DPDPA is now in force in India. Run a free privacy scan on your site. Scan now

Rights & evidence

What is Legitimate Interest?

In short
Legitimate interest is a lawful basis under the GDPR for processing personal data without consent when the organisation's interest is not overridden by the individual's rights, established through a balancing test.

Legitimate interest is sometimes used for analytics or fraud prevention, but it does not apply to setting non-essential cookies, which still need consent, and it is not a basis recognised the same way under India's DPDPA, which is consent-and-legitimate-uses based. Document a balancing test before relying on it, and never use it to bypass cookie consent.

Put Legitimate Interest into practice

ConsentX turns these requirements into enforced, provable consent. Free to start.