Choose a lawful basis for each purpose before processing customer information. The fact that someone is a customer does not make every use necessary for a contract. Identify the actual activity and assess the available basis under the current UK framework.
Contract necessity, legal obligations, consent and legitimate interests involve different tests and consequences. Sensitive categories can require additional conditions. Record the reasoning and communicate the relevant information; do not switch labels later merely because a preferred activity proves difficult to justify.
Separate the uses before choosing a basis
A customer database can support several different activities. Completing an order, checking fraud indicators, handling a complaint and building an advertising audience do not become one purpose merely because they use the same email address. Create a row for each use, identify the minimum information needed and describe the actual benefit or obligation. This makes it easier to reject unnecessary processing before a broad label becomes embedded in the software configuration.
For contract necessity, ask whether the processing is genuinely needed to perform a contract with that individual or take requested steps before it. Adding a clause to terms does not by itself make a desirable business activity necessary. An employee's contact details used in a contract with their employer also need careful analysis: the employee and the contracting company are different people for this purpose.
Write down the reasoning for legitimate interests
Where ordinary legitimate interests is proposed, examine the purpose, necessity and balance against the individual's interests and rights. The ICO distinguishes this assessment from the separate recognised legitimate interests basis introduced by the updated framework. Do not assume an ordinary commercial objective belongs to the recognised category. [1] Record why the use is expected, what adverse effects could occur and which safeguards actually reduce those effects.
A useful assessment discusses realistic alternatives. Could the business use aggregated figures instead of individual histories? Could a shorter contact period achieve the same objective? If the answer is yes, explain why the more intrusive option is still needed or choose the less intrusive design. Avoid a form in which every answer simply says low risk; a reviewer should understand the trade-off without interviewing the original project manager.
Distinguish consent from customer acknowledgement
Consent requires a suitable choice and a process for withdrawal. A tick confirming that the person has read a privacy notice is not automatically consent to unrelated processing. Consider whether refusing would have an unnecessary adverse consequence and whether the business can honour withdrawal across connected systems. Where another basis properly applies, asking for apparent consent can confuse customers about what the organisation will actually stop doing.
Marketing adds separate electronic communications rules. A UK GDPR basis does not override PECR requirements for the chosen channel or subscriber type. [2] Use Marketing emails to business contacts when planning business email campaigns and Marketing consent and customer preferences when designing preference records. Keep service communications distinct from promotional additions; an operational email may change character if it is used to sell a new product.
Check sensitive information and changes of purpose
Health information or other special category data needs an additional applicable condition, not merely an ordinary lawful basis. Criminal offence information has a separate framework. Identify such material before collection, including free-text fields that invite customers to reveal more than intended. If that information is unnecessary, redesign the question rather than relying on a privacy paragraph to justify keeping it.
Bring a purpose register, sample forms and proposed automations to Business privacy notice review. Ask for a conclusion on each uncertain activity and the safeguards needed before it starts. Record the decision alongside the operational owner, notice wording and system settings. When a new use is proposed later, revisit the assessment instead of silently changing the legal label after the original basis becomes inconvenient.
Test a proposed reuse with a concrete example
Suppose an account manager wants to upload former customers' telephone numbers to an advertising platform. The original purpose of arranging appointments does not settle whether this new activity is permissible. Describe the audience matching, what the platform receives and what happens to unmatched contacts. Consider the source of the numbers, the explanation originally supplied and any recorded objections.
Keep the decision separate from approval of the campaign's creative material. A marketing manager can confirm that an advert is accurate without being able to confirm the proposed data use. Record who must resolve that question before the upload, and ensure an agency cannot perform the same activity from an exported spreadsheet while the internal assessment remains unfinished.
Illustrative scenario
An online retailer needs an address to deliver an order and separately wants to share buying behaviour with an advertising provider. These are different purposes. The retailer assesses each activity on its own facts instead of treating the sales contract as permission for all later profiling and promotion.
Preparation checklist
- Write a specific purpose for each use of customer data.
- Explain why the selected basis applies to that purpose.
- Check extra conditions for sensitive information.
- Keep the assessment consistent with notices and operational settings.
Frequently asked questions
Can one lawful basis cover our whole database?
A database can contain several purposes requiring different assessments. Document the basis for each actual use; the software product or customer relationship is not itself a lawful basis.
Is direct marketing automatically a recognised legitimate interest?
Do not assume so. Ordinary legitimate interests and recognised legitimate interests are distinct routes. Check the current ICO guidance and separately assess electronic marketing requirements.
What should a legitimate interests assessment retain?
Keep the purpose, necessity analysis, likely effects on people, safeguards and reasoned conclusion. Include alternatives considered so later reviewers can understand why the chosen design was proportionate.
Can we change the basis after a complaint?
Do not relabel past processing simply to avoid the consequences of the original choice. Review the facts and obtain advice on the existing processing and any proposed future activity.
Official sources
Sources checked: 8 September 2026. Check the linked guidance for subsequent changes.
General information only. The appropriate action depends on your circumstances and the applicable jurisdiction.
Report a correction