Lawful basis for processing data

The General Data Protection Regulation (GDPR) 2018 requires the Trust to have a legal basis under Article 6 (and in the case of special category data Article 9) of the GDPR for the processing of personal data. In the main, the following legal bases apply to the Trust’s processing of personal data:

Special category personal data

Article 9(2)(b) – “processing is necessary for the purposes of carrying out the obligations and exercising specific rights of the controller or of the data subject in the field of employment and social security and social protection law

Article 9(2)(c) “processing is necessary to protect the vital interests of the data subject or of another natural person  where the data subject is physically or legally incapable of giving consent”

Article 9(2)(f) – “processing is necessary for the establishment, exercise or defence of legal claims

Article 9(2)(g) – “processing is necessary for reasons of substantial public interest

Article 9(2)(h) – “processing is necessary for the purposes of preventive or occupational medicine, for the assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment or the management of health or social care systems and services”

Personal data

Article 6(1)(e) – “processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller”

Article 6(1)(b) – “processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract

Article 6(1)(d) – “ processing is necessary in order to protect the vital interests of the data subject or of another natural person” Article 6 (1) (f) – “processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party”  – this basis might be applicable for example in our use of CCTV (see further below) or in the way we process data for car parking management.

Translate