Under GDPR, can a controller rely on more than one lawful basis for the same processing activity?
- A.No, only one basis may ever apply, citing Article 6(1)(e), which requires a specific statute for every single instance of public-task processing rather than a legal basis in law generally
- B.Yes, and no documentation is needed, and GDPR excludes employee records
- C.No, multiple bases are explicitly prohibited
- D.Yes, but the primary basis must be identified in advance and documented
Why D is correct
While a controller should identify and document the most appropriate lawful basis before processing begins, the EDPB recognises that in some situations more than one basis may apply, though the primary one should be clearly identified.
Know someone studying for GDPR? Send them this one.