DPDPA is now in force in India. Run a free privacy scan on your site. Scan now

Rights & evidence

What is Legitimate Interest?

Legitimate interest is a lawful basis for processing personal data under Article 6(1)(f) of the GDPR and UK GDPR. It allows an organisation to process personal data when the processing is necessary for a legitimate interest pursued by the organisation or a third party, provided that the individual's interests, rights, and freedoms do not override that interest.

Unlike consent, legitimate interest does not require the individual to actively agree to the processing. However, an organisation must be able to justify why the processing is lawful, necessary, and proportionate.

A legitimate interest assessment (LIA) is commonly used to document this analysis.

Important: Legitimate interest is not a blanket exemption from consent requirements. In particular, using legitimate interest does not automatically permit non-essential cookies, advertising trackers, or other technologies where applicable ePrivacy rules require consent.

Legitimate Interest in simple terms

Legitimate interest means an organisation has a genuine and lawful reason to use personal data, the processing is necessary to achieve that purpose, and the individual's privacy interests do not override the organisation's interest.

For example, an organisation might have a legitimate interest in:

  • Preventing fraud
  • Protecting network and information security
  • Detecting abuse
  • Maintaining an existing customer relationship
  • Certain forms of direct marketing
  • Recovering debts
  • Protecting legal claims
  • Improving internal business operations
  • Preventing misuse of services

Whether legitimate interest applies depends on the specific circumstances.

The fact that an activity is commercially useful does not automatically make it a legitimate interest.

Is Legitimate Interest a lawful basis under GDPR?

Yes.

Article 6(1)(f) of the GDPR recognises legitimate interests as one of the lawful bases for processing personal data.

It applies when:

  • The organisation or a third party has a legitimate interest.
  • Processing the personal data is necessary for that interest.
  • The individual's interests, rights, or freedoms do not override the legitimate interest.

These conditions are cumulative. All three need to be satisfied.

The three-part Legitimate Interest Test

The core of legitimate interest is a three-part assessment.

1

Purpose test

First, identify the legitimate interest.

Ask:

  • What are we trying to achieve?
  • Who benefits from the processing?
  • Is the interest lawful?
  • Is the interest clearly defined?
  • Is there a genuine and present interest?

Possible interests can include commercial, individual, operational, security, or broader societal interests.

The interest should be clearly articulated rather than described in vague terms such as “business purposes.”

2

Necessity test

Next, determine whether processing personal data is actually necessary to achieve that interest.

Ask:

  • Does the proposed processing help achieve the identified objective?
  • Is the processing reasonably necessary?
  • Could the same objective be achieved another way?
  • Is there a less intrusive method?

If an equally effective and less privacy-intrusive method is reasonably available, legitimate interest may not be an appropriate basis.

The necessity test therefore does not simply mean that processing is convenient.

3

Balancing test

Finally, balance the organisation's legitimate interest against the individual's interests, rights, and freedoms.

Consider:

  • What personal data is being processed?
  • How sensitive is it?
  • What is the likely impact on individuals?
  • Would individuals reasonably expect the processing?
  • How strong is the organisation's interest?
  • Is the processing intrusive?
  • Are children or vulnerable individuals involved?
  • What safeguards can reduce the impact?

If the individual's interests, rights, or freedoms override the organisation's legitimate interest, Article 6(1)(f) cannot be relied upon for that processing.

What is a Legitimate Interest Assessment (LIA)?

A Legitimate Interest Assessment (LIA) is a documented assessment used to determine whether legitimate interest is an appropriate lawful basis for a particular processing activity.

A good LIA should normally document:

  • The purpose of the processing
  • The legitimate interest being pursued
  • The parties that benefit
  • The personal data involved
  • Why processing is necessary
  • Alternative methods considered
  • The potential impact on individuals
  • Individuals' reasonable expectations
  • Relevant safeguards
  • The balancing conclusion
  • Any conditions or limitations on the processing

The assessment should be performed before relying on legitimate interest for the processing.

The ICO describes an LIA as a light-touch risk assessment based on the specific circumstances of the proposed processing and recommends documenting the outcome.

Can Legitimate Interest replace Consent?

No, not generally.

Legitimate interest can sometimes be an alternative lawful basis under GDPR for a particular processing activity, but it does not override other legal requirements.

This distinction is especially important for websites.

For example, an organisation might have a legitimate interest in maintaining website security. That does not automatically mean it can place every analytics or advertising cookie without consent.

Cookie and electronic-communications rules can impose additional requirements beyond the GDPR lawful basis analysis.

Therefore:

GDPR lawful basis ≠ automatic permission to place cookies or tracking technologies.

This is one of the most important distinctions for privacy teams to understand.

Legitimate Interest and Cookies

Legitimate interest should not be used as a blanket justification for non-essential cookies.

For example, a website cannot simply label an advertising tracker as “legitimate interest” and assume that the tracker can load before consent where applicable cookie/ePrivacy rules require prior consent.

A proper analysis should separately consider:

  • Whether the processing of personal data has a valid GDPR lawful basis.
  • Whether the technology used to collect or access information is subject to additional cookie/ePrivacy requirements.
  • Whether consent is required before the technology operates.
  • Whether the processing is compatible with the individual's expectations and rights.

This distinction prevents organisations from confusing GDPR lawful basis with cookie-storage/access requirements.

Legitimate Interest and Analytics

Analytics can involve several different processing activities.

An organisation should not automatically classify all analytics as legitimate interest.

Consider:

  • What information is collected?
  • Is the data aggregated or identifiable?
  • Are persistent identifiers used?
  • Is information shared with third parties?
  • Is cross-site tracking involved?
  • Is profiling performed?
  • What expectations does the user have?
  • Are cookies or similar technologies involved?
  • Is another less intrusive analytics method available?

A low-impact internal analytics activity may have a different legal analysis from behavioural tracking across websites and services.

The lawful basis should therefore be assessed based on the actual implementation.

Legitimate Interest and Fraud Prevention

Fraud prevention is a commonly considered legitimate interest.

An organisation may have a strong interest in detecting:

  • Account takeover
  • Payment fraud
  • Fake accounts
  • Credential abuse
  • Automated attacks
  • Suspicious transactions
  • Service misuse

However, fraud prevention is not automatically lawful simply because the organisation describes it as security-related.

The organisation should still assess necessity, proportionality, impact, reasonable expectations, and applicable safeguards.

Legitimate Interest and Direct Marketing

Direct marketing can sometimes rely on legitimate interest under GDPR/UK GDPR, but this requires a context-specific analysis and may be subject to additional electronic-marketing rules.

The ICO notes that legitimate interest can apply to direct marketing where applicable electronic-communications rules do not require consent, provided the processing is proportionate, has a minimal privacy impact, and is not unexpected or likely to cause unjustified objection.

For this reason, a company should not treat:

“We have a legitimate interest in marketing”

as sufficient justification by itself.

It should separately consider:

  • The nature of the relationship
  • Existing customer status
  • What individuals reasonably expect
  • The type of marketing
  • The communication channel
  • Applicable ePrivacy/direct-marketing rules
  • The individual's right to object

Legitimate Interest and Profiling

Profiling can sometimes be based on legitimate interest, but the analysis becomes more important as the impact on individuals increases.

Consider:

  • What information is used?
  • What characteristics are inferred?
  • Is the profiling used for advertising?
  • Does it affect access to products or services?
  • Is there a significant effect on individuals?
  • Would people reasonably expect the profiling?
  • Can they object?
  • What safeguards are available?

A legitimate interest assessment should reflect the actual consequences of the profiling rather than treating profiling as ordinary processing.

Legitimate Interest and Data Subject Rights

Individuals retain important rights even when processing is based on legitimate interest.

Under GDPR, an individual can object to processing based on Article 6(1)(e) or 6(1)(f) on grounds relating to their particular situation.

If the objection is to direct marketing, the right to object is stronger: the personal data must no longer be processed for direct marketing purposes.

This means organisations relying on legitimate interest should have processes for:

  • Receiving objections
  • Assessing objections
  • Recording objections
  • Updating processing preferences
  • Stopping processing where required
  • Documenting any lawful reason for continuing processing where permitted

Legitimate Interest and Children

Children require particular care.

Under GDPR Article 6(1)(f), the rights and freedoms of the data subject, particularly where the person is a child, are expressly relevant to the legitimate-interest analysis.

