Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: Privacy Principles

Legitimate Interest

Also known as: Legitimate Interests, Legitimate Interests Basis, LI
Simply put

Legitimate interest is one of the lawful bases an organisation can rely on to process personal data under data protection law, used when the organisation (or a third party) has a genuine, justifiable reason to use the data. Unlike relying on consent, it does not require the individual to actively agree, but the organisation must weigh its own interests against the rights and expectations of the people whose data it uses. It is not a default or a way to avoid other rules; it only applies where the individual's interests do not override the organisation's reason for processing.

Formal definition

Under the UK GDPR, legitimate interests is one of the lawful bases for processing personal data, allowing a controller to process where processing is necessary for the purposes of legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject. Reliance on this basis generally involves a three-part assessment (a purpose test, a necessity test, and a balancing test) documented in a legitimate interests assessment. A material limitation applies: under the EU GDPR (Article 6(1)(f)), this basis does not apply to processing carried out by public authorities in the performance of their tasks, so public-sector bodies generally cannot rely on it for such processing. Practitioners should note that lawful-basis provisions differ between jurisdictions—the EU GDPR sets out six lawful bases in Article 6, whereas the UK framework was amended in 2025 to introduce an additional 'recognised legitimate interest' basis that does not exist in the EU GDPR—and that the count and detail of lawful bases should therefore be verified against the applicable current text. This entry does not address related-but-distinct bases such as consent, contract, or legal obligation, nor sector-specific rules (for example under ePrivacy/cookie regimes), and application to any particular processing activity requires case-specific professional judgement.

Why it matters

Legitimate interest is one of the most flexible lawful bases under data protection law, but that flexibility is also what makes it a frequent source of compliance risk. Because it does not require the individual to actively agree in the way consent does, organisations sometimes treat it as a convenient default for processing that would otherwise demand explicit permission. That approach misreads the basis: it is only available where the organisation's genuine reason for processing is not overridden by the interests, rights, and freedoms of the people whose data is used. Choosing this basis therefore shifts the burden onto the organisation to justify and document its reasoning, rather than removing an obligation.

The stakes are heightened by material limitations that are easy to overlook. Under the EU GDPR, the legitimate-interest basis does not apply to processing carried out by public authorities in the performance of their tasks, so public-sector bodies generally cannot rely on it for such processing and must look to another basis. Getting the lawful basis wrong is not a technicality: it can render an entire processing activity unlawful, undermine the transparency information given to individuals, and complicate an organisation's ability to respond to objections and other data subject rights.

Jurisdictional divergence adds a further layer of care. The EU GDPR sets out six lawful bases in Article 6, while the UK framework was amended in 2025 to introduce an additional 'recognised legitimate interest' basis that does not exist in the EU GDPR. Organisations operating across both regimes cannot assume that a lawful-basis analysis valid in one jurisdiction transfers cleanly to the other, and the count and detail of available bases should always be verified against the applicable current text.

Who it's relevant to

Data protection officers and privacy teams
Those responsible for selecting and documenting lawful bases need to understand when legitimate interest is appropriate and how to carry out and record the purpose, necessity, and balancing tests. They must also confirm which lawful bases are available in the relevant jurisdiction, given the differences between the EU GDPR and the UK framework.
Public-sector bodies
Public authorities should be particularly cautious: under the EU GDPR, the legitimate-interest basis does not apply to processing carried out in the performance of their tasks, so they generally cannot rely on it for such processing and must identify an alternative basis.
Legal and compliance counsel
Advisers assessing processing activities need to keep legitimate interest distinct from consent, contract, and legal obligation, and to account for jurisdictional divergence—including the UK's 2025 introduction of a 'recognised legitimate interest' basis that has no EU GDPR equivalent. Application to specific circumstances requires professional judgement.
Marketing and product teams
Teams designing data-driven activities often consider legitimate interest as an alternative to consent, but they should understand that it is not a way to avoid other obligations. Where sector-specific rules such as ePrivacy or cookie regimes apply, those requirements operate separately from the lawful-basis analysis.

Inside Legitimate Interest

Lawful basis under Article 6
Legitimate interests is one of the lawful bases for processing personal data under Article 6(1) of the EU GDPR, which sets out six such bases. The UK GDPR reflects the same structure, though readers should note that UK reforms have introduced additional provisions in this area; verify the current position against the latest UK text where UK processing is concerned. This entry does not address special-category data, which requires a separate condition under Article 9.
The three-part test
Reliance on legitimate interests generally requires satisfying three elements: (i) a purpose test identifying a legitimate interest pursued by the controller or a third party; (ii) a necessity test confirming the processing is necessary to achieve that interest; and (iii) a balancing test weighing that interest against the interests, rights, and freedoms of the data subject. The interest does not automatically prevail; it can be overridden where the individual's rights carry greater weight.
Exclusion for public authorities
Under Article 6(1)(f) of the GDPR, the legitimate-interest basis does not apply to processing carried out by public authorities in the performance of their tasks. Public-sector bodies generally must rely on other lawful bases for such processing. National implementations and the UK regime may treat this exclusion with variations, so public-sector readers should confirm the applicable rule.
Legitimate Interests Assessment (LIA)
A documented record demonstrating that the three-part test has been considered and satisfied. It is not a statutory certification but a practical accountability tool that helps evidence the reasoning behind reliance on this basis. Its precise form is not prescribed by the regulation.
Relationship to data subject rights
Where processing relies on legitimate interests, data subjects generally have a right to object, and controllers must stop processing unless they can demonstrate compelling legitimate grounds that override the individual's interests. This distinguishes the basis from consent, where withdrawal operates differently, and from contractual necessity.

