Article 6(1)(f) GDPR permits processing on the basis of legitimate interests where the processing is necessary for a legitimate interest pursued by the controller or a third party, except where those interests are overridden by the interests or fundamental rights of the data subject. Applying this legal basis correctly requires completing a structured three-part assessment.
What is the three-part legitimate interest test?
The legitimate interest assessment (LIA) has three sequential elements, each of which must be satisfied before the legal basis can be relied upon.
Purpose test: Is the interest pursued by the controller a legitimate one? The interest must be real, present, and not prohibited by law. It need not be exceptional – routine commercial interests such as fraud prevention, IT security, network administration, and direct marketing to existing customers have all been recognised as potentially legitimate. The interest must be articulated with specificity; a vague reference to "business purposes" is insufficient.
Necessity test: Is the processing necessary for that interest? This requires genuine assessment of whether less privacy-invasive means could achieve the same purpose. If the same result could be achieved by processing less data, or by processing data in a less intrusive way, the necessity requirement is not met.
Balancing test: Do the interests or fundamental rights of the data subject override the controller's legitimate interest? This is where the most detailed analysis is required. Relevant factors include the nature of the data (with sensitive or personal data attracting more weight to the data subject side), the reasonable expectations of the data subject (would they expect this processing?), the potential impact of the processing, and whether the data subject has the right to object and what the practical effect of that right is.
How should the assessment be documented?
The LIA should be documented in a way that demonstrates the analysis was genuinely conducted and not merely a conclusion. Each of the three elements should be addressed with specific reference to the processing activity in question. The documentation should be maintained as part of the Record of Processing Activities and reviewed when processing activities change.
The EDPB has noted in its one-stop-shop decisions on legitimate interest that a legitimate interest assessment carried out at a high level of generality, applied identically to multiple processing activities regardless of their specific characteristics, is unlikely to satisfy the accountability requirements of Article 5(2).
What processing activities are excluded from legitimate interest?
Article 6(1)(f) explicitly excludes processing by public authorities in the performance of their tasks. The recitals clarify that processing for direct marketing purposes may constitute a legitimate interest, but this is subject to the right to object under Article 21(2). Processing of children's data on the basis of legitimate interest faces heightened scrutiny and is generally considered inappropriate.
What this means for your organisation
- Selecting legitimate interest as a legal basis without completing and documenting a three-part LIA is not compliant. The EDPB has scrutinised LIA quality closely in its one-stop-shop decisions.
- Processing activities that have relied on legitimate interest for years should be reviewed – enforcement trends show that generic or templated LIAs drawn up before GDPR came into force do not satisfy the accountability requirement.
- Data subjects have the right to object to processing based on legitimate interest. Organisations must be able to demonstrate they assessed this right in the balancing test and concluded their interests were not overridden.
- Children's data and direct marketing each require particular care when legitimate interest is the proposed legal basis.
What you should do now
- Identify every processing activity in your ROPA that currently relies on legitimate interest as the legal basis.
- For each, confirm a documented LIA exists covering all three elements: purpose test, necessity test, and balancing test.
- Review any LIAs that are generic or undated – they are unlikely to withstand regulatory scrutiny.
- Ensure your privacy notice accurately describes the legitimate interest relied upon for each processing activity.
- Build LIA review into your change management process so that changes to processing activities trigger a reassessment of the legal basis.
How Priventia helps
Priventia's Controls Library includes a Legitimate Interest Assessment module that links documented LIA outputs to the applicable processing activities in the Record of Processing Activities. The Compliance Intelligence Assessment flags processing activities relying on legitimate interest where LIA documentation is absent or incomplete.