The principle of lawfulness in Article 5(1)(a) GDPR requires that processing be lawful. In conceptual terms, what does this principle most directly demand of a controller?
- AThat the controller keeps written records of processing activities and registers them with the supervisory authority before starting.
- BThat each processing operation rests on at least one valid lawful basis set out in Article 6, and a further condition under Article 9 where special category data is involved. Correct
- CThat the controller obtains the data subject's freely given consent before any personal data is processed.
- DThat the controller processes the data only in ways the data subject would reasonably expect given the context of collection.
Why A is wrong: Record-keeping under Article 30 is an accountability measure and prior registration was a feature of the old Directive that the GDPR largely abolished. Neither is what the lawfulness principle itself requires, so this confuses a separate obligation with lawful grounding.
Why B is correct: Lawfulness means processing must be grounded in a legal basis. Article 5(1)(a) is operationalised through Article 6, which lists the six bases, and Article 9 adds a condition for special category data, so identifying a valid basis is the direct demand of the principle.
Why C is wrong: Consent is only one of the six lawful bases in Article 6, and is often not the most appropriate. Treating lawfulness as a consent-only requirement is a common error, since contract, legal obligation, vital interests, public task and legitimate interests are equally valid bases.
Why D is wrong: Reasonable expectation relates more closely to the fairness and purpose limitation principles than to lawfulness. It is a relevant consideration, but the lawfulness limb specifically requires an identifiable legal basis rather than a mere alignment with expectations.