Legitimate interest is the most flexible of GDPR's six lawful bases but also the most demanding to use correctly. Relying on it requires a Legitimate Interest Assessment (LIA) that runs a three-part test: is there a genuine legitimate interest pursued; is the processing necessary to achieve that interest (not whether it is convenient, whether it is needed); and do the data subject's rights and freedoms override that interest on balance. All three must be answered in favor of processing. LI cannot be used for special-category data, cannot be invoked by public authorities for their public tasks, and cannot dodge the principle of transparency — the LIA must be documented and surfaced in the privacy notice. Classic legitimate-interest use cases: fraud prevention, network and information security, direct marketing to existing customers (within limits), and cookieless analytics where the processing is low-risk and proportionate. Because cookieless analytics does not store or access information on the user's device, the ePrivacy consent requirement does not trigger, and GDPR's legitimate interest basis is available without a banner.