Legal basis follows purpose

Article 6 of the GDPR sets out the lawful bases for processing personal data. For product teams, the most useful habit is to map each processing purpose separately instead of choosing one basis for the whole company.

A SaaS product may process the same user's data for account creation, service delivery, billing, fraud prevention, support, analytics, marketing, and legal recordkeeping. Those purposes can have different legal bases, different user choices, and different retention rules.

Contract is not a shortcut for everything

Contract may fit processing that is objectively necessary to provide the service a user requested, such as creating an account, authenticating the user, managing a workspace, delivering core product features, or taking payment for a subscription.

It is weaker for activities that are useful to the business but not necessary for the service requested by the user. Optional analytics, advertising pixels, newsletter personalization, and product research should be assessed separately rather than bundled into contract language.

Consent needs a real choice

Consent is most credible when the user has a genuine, specific, informed, and unambiguous choice, and when withdrawal is as easy to understand as giving consent. EDPB guidance on consent emphasizes that consent should not be treated as valid where there is no real freedom to refuse.

For SaaS teams, consent often appears around optional marketing emails, certain cookies or tracking technologies, and optional features that are not needed for the basic service. If the product will keep working without the processing, consent may be easier to explain and operationalize.

Legitimate interests need context

Legitimate interests can be relevant for security logging, abuse prevention, fraud detection, limited service improvement, and some business communications. The privacy notice should still identify the interest pursued when processing relies on Article 6(1)(f).

The internal work should go further than the notice. Teams should document the interest, the necessity of the processing, and the balancing of that interest against the person's rights and expectations. A short public sentence is easier to trust when it is backed by a real assessment.

Legal obligation is narrow but important

Legal obligation can fit tax records, accounting records, compliance logs, and other retention that the company is required to maintain under applicable law. It should be tied to the specific obligation rather than used as a broad fallback.

This matters for deletion requests. If some records must be retained despite account deletion, the product and support teams need to know which records, why they are kept, and when they can finally be erased or anonymized.