MUST be established and documented before any personal data is collected or processed.
- MUST be chosen from the actual nature of the processing and the relationship with the individual, not convenience or perceived safety.
- MAY combine more than one basis for one activity where each genuinely applies (e.g., treatment under contract, record retention under legal obligation).
Classification
- Quality attributes
- Transparency and accountability (NIST AI RMF: accountable and transparent)
- Risks mitigated
- Unlawful processing
- Frameworks & regulations
- GDPR Art. 6
Sources
- Ch9.7: T. Nguyen, "GDPR and Data Protection Regulations," in Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam, 1st ed. 2026, ch. 9.7. ISBN: 9798244538229.
- Ref9.05: "Privacy and Data Protection for AI Systems," unpublished reference note (references/Chapter 9 - Safety, Ethics, and Compliance/05-Privacy-Data-Protection.md), Mastering Agentic AI Systems: Guide for the NVIDIA NCP-AAI Exam supplementary materials, 2026. unpublished note