Privacy

What Is Legitimate Interest Under GDPR

Learn what legitimate interest means under the GDPR, how to conduct an LIA (Legitimate Interests Assessment), and when it is the right lawful basis to use.

Editorial Team ·
8 min read beginner

Introduction

Under the General Data Protection Regulation (GDPR), you cannot simply collect and process personal data because you want to. You must have a legally valid reason, known as a “lawful basis.” The GDPR outlines six of these bases. The most famous is Consent (the user checks a box). Another common one is Contract (you need their address to ship the product they bought). But what happens when you need to process data for fraud prevention, network security, or internal analytics? Asking for consent is impractical, and you don’t have a contract. That’s where Legitimate Interest — the most flexible, yet most misunderstood, lawful basis under the GDPR — comes into play.

Legitimate interest is the workhorse of the GDPR. It acknowledges that businesses have valid, everyday reasons to process data that don’t neatly fit into contracts or consent forms. However, because of this flexibility, it is frequently abused by organizations attempting to bypass strict consent rules, particularly in the marketing and AdTech sectors. Regulatory authorities are acutely aware of this abuse and aggressively penalize companies that claim legitimate interest without doing the rigorous legal homework required to justify it. Understanding how to properly apply legitimate interest is essential for maintaining business operations without crossing the line into non-compliance.

What Is Legitimate Interest?

Legitimate interest is established in Article 6(1)(f) of the GDPR. It states that processing personal data is lawful if it is “necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject.”

Unlike consent, which puts the decision in the hands of the user, legitimate interest shifts the burden of responsibility entirely onto the Data Controller. The organization itself decides if the processing is justified. However, this is not a blank check. To rely on this basis, you must be able to prove that your interest is valid, that you strictly need the data to achieve your goal, and crucially, that your business goal does not unfairly infringe upon the privacy rights of the individual.

If a user would be surprised to learn you are processing their data, or if they would likely object to it, legitimate interest is almost certainly the wrong lawful basis. It works best for processing activities that are expected, low-risk, and have a minimal privacy impact.

How Legitimate Interest Works: The LIA

You cannot simply declare “we have a legitimate interest” and start processing data. The GDPR requires accountability. To legally rely on this basis, you must conduct and document a Legitimate Interests Assessment (LIA) before any data processing begins. An LIA is a formal three-part test. If you fail any of the three parts, you cannot use legitimate interest.

  1. The Purpose Test (Identify the interest): You must clearly articulate what your legitimate interest is. Is it a commercial interest (e.g., direct marketing to existing B2B clients)? Is it a security interest (e.g., analyzing server logs to prevent DDoS attacks)? Is it a societal benefit? The interest must be lawful, clearly defined, and real, not speculative.
  2. The Necessity Test (Is processing necessary?): You must prove that processing the personal data is the only reasonable way to achieve your purpose. If you can achieve the exact same business goal without using personal data (for example, by using anonymized aggregated data instead), then the processing is not “necessary,” and the test fails. This ties directly into the principle of data minimization.
  3. The Balancing Test (Weighing rights vs interests): This is the hardest part. You must weigh your company’s interests against the individual’s rights and freedoms. You must consider the nature of the data (is it sensitive?), the reasonable expectations of the individual (would they expect this processing?), and the potential impact (could it cause harm, financial loss, or distress?). If the individual’s rights outweigh your business interests, the test fails.

If the LIA passes, you may proceed. However, you must include your reliance on legitimate interest in your privacy policy, explicitly telling users what your legitimate interests are, and informing them of their absolute right to object.

Watch this explanation of how to properly apply and document legitimate interest.

Organizations often struggle to choose between Legitimate Interest and Consent. Choosing the wrong basis can invalidate your entire processing activity.

FeatureLegitimate InterestConsent
User ControlOrganization decides, user can object later.User decides upfront (opt-in).
Documentation BurdenHigh (Requires a documented LIA).Moderate (Must keep records of consent).
Best Used ForExpected, low-risk, necessary operations (e.g., security, internal analytics).Unexpected, high-risk, intrusive processing (e.g., tracking cookies, data selling).
User RightsRight to Object (Organization must stop unless compelling reasons exist).Right to Withdraw (Organization must stop immediately).
ValidityRemains valid as long as the balancing test holds true.Invalidates immediately if the user withdraws it.
Comparing Legitimate Interest and Consent as lawful bases for data processing.

As a rule of thumb, if the processing is highly intrusive, involves sensitive data, or involves tracking users across different websites (like third-party advertising cookies), the balancing test will fail, meaning you cannot use legitimate interest and must rely on explicit consent.

Real-World Use Cases

When applied correctly, legitimate interest is highly practical. It powers many of the background processes that keep the digital economy secure and functional.

Network and Information Security: A company monitors its employee network traffic and server access logs. The data includes IP addresses, MAC addresses, and usernames. The purpose is to detect unauthorized access, malware infections, and data exfiltration. Asking hackers for consent to log their IP addresses is absurd. The company conducts an LIA, determining that their legitimate interest in securing their network heavily outweighs the minimal privacy impact of logging employee IP addresses for security purposes. Legitimate interest is the perfect lawful basis here.

