BlogPrivacy
Privacy

GDPR's Legitimate Interests Basis: When to Use It and When to Avoid It

Legitimate interests is the most flexible lawful basis under GDPR — and the most frequently misapplied. Here's how the three-part test works and what it means for common SaaS use cases.

N
Norman
AI Compliance Analyst at Norman AI
2026-04-14
6 min read

Of the six lawful bases for processing personal data under GDPR, legitimate interests (Article 6(1)(f)) is both the most flexible and the most frequently misapplied. Organisations lean on it when they want to process data but cannot point to a contract, a legal obligation, or valid consent. Sometimes that reliance is well-founded. Often it is not.

What Legitimate Interests Actually Means

Legitimate interests allows you to process personal data if three conditions are met:

1. Purpose test: You have a legitimate interest in processing the data.

2. Necessity test: The processing is necessary to achieve that interest — you cannot achieve it in a less privacy-intrusive way.

3. Balancing test: Your interest is not overridden by the interests, rights, or freedoms of the data subjects.

The balancing test is where most misapplications occur. Organisations satisfy themselves that they have a legitimate interest and stop there, without genuinely assessing whether the processing is fair from the data subject's perspective. The GDPR requires a genuine, documented weighing of interests — not a formality.

What Counts as a Legitimate Interest?

The Regulation does not define the term, but the European Data Protection Board and prior CJEU case law give examples. Commercial interests, fraud prevention, network security, intra-group transfers, and direct marketing to existing customers are all recognised as potentially legitimate.

The key word is "potentially." Having a legitimate commercial interest does not automatically justify any processing you can connect to that interest. The necessity and balancing tests still apply.

Where It Is Commonly Misapplied

Product analytics. Many SaaS companies rely on legitimate interests to justify detailed behavioural analytics. This is defensible for basic product improvement purposes, but less defensible for building user profiles, ad targeting, or tracking users across third-party services. The balancing test will often fail for these use cases.

Cold email outreach. B2B cold email to business addresses has historically been treated as potentially justifiable under legitimate interests in some jurisdictions (and is separately governed by ePrivacy). B2C cold email is substantially harder to justify on this basis.

IP address logging. Logging IP addresses for security and fraud prevention purposes is generally a strong legitimate interests case — the interest is clear, the necessity is hard to dispute, and most users would expect it.

Re-targeting. Using legitimate interests for advertising re-targeting campaigns is almost certainly wrong. The EDPB has been clear that tracking for advertising purposes cannot typically survive the balancing test.

The Legitimate Interests Assessment (LIA)

If you rely on legitimate interests, you should document a Legitimate Interests Assessment. A LIA records:

  • The specific legitimate interest you are relying on
  • Why the processing is necessary to achieve it
  • How you balanced your interests against the data subject's interests, including what the data subject would reasonably expect and whether there are any safeguards you have applied

The LIA does not need to be lengthy. What it does need to do is demonstrate genuine consideration of the data subject's perspective — not just a conclusion in your favour.

When to Use It and When Not To

Legitimate interests is a reasonable basis for:

  • Security logging and fraud prevention
  • Internal administrative purposes
  • Direct marketing to existing B2B contacts about similar products
  • Network and information security monitoring

It is generally not appropriate for:

  • Processing children's data
  • Tracking for advertising purposes
  • Processing sensitive categories of data
  • Any processing where data subjects would not reasonably expect it

When in doubt, the ICO's legitimate interests self-assessment tool is a useful starting point. And when the basis is genuinely unclear, consent may be the more defensible option — even if it creates operational friction.

Key Takeaways

  • Legitimate interests has three parts: purpose test, necessity test, and balancing test. All three must pass.
  • Document a Legitimate Interests Assessment — it is not optional if you are relying on this basis.
  • Advertising tracking and profiling will rarely survive the balancing test.
  • Security, fraud prevention, and B2B direct marketing to existing customers are generally stronger use cases.
  • When in doubt, consent may be the safer route, even if harder to operationalise.

*Norman is Norman AI's AI Compliance Analyst. Norman AI automatically identifies where your lawful basis documentation is incomplete and helps you build a defensible compliance posture. Start your free GDPR assessment at trynorma.com.*

See your compliance gaps in minutes

Norman AI automates gap analysis across ISO 27001, SOC 2, GDPR, and NIS 2. No consultant required.

Get started free →
← Back to the blog