Home / Data Protection Guidance and Insights / When Can a UK Organisation Rely on Legitimate Interests?

When Can a UK Organisation Rely on Legitimate Interests?


Legitimate interests is flexible, but organisations must be able to explain the purpose, show that the processing is necessary and assess the effect on the people whose information is used.

Did you know? The Data (Use and Access) Act 2025 introduced a separate recognised legitimate interest lawful basis for a limited number of public-interest purposes. It is not a shortcut for ordinary commercial processing.

Legitimate interests can be a useful lawful basis when an organisation has a genuine reason for using personal information, the processing is necessary for that purpose, and the impact on people is properly considered. It is flexible, but it is not a default option to use when another lawful basis is inconvenient.


What is the legitimate interests lawful basis?

Legitimate interests is one of the lawful bases available under the UK GDPR. It may support processing for a reasonable business, third-party or wider societal purpose, provided the organisation can satisfy the required three-part test. The assessment must be specific to the activity rather than a broad statement that the processing is in the organisation’s interests.


The three-part test

Before relying on legitimate interests, work through all three parts of the test:

  1. Purpose test: identify the legitimate interest and explain the benefit you are trying to achieve.
  2. Necessity test: decide whether using the personal information is genuinely necessary. If a less intrusive method would achieve the purpose reasonably well, this part of the test may not be met.
  3. Balancing test: consider whether the person’s interests, rights or freedoms override the interest you have identified.

The balancing exercise should consider the nature of the information, the relationship with the person, their reasonable expectations, possible harm or loss of control, whether children or vulnerable people are involved, and the safeguards you can put in place.


When might legitimate interests be appropriate?

It may be appropriate where the processing is reasonably expected, has a limited privacy impact and there is a clear justification. Examples can include proportionate fraud prevention, network and information security, some intra-group administration and some direct marketing activity. The facts still matter, and separate PECR rules may apply to electronic marketing.


When is it less likely to be appropriate?

  • People would not reasonably expect the processing or are likely to find it intrusive.
  • The purpose could be achieved through a less privacy-invasive method.
  • The organisation cannot explain a real and specific benefit.
  • The processing involves children, vulnerable people or information that could cause significant harm without strong safeguards.
  • The proposed use conflicts with what people were told when their information was collected.


How should an organisation document an LIA?

A legitimate interests assessment (LIA) is the practical record of your decision. Complete it before the processing starts and record the evidence both for and against relying on the basis. The document should identify the activity, purpose, necessity, balancing factors, safeguards, outcome, owner, approval date and review date.


If the assessment identifies a high risk to people, an LIA may not be enough on its own. You should consider whether a data protection impact assessment is also required.


What is recognised legitimate interest?

Recognised legitimate interest is a separate lawful basis introduced by the Data (Use and Access) Act 2025 for a limited list of pre-approved public-interest purposes. Where its conditions are met, there is still a necessity test but no additional balancing test. It should not be confused with the ordinary legitimate interests basis used for many commercial activities.


Review the decision when circumstances change

An LIA is not a one-off document. Review it if the purpose changes, new information is collected, the technology or recipients change, complaints are received, people object, or the impact becomes more significant. Make sure the privacy notice accurately identifies legitimate interests and explains the interests pursued.


For further detail, see the ICO’s current legitimate interests guidance.

Frequently asked questions


Is an LIA legally required?

The UK GDPR does not prescribe a particular LIA form. However, the three-part test must be satisfied and organisations should document their reasoning to demonstrate accountability.


Can legitimate interests be used for direct marketing?

Potentially, yes. Direct marketing may be a legitimate interest, but the balancing test still matters and PECR may require consent or another applicable permission for the communication itself.


Do we need a separate LIA for every activity?

The assessment must be specific enough to reflect the purpose, data, people affected and risks. Similar low-risk activities may sometimes be assessed together, but a generic organisation-wide statement is unlikely to be sufficient.


What happens if someone objects?

You must consider the objection and stop processing unless you can demonstrate compelling legitimate grounds that override the person’s interests, rights and freedoms, or the processing is needed for legal claims. Direct marketing must stop when someone objects.

Written by Clara Westbrook, solicitor and founder.


Speak to our team

This is a photo of alexander hazell, a data protection consultant at westbrook data protection services

Alexander Hazel

Consultant

Our team have a deep understanding of the following areas of law and continue to add value to our clients’ businesses.


Latest Insights