Legitimate Interests under GDPR

Legitimate interests under the GDPR can be a lawful basis for data processing.

Navigating the General Data Protection Regulation (GDPR) requires a full understanding of the different lawful bases for processing personal data. “Legitimate Interests” can give organisations with a pathway for responsible and lawful data processing. This article delves into the depths of this lawful basis, exploring its definition, conditions, and implications.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

Defining Legitimate Interests

Legitimate interests refer to one of the lawful grounds on which an organisation can process personal data. There is no need to seek explicit consent, but the usual GDPR rights and obligations apply (see below). This basis recognises that data processing is often a necessary part of legitimate business activities. It allows organisations to balance their interests with the privacy rights of individuals.

Exploring Article 6(1)(f) and Recital 47 of GDPR

Article 6(1)f of the UK GDPR says:

“Processing shall be lawful only if and to the extent that at least one of the following applies:

… processing is necessary for the purposes of the legitimate interests pursued by the controller[1] or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.”

[1] A data controller is the organisation that decides what data is needed and for what purposes. They control the processing of personal data and therefore have primary responsibility for GDPR compliance

Recital 47

Recital 47 of the GDPR goes on to say:

“…Such legitimate interest could exist for example where there is a relevant and appropriate relationship between the data subject and the controller in situations such as where the data subject is a client or in the service of the controller.

At any rate the existence of a legitimate interest would need careful assessment including whether a data subject can reasonably expect at the time and in the context of the collection of the personal data that processing for that purpose may take place.

The interests and fundamental rights of the data subject could in particular override the interest of the data controller where personal data are processed in circumstances where data subjects do not reasonably expect further processing.

Given that it is for the legislator to provide by law for the legal basis for public authorities to process personal data, that legal basis should not apply to the processing by public authorities in the performance of their tasks.

The processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned.

The processing of personal data for direct marketing purposes may be regarded as carried out for a legitimate interest.”

What Does This Mean?

  • there must be a defined legitimate interest that would allow the processing of data to go ahead

  • it does not need to be the legitimate interest of the data subject

  • the legitimate interest cannot be used if it has a significant impact on the privacy and rights to control their data of the data subject

  • it is harder to rely on legitimate interests where the data subject is a child

  • there is a need to understand the reasonable expectations of data subjects when it comes to their data processing

  • public authorities should rely on the public authority lawful basis where at all possible, instead of legitimate interests, for data processing

You can read more about other lawful bases for data processing, including consent and public task, here.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

Accountability

As noted above, the data controller is accountable for demonstrating compliance with the GDPR. Therefore as a data controller it is important you can demonstrate why legitimate interests is the right lawful basis. You must know what legitimate interest you are relying on, and how you ensured it is both reasonable and not excessive.

Find out more about the principle of accountability here.

Identifying and justifying a legitimate interest

Understanding the conditions for establishing legitimate interests is paramount. The processing must be necessary, balanced, and aligned with the reasonable expectations of individuals. Striking this balance requires a thorough assessment of the potential impact on data subjects.

Step 1: Identify the Legitimate Interest

  • Clearly define the legitimate interest that the organisation is pursuing. This interest should be specific, measurable, achievable, relevant, and time-bound (SMART).

  • Ensure that the legitimate interest is not simply an interest in making more money or improving marketing effectiveness. It should be a genuine interest that is necessary for the organisation to fulfill its objectives.

Step 2: Assess the Necessity of Processing

  • Evaluate whether processing the personal data is necessary to achieve the legitimate interest. Consider alternative ways to achieve the interest without processing personal data or by processing less or different data.

  • Use this legitimate interest assessment to demonstrate that the organisation cannot reasonably achieve its legitimate interest without processing the personal data.

Step 3: Balance Interests

  • Conduct a balancing test to weigh the organisation’s legitimate interest against the rights and freedoms of the individuals whose data is being processed. This involves identifying the potential impacts of processing on individuals, including potential risks to their privacy, autonomy, and other fundamental rights.

  • Consider the nature, sensitivity, and amount of personal data being processed, the purpose of processing, the context in which the processing is taking place, the safeguards in place, and the likelihood of harm to individuals.

Step 4: Document the Assessment

  • Document the LIA process, including the identified legitimate interest, the assessment of necessity, the balancing test, and the conclusions reached.

  • The documentation should be clear, concise, and provide sufficient evidence to support the organisation’s reliance on the legitimate interests basis.

Step 5: Ongoing Review and Monitoring

  • Regularly review and update the LIA as circumstances change or new risks emerge.

  • Monitor the processing of personal data and its impact on individuals to ensure that the organisation continues to comply with the GDPR’s principles and requirements.

Remember that conducting a legitimate interests assessment is an ongoing process, not a one-time exercise. Organisations should continuously evaluate their processing activities and ensure that they are justified and proportionate to their legitimate interests while upholding the rights and freedoms of individuals.

Practical application of legitimate interests

As hinted at above there are a wide range of activities where companies can use legitimate interests as a lawful basis. These are still subject to the purpose test set out above to ensure legitimate interests is the appropriate basis for processing data.

Here are some examples of scenarios where legitimate interests may be the lawful basis for processing personal data:

1. Fraud Prevention:

  • Financial institutions may process personal data to detect and prevent fraud, such as analysing transaction patterns and identifying suspicious activity.

  • The legitimate interest is to protect the organisation from financial losses and to maintain the integrity of its financial systems.

2. Credit Risk Assessment:

  • Lenders may process personal data to assess creditworthiness and make informed lending decisions.

  • The legitimate interest is to manage credit risk and ensure that loans are repaid.

3. Marketing and Customer Relationship Management:

  • Companies may process personal data to understand customer preferences, send targeted marketing communications, and improve customer service.

  • The legitimate interest is to grow their business and retain customers.

In each of these scenarios, the organisation must carefully consider the potential impact of processing on individuals and ensure that its legitimate interests are not overridden by the individuals’ rights and freedoms. If the organisation cannot demonstrate that its processing is necessary and proportionate, it should consider using another lawful basis for processing, such as consent or contractual obligation.

Limits and Challenges

Legitimate interests are not a one-size-fits-all solution. The context of data processing activities, the nature of the data involved, and the potential impact on individuals must be carefully considered.

Because of their vulnerability it is harder to rely on legitimate interests for the processing of children’s data. Also, legitimate interests is not an appropriate basis for the processing of sensitive personal data such as:

  • health related data

  • data relating to characteristics such as gender, ethnicity or sexual orientation

  • the processing of certain employment related activities such as occupational health.

Finally there are people’s rights to consider. People have the right to object to the processing of personal data under the legitimate interests lawful basis. You will need to consider how you will respond to people exercising their data rights when processing data on this basis.

Transparency and Communication

No matter what lawful basis you rely on it is important to understand that people’s GDPR rights still apply. How may vary, but there is one right you must comply with absolutely: the Right to Be Informed.

This is part of meeting the first GDPR privacy principle: that data processing must be lawful, fair and transparent.

Organisations should communicate openly with data subjects about how their data is processed based on legitimate interests, ensuring individuals are informed and have avenues for clarification. This is typically done through a privacy statement or similar privacy information that is provided at the point of data collection.

You can find out more about the right to be informed and the first GDPR privacy principle here.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial

Conclusion

In the intricate dance of data processing and privacy rights, legitimate interests emerge as a key partner, offering organisations a lawful route to conduct necessary activities. However, this privilege comes with responsibilities – organisations must conduct thorough assessments, respect objections, and prioritise transparent communication. Navigating the realm of legitimate interests requires a delicate balance, ensuring that data processing serves both organisational goals and the fundamental rights of individuals. As organisations tread this fine line, they not only ensure GDPR compliance but also foster a culture of accountability and respect for privacy.