CIPP/E Study Guide
Ch 6.3 - Purpose limitation

Purpose limitation

Purpose limitation means data must be collected for specified, explicit and legitimate purposes and not further processed in a way incompatible with those purposes. Secondary (further) processing is only lawful if it is compatible with the original purpose - judged with a five-factor compatibility test. Statistical, public-interest, scientific and historical research purposes are treated as compatible (within legal limits). If processing is incompatible, the controller needs a separate legal basis (e.g. fresh consent).

Controllers must first identify the specified, explicit and legitimate purposes. Those purposes become the boundaries. Secondary processing is only lawful if compatible with the original purpose. If compatible, no separate legal basis is needed. If incompatible, the controller must inform the data subjects and either get separate consent or satisfy another lawful basis.

  • Any link between the original and new purposes
  • The context of collection and the reasonable expectations of data subjects
  • The nature of the personal data
  • The consequences of further processing for data subjects
  • The existence of appropriate safeguards in both operations
Compatible vs incompatible further processing
Original purposeFurther useVerdict
Fitness app: personalised routinesFixing technical errors / improving the appCompatible - linked and reasonably expected
Medication-reminder appSharing data with a company that sells the medication (promotion)Incompatible - not linked to the reminder purpose
Health professional treats patientsSharing patient list with an insurer to sell insuranceIncompatible - separate legal basis needed
Compatible = no new basis

If further processing is compatible, you reuse the original legal basis - no separate legal ground is required. Only incompatible reuse triggers the need for fresh consent or another Article 6 basis.

Key terms - quick answers

What is “Purpose limitation”?
Collect data only for specified, explicit and legitimate purposes; don't reuse it for incompatible purposes.
What is “Compatible further processing”?
Secondary use that is consistent with the original purpose - no new legal basis needed.
What is “Compatibility test”?
Recital 50 factors used to decide whether a secondary purpose is compatible: link, context/expectations, nature of data, consequences, safeguards.