Legal Basis Register

Document the Lawful Basis for Every Processing Activity

Maintain a defensible lawful basis for each activity — per jurisdiction, with multiple bases where one isn't enough — instead of a single free-text cell that can't be reconstructed under audit.
For
DPO
ISO
GDPR Art. 6(1)
GDPR Art. 30(1)(c)
GDPR Art. 9
The challenge

A basis you can't reconstruct won't survive an audit

Under GDPR Art. 6(1), every processing activity needs a lawful basis — and Art. 30(1)(c) requires you to record it. In practice, that basis lives in someone's head, a stale spreadsheet cell, or a free-text note that doesn't hold up when a supervisory authority asks.

The problem compounds across jurisdictions. The same activity may rest on consent in one country, legitimate interests in another, and a different statutory basis where another regulation applies. A single dropdown can't capture that, and manual mapping drifts the moment the processing changes.

When an inspection comes, the question isn't whether you have a basis — it's whether you can show, per activity and per jurisdiction, which one and why.

What you can do

What you can do with the Legal Basis Register

  • Define the six standardized GDPR bases — consent, contract, legal obligation, vital interests, public task, legitimate interests — plus regulation-specific bases.
  • Map each basis to applicable laws by jurisdiction, so the right basis attaches to the right region.
  • Attach multiple bases to one activity and track which combinations apply across international transfers.
  • Document each basis with a description and references to your supporting evidence.
  • Filter out non-applicable bases on transfers so selections stay accurate as activities change.
  • Import and export basis definitions across companies to keep multi-entity records consistent.
Business outcomes

What it delivers to your program

  • Answer the regulator per activity — show the lawful basis and its jurisdiction without reconstructing it under deadline.
  • Reduce basis errors — non-applicable filtering on transfers keeps selections accurate as processing changes.
  • Stay defensible across borders — multiple bases per activity capture cross-jurisdiction reality instead of flattening it.
  • Keep entities aligned — import and export carry consistent definitions across companies, so records don't fork.
Built for compliance

Built for compliance

DPMS helps you evidence the specific obligations that govern lawful basis — mapped to the article and control, never to "the GDPR."

What DPMS doesMaps toHow
Records the lawful basis per processing activityGDPR Art. 6(1)Standardized bases selectable and documented per activity
Captures legal basis as a record elementGDPR Art. 30(1)(c)Basis stored against each activity with descriptions and evidence references
Documents bases for special-category dataGDPR Art. 9A dedicated register branch for special-category conditions, including explicit consent
See how this maps to your obligations — book a 30-minute demo focused on the Legal Basis Register.
Book a demo
Why Priverion

Why Priverion

The register isn't a standalone list. It lives inside one unified privacy and InfoSec platform, so the basis you document flows to your processing records (ROPA) without re-keying. Unlike general-purpose GRC tools that offer a single basis field, Priverion lets you attach multiple bases per activity and map them to applicable laws by jurisdiction — the structure regulated, multi-entity organizations actually need. That integration across your records is the part that's hard to copy.

FAQ

Questions DPOs ask before a demo

Can one activity have more than one legal basis?
Yes. You attach multiple bases to a single activity and track which combinations apply, including across international transfers — not a single forced choice.
Does it handle regulations beyond GDPR?
You define the six standardized GDPR bases plus regulation-specific bases, and map them to applicable laws by jurisdiction.
How does it reduce manual errors on transfers?
The register filters out non-applicable bases on international transfers, so you select from what genuinely applies rather than the full list.
Can we share definitions across our entities?
Yes. You import and export legal-basis definitions across companies to keep documentation consistent across multiple entities.

Ready to document a defensible basis for every activity?

Book a 30-minute demo focused on the Legal Basis Register and see it handle multiple bases and per-jurisdiction mapping on your own processing.
Book a demo