What are "Legitimate Interests" under the GDPR?

Legitimate interests is the GDPR's most flexible lawful basis, but it requires careful analysis. This practical checklist walks through the Legitimate Interests Assessment (LIA), balancing test, documentation requirements, and safeguards organizations should consider before relying on this basis.

What are "Legitimate Interests" under the GDPR?

Key points: (1) The legitimate interests lawful basis applies when processing is necessary to pursue a legitimate interest, provided that interest is not overridden by the individual's rights and freedoms. (2) It is generally appropriate where the processing is reasonably expected, has a minimal impact on privacy, or is supported by a compelling justification. Public authorities cannot rely on this basis when carrying out their official public tasks. (3) Controllers must complete the three-part Legitimate Interests Assessment (LIA) by: (a) identifying a legitimate interest, (b) demonstrating that the processing is objectively necessary, and (c) balancing that interest against the individual's rights and freedoms. (4) Legitimate interests may include commercial, individual, or broader societal interests. If the same objective can reasonably be achieved in a less intrusive way, this lawful basis does not apply. (5) Controllers should document their Legitimate Interests Assessment (LIA), include the legitimate interests in their privacy notice, and be able to justify why their interests are not overridden by the individual's rights and freedoms.

What is the ‘legitimate interests’ basis?

Legitimate interests is the most flexible lawful basis, but is not always appropriate but relying on legitimate interests requires taking on extra responsibility for ensuring individual’s rights and interests are fully considered and protected.

Controllers can rely on legitimate interests for marketing activities if they can show that the processing is proportionate, has a minimal impact on individual rights, and people would not be surprised or likely to object.

  • Controllers can rely on legitimate interest for processing children’s data, but they must take extra care to make sure the children’s interests are protected.
  • Controllers may be able to rely on legitimate interests to lawfully disclose personal data to a third party but they need to consider why the third party wants the information, whether it actually needs it, and what it will do with the personal data.

Public authorities cannot rely on legitimate interests for any processing required to perform their tasks as a public authority. However, if they have other legitimate purposes they can consider legitimate interests where appropriate.

A wide range of interests, whether compelling or not, may be legitimate interests including the controller´s own interests or the interests of third parties. Commercial interests as well as wider societal benefits can also be considered. Trivial interests may be more easily overridden in the balancing test.

  • The GDPR specifically mentions use of client or employee data, marketing, fraud prevention, intra-group transfers, or IT security as potential legitimate interests, but this is not an exhaustive list.
  • It also says that controllers have a legitimate interest in disclosing information about possible criminal acts or security threats to the authorities.

When can we rely on legitimate interests?

Controllers must balance their interests against the individual’s interests. In particular, if individuals would not reasonably expect the processing, or it would cause them unwarranted harm, their interests are likely to override the interest of the controller.

To rely on legitimate interests, an organization should complete the GDPR's three-part test:

  1. Purpose test: Identify the legitimate interest being pursued.
  2. Necessity test: Determine whether the processing is necessary to achieve that interest.
  3. Balancing test: Assess whether the organization's interests are overridden by the rights, freedoms, or interests of the individuals concerned.

What is a Legitimate Interests Assessment (LIA)?

A Legitimate Interests Assessment (LIA) is a documented analysis used to determine whether an organization may rely on legitimate interests as the legal basis for processing personal data under Article 6(1)(f) GDPR. Although the GDPR does not expressly require organizations to complete an LIA, it is widely recognized as the best way to demonstrate that reliance on legitimate interests is lawful and well justified.

An LIA is a practical, risk-based assessment that examines the specific circumstances of the proposed processing. Its purpose is to confirm that the organization's legitimate interests are real and lawful, that the processing is necessary to achieve those interests, and that those interests are not overridden by the rights and freedoms of the individuals whose data is being processed.

Completing an LIA helps organizations make informed, accountable decisions before relying on legitimate interests. It encourages organizations to:

  • clearly identify the legitimate interest they are pursuing;
  • assess whether the processing is genuinely necessary to achieve that purpose;
  • objectively consider the reasonable expectations of the individuals affected;
  • evaluate the potential impact of the processing on those individuals; and
  • identify safeguards that can reduce privacy risks.

Documenting the assessment also provides an audit trail demonstrating compliance with the GDPR's accountability principle. If a supervisory authority or a court later questions the organization's reliance on legitimate interests, a well-documented LIA provides evidence that the required balancing exercise was carried out thoughtfully and in good faith.

The LIA should be completed before the organization begins processing the personal data. This is because the assessment is intended to help determine whether legitimate interests is an appropriate lawful basis. A valid lawful basis must be identified before the processing begins.

The level of detail required will depend on the nature and risks of the processing. A brief assessment may be sufficient for routine, low-risk activities, while more complex or intrusive processing may require a more detailed analysis. If the balancing identifies significant risks, the controller should consider whether a Data Protection Interest Assessment (DPIA) is required.

Keeping a record of the balancing test and the determination is necessary to demonstrate compliance. The balancing should be reviewed and refreshed if there are significant changes in the purpose, nature or context of the processing.

There’s no foolproof formula for the outcome of the balancing test but there are three steps controllers should follow:

Step One: The Purpose Test

The first step is to identify the interest the organization is seeking to pursue and determine whether it qualifies as a legitimate interest.

The purpose should be described as specifically as possible. Broad statements such as “improving services” or “supporting business operations” are unlikely to provide enough information to properly assess necessity or balance the organization’s interests against the rights of individuals.

When completing the purpose test, the organization should consider:

  • why it wants to process the personal data;
  • what benefit it expects the processing to provide;
  • whether the organization, a third party, or the public will benefit;
  • how significant those benefits are;
  • what would happen if the processing could not proceed;
  • what outcome the processing is intended to produce for the individuals affected;
  • whether the processing complies with other applicable laws;
  • whether it is consistent with relevant industry standards, guidelines, or codes of conduct; and
  • whether the processing raises any legal, ethical, or fairness concerns.

A legitimate interest may be commercial, operational, societal, or connected to the interests of a third party. However, the interest must be lawful, sufficiently specific, and genuinely pursued.

The GDPR identifies certain activities as potential legitimate interests, including:

  • transferring personal data within a corporate group for internal administrative purposes;
  • direct marketing; and
  • protecting network and information security.

These examples indicate that such purposes may satisfy the purpose test, but they do not automatically make the processing lawful. The organization must still establish that the processing is necessary and that its interests are not overridden by the rights, freedoms, or interests of the individuals concerned.

Organizations should also consider whether the processing falls within a separate or more specific lawful basis. Where another basis more accurately reflects the nature and purpose of the processing, that basis should be used instead.

Step Two: The Necessity Test

Once the legitimate interest has been identified, the organization must determine whether the proposed processing is necessary to achieve that purpose.

"Necessary" does not mean absolutely indispensable. Rather, it requires that the processing be a reasonable and proportionate way of achieving the identified objective. If the same result can be achieved through a less intrusive method or by processing less personal data, the processing may not satisfy this test.

When conducting the necessity test, organizations should consider questions such as:

  • Will the proposed processing actually help achieve the identified purpose?
  • Is the processing proportionate to that purpose, or is it excessive?
  • Can the objective be achieved without processing personal data?
  • Can the same objective be achieved by processing less personal data?
  • Is there another practical approach that would be less intrusive for the individuals concerned?

The assessment should be objective and realistic. Simply preferring a particular business model or operational approach does not automatically make the processing necessary. If there are reasonable alternatives that are less intrusive, the organization should explain why those alternatives would not adequately achieve the intended purpose.

If it becomes difficult to demonstrate why the processing is necessary, the organization should revisit the purpose identified in the first step. A clearly defined and specific purpose often makes it easier to demonstrate that the processing is genuinely necessary.

Step Three: The Balancing Test

The final step is to determine whether the organization's legitimate interests are outweighed by the rights, freedoms, or interests of the individuals whose personal data will be processed.

This balancing exercise lies at the heart of the legitimate interests assessment. Even where an organization has a legitimate objective and the processing is necessary to achieve it, legitimate interests cannot be relied upon if the impact on individuals is disproportionate.

The assessment must take into account all relevant circumstances, including the reasonable expectations of the individuals. People should not generally be surprised by how their personal data is used. Processing that is unexpected, particularly intrusive, or significantly affects individuals is more likely to weigh against reliance on legitimate interests.

Among other factors, organizations should consider:

  • the nature and sensitivity of the personal data;
  • the relationship between the organization and the individuals;
  • how the data was collected;
  • whether the individuals would reasonably expect the processing;
  • the likelihood and severity of any impact on the individuals;
  • whether the processing could cause financial, physical, emotional, or reputational harm;
  • whether the processing could result in discrimination, exclusion, or other adverse consequences; and
  • what technical and organizational safeguards can be implemented to reduce privacy risks.

Determining the Outcome of the LIA

After completing the three-part test, the organization should objectively weigh all of the factors identified during the assessment to determine whether its legitimate interests outweigh the risks to the rights and freedoms of the individuals concerned.

A key consideration is whether individuals would reasonably expect their personal data to be used in the proposed way. This objective assessment should take into account factors such as the organization's relationship with the individual, how and when the personal data was collected, what individuals were told at the time of collection, and whether the processing would be expected in the particular circumstances. Where expectations are unclear, organizations may consider evidence such as user research or surveys. Special care should always be taken when processing children's personal data.

Organizations should also evaluate the potential impact of the processing on individuals and society, including risks such as financial loss, identity theft, discrimination, reputational harm, or loss of privacy. Where appropriate, safeguards—such as data minimization, strong security measures, greater transparency, and simple mechanisms for exercising the right to object—should be implemented to reduce those risks.

The final decision, together with the reasoning supporting it, should be documented as part of the LIA. In many cases the outcome will be straightforward, while more complex situations may require a more detailed explanation of why the balancing test has been satisfied.

Further reading

ICO's detailed guidance on legitimate interests.

Subscribe to The de la Torre Review

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe