Legitimate interest is the most flexible lawful basis in GDPR, and the one teams get wrong most often. It's tempting because it doesn't need a consent banner or a signed contract. You decide you have a good reason to process someone's data, and you proceed. But that flexibility comes with a condition most people skip: you have to run a legitimate interests assessment first, and you have to be able to show it.

An LIA isn't a formality. It's the record that proves you weighed your interest against the rights of the people whose data you're using, and concluded you could go ahead. Without it, "legitimate interest" is just a phrase you wrote in a policy. This guide covers what the basis is, the three-part test that backs it up, when to use it instead of consent, and how to keep the assessment as living evidence in OptiTech.

What legitimate interest actually is

GDPR gives you six lawful bases for processing personal data, and every processing activity needs at least one. Consent and contract are the two most people know. Legitimate interest is the sixth, set out in Article 6(1)(f), and it's the broadest.

It lets you process personal data when you have a genuine, specific reason and that reason isn't overridden by the interests or fundamental rights of the individual. Think fraud detection, network security, direct marketing to existing customers, or sharing data within a group of companies for internal administration. These are cases where asking for consent would be impractical, or where a contract doesn't quite fit, but you still have a real and defensible need.

The catch is accountability. Because you're the one deciding your interest is legitimate, the burden is on you to prove it. That proof is the LIA.

The three-part test

A defensible LIA works through three questions in order. If you can't clear all three, legitimate interest isn't your basis and you need to look elsewhere.

The purpose test

First, is there a legitimate interest at all? Name it specifically. "Improving the business" is too vague to defend. "Detecting fraudulent transactions to protect customers and reduce chargebacks" is a real purpose you can stand behind. The interest can be yours, a third party's, or the wider public's, and it can be commercial. It just has to be genuine and clearly articulated.

The necessity test

Second, is the processing actually necessary to achieve that purpose? Necessary doesn't mean convenient. If you could reach the same result with less personal data, or without processing personal data at all, then the processing isn't necessary and the basis fails. This is where data minimization does real work: you're checking that the data you use is the least you need for the job.

The balancing test

Third, do your interests override the rights and freedoms of the individual? This is the heart of the LIA. You weigh your interest against the impact on the person: what they'd reasonably expect, how intrusive the processing is, whether it involves children or sensitive data, and whether they can easily opt out. If a reasonable person would be surprised or uncomfortable, the balance may tip against you. Safeguards, like clear notice and an easy way to object, can shift it back.

Teams often default to consent because it feels safe. It isn't always. Consent must be freely given, specific, informed, and as easy to withdraw as it is to give. If people can't realistically say no, or you'd keep processing after they withdraw, then consent is the wrong basis, and using it anyway is worse than not having one.

Legitimate interest fits when processing is low-risk, within what people would expect, and you're prepared to take responsibility for the judgment. Consent fits when the processing is genuinely optional and the person should be in control, like marketing to someone who has no existing relationship with you, or anything involving special category data. Pick the basis that matches reality, not the one that's least effort to set up.

You can't switch bases mid-stream

Choose your lawful basis before you start processing and stick with it. If you claim legitimate interest and then fall back on consent when someone objects, you've undermined both. The LIA is how you commit to the right basis up front.

Documenting the LIA

Accountability under GDPR means you demonstrate compliance, not just assert it. For legitimate interest, the LIA is that demonstration. It should record the purpose you identified, why the processing is necessary, how you weighed the balance, the safeguards you put in place, and the date you reached the decision.

Documentation also protects you over time. Circumstances change: a purpose expands, a new data source appears, a processing activity starts touching more sensitive information. A dated LIA tells you what you decided and on what facts, so you know when it's time to reassess. An assessment done once and forgotten is nearly as weak as no assessment at all.

The rights that still apply

Choosing legitimate interest doesn't lower your obligations to the individual. Several rights apply with particular force.

The right to object is the big one. When you rely on legitimate interest, people can object to the processing, and you have to stop unless you can show compelling grounds that override their interests. For direct marketing, the objection is absolute: if someone objects, you stop, no exceptions.

The right to be informed also matters more here. You have to tell people you're relying on legitimate interest and name the interest, usually in your privacy notice. People can't exercise a right to object they don't know they have. The usual rights to access, rectification, and erasure apply as they would under any basis.

Attaching the LIA to a processing activity in OptiTech

An LIA is only useful if it's connected to the thing it justifies. In OptiTech, each processing activity in your record links to its lawful basis, and when that basis is legitimate interest, you attach the LIA to the activity as evidence.

That connection does a few things at once. Anyone reviewing the processing activity in the OptiTech Console can see the basis and open the assessment behind it, so the reasoning travels with the record instead of living in someone's inbox. When you review your program, activities relying on legitimate interest are easy to find and reassess. And when a customer or an auditor asks how you justify a particular use of data, the answer is attached to the activity, dated and complete, rather than reconstructed under pressure.

The same evidence feeds your trust center. A buyer running a security review can see that your legitimate interest claims are backed by real assessments, which turns a hard question into a short one.

Getting started

You don't need to assess everything at once. A sensible first pass looks like this:

  1. List the activities that rely on legitimate interest today. Marketing to existing customers and security monitoring are common starting points.
  2. Run the three-part test on each and write down purpose, necessity, and balance.
  3. Attach each LIA to its processing activity in OptiTech so the basis and the evidence stay together.
  4. Set a review cadence so assessments get revisited when the processing or the risk changes.

Legitimate interest rewards teams who treat it as a judgment they can defend, not a shortcut around consent. Do the assessment, write it down, and keep it connected to the work it justifies.

Ready to keep your lawful bases and their evidence in one place? Book a demo and see how OptiTech attaches an LIA to the processing activity it justifies.