Article 6(1)(f) GDPR · EDPB Guidelines 1/2024

Legitimate Interest Under GDPR: The Three-Part Test Explained

Grounded in Regulation (EU) 2016/679 and EDPB Guidelines 1/2024 · Last reviewed 2026-07-22

Legitimate interest is one of the six lawful bases for processing personal data under Article 6(1)(f) GDPR. It lets a controller process data without consent when it can show a real interest, that the processing is necessary for it, and that this interest is not outweighed by the individual’s own rights and freedoms. It is also one of the most misapplied bases in practice — this guide walks through the exact three-part test, using the European Data Protection Board’s own 2024 guidance on it.

Key facts at a glance

Legal basis
Article 6(1)(f), Regulation (EU) 2016/679
Cumulative conditions
3 — legitimate purpose, necessity, balancing
Not available to
Public authorities acting in the performance of their tasks
Key guidance
EDPB Guidelines 1/2024 on Art. 6(1)(f) GDPR (version 1.0, adopted 8 October 2024)
Right to object
Art. 21(1) case-by-case; Art. 21(2) unconditional for direct marketing
Status of guidelines
Adopted for public consultation; EDPB guidelines are interpretative, not binding law

On this page

  1. What legitimate interest is
  2. The exam trap: vs. consent
  3. The three-part test
  4. Do you need a documented assessment?
  5. Direct marketing
  6. The right to object
  7. Children’s data
  8. FAQ

What is legitimate interest under the GDPR?

Legitimate interest (Article 6(1)(f)) is a lawful basis that lets a controller process personal data where it — or a third party — has a genuine interest in doing so, the processing is necessary for that interest, and this is not overridden by the data subject’s own interests, rights and freedoms. Recital 47 gives examples of interests that can qualify, including fraud prevention and, in some circumstances, direct marketing. One express carve-out is built into Article 6(1)(f) itself: it does not apply to processing carried out by public authorities in the performance of their tasks — they need a different legal basis, such as a legal obligation or public task (see our complete guide to the six lawful bases).

No, not automatically — and industry commentary on this exact question is one of the most consistently republished pieces of GDPR content, because the wrong answer is such a common compliance mistake. Legitimate interest and consent are two separate, non-hierarchical lawful bases; neither is a "backup" for the other. If a specific rule requires consent for a particular processing activity — for example, the ePrivacy Directive’s consent requirement for marketing emails and non-essential cookies — you cannot substitute legitimate interest to avoid asking. Where no such specific consent requirement applies, legitimate interest is only valid if it independently passes all three conditions below; it is not a shortcut for situations where consent would be inconvenient to obtain.

Legitimate interestConsent
No opt-in needed; the controller does the assessmentRequires a freely given, specific, informed, unambiguous opt-in (Art. 4(11))
Data subject can object at any time (Art. 21)Data subject can withdraw at any time, as easily as it was given (Art. 7)
Burden is on the controller to justify and document the testBurden is on the controller to prove consent was validly obtained
Cannot be used where a law specifically requires consentSometimes the only basis a specific law allows (e.g. marketing emails)

What is the GDPR legitimate interest balancing test?

The balancing test is the third of three cumulative conditions that all must be met before legitimate interest can be relied on, as set out in EDPB Guidelines 1/2024.

1. Purpose test

Is there a legitimate interest at all? The EDPB guidelines say only interests that are lawful, clearly and precisely articulated, and real and present qualify — a vague or generic interest ("business purposes") is not enough.

2. Necessity test

Is the processing actually necessary to achieve that interest? If the same purpose could reasonably be achieved by a less intrusive means, legitimate interest cannot be relied on for the more intrusive option.

3. Balancing test

Do the data subject’s own interests, rights and freedoms override the controller’s interest? The EDPB guidelines (para. 32) say the controller must weigh:

Only if the outcome favours the controller — including after considering any extra safeguards, such as stronger anonymisation — can the processing go ahead on this basis.

See how this is tested in practice

Lawful bases are a heavily tested GDPR topic. Practise recognising legitimate interest, consent and the other bases in realistic multiple-choice questions.

Start free Try 30 questions free — no time limit, no credit card.

Do you need a documented Legitimate Interests Assessment?

The GDPR does not use the term "LIA," but EDPB Guidelines 1/2024 (Executive Summary) say controllers "should carefully assess and document" whether the three conditions are met, before the processing starts. This documentation duty flows from the accountability principle in Article 5(2) GDPR: a controller must be able to demonstrate compliance, not just achieve it. "LIA" (Legitimate Interests Assessment) is simply the practitioner shorthand that has grown up around this documented three-part test; calling it something else does not remove the underlying obligation to assess and record it before relying on Article 6(1)(f).

Can legitimate interest be used for direct marketing?

