Privacy & legal
Also known as: LI, Article 6(1)(f)

Legitimate Interest

One of GDPR's six lawful bases for processing personal data (Article 6(1)(f)), available when the processing is necessary for the controller's or a third party's legitimate interests and those interests are not overridden by the data subject's rights — widely used for fraud prevention, security, and cookieless analytics.

Legitimate interest is the most flexible of GDPR's six lawful bases but also the most demanding to use correctly. Relying on it requires a Legitimate Interest Assessment (LIA) that runs a three-part test: is there a genuine legitimate interest pursued; is the processing necessary to achieve that interest (not whether it is convenient, whether it is needed); and do the data subject's rights and freedoms override that interest on balance. All three must be answered in favor of processing. LI cannot be used for special-category data, cannot be invoked by public authorities for their public tasks, and cannot dodge the principle of transparency — the LIA must be documented and surfaced in the privacy notice. Classic legitimate-interest use cases: fraud prevention, network and information security, direct marketing to existing customers (within limits), and cookieless analytics where the processing is low-risk and proportionate. Because cookieless analytics does not store or access information on the user's device, the ePrivacy consent requirement does not trigger, and GDPR's legitimate interest basis is available without a banner.

Examples

  • A bank relying on legitimate interest to run anti-fraud pattern detection on transaction logs.
  • A privacy-first analytics tool documenting LI as its lawful basis for cookieless visitor counts.

Related terms