Skip to content
+370 5 212 1506 info@dat.lt

Legitimate interest: when it is enough and when it is not

24 September 2026 · Good to know

Legitimate interest is enough when three conditions are met: you have a specific, legitimate interest, the processing is genuinely necessary for it, and the person’s interests and rights do not override it (Article 6(1)(f) GDPR). The EDPB advises making the assessment before processing starts and writing it down, because the controller must be able to demonstrate compliance (Article 5(2) GDPR). Legitimate interest is not enough when the law requires consent, for example for electronic marketing to individuals, when special category data is processed and no Article 9(2) GDPR exception applies, and when a public authority processes data in performing its tasks.

Legitimate interest is often chosen because it looks like the easiest basis: no consent, no contract. That is exactly why it fails most often. Our partners at Privacio (in Lithuanian) explain step by step how to run the balancing test. Here we cover when this basis is enough, where it does not work, and what happens when it is relied on without grounds.

What the law requires

Article 6(1)(f) GDPR allows processing that is necessary for the legitimate interests of the controller or a third party, except where the person’s interests or fundamental rights and freedoms override them. In particular where that person is a child.

The European Data Protection Board (EDPB), in its Guidelines 1/2024 on legitimate interest (version of 8 October 2024, published for public consultation), calls these three cumulative conditions. It is not a final document, so we use it as the EDPB’s position, not as a binding rule. The interest must be lawful, precisely articulated and present, not hypothetical. Processing is not necessary if the same purpose can reasonably be achieved just as effectively in a less intrusive way. Then legitimate interest cannot be relied on.

Two more duties follow from the Regulation. The controller must be able to demonstrate compliance with the principles (Article 5(2) GDPR). That is why the EDPB says the assessment should be made at the outset and documented. And the privacy notice must state which legitimate interest is pursued (Article 13(1)(d) GDPR). Writing just “legitimate interest” is not enough.

Recital 47 GDPR gives guidance on how to assess. What matters is whether the person, at the time the data is collected, can reasonably expect such processing. If they do not, their interests may override yours.

Example: a phone number on a blocking list

A client asked whether it could keep a phone number or email address on a blocking list after a user deletes their account. The purpose was clear: to stop a person removed for abuse from registering again.

Our answer: yes, based on legitimate interest. Recital 47 GDPR gives processing to the extent strictly necessary for preventing fraud as an example of a legitimate interest. If the abuse is not fraud (for example harassment or spam), the interest can still be legitimate, but the assessment must justify it. Either way, only on conditions:

  • prepare and keep a written legitimate interest assessment;
  • keep as little as possible: ideally not the number itself but its hash value, with no profile. A hash is still personal data, because it can be linked back to the person (Recital 26 GDPR), so the other conditions still apply;
  • use it only for this purpose, not for marketing;
  • set a retention period and delete afterwards. The period must be justified by the purpose. If the list is also used to bring or defend possible damages claims, the period can be linked to the limitation period: such claims have a three-year limitation period (Article 1.125(9) CK);
  • say so in the privacy notice.

This example shows the limit well. The EDPB stresses that fraud prevention is not an automatic permission. The controller must name the specific abuse it wants to prevent and the data it needs for that. A generic phrase such as “to combat fraud” in the privacy notice is not sufficient. If the full profile of the deleted account were kept instead of a hash of the number, the same interest would no longer justify it.

When legitimate interest is not enough

Electronic marketing to individuals. Sending marketing messages by email or SMS is allowed only with the recipient’s prior consent (Article 81(1) ERĮ). The only exception for individuals is using email contact details obtained from your own customer in the course of selling goods or services, for marketing your own similar products or services. The contacts must have been obtained in line with the GDPR, and the customer must be given a clear, easy way to object at no cost, when the data is collected and in every message (Article 81(2) ERĮ). Under the wording of Article 81 ERĮ in force since 22 April 2026, where the recipient is a legal person, consent is not needed, but an opt-out at no cost must be offered (Article 81(1) ERĮ). The EDPB says that where the law requires consent, legitimate interest cannot be relied on. We cover this in more detail in our article on direct marketing by email and SMS.

A similar question arises when customer email addresses are passed to an advertising platform to build audiences. This is not prohibited, but you need a legal basis, information in the privacy notice, an entry in the records of processing and a contract with the platform. Most importantly, a person can object to direct marketing at any time, and the data is then no longer processed for that purpose (Article 21(2) and (3) GDPR).

Special category data. Processing health, biometric and other special category data is prohibited (Article 9(1) GDPR), unless one of the exceptions in Article 9(2) GDPR applies. Legitimate interest does not lift this prohibition. You need both a basis under Article 6 GDPR and a separate exception under Article 9(2).

Public authorities. Public authorities cannot rely on legitimate interest when they process data in performing their tasks (Article 6(1), second subparagraph, GDPR). Their basis must come from the law.

When the law requires the processing. Then the basis is a legal obligation, not legitimate interest. The EDPB says so for fraud prevention too: where the law specifically requires the processing, Article 6(1)(c) GDPR applies.

What happens when it is relied on without grounds

The first risk is an objection. Where processing is based on legitimate interest, the person can object at any time on grounds relating to their particular situation. The controller must then stop, unless it demonstrates compelling legitimate grounds that override the person’s interests, or the data is needed to establish, exercise or defend legal claims (Article 21(1) GDPR). The burden of proof is on you, not on the person. If there is no assessment, you end up writing one in a hurry within the response deadline, and it usually reads like an excuse.

The second risk is an inspection or a complaint. VDAI asks what the processing is based on. An assessment that was never written down proves nothing, and Article 5(2) GDPR puts the burden on the controller. Breaches of the lawfulness rules fall into the highest fine band: up to 20 million euros or, for an undertaking, up to 4 % of total worldwide annual turnover of the preceding financial year, whichever is higher (Article 83(5)(a) GDPR).

The third risk is a basis that is wrong in substance. If legitimate interest was chosen for marketing that needs consent, no assessment can fix it. The processing has to stop, and individuals’ contacts can be used for marketing again only with their consent or, for your own customers, under the conditions of Article 81(2) ERĮ. When consent is valid, and when it is not, is covered in Consent under the GDPR: when you need it and when it is invalid.

For why consent almost never works in employment, and when legitimate interest helps instead, see our article on employee consent.

When to call a lawyer

  • when you base monitoring, profiling or long data retention on legitimate interest;
  • when the processing involves children, employees or special category data;
  • when you want to use data for marketing or pass it to an advertising platform;
  • when a person has objected or VDAI has asked you to justify your legal basis;
  • when you are not sure whether your organisation counts as a public authority.

Frequently asked questions

Does the legitimate interest assessment have to be in writing?

The GDPR does not use the word “in writing”, but the controller must be able to demonstrate compliance (Article 5(2) GDPR). The EDPB says the assessment should be made before the processing starts and documented. In a dispute, an assessment that was never written down cannot be proved, so in practice it is as if it never existed.

Can we send a newsletter based on legitimate interest?

To individuals by email or SMS, usually not, because Article 81 ERĮ requires prior consent. The exception is email contact details obtained from your own customers when selling goods or services, used to market your own similar products or services, provided the customers can easily object at no cost. For legal persons, consent is not needed, but an opt-out at no cost must be offered.

What should we do when someone objects to the processing?

Stop processing their data, unless you can demonstrate compelling legitimate grounds that override their interests, or the data is needed to establish, exercise or defend legal claims. If the objection is to direct marketing, there are no exceptions: the data is no longer processed for that purpose.

Can a state or municipal body rely on legitimate interest?

No, not when it processes data in performing its tasks. Article 6(1), second subparagraph, GDPR says so directly. In that case the basis must be a function set by law or a legal obligation.

How to start

List the processing activities for which you currently rely on legitimate interest, and send us your existing assessments and privacy notice. We will tell you where this basis is enough, where you need another one and which assessments are missing.

You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).

Email: info@linden.lt

More about this service: GDPR audit, compliance documents and consultations.

Get a free assessment

Related articles