Processing involving children may therefore require stronger safeguards and a more cautious balancing assessment.

An organisation should not assume that a legitimate interest that is acceptable for adults automatically remains appropriate for children.

Legitimate Interest and Sensitive Data

Legitimate interest under Article 6(1)(f) is not by itself sufficient to process special category data under GDPR.

Where special category data is involved, an organisation generally needs:

  • A lawful basis under Article 6; and
  • An applicable condition under Article 9.

The analysis may therefore require additional legal safeguards.

Similarly, criminal-offence data has additional requirements.

Legitimate Interest vs Contract

Legitimate interest and contractual necessity are separate lawful bases.

Contractual necessity

Processing is necessary to perform a contract with the individual or take steps at their request before entering into a contract.

Legitimate interest

Processing is necessary for a legitimate interest, subject to the three-part balancing test.

An organisation should not use contract as a basis merely because the processing is useful to its business.

Likewise, legitimate interest should not be used when contractual necessity is the more appropriate basis.

The lawful basis should reflect the actual purpose and necessity of the processing.

Legitimate Interest vs Legal Obligation

A legal obligation applies where processing is necessary to comply with a legal requirement imposed on the organisation.

Legitimate interest is different.

For example:

Legal obligation:

processing required by applicable law.

Legitimate interest:

processing necessary for a legitimate business, security, operational, or third-party interest that survives the balancing test.

Choosing the correct lawful basis matters because the associated rights and compliance requirements can differ.

Legitimate Interest and Privacy Notices

When relying on legitimate interest, organisations should explain the relevant legitimate interests in their privacy information.

The privacy notice should not simply state:

“We process your information based on legitimate interest.”

It should provide meaningful information about the legitimate interest being pursued.

This helps individuals understand:

  • Why their data is being processed
  • What the organisation is trying to achieve
  • How the processing affects them
  • What rights they have
  • How they can object

The EDPB's guidance states that controllers relying on Article 6(1)(f) should inform data subjects of the legitimate interests pursued.

Legitimate Interest under the DPDPA

India's Digital Personal Data Protection Act, 2023 (DPDP Act) uses a different structure from GDPR.

The Act provides that personal data may be processed for a lawful purpose based on:

  • Consent; or
  • Certain legitimate uses.

Section 7 defines these “certain legitimate uses” and lists specific circumstances in which a Data Fiduciary may process personal data.

This is an important distinction.

The GDPR concept of legitimate interest under Article 6(1)(f) should not simply be copied into an Indian DPDPA compliance framework.

Instead:

GDPR:

legitimate interest is a specific lawful basis under Article 6(1)(f).

DPDPA:

“certain legitimate uses” are specific statutory grounds under Section 7.

ConsentX should preserve this distinction throughout its India-focused content.

Examples of Certain Legitimate Uses under the DPDPA

Section 7 includes specific circumstances such as processing personal data for a specified purpose for which the Data Principal voluntarily provided the data and has not indicated non-consent.

The Act also provides other categories of legitimate use involving areas such as:

  • State benefits and services
  • Functions of the State
  • Legal obligations and disclosures
  • Medical emergencies
  • Certain employment-related purposes
  • Publicly available personal data in specified circumstances

The precise conditions depend on the applicable provision and circumstances.

Therefore, ConsentX should avoid describing the DPDPA as simply having a GDPR-style “legitimate interest” lawful basis.

This distinction is especially important for organisations operating in both Europe and India.

Legitimate Interest and Consent Management Platforms

A Consent Management Platform (CMP) primarily manages consent and preference signals.

It does not automatically determine whether an organisation can rely on legitimate interest.

A CMP may help with:

  • Recording consent
  • Recording refusals
  • Managing preference changes
  • Enforcing consent choices
  • Presenting privacy choices
  • Supporting audit evidence

But an organisation should separately document its lawful-basis analysis.

For legitimate interest, this may include maintaining an LIA alongside the relevant privacy and processing records.

Should Legitimate Interest be recorded?

Yes.

A documented LIA helps demonstrate why legitimate interest was selected and how the organisation assessed the processing.

The record should not be a generic template copied across unrelated processing activities.