Sometimes, but the GDPR does not give direct marketing a free pass: Recital 47 says it "may be regarded as carried out for a legitimate interest," while EDPB Guidelines 1/2024 stress this does not mean legitimate interest is automatically available for every marketing activity. In practice, the ePrivacy Directive usually requires prior consent for marketing by email, SMS and similar electronic messages, which rules out legitimate interest for those channels — except for a narrow "soft opt-in": a business may email its own existing customers about similar products, provided they were told about this at collection and can opt out easily, free of charge, every time (Art. 13(2) ePrivacy Directive). Where legitimate interest can apply, the EDPB notes that intrusive practices — such as tracking individuals across multiple sites or devices for ad targeting — are unlikely to survive the balancing test, while lower-intrusion activities, like mailing a catalogue to existing customers who bought similar products, are more defensible.

Does the right to object apply to legitimate interest processing?

Yes, and the GDPR gives two different strengths of objection depending on the purpose. Under the general right to object (Article 21(1)), a data subject can object "on grounds relating to his or her particular situation," and the controller must stop unless it can show "compelling legitimate grounds" that override the individual’s interests — a higher bar than the original balancing test, and one the EDPB guidelines say cannot be satisfied just by re-running the same assessment. For direct marketing specifically (Article 21(2)–(3)), the right to object is unconditional: no reasoning is required from the data subject, no counter-balancing is available to the controller, and processing for that purpose must stop.

Can legitimate interest be used to process children’s data?

Only with extra caution: Article 6(1)(f) itself singles out children as a factor that can tip the balance against the controller, "in particular where the data subject is a child." The EDPB guidelines add that children merit specific protection because they may be less aware of the risks, consequences and safeguards involved, and that this protection applies in particular to processing for marketing, profiling, or services aimed directly at children (Recital 38; CJEU, Meta v. Bundeskartellamt, C-252/21). This does not rule out legitimate interest for processing involving children, but it substantially raises what the balancing test has to show.

Preparing for a DPO / GDPR certification exam?

GDPR Exam Trainer turns material like this into hundreds of practice questions, chapter training and a timed exam simulation, with AI explanations for every answer.

Create your free account No in-person course required · Cancel anytime.

Frequently asked questions

Can a company use legitimate interest instead of asking for consent?

Sometimes, but only if all three conditions of Article 6(1)(f) are met — and if another rule specifically requires consent (such as the ePrivacy Directive’s consent requirement for marketing emails and cookies), legitimate interest cannot be used instead. If consent is legally required for the specific processing, choosing legitimate interest to avoid asking is not a lawful workaround.

What is the GDPR legitimate interest balancing test?

It is the third of three cumulative conditions under Article 6(1)(f): after confirming a legitimate interest exists and the processing is necessary, the controller must weigh that interest against the data subject’s own interests, rights and freedoms, taking into account the impact of the processing and the data subject’s reasonable expectations (EDPB Guidelines 1/2024, para. 32).

Do I need a documented Legitimate Interests Assessment (LIA)?

The GDPR itself does not use the term "LIA" — that is the common practitioner label — but the EDPB guidelines say controllers "should carefully assess and document" whether the three conditions are met (Executive Summary), and the accountability principle in Article 5(2) requires you to be able to demonstrate that assessment on request.

Can legitimate interest be used for direct marketing?

Recital 47 says direct marketing "may be regarded as carried out for a legitimate interest," but this is not automatic: for marketing emails, SMS and similar electronic messages, the ePrivacy Directive normally requires prior consent instead, subject to a narrow "soft opt-in" exception for a business’s own existing customers marketing similar products (Article 13(2) ePrivacy Directive). Where legitimate interest can apply, the full three-part test still has to be passed.

Does the right to object apply to processing based on legitimate interest?

Yes, in two different forms. Under the general right to object (Article 21(1)), you can object on grounds relating to your particular situation, and the controller must stop unless it demonstrates "compelling legitimate grounds" that override your interests. For direct marketing specifically (Article 21(2)), the right to object is unconditional: no balancing, no justification needed, and the controller must stop.

Can legitimate interest be used to process a child's data?

Article 6(1)(f) itself names children explicitly as a factor that can tip the balance against the controller ("in particular where the data subject is a child"). The EDPB guidelines add that children need specific protection because they may be less aware of the risks involved, especially for marketing, profiling or services aimed directly at them.

Primary sources

This guide summarises the GDPR and EDPB Guidelines 1/2024 for study and general information. EDPB guidelines are interpretative guidance, not binding legislation, and the version cited here was adopted for public consultation. This is not legal advice; article numbers and thresholds are simplified for clarity. For a binding interpretation, consult the official text on EUR-Lex, the EDPB, your competent supervisory authority, or a qualified data protection lawyer.