Fraud Prevention in E-commerce: A payment processor analyzes the location data, device fingerprints, and purchase history of users during checkout to calculate a real-time risk score. The goal is to block fraudulent credit card transactions. This processing is strictly necessary to protect both the merchant from chargebacks and the consumer from identity theft. An LIA would easily conclude that the interest in preventing financial crime overrides the privacy impact of the background analysis.

B2B Direct Marketing (with caveats): A software company selling enterprise cybersecurity tools finds the professional email addresses of Chief Information Security Officers (CISOs) on LinkedIn. They send a targeted, relevant email offering their software. In many jurisdictions, B2B marketing to corporate email addresses can be justified under legitimate interest, provided the product is highly relevant to the recipient’s job role and a clear “unsubscribe” link is provided (the right to object). However, doing this for B2C (consumer) marketing usually violates separate ePrivacy laws, which require strict opt-in consent.

Common Mistakes to Avoid

The single biggest mistake is using legitimate interest as a fallback for invalid consent. If you build a marketing campaign and ask users for consent, but the users say “no,” you cannot magically pivot and say, “Well, we’ll just process your data under legitimate interest instead.” Regulators view this as fundamentally unfair and deceptive. You must choose your lawful basis before you start processing, and you generally cannot swap bases mid-stream if the first one fails.

Another major compliance failure is claiming legitimate interest without documenting the LIA. Data protection authorities operate on the principle of accountability: “If it isn’t documented, it didn’t happen.” If a regulator audits your company and asks why you are processing user data without consent, and you reply “legitimate interest” but cannot produce a written Legitimate Interests Assessment, you will be fined for processing data without a lawful basis.

Finally, organizations frequently fail to respect the Right to Object. Article 21 of the GDPR states that if you rely on legitimate interest, the user can object at any time. When they do, you must halt processing immediately unless you can demonstrate “compelling legitimate grounds.” For direct marketing, this right is absolute — there are no compelling grounds that allow you to keep marketing to someone who has objected. Organizations often fail to build the technical mechanisms required to process these objections efficiently.

Getting Started

To utilize legitimate interest safely, you must institutionalize the LIA process. Create a standardized Legitimate Interests Assessment template for your organization (the UK’s ICO provides excellent free templates). Mandate that no team can begin a new data processing activity relying on legitimate interest until the Data Protection Officer (DPO) or legal counsel has reviewed and signed off on the completed LIA.

Next, audit your existing privacy policy. Ensure that every processing activity relying on legitimate interest is explicitly listed, along with a plain-English explanation of exactly what that interest is. Verify that the privacy policy prominently informs users of their right to object to this processing.

Finally, work with your engineering teams to build automated mechanisms to handle objections. If a user clicks an “unsubscribe” link or submits a privacy request objecting to analytics tracking, your systems must instantly sever their data from those processing pipelines. Relying on manual database edits by developers is unsustainable and prone to human error, exposing the company to significant compliance risk.

FAQ

Common questions — answered in plain English.

What is legitimate interest under the GDPR?
Legitimate interest is one of the six lawful bases for processing personal data under the GDPR. It allows an organization to use personal data without explicit consent, provided the organization's interests are not overridden by the fundamental rights and freedoms of the individual.
Is legitimate interest a loophole to avoid getting consent?
No. Legitimate interest is not a get-out-of-jail-free card. It requires a rigorous, documented balancing test called a Legitimate Interests Assessment (LIA). If the processing poses a high risk to the individual, or if they would not reasonably expect the processing, legitimate interest fails and you must seek consent.
What is a Legitimate Interests Assessment (LIA)?
An LIA is a mandatory three-part test used to justify legitimate interest. You must identify a legitimate interest (Purpose Test), show that processing the data is necessary to achieve it (Necessity Test), and balance it against the individual's rights and freedoms (Balancing Test).
Can we use legitimate interest for direct email marketing?
It depends, but generally no for B2C cold outreach. Electronic marketing (like email) is governed by the ePrivacy Directive, which usually requires strict opt-in consent. Legitimate interest can sometimes be used for B2B marketing or for emailing existing customers about similar products (the 'soft opt-in').
Do users have the right to object to legitimate interest processing?
Yes, absolutely. The GDPR grants data subjects the absolute right to object to data processing based on legitimate interest. If they object, you must stop processing their data immediately unless you can demonstrate compelling, overriding legitimate grounds (which is very difficult).
Can public authorities use legitimate interest?
Generally, no. The GDPR explicitly states that public authorities cannot rely on legitimate interest for processing carried out in the performance of their official tasks. They must rely on other bases, such as 'public task' or 'legal obligation.'

References

  1. [1]
  2. [2]
  3. [3]
    Guide to the UK GDPR: Legitimate interestsInformation Commissioner's Office (ICO), 2021
  4. [4]
    GDPR Article 21: Right to objectIntersoft Consulting, 2016
  5. [5]