A useful LIA should be specific to:

  • The processing purpose
  • The data involved
  • The people affected
  • The technology used
  • The expected impact
  • The safeguards applied
  • The conclusion

The ICO recommends documenting the outcome of the three-part assessment and doing so before processing begins.

Legitimate Interest Assessment Checklist

Before relying on legitimate interest, ask:

Purpose

  • What legitimate interest are we pursuing?
  • Is it lawful and clearly defined?
  • Who benefits?

Necessity

  • Is processing personal data actually necessary?
  • Does it materially contribute to the purpose?
  • Is there a less intrusive alternative?

Balancing

  • What impact will processing have?
  • What would individuals reasonably expect?
  • Is the data sensitive or private?
  • Could the processing cause harm?
  • Are children involved?
  • Do individual rights override the organisation's interest?

Safeguards

  • Can we minimise the data?
  • Can we reduce retention?
  • Can we pseudonymise information?
  • Can we restrict access?
  • Can we reduce the scope of profiling?
  • Can we give individuals meaningful controls?

Accountability

  • Has the LIA been documented?
  • Has the privacy notice been updated?
  • Is the legitimate interest clearly described?
  • Is there a process for handling objections?
  • Can the organisation demonstrate why the lawful basis was selected?

Common Legitimate Interest mistakes

Mistake 1

Treating legitimate interest as “no consent required”

Legitimate interest can be a lawful basis under GDPR, but additional laws may still require consent for particular technologies or communications.

Mistake 2

Skipping the LIA

Simply writing “legitimate interest” in a privacy policy is not the same as performing the three-part test.

Mistake 3

Using a generic LIA

A legitimate-interest assessment should reflect the actual processing and context.

Mistake 4

Ignoring reasonable expectations

Whether people would reasonably expect the processing is an important part of the balancing exercise.

Mistake 5

Ignoring less intrusive alternatives

If the same objective can reasonably be achieved with less personal-data processing, necessity may fail.

Mistake 6

Treating commercial benefit as sufficient

A business benefit does not automatically override an individual's rights and freedoms.

Mistake 7

Using legitimate interest to bypass cookie consent

A GDPR lawful basis does not automatically override applicable cookie or ePrivacy requirements.

Mistake 8

Treating GDPR legitimate interest and DPDPA legitimate uses as identical

The two frameworks use different legal structures and should be analysed separately.

Legitimate Interest and ConsentX

ConsentX helps organisations manage consent, privacy preferences, consent records, and audit evidence across privacy frameworks.

For legitimate-interest workflows, ConsentX can complement consent management by helping organisations distinguish between:

  • Processing that requires consent
  • Processing based on another lawful basis
  • Consent preferences
  • Objections and preference changes
  • Consent evidence
  • Privacy compliance documentation

This distinction is particularly important for websites using analytics, advertising, personalisation, and other third-party technologies.

ConsentX should not be positioned as automatically deciding that a processing activity qualifies for legitimate interest. The organisation remains responsible for determining and documenting its lawful basis.

Legitimate Interest: Key Takeaways

  • Legitimate interest is a GDPR and UK GDPR lawful basis under Article 6(1)(f).
  • It requires a three-part assessment: purpose, necessity, and balancing.
  • A Legitimate Interest Assessment (LIA) should normally be documented before processing begins.
  • Legitimate interest does not require affirmative consent, but it does require accountability and protection of individual rights.
  • Individuals have a right to object to processing based on legitimate interest in applicable circumstances.
  • Direct marketing requires additional consideration of applicable electronic-marketing rules.
  • Legitimate interest does not automatically authorise non-essential cookies or tracking technologies.
  • Special category data and criminal-offence data have additional requirements.
  • Under India's DPDPA, certain legitimate uses under Section 7 are distinct from GDPR Article 6(1)(f).
  • A CMP manages consent and preferences; it does not by itself establish that legitimate interest applies.
  • Strong privacy programs document the lawful basis for each processing activity rather than treating one legal basis as suitable for everything.

Know which processing needs consent, and prove it

ConsentX helps organisations manage consent, privacy preferences, consent records, and audit evidence across privacy frameworks, so teams can distinguish processing that requires consent from processing based on another lawful basis. The organisation remains responsible for determining and documenting its lawful basis.

Frequently asked questions