Back to the hub

GDPR legitimate interests: when can you rely on it?

Legitimate interests is one of the six Article 6 lawful bases. Under Article 6(1)(f) you may process personal data where it is necessary for interests pursued by you or a third party, unless the individual's rights override them. It needs a documented balancing test and does not apply to public authorities' tasks.

Applies to: Controllers considering legitimate interests as the lawful basis for a processing activity under the GDPR, other than public authorities acting in the performance of their tasks.

Find out what applies to you

Run the free 2-minute Obligation Scan and get a plain-language list of what your business has to do, and by when.

Run the free 2-minute Obligation Scan

Founding 30% off with code FOUNDING until 15 August 2026

Legitimate interests is the most flexible of the six lawful bases, and the most misunderstood. It is not a fallback you reach for when nothing else fits, and it is not a free pass. Article 6(1)(f) lets you process personal data for interests you or a third party hold, but only after you have weighed those interests against the rights of the person whose data it is, and only where you can show the processing is genuinely necessary.

What does Article 6(1)(f) actually say?

Processing is lawful under Article 6(1)(f) where it is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the data subject, in particular where the data subject is a child. The article closes with an important limit: it does not apply to processing carried out by public authorities in the performance of their tasks. A public body cannot lean on legitimate interests for its official functions and has to find another basis.

How the balancing test works

The standard way to operationalise Article 6(1)(f) is a three-part assessment, often called a legitimate interests assessment. First, name the interest: it has to be real and specific, such as preventing fraud, keeping a network secure, or contacting existing business customers. Second, show necessity: the processing must actually achieve that interest, and there must be no less intrusive route. Third, balance it. Recital 47 frames this around the data subject's reasonable expectations based on their relationship with you, for example where they are a client or in your service. If a person would be surprised or harmed by the processing, the balance tips against you. Do the assessment before you start, and write it down.

Where SaaS companies use it

Legitimate interests typically supports security and fraud prevention, some product analytics, network and information security, internal administration across a corporate group, and business-to-business outreach. It rarely fits things people would not expect, such as selling data to third parties or intrusive profiling that produces significant effects, and it cannot carry special category data, which needs a separate Article 9 condition. For the core service a customer signed up for you usually rely on contract instead, and for marketing emails and non-essential cookies you usually need consent. Legitimate interests is one basis among several, and one product often uses several across its different activities.

The right to object

Choosing legitimate interests carries a condition the other bases do not. Under Article 21(1) a person can object on grounds relating to their particular situation, and you must stop unless you show compelling legitimate grounds that override their interests, or you need the data for legal claims. For direct marketing the right is absolute: Article 21(2) lets a person object at any time, and once they do you must stop processing their data for that purpose. Record your reliance on legitimate interests in your record of processing activities and explain it in your privacy notice, so the basis is visible and the objection routes are clear.

Next step

If you already know the GDPR applies to you, legitimate interests is worth getting right because it is where a lot of everyday processing sits. The free 2-minute Obligation Scan flags which activities you are resting on legitimate interests, where a balancing test is missing, and where consent is really the safer basis. The GDPR compliance hub sets out the wider duties.

Compliance checklist

  • Write down the specific legitimate interest, yours or a third party's, that the processing serves.
  • Confirm the processing is necessary for that interest and that no less intrusive route achieves it.
  • Balance the interest against the person's rights, freedoms and reasonable expectations, and record the outcome.
  • Do not rely on legitimate interests if you are a public authority carrying out your tasks; use another basis.
  • Honour objections: stop on an Article 21(1) objection unless compelling grounds override, and always stop for direct marketing under Article 21(2).

Sources

Last verified: 2026-08-13

Informational, not legal advice.