Skip to content

Legitimate Interests vs Consent Under EU GDPR: How to Choose

Legitimate interests vs consent under EU GDPR: apply purpose, necessity and balancing tests, check ePrivacy rules, and record why the chosen basis fits.

An isometric balance holds an open interest route against safeguard weights and a separate permission gate.
By AI Priority Map Editorial

A sales team wants to email people who downloaded a pricing sheet. One colleague asks for consent; another says legitimate interests. The legitimate interests vs consent decision cannot be settled by choosing the label that feels more cautious. It starts with the exact purpose, the person's real choice, whether the activity must continue and any channel-specific law 1,2,3.

Quick Answer. For legitimate interests vs consent, use consent only for genuine choice where processing can stop. Legitimate interests requires a lawful, specific interest, necessity and a balance that favours the processing. Check ePrivacy and national channel rules separately, honour withdrawal or objection, and document the decision before processing begins 1,2,3,4.

Begin with the operation, not the preferred label

A single product can contain several processing operations. An account may need an email address to deliver login links, an audit trail to prevent fraud, analytics to improve a service and a newsletter to promote another product. Those purposes do not inherit one lawful basis merely because they share a database.

Describe each operation as a verb with an outcome: send a requested download, detect repeated failed logins, measure feature use, send a weekly offer. Name the data, people, source, recipients, timing and consequence. This prevents a broad phrase such as “customer engagement” from hiding activities with different necessity and expectations.

Processing operationFirst questionWhy it matters
Deliver a requested serviceIs processing necessary for the contract or request?Consent may falsely imply an optional choice
Prevent account fraudIs a defined interest served by necessary, proportionate processing?A legitimate-interests assessment may fit
Send promotional emailWhat do ePrivacy and national rules permit for this recipient and channel?EU GDPR alone cannot permit the message
Publish a customer storyCan the person genuinely refuse publication?Consent may fit a genuinely optional use
Keep evidence of an opt-outWhat minimum record is needed to honour the choice?Suppression is different from continued marketing

The lawful basis is selected for the defined purpose before processing begins and appears in privacy information. It is not an explanation invented when a complaint arrives. If the purpose or method changes, reassess the new operation rather than stretching the old record 1,3.

Valid consent requires a freely given, specific, informed and unambiguous indication expressed through a clear affirmative action 1,2. Each word changes the design. Bundling optional marketing into service terms is not specific. Pre-ticked boxes are not affirmative. A choice that blocks an unrelated service may not be freely given.

The decisive operational question is what happens after “no”. If the organisation will continue the activity anyway, consent is not describing reality. If refusal means a worker loses an ordinary workplace benefit, or a customer cannot buy a product that does not need the optional data, the choice may be impaired.

Consent also has to remain usable after collection. The organisation needs evidence of who consented, when, what they were told, which action they took and which purposes were covered. It needs a withdrawal route that is as easy as giving consent and reaches campaign tools, spreadsheets, agencies and future uploads 1,2.

Consent fits best where the optional choice is part of the purpose itself: publishing an identifiable customer story, enabling a non-essential feature, or sending a marketing message where applicable channel law requires consent. In each case, refusal leaves the ordinary service intact. That differs from adding a consent box to fraud prevention, payroll or another activity the organisation intends or is required to perform regardless of the answer.

Withdrawal stops future processing that depends on that consent. It does not make earlier lawful processing unlawful 1,2. This distinction matters when a campaign report already exists or a photograph was used during the consent period. The organisation stops the future activity, updates recipients where necessary and records the change; it does not rewrite history.

Legitimate interests uses a written three-part test

Article 6(1)(f) sets three cumulative conditions: pursuit of a legitimate interest by the controller or a third party, necessity of the processing for that interest, and a balance in which the person's interests or fundamental rights and freedoms do not take precedence 1,3. Current UK law also has a recognised-legitimate-interest route for specified purposes: balancing drops out, although necessity remains. EU GDPR has no equivalent. Every EU reliance on Article 6(1)(f) must therefore satisfy the ordinary three-part analysis, which is the material legal divergence between the two decisions.

Begin with an interest that is lawful, clearly and precisely articulated, real and present. Preventing fraud, securing premises or following up a genuine business enquiry may be interests. “Growing revenue” or “using our data” is too broad to expose what the processing does to people. The EDPB's 2026 case digest confirms that supervisory authorities apply this three-step framework to concrete facts rather than accepting a label 3,5.

The necessity test asks whether the processing is a targeted and proportionate way to achieve that interest. Necessary does not always mean indispensable, but a less intrusive method that works equally effectively weighs against the proposed processing. Aggregated information, a shorter period, a smaller audience or a non-tracking method may change the conclusion. The organisation must compare realistic alternatives rather than dismissing every other design as inconvenient 3.

The balancing test brings the person into the decision. Consider the nature of the data, source, relationship, reasonable expectations, scale, frequency, vulnerability, likely benefit and possible harm. An existing business contact may reasonably expect a limited response about the same request; a person whose details were copied from an unrelated public page may not expect a sustained sales sequence.

Balancing factorEvidence to capture
RelationshipCustomer, prospect, worker, visitor or no prior relationship
ExpectationWhat the collection context and relationship make reasonable
Data and sourceOrdinary contact details, observed behaviour, inferred interests or sensitive data
ImpactAnnoyance, loss of control, exclusion, financial effect or exposure
Scale and frequencyOne response, periodic service message or persistent campaign
SafeguardsNarrow audience, short retention, easy objection, human review and suppression

Safeguards can change the balance, but they do not erase a fundamentally unexpected activity. Record negative factors as well as supportive ones. An assessment that lists only business benefits is not a balancing exercise, and a privacy notice alone does not create a reasonable expectation 3.

Compare the two bases by their consequences

Consent and legitimate interests create different controls. Under consent, the organisation proves the choice and stops dependent processing after withdrawal. Under legitimate interests, it proves the three cumulative conditions, explains the interest and handles the right to object. The selection should match which set of facts is true.

Decision pointConsentLegitimate interests
Person's choiceMust be genuine and informedImpact can occur without prior agreement
Core recordConsent wording, action, time and versionInterest, necessity and balancing assessment
Main controlRefusal and withdrawal must workObjection and reassessment must work
If challengedProve valid consentProve all three cumulative conditions
FragilityChoice can be withdrawn at any timeFacts or objections can change the balance

Neither column is a shortcut. Consent is not stronger merely because a person clicked. Legitimate interests is not easier merely because no click is needed. Both depend on purpose limitation, minimisation, transparency, security, retention and rights 1,2,3.

A useful stress test is to write the rejection path. If consent is refused, does the feature still work? If a person objects to legitimate-interests processing, who receives it, what is restricted while the objection is assessed, which grounds are reconsidered and how is the outcome explained? A basis that cannot survive its own rights mechanism is not ready.

Keep the lawful basis separate from other conditions

Choosing between consent and legitimate interests answers only one part of the EU GDPR analysis. It does not decide whether the organisation may process special-category data, use criminal-conviction data, make a solely automated decision, send a message under national ePrivacy rules or transfer data internationally. Each additional condition has its own facts and record 1,3,4.

This separation prevents a common false conclusion: “the person consented, so every use is permitted.” Consent covers specified purposes described at the time of choice. It does not waive minimisation, accuracy, security or retention, and it does not silently extend to a later recipient or incompatible purpose. The same limit applies to legitimate interests.

The decision works in layers. The processing operation and purpose come first, followed by the GDPR lawful basis that genuinely fits them. Data types and automated decisions are then checked for additional GDPR conditions, while the communication channel receives its own ePrivacy and Member State analysis where relevant.

Transparency, rights, recipients, security, retention and transfer controls remain separate checks. Finally, system configuration must make refusal, withdrawal and objection produce the recorded outcome across the original application, connected services, audience exports and any processor that receives the preference.

A sales platform that infers a prospect's health condition from browsing and sends a tailored email exposes the layers clearly. A legitimate commercial interest does not answer the special-category issue. Consent to receive one newsletter does not necessarily cover the inference. A privacy notice cannot substitute for the ePrivacy analysis. Keeping those questions apart stops one positive answer from becoming permission for the whole design.

The layered record also makes later change manageable. If the team changes only the email cadence, it can locate the ePrivacy and balancing effects. If it adds inference, it opens the data-condition analysis. If it changes purpose, it returns to the basis. One broad “consent versus legitimate interests” checkbox cannot show which part moved.

ePrivacy can decide the channel first

For electronic mail and access to information on terminal equipment, the ePrivacy Directive can impose consent or another specific condition before the Article 6 basis is assessed 3,4. Member States implement the Directive through national law, so the exact rule and authority guidance must be checked for the country and recipient involved. “We use legitimate interests for marketing” is incomplete: it may describe personal-data processing while saying nothing about whether the message may be sent.

Article 13 of the Directive requires prior consent for unsolicited electronic direct marketing to subscribers, subject to a defined exception where an organisation obtained contact details from its own customer during a sale, markets its own similar products or services, and offered a clear, free and easy objection both at collection and in every message 4. National implementing rules can affect scope, including treatment of professional recipients.

If the applicable channel rule requires consent and valid consent is absent, a legitimate-interests assessment cannot repair the message. If the rule permits the message, the organisation still needs a GDPR lawful basis for processing the address and campaign data. The two analyses sit together, not in competition 3,4.

Terminal-equipment access creates the same layered problem. A lawful-basis label in a privacy policy does not make a tracker operate lawfully before any consent required under Article 5(3). The device-access rule and the legal basis for later personal-data processing must each be satisfied 3,4.

