Privacy Principles
What is Legitimate Interest?
Legitimate interest is one of the six lawful bases for processing personal data under GDPR Article 6(1)(f), allowing processing necessary for a genuine business or third-party interest — but only where that interest is not overridden by the individual's rights, as determined through a documented three-part balancing test.
Legitimate interest is GDPR's flexible basis: no consent required, no contract needed, but a burden of justification instead. Reliance on it requires the three-part test regulators formalized as the Legitimate Interests Assessment (LIA). Purpose: is the interest real and lawful — fraud prevention, network security, direct marketing to existing customers, internal administration? Necessity: does achieving it genuinely require this processing, or would something less intrusive work? Balancing: do the individual's interests, rights, and reasonable expectations override — considering the relationship, the data's nature, and what the person would expect at collection?
Reasonable expectations do heavy lifting in the balance. GDPR's recitals note that direct marketing 'may be regarded as' a legitimate interest, and an existing customer plausibly expects the brand they bought from to email them (with an opt-out always available under Article 21's absolute objection right for marketing). A stranger being profiled across the web has no such expectation, which is why regulators and courts have rejected legitimate interest as a basis for third-party behavioral advertising — most prominently in EU decisions against Meta's ad processing.
The critical boundary for web tracking: legitimate interest cannot substitute for ePrivacy consent. Storing or reading cookies and similar identifiers requires consent under Article 5(3) of the ePrivacy Directive regardless of GDPR basis — 'we process analytics cookies under legitimate interest' is a category error that appears in many non-compliant banners, including TCF-based ones regulators have struck down.
Used honestly, legitimate interest requires paperwork: a written LIA before processing begins, disclosure of the interest in the privacy notice, and a working objection route. It is a justification you must be able to produce, not a label you apply.
Why it matters for eCommerce
Legitimate interest legitimately covers a store's fraud screening, security logging, order-related communications, and — carefully — postal or email marketing to existing customers where local law allows the soft opt-in. It does not cover marketing cookies, pixels, or audience syncs for EU visitors: those need ePrivacy consent, full stop. Banners offering 'legitimate interest' toggles for advertising are a red flag auditors know well.
Frequently asked questions
- Can we use legitimate interest instead of asking for cookie consent?
- No. Cookie and tracker access to a user's device is governed by ePrivacy consent requirements, which legitimate interest cannot replace. Legitimate interest is a GDPR basis for processing, not an exemption from the separate rule requiring consent to store or read information on a device.
- What is a Legitimate Interests Assessment (LIA)?
- The documented three-part test — purpose, necessity, balancing — performed before relying on legitimate interest. It records why the interest is genuine, why the processing is needed, and why individuals' rights do not override, and it is the document a regulator asks for first.
- Can individuals object to legitimate-interest processing?
- Yes — Article 21 grants an objection right requiring the controller to stop unless it shows compelling overriding grounds. For direct marketing, the objection is absolute: the processing must stop, no balancing allowed.
Related terms
Wondering how this applies to your own site? Get a free compliance scan — see every tracker that fires before consent, graded against CIPA, GDPR, CCPA/CPRA, and MHMD.
Run a free scan