A lawful basis is the legal justification that allows an organization to process personal data under GDPR.
The important operational point is not just picking a basis once in a policy, but making sure the chosen basis actually matches the real workflow, data use, retention logic, and user experience in production.