Work through one sales follow-up example

Suppose a finance manager downloads a detailed pricing guide after giving a work email address. The page promises the guide and says a specialist may answer questions. The sales team wants a three-message sequence over ten days, then to add the address to a monthly newsletter.

Split the operations. Sending the requested guide follows the request itself. A short, relevant follow-up may be assessed for necessity and reasonable expectations, but the team should not treat that conclusion as automatic. Record the relationship, wording at collection, message content, frequency, source, impact, easy objection and the applicable national channel rule 3,4.

The monthly newsletter is another purpose and cadence. If the team wants consent, the choice must be separate and optional, with no pre-ticked box. Evidence must preserve the wording and action. If consent is not obtained, the address does not enter that stream merely because the earlier follow-up passed a different assessment.

Now change one fact: the address came from a conference attendee list supplied by another organiser, and the person did not ask this business for anything. Expectations and source change sharply. The same copy and frequency may now fail the balancing or channel analysis. A template cannot replace those facts.

Withdrawal and objection need different workflows

A withdrawal request is not an invitation to choose a new label. Stop future processing that relies on the withdrawn consent, update the consent record and send the preference to systems and recipients. Keep only what is needed to demonstrate and honour the withdrawal under an independently assessed purpose 1,2.

An objection to legitimate-interests processing triggers a different decision. For general processing, the organisation restricts or stops the processing while assessing whether compelling legitimate grounds override the person's interests, rights and freedoms, or whether legal claims require continuation. The post-objection assessment must address the person's particular situation; repeating the original general balance is not enough 1,3.

Incoming signalImmediate actionRecord
Consent refusedDo not start the optional operationChoice, wording and system outcome
Consent withdrawnStop dependent future processingTime, scope, systems and recipients updated
General objectionRestrict or stop while grounds are assessedParticular situation, grounds and response
Marketing objectionStop direct-marketing processingSuppression route and campaign systems updated
New purpose proposedReassess before usePurpose, basis, notice and controls

An objection to direct marketing is absolute for processing for that purpose: the organisation cannot continue by presenting compelling grounds 1,3. Suppression is often necessary so a person is not re-imported. It should be minimal, secured and used only to respect the choice. Deleting every trace without preserving a suppression control can cause the marketing the person asked to stop.

Record one decision that another person can operate

The final record should name the operation, purpose, data, people, source, recipients, frequency, lawful basis, ePrivacy position, relevant national rule, rights path, retention and reviewer. Attach the consent evidence design or legitimate-interests assessment rather than writing “GDPR compliant” in a spreadsheet cell.

Translate the record into system behaviour. Consent fields need version and timestamp evidence. Objection routes need an owner and response process. Marketing lists need suppression before each send. Vendors need instructions that preserve the same purposes and choices.

Use a decision register rather than isolated documents. One row can identify the processing operation, owner, live systems, basis, assessment link, privacy-notice version, channel-law conclusion, rights route and next review. Supporting evidence stays attached, but the register lets a new colleague find the decision before changing a campaign.

The owner should be able to demonstrate three tests without reconstructing them from memory. First, the legal test: why the basis applies. Second, the truth test: whether the product behaves as the record says. Third, the rights test: whether a real refusal, withdrawal or objection reaches every downstream system. A policy passes only the first and sometimes not even that.

Post-launch sampling should exercise the workflow. A test contact gives no consent and the optional field must remain empty; an existing consent is withdrawn and the event is traced through the customer platform and email service; a marketing objection must affect both active campaigns and the next audience import. Evidence from these different paths proves more than a screenshot because it follows the choice through each integration.

Supplier contracts and instructions should preserve the distinction between operations. A processor should not treat every address in the platform as marketable, infer new consent from continued use or discard suppression data during routine cleanup. Where several controllers receive a choice, the wording and withdrawal route need to explain who acts and how the signal reaches them 1,2.

Review is triggered by a new data source, audience, Member State, channel, frequency, profiling method, consequence or complaint pattern. It is also triggered when evidence changes reasonable expectations. Do not wait for an annual date if the processing has already changed.

The first action is to take one proposed message and write two sentences: the exact purpose, and what happens if the person says no. If the activity must continue, do not ask for consent. If the purpose is optional but the organisation cannot stop, repair the workflow before choosing any lawful-basis label.

Last updated: 26 August 2026.

Frequently Asked Questions

Is consent safer than legitimate interests under EU GDPR?
No lawful basis is automatically safer. Consent is appropriate only when the person has genuine choice and the organisation can stop the processing if consent is refused or withdrawn. Legitimate interests can fit necessary, proportionate processing after a documented three-part assessment. The defensible basis is the one that truthfully describes the activity and consequences [1][2][3].
What is the three-part legitimate interests test?
First identify a lawful, specific, real and present interest. