When can an organisation process personal data because it is in its legitimate interests, and how does it demonstrate that those interests do not override people’s rights?
- Legitimate interests is one of the lawful bases available under Article 6.
- It can be flexible, but that does not make it a fallback basis.
- Organisations normally need to demonstrate purpose, necessity and balancing before relying upon it.

Legitimate Interests at a Glance
- Legitimate interests is an Article 6 lawful basis.
- The interest can belong to the controller, a third party or potentially wider society.
- Processing must be necessary to achieve that interest.
- The individual’s interests, rights and freedoms must not override it.
- Reasonable expectations are an important part of the assessment.
- Children and vulnerable people require particular care.
- Organisations should normally document their decision through an LIA.
- Individuals have a right to object to certain processing based on legitimate interests.
Defining Legitimate Interests
Legitimate interests refer to one of the lawful grounds on which an organisation can process personal data. There is no need to seek explicit consent, but the usual GDPR rights and obligations apply (see below). This basis recognises that data processing is often a necessary part of legitimate business activities. It allows organisations to balance their interests with the privacy rights of individuals.

Exploring Article 6(1)(f) and Recital 47 of GDPR
Article 6(1)f of the UK GDPR says:
“Processing shall be lawful only if and to the extent that at least one of the following applies:
… processing is necessary for the purposes of the legitimate interests pursued by the controller[1] or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.”
[1] A data controller is the organisation that decides what data is needed and for what purposes. They control the processing of personal data and therefore have primary responsibility for GDPR complianceRecital 47
Recital 47 of the GDPR goes on to say:
“…Such legitimate interest could exist for example where there is a relevant and appropriate relationship between the data subject and the controller in situations such as where the data subject is a client or in the service of the controller.
At any rate the existence of a legitimate interest would need careful assessment including whether a data subject can reasonably expect at the time and in the context of the collection of the personal data that processing for that purpose may take place.
The interests and fundamental rights of the data subject could in particular override the interest of the data controller where personal data are processed in circumstances where data subjects do not reasonably expect further processing.
Given that it is for the legislator to provide by law for the legal basis for public authorities to process personal data, that legal basis should not apply to the processing by public authorities in the performance of their tasks.
The processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned.
The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.”
What Does This Mean?
- there must be a defined legitimate interest that would allow the processing of data to go ahead
- it does not need to be the legitimate interest of the data subject
- the legitimate interest can be used if it has a significant impact on the privacy and rights to control their data of the data subject. The question is whether the individual’s interests or fundamental rights and freedoms override the legitimate interest, and what safeguards can be put in place.
- it is harder to rely on legitimate interests where the data subject is a child
- there is a need to understand the reasonable expectations of data subjects when it comes to their data processing
- public authorities should rely on the public authority lawful basis where at all possible, instead of legitimate interests, for data processing. Public authorities cannot rely on Article 6(1)(f) for processing carried out in the performance of their tasks. But that does not necessarily mean a public authority can never rely on legitimate interests for processing outside those tasks.
You can read more about other lawful bases for data processing, including consent and public task, here.
The Legitimate Interests Assessment
- Purpose test
Is there a legitimate interest? That means, have you identified an outcome that serves the interests of you, the data subject or another person that in principle justifies the data processing? - Necessity test
Is processing the personal data necessary to achieve that outcome? Can it be done without using personal data? - Balancing test
Do the individual’s interests, rights and freedoms override the legitimate interest?
Legitimate interests At A Glance

Accountability
As noted above, the data controller is accountable for demonstrating compliance with the GDPR. Therefore as a data controller it is important you can demonstrate why legitimate interests is the right lawful basis. You must know what legitimate interest you are relying on, and how you ensured it is both reasonable and not excessive.
Find out more about the principle of accountability here.
Identifying and justifying a legitimate interest
Understanding the conditions for establishing legitimate interests is paramount. The processing must be necessary, balanced, and aligned with the reasonable expectations of individuals. Striking this balance requires a thorough assessment of the potential impact on data subjects.
Step 1: Identify the Legitimate Interest
an interest should be:
- lawful;
- genuine;
- sufficiently specific;
- clearly articulated.
Too vague:
“We want to improve the business.”
Better:
“We need to prevent fraudulent transactions and protect customers and the organisation from financial loss.”
Making money or improving marketing effectiveness can constitute an interest. There is no reason why commercial interests should not be the foundation for data processing. The important questions concern legitimacy, necessity and balancing.
Step 2: Assess the Necessity of Processing
You should evaluate whether processing the personal data is necessary to achieve the legitimate interest. Consider alternative ways to achieve the interest without processing personal data or by processing less or different data.
Use this legitimate interest assessment to demonstrate that the organisation cannot reasonably achieve its legitimate interest without processing the personal data.
“Necessary” does not necessarily mean absolutely essential.
The practical question is whether processing is a proportionate way of achieving the legitimate interest.
Ask:
Could we reasonably achieve the same objective in a less intrusive way?
For example:
An organisation wants to protect its office.
Installing CCTV covering entrances might be necessary and proportionate.
Recording every employee continuously at their desk would require a much more difficult justification.
Step 3: Balance Interests
The third step is to conduct a balancing test to weigh the organisation’s legitimate interest against the rights and freedoms of the individuals whose data is being processed. This involves identifying the potential impacts of processing on individuals, including potential risks to their privacy, autonomy, and other fundamental rights.
Consider the nature, sensitivity, and amount of personal data being processed, the purpose of processing, the context in which the processing is taking place, the safeguards in place, and the likelihood of harm to individuals.
What should organisations consider?
Nature of the data
- Is it sensitive, confidential or potentially harmful? This makes justifying necessity and proportionality harder.
Volume
- How much information is involved? A very large volume of data might rely on several lawful bases as information passes through its lifecycle, rather than one legitimate interest
Relationship
- What is the relationship between the individual and organisation?
Reasonable expectations
- Would they reasonably expect this use? Expectation isn’t decisive by itself. Unexpected processing isn’t automatically unlawful, nor does expected processing automatically make legitimate interests appropriate. However, it is an important factor in the balancing exercise.
Impact
- What happens to them as a result?
Intrusiveness
- How closely are they being monitored, analysed or profiled?
Vulnerability
- Are children or vulnerable adults involved? Extra care should be taken with people who may not be able to understand how their data are used or the consequences of this.
Power imbalance
- Can the individual realistically exercise control?
Safeguards
Can the risk be reduced? An organisation might initially identify significant privacy risks but be able to reduce them through:
- data minimisation;
- pseudonymisation;
- access restrictions;
- retention limits;
- opt-outs;
- transparency;
- aggregation;
- security controls;
- reduced monitoring;
- restrictions on onward use.
- If using sensitive data or processing data about vulnerable people you should consider completing a Data Protection Impact Assessment (DPIA)
Step 4: Document the Assessment
- Document the LIA process, including the identified legitimate interest, the assessment of necessity, the balancing test, and the conclusions reached.
- The documentation should be clear, concise, and provide sufficient evidence to support the organisation’s reliance on the legitimate interests basis.
Step 5: Ongoing Review and Monitoring
- Regularly review and update the LIA as circumstances change or new risks emerge.
- Monitor the processing of personal data and its impact on individuals to ensure that the organisation continues to comply with the GDPR’s principles and requirements.
Remember that conducting a legitimate interests assessment is an ongoing process, not a one-time exercise. Organisations should continuously evaluate their processing activities and ensure that they are justified and proportionate to their legitimate interests while upholding the rights and freedoms of individuals.
Practical application of legitimate interests
As hinted at above there are a wide range of activities where companies can use legitimate interests as a lawful basis. These are still subject to the purpose test set out above to ensure legitimate interests is the appropriate basis for processing data.
Here are some examples of scenarios where legitimate interests may be the lawful basis for processing personal data:
1. Fraud Prevention:
- Financial institutions may process personal data to detect and prevent fraud, such as analysing transaction patterns and identifying suspicious activity.
- The legitimate interest is to protect the organisation from financial losses and to maintain the integrity of its financial systems.
- In some circumstances a legitimate interest assessment may not be required if the organisation can demonstrate the processing falls within the scope of Recognised Legitimate Interests, which is a new approach to legitimate interests introduced by the Datra Use and Access Act
2. Marketing and Customer Relationship Management:
- Companies may process personal data to understand customer preferences, send targeted marketing communications, and improve customer service.
- The legitimate interest is to grow their business and retain customers.
- However, this does not mean the Privacy and Electronic Communications Regulations do not apply.
In each of these scenarios, the organisation must carefully consider the potential impact of processing on individuals and ensure that its legitimate interests are not overridden by the individuals’ rights and freedoms. If the organisation cannot demonstrate that its processing is necessary and proportionate, it should consider using another lawful basis for processing, such as consent or contractual obligation.
Other examples where legitimate interests may be an appropriate lawful basis include:
- network and information security;
- physical security;
- debt recovery;
- maintaining customer relationships;
- some internal administration;
- protecting organisational assets.
Limits and Challenges
Children’s Data
Legitimate interests are not a one-size-fits-all solution. The context of data processing activities, the nature of the data involved, and the potential impact on individuals must be carefully considered.
Because of their vulnerability it is harder to rely on legitimate interests for the processing of children’s data.
Children may:
- be less able to understand processing;
- have different reasonable expectations;
- be more vulnerable to harm;
- be less able to exercise their rights.
Article 6(1)(f) itself specifically highlights situations where the data subject is a child.
Special Category Data
For special category data such as health related data, or data relating to characteristics such as gender, ethnicity or sexual orientation an organisation needs:
an Article 6 lawful basis
PLUS
an Article 9 condition.
Article 6(1)(f) legitimate interests can potentially be the Article 6 basis. The organisation then separately needs an appropriate Article 9 condition.
While the general lawful bases set out in Article 6 are broad categories, Article 9 conditions are very focussed. Examples include:
- health data for employment or social security purposes
- political opinions for not-for-profit groups
- ethnicity data for equality monitoring in the workplace
This makes the legitimate interests assessment more complex because two additional steps are needed:
- identifying where the identified interest involves processing special category data
- identifying the appropriate article 9 condition
You will also need to be more careful about considering impact and where safeguards are needed.

People’s Data Rights
Finally there are people’s rights to consider. People have the right to object to the processing of personal data under the legitimate interests lawful basis. You will need to consider how you will respond to people exercising their data rights when processing data on this basis.
The right to object is itself absolute when it comes to direct marketing, so if you use legitimate interests for your marketing activities you must stop processing data for this purpose when an objection is received.
Transparency, Communication, and Record Keeping
No matter what lawful basis you rely on it is important to understand that people’s GDPR rights still apply. How may vary, but there is one right you must comply with absolutely: the Right to Be Informed.
This is part of meeting the first GDPR privacy principle: that data processing must be lawful, fair and transparent.
Organisations should communicate openly with data subjects about how their data is processed based on legitimate interests, ensuring individuals are informed and have avenues for clarification. This is typically done through a privacy statement or similar privacy information that is provided at the point of data collection.
Your legitimate interests assessment should overall be used to comply with a range of statutory duties under the GDPR. Privacy information should explain, as applicable:
- what you’re doing;
- why;
- the legitimate interests pursued;
- how individuals can exercise their rights.
This also connects the legitimate interests assessment with your Record of Processing Activity (ROPA) and then your privacy notice:
Assessment: Can we justify it?
ROPA: How do we document the processing?
Privacy information: How do we explain it to people?
You can find out more about the right to be informed and the first GDPR privacy principle here.
When Not to Use Legitimate Interests
Legitimate interests is a useful lawful basis but it would be as much as mistake to assume it can, or should, cover everything in the same way people do when relying on consent. It may be that your legitimate interests test suggests you cannot proceed, but that may just mean another lawful basis would be a better fit. This may be true, for example, when dealing with special category data.
Examples where legitimate interests may not always or easily work include where:
- another lawful basis more accurately reflects the processing;
- the processing isn’t necessary;
- a less intrusive alternative exists;
- the impact on individuals is disproportionate;
- people would reasonably not expect the processing;
- the organisation cannot adequately mitigate the risks;
- individuals’ interests, rights or freedoms override the organisation’s interest.
Legitimate interests is flexible, but it is not a fallback basis for processing that cannot otherwise be justified.
Common Mistakes with Legitimate Interests
It can be easy to fall into the trap of using legitimate interests without any of the additional work involved. A number of mistakes are made with this lawful basis and the risk here is that these problems will not come to light until someone complains or there is a data breach. Mistakes to avoid include:
“We have a business interest, therefore it’s legitimate.”
Not enough. Business interests are a great start, but that is only step one of the process outlined above.
Skipping the necessity test
Convenient doesn’t mean necessary. You MUST need to process the data for this lawful basis to be valid. Wanting to is not enough.
Treating the test as a formality
The conclusion shouldn’t be predetermined. Each assessment must be made openly and honestly under the circumstances of the day.
Ignoring reasonable expectations
Although the legitimate interests you rely on may not be those of the data subject the use of their data must be reasonable, to the extent that a person in the street would be able to see why and how the data use was appropriate. This test of reasonableness is a good benchmark and will help with any accountability challenges later.
Ignoring vulnerability
Where vulnerabilities exist is can be tempting to use legitimate interests to get around them but you must identify those vulnerabilities and put in place the appropriate limits and safeguards.
Assuming safeguards automatically make processing acceptable
Safeguards reduce risk; they don’t eliminate them or the need for balancing test. As noted above you may need to do a Data Protection Impact Assessment for riskier data processing.
Privacy notices don’t match the legitimate interests assessment
This is not uncommon and can cause accountability problems. Your privacy notice should, even if only in summary form, explain the legitimate interests you are relying on (why you are processing the data) and the categories of data you process under them
Using legitimate interests as the default
Choose the basis that genuinely reflects the processing.
Your Practical Checklist

You can download a practical checklist as an excel spreadsheet below. The checklist covers the following steps:
Legitimate Interests Assessment Checklist
Purpose
☐ What are we trying to achieve?
☐ Who benefits?
☐ Is it sufficiently specific?
Necessity
☐ Is processing personal data necessary?
☐ Could we achieve the objective without personal data?
☐ Could we use less data?
☐ Is there a less intrusive alternative?
Balancing
☐ What data are involved?
☐ What would individuals reasonably expect?
☐ What impact could processing have?
☐ Are children or vulnerable people involved?
☐ Is there a power imbalance?
☐ Could processing cause harm?
Safeguards
☐ Can we minimise the data?
☐ Can we pseudonymise it?
☐ Can we restrict access?
☐ Can we reduce retention?
☐ Can individuals opt out?
Accountability
☐ Have we documented the LIA?
☐ Is our ROPA accurate?
☐ Does our privacy information explain the legitimate interest?
☐ Have we considered the right to object?
☐ When will we review the decision?
Conclusion
Legitimate interests is a good lawful basis for data processing. To be fully GDPR compliant organisations using this basis must take steps to ensure they have chose it correctly, and are applying it safely – understanding the impact and reducing risks. The right legitimate interests assessment will improve confidence and accountability while building trust and avoiding problems in the future.
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: