Imagine that you own a small online store that sells homemade chocolates. Your website collects personal information from customers, such as their names, addresses, and email addresses, to process their orders and provide customer support.
One day, you decide to start sending promotional emails to your customers to inform them about new products and special deals. However, you're not sure if you have a legitimate interest in processing their personal data for this purpose.
The General Data Protection Regulation (GDPR) provides six lawful bases for processing personal data, one of which is the concept of legitimate interest. This means that you can process personal data if you have a legitimate interest in doing so, provided that the processing is necessary and does not infringe on the rights and freedoms of the individuals concerned.
The concept of legitimate interest allows organizations to process personal data without obtaining explicit consent from individuals. However, Recital 47 of the GDPR emphasizes that individuals reasonably expect their data to be processed only for specific purposes consistent with their relationship with the data controller. Suppose the processing purpose is not within the reasonable expectations of the individuals at the time of data collection and would infringe upon their rights and freedoms. In that case, it cannot be considered a valid basis for processing.
Some examples of processing activities that may constitute legitimate interest are:
- We are processing personal data for fraud prevention or intragroup transfer of personal data.
- It sends emails to existing donors through a charity that provides updates on its activities and details of upcoming events.
- An e-commerce company may rely on legitimate interests to remember the items you have added to your shopping cart.
- A supermarket is installing CCTV cameras to prevent theft.
Limitations and Considerations for Legitimate Interest Processing
While legitimate interest is a lawful basis for processing personal data under the GDPR, organisations must be aware of several issues when relying on this basis.

Firstly, it can be challenging to establish whether there is a legitimate interest in processing personal data and whether that interest outweighs the rights and freedoms of the individuals concerned. This requires a thorough assessment of the specific circumstances and consideration of the potential risks and benefits of the processing.
Secondly, legitimate interest is not an absolute right, and organizations must ensure that the processing is necessary and proportionate to the legitimate interest being pursued. If there are less intrusive means of achieving the same objective, the organization must use them instead of processing personal data.
Individuals also have the right to object to processing their data based on legitimate interest. To address these issues, organizations that rely on legitimate interest must conduct a legitimate interest assessment (LIA) before processing the personal data. By conducting an LIA, organizations can demonstrate their legitimate interest and ensure that their processing activities are lawful, fair, and transparent. It also helps data controllers comply with the accountability principle of GDPR.
How do you think you could conduct a legitimate interest assessment?
The Legitimate Interests Assessment (LIA) involves a three-part test. These include:
1. Identifying a Legitimate Interest
2. Carrying out the necessary Test
3. Carrying out the balancing Test
Stage 1: Identify a Legitimate Interest
(i) To understand the purpose of processing Personal Data and why it is essential to process such personal data. Once the purpose is identified and based on the controller's objectives, the same should be communicated to the data subjects in clear words.
(ii) LIA about the controller and a third party— Legitimate Interests can be those of the Controller or a Third Party to whom the personal data may be disclosed.
(iii)There can be one legitimate interest for multiple parties in processing personal data;
You are obliged to identify only one Legitimate Interest. Controller’s legitimate interest covers only its relevant processing and the disclosure of personal data.
(iv) A Third Party would have to conduct its own LIA for its own processing purposes.
Stage 2: Carry out a Necessity Test
(i) The necessity test is to identify whether the processing of Personal Data is “necessary” to pursue its commercial or business objectives.
(ii) Necessary term is described as neither “indispensable" nor as "ordinary”.
(iii) An important question is to ask if there is another way of achieving the identified interest?”
(iv) If there isn’t, then clearly, the processing is necessary;
(v) If there is another way, but it would require disproportionate effort, then you may determine that the processing is still necessary; or
(vi) If the objective can be achieved in multiple ways, then a Data Protection Impact Assessment (DPIA) should be conducted to identify the least intrusive processing activity.
Stage 3: Carry out a Balancing Test
(i) Balancing tests will be passed only if the processing of personal data has been evaluated. 
(ii) Evaluation is such that the rights and freedom of individuals do not override the controller’s legitimate interest.
(iii) Several factors to consider when deciding whether an individual’s rights would override a Controller’s Legitimate Interest are:
(iv) The nature of the interests- The nature of the interests is dependent on these three criteria:
The reasonable expectations of the individual—Would the data subject expect the processing to take place, and if they do, how much impact has already been considered by them and accepted? If they have fewer expectations, the effect is more significant and has more weight in the balancing test.
The type of data—To identify which category of data the organization is processing, is it data relating to a child or a special category? Sensitive data is subject to stricter rules on its use.
The nature of the interests of the Controller- The interest of the controller may be multiple:
Can it be of public interest?
Interests of the individual?
Does it add value or convenience?
Is there any unwarranted harm to an individual? rights or freedom?
(v) The impact of processing-
What are the impacts on the individual, and is there any bias or prejudice against the Controller, Third Party, or society for not conducting the processing?
Can it be of public interest?
Likelihood of impact on the individual and the severity of that impact. Do you think it's justified? Is there any likelihood of unwarranted harm occurring to any individual?
What is the status of the individual – a customer, a child, an employee, or another,
What is the status of the Controller - such as, whether a business organization is in a dominant market position,
What are how data are processed?
(vi) Any safeguards that can be adopted- A range of compensation controls or measures
maybe put in place. Control will assist in protecting the individual or reduce
any risks of processing. Data Protection Impact Assessment conducted about
the proposed activity may identify risks associated with processing.

