Legitimate Interest
Legitimate interest is one of the lawful bases an organisation can rely on to process personal data under data protection law, used when the organisation (or a third party) has a genuine, justifiable reason to use the data. Unlike relying on consent, it does not require the individual to actively agree, but the organisation must weigh its own interests against the rights and expectations of the people whose data it uses. It is not a default or a way to avoid other rules; it only applies where the individual's interests do not override the organisation's reason for processing.
Under the UK GDPR, legitimate interests is one of the lawful bases for processing personal data, allowing a controller to process where processing is necessary for the purposes of legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. Reliance on this basis generally involves a three-part assessment (a purpose test, a necessity test, and a balancing test) documented in a legitimate interests assessment. A material limitation applies: under the EU GDPR (Article 6(1)(f)), this basis does not apply to processing carried out by public authorities in the performance of their tasks, so public-sector bodies generally cannot rely on it for such processing. Practitioners should note that lawful-basis provisions differ between jurisdictions—the EU GDPR sets out six lawful bases in Article 6, whereas the UK framework was amended in 2025 to introduce an additional 'recognised legitimate interest' basis that does not exist in the EU GDPR—and that the count and detail of lawful bases should therefore be verified against the applicable current text. This entry does not address related-but-distinct bases such as consent, contract, or legal obligation, nor sector-specific rules (for example under ePrivacy/cookie regimes), and application to any particular processing activity requires case-specific professional judgement.
Why it matters
Legitimate interest is one of the most flexible lawful bases under data protection law, but that flexibility is also what makes it a frequent source of compliance risk. Because it does not require the individual to actively agree in the way consent does, organisations sometimes treat it as a convenient default for processing that would otherwise demand explicit permission. That approach misreads the basis: it is only available where the organisation's genuine reason for processing is not overridden by the interests, rights, and freedoms of the people whose data is used. Choosing this basis therefore shifts the burden onto the organisation to justify and document its reasoning, rather than removing an obligation.
The stakes are heightened by material limitations that are easy to overlook. Under the EU GDPR, the legitimate-interest basis does not apply to processing carried out by public authorities in the performance of their tasks, so public-sector bodies generally cannot rely on it for such processing and must look to another basis. Getting the lawful basis wrong is not a technicality: it can render an entire processing activity unlawful, undermine the transparency information given to individuals, and complicate an organisation's ability to respond to objections and other data subject rights.
Jurisdictional divergence adds a further layer of care. The EU GDPR sets out six lawful bases in Article 6, while the UK framework was amended in 2025 to introduce an additional 'recognised legitimate interest' basis that does not exist in the EU GDPR. Organisations operating across both regimes cannot assume that a lawful-basis analysis valid in one jurisdiction transfers cleanly to the other, and the count and detail of available bases should always be verified against the applicable current text.
Who it's relevant to
Inside Legitimate Interest
Common questions
Answers to the questions practitioners most commonly ask about Legitimate Interest.