Common questions

Answers to the questions practitioners most commonly ask about Legitimate Interest.

Does the EU GDPR now recognise seven lawful bases, including a distinct 'recognised legitimate interest'?
No. The EU GDPR sets out six lawful bases for processing under Article 6(1), one of which is legitimate interests (Article 6(1)(f)). The concept of a separate 'recognised legitimate interest' basis was introduced into UK law through amendments to the UK data protection regime and does not form part of the EU GDPR. Readers should not assume the UK and EU positions are identical here, and should verify the number and framing of lawful bases against the current official text of whichever regime applies to them, as both have been subject to amendment.
Can a public authority rely on legitimate interests for its official functions?
Generally no in that context. Under GDPR Article 6(1)(f), the legitimate-interest basis does not apply to processing carried out by public authorities in the performance of their tasks. Public authorities acting in that capacity typically need to identify a different lawful basis, such as public task or legal obligation. This limitation is material for public-sector readers. The precise boundary of what counts as processing 'in the performance of their tasks' can require careful analysis, and application to particular functions calls for professional judgment against the current text and relevant regulator guidance.
What is the legitimate interests assessment (LIA), and how is it typically structured?
An LIA is the documented analysis used to establish and evidence reliance on the legitimate-interest basis. It is commonly structured as a three-part test: a purpose test (identifying a real and specific interest), a necessity test (whether the processing is necessary to achieve that interest, or whether a less intrusive means exists), and a balancing test (weighing that interest against the interests, rights, and freedoms of the individuals concerned). This structure reflects regulator guidance rather than a prescribed statutory form, so the exact template and depth may vary; verify expectations against current guidance from the applicable authority.
How should the balancing test weigh individuals' interests against the organisation's interest?
The balancing test generally considers factors such as the nature of the data, the reasonable expectations of the individuals given the relationship and context, the potential impact of the processing, and any safeguards that reduce that impact. Processing that individuals would not reasonably anticipate, or that involves higher-risk or special-category considerations, tends to weigh more heavily against reliance on legitimate interests. The outcome is fact-specific and may differ between comparable organisations; it is not a fixed formula, and the assessment should be revisited if the processing or context changes.
What documentation and transparency obligations accompany reliance on legitimate interests?
In most cases organisations should retain the completed LIA as part of their accountability records and be able to produce it on request. Transparency obligations generally require informing individuals that legitimate interests is the basis relied upon and describing the specific interests pursued, typically within a privacy notice. The exact placement and wording depend on the applicable regime and regulator guidance, so the specifics should be verified against current official sources rather than assumed.
How does relying on legitimate interests affect individuals' rights, such as the right to object?
Where processing is based on legitimate interests, individuals generally have a right to object, and the organisation must then stop unless it can demonstrate compelling legitimate grounds that override the individual's interests, or the processing is needed for legal claims. Certain rights, and the strength of the objection right, can differ depending on the lawful basis chosen and the processing purpose (for example, direct marketing is treated distinctly). Because the interaction between lawful basis and data-subject rights is nuanced and jurisdiction-dependent, confirm the applicable rights against the current text and guidance for your regime.

Common misconceptions

Legitimate interests is a catch-all basis that can justify any processing when other bases are inconvenient.
It is not a default or fallback that removes the need for analysis. Reliance generally requires passing the purpose, necessity, and balancing tests, and the outcome is fact-specific. Where the balance favours the data subject's rights, the basis cannot be used.
Any organisation can rely on legitimate interests for any activity.
Public authorities generally cannot use this basis for processing carried out in the performance of their tasks, per Article 6(1)(f). The basis is also unsuitable where individuals would not reasonably expect the processing or where less intrusive means exist.
Once a legitimate interest is established, no further obligations apply.
Data subjects generally retain a right to object, and controllers must reassess if circumstances change. Reliance is not permanent, and the balancing analysis may need revisiting over time or as processing evolves.

Best practices

Conduct and document a Legitimate Interests Assessment before relying on this basis, addressing the purpose, necessity, and balancing tests explicitly.
Confirm that your organisation is not a public authority processing in the performance of its tasks, since the legitimate-interest basis generally does not apply to such processing under Article 6(1)(f).
Verify the current lawful-basis framework against the applicable text, noting that the EU GDPR and the UK GDPR may diverge and that UK reforms are subject to change.
Establish a clear process for handling data subjects' objections, and be prepared to demonstrate compelling grounds where you intend to continue processing.
Reassess your reliance periodically and whenever the purpose, scope, or context of processing changes materially.
Seek professional judgement for fact-specific situations, treating this entry as informational rather than as legal advice, and confirm details against the latest authoritative source.
Application Security Isn’t Optional Anymore.