An advanced practitioners' guide to public task and official authority — where administrative law, fundamental rights, and data protection converge.
Processing is lawful where it is necessary for the performance of a task carried out in the public interest, or necessary for the exercise of official authority vested in the controller.
Public authorities, public bodies, and regulators
Courts acting in administrative capacities and statutory agencies
Private entities entrusted with public functions by law
Outsourced service providers acting on behalf of public authorities where the underlying task remains a public task
Unlike consent (6(1)(a)): Processing does not depend on a freely given choice. Withdrawal of consent is irrelevant because consent is not the legal basis.
Unlike legitimate interests (6(1)(f)): No balancing test is required. The public task itself provides the legal justification — though proportionality and necessity remain mandatory.
Unlike contract (6(1)(b)): The basis is rooted in public law, not private agreement.
Four cumulative requirements must all be satisfied. Failure of any single element invalidates reliance on Article 6(1)(e).
A genuine public-interest task or officially conferred authority must exist — not merely a convenient or beneficial purpose.
The task or authority must be grounded in EU law or national legislation. Controllers cannot self-designate their own public tasks.
A rational, proportionate connection must exist between the processing activity and the public task. Less intrusive alternatives must be considered.
All other GDPR principles and obligations under Article 5 and beyond must be satisfied simultaneously — Article 6(1)(e) is not a blanket exemption.
Public interest is not defined autonomously by the controller. The concept must be derived from EU law, national legislation, statutory instruments, constitutional mandates, or public-sector regulatory frameworks.
Public health surveillance and disease notification systems
Tax administration and electoral administration
Social welfare and environmental protection monitoring
Education administration by public authorities
Child safeguarding and national archives
Public statistics, transportation safety oversight, financial supervision
A public authority operating a purely commercial loyalty programme
Marketing unrelated to statutory functions
Optional services lacking a legal mandate
Research projects where no legal basis establishes the public task
Processing performed merely because it is convenient
Official authority involves powers conferred by law — not assumed, implied by convenience, or self-declared. The following indicators signal the presence of official authority.
Powers to investigate, inspect, and regulate conduct within a defined sector or jurisdiction.
Powers to grant, refuse, suspend, or revoke licences and permits.
Powers to enforce compliance, impose sanctions, and make binding administrative decisions.
Powers to make determinations affecting individuals' rights, obligations, or entitlements.
Illustrative examples: A regulator investigating market abuse · A local authority issuing planning permits · A tax authority assessing liabilities · A licensing authority reviewing applications · An immigration authority processing visa applications.
Article 6(3) is critical. Article 6(1)(e) cannot stand alone. The public task or official authority must be established by EU law or Member State law.
The purpose of processing and the relevant public function
The categories of processing contemplated
The conditions applicable to processing
Appropriate safeguards where required
Necessity is often the most misunderstood element of Article 6(1)(e). It carries a precise legal meaning that is considerably more demanding than everyday usage suggests.
A rational connection exists between processing and the public task
The objective cannot reasonably be achieved through less intrusive means
The processing scope is proportionate to the aim pursued
Compliance with Article 6(1)(e) does not create an exemption from Article 5. A common compliance failure is treating Article 6(1)(e) as sufficient in itself whilst neglecting Article 5 requirements. All nine principles apply in full.
Processing must have a valid legal basis, be conducted fairly, and individuals must be informed in a clear and accessible manner.
Data must be collected for specified, explicit, and legitimate purposes. Only data that is adequate, relevant, and limited to what is necessary may be processed.
Data must be accurate and kept up to date. It must not be retained in identifiable form for longer than necessary for the public task.
Appropriate technical and organisational security measures must be in place. Controllers must be able to demonstrate compliance with all principles.
Individuals must be able to understand why their data is processed, which legal authority authorises processing, which public task is being performed, who receives the data, and what rights they hold.
Article 6(1)(e) as the lawful basis for processing
The specific statutory authority underpinning the task
Relevant legislative references enabling the processing
Rights remain applicable unless restricted by law. Public authorities often underestimate the scope of rights that continue to apply when relying on Article 6(1)(e).
Individuals retain the right to access their data (Article 15) and to have inaccurate data corrected (Article 16).
The right to restrict processing (Article 18) applies in defined circumstances, including where accuracy is contested.
Controllers must generally stop processing unless they demonstrate compelling legitimate grounds overriding the individual's interests, rights and freedoms — or processing is for legal claims.
Individuals retain the right to lodge complaints with the relevant supervisory authority at any time.
Article 6(1)(e) alone never authorises special category data processing. A separate Article 9 condition is always required. Controllers must identify both bases before any sensitive data is processed.
Substantial public interest
Health and social care
Public health
Research and statistics
Criminal offence data requires Article 10 compliance in addition to Article 6(1)(e). Examples include police vetting, regulatory enforcement databases, and safeguarding checks. Article 6(1)(e) remains necessary but is not sufficient.
Public authorities relying on Article 6(1)(e) must also evaluate Article 22 obligations, applicable Member State legislation, and due process safeguards whenever automated processing is used to make decisions with significant effects on individuals.
Determine whether the system makes solely automated decisions producing legal or similarly significant effects.
Evaluate whether an Article 22 exception applies — including where authorised by Union or Member State law with suitable safeguards.
Ensure human review, the right to contest decisions, and meaningful explanation are built into the process.
Examples requiring Article 22 analysis: Welfare eligibility systems · Tax fraud detection algorithms · Automated licensing decisions · Benefits assessment tools.
Article 6(1)(e) often supports national statistics, public policy research, and official government research programmes. However, additional safeguards are required.
Article 89 — Safeguards for research, statistics, and archiving
Article 5(1)(b) — Compatible purposes principle
Article 9 — Where special category data is involved
Article 6(1)(e) does not authorise international transfers. Separate compliance with Chapter V is always required.
Controllers must assess:
Article 6(1)(e) compliance requires simultaneous engagement with a wide range of GDPR provisions. The following reference map identifies every intersecting article that advanced practitioners must consider.

Controls 1–7 address the foundational legal, governance, and data-management requirements for Article 6(1)(e) compliance.
Maintain a documented inventory linking every processing activity to specific statutory powers, delegated authority, or public-interest mandates.
Record the exact Article 6 basis for every processing activity and document why Article 6(1)(e) is more appropriate than alternative legal bases.
Require documented analysis showing why each processing activity is necessary rather than merely beneficial.
Evaluate whether less intrusive alternatives exist and require justification for rejecting those alternatives.
Maintain controlled purpose statements linked to statutory objectives and prevent unauthorised purpose expansion.
Configure systems to collect only fields demonstrably required for the public task.
Implement automated retention schedules aligned with legal mandates and enforce defensible disposal procedures.
Controls 8–14 address change management, transparency, rights workflows, and specialist data governance requirements.
Require legal review whenever processing scope changes. Assess whether the original public-task mandate still applies to the modified activity.
Maintain comprehensive Article 30 records integrated with operational systems to ensure accuracy and completeness.
Ensure privacy notices accurately identify statutory authority, public task, purposes, recipients, retention periods, and rights.
Implement case-management systems capable of handling access, objection, rectification, restriction, and complaint requests within statutory timeframes.
Establish formal procedures for evaluating objections and documenting override justifications with compelling legitimate grounds.
Require validation of both Article 6 and Article 9 conditions before processing sensitive data. No exceptions.
Implement enhanced authorisation, logging, segregation, and legal review controls for all Article 10 processing activities.
Controls 15–20 address impact assessment, privacy engineering, access control, audit, third-party governance, and continuous assurance.
Conduct recurring legal reviews, compliance audits, control testing, DPIA reassessments, legislative monitoring, and supervisory-guidance reviews to ensure processing remains necessary, proportionate, and legally authorised.
Ensure processors and delegated service providers operate strictly within the controller's public-task mandate. Verify contractual and operational compliance.
Log collection, access, modification, disclosure, export, and deletion events. Monitor continuously for unauthorised use.
Restrict access according to operational necessity and statutory responsibilities. Continuously review privilege allocations.
Embed minimisation, pseudonymisation, access control, and segregation requirements into system design from the outset.
Trigger Data Protection Impact Assessments for high-risk processing involving public-interest functions, as required by Article 35.
The most sophisticated understanding of Article 6(1)(e) is that it functions as a nexus between administrative law, constitutional principles, fundamental rights protection, sector-specific legislation, and data protection law.
Mature Article 6(1)(e) compliance requires a layered legal, organisational, and technical control framework in which the following operate together — never as isolated activities:
GDPR Article 6(1)(e): A Constitutional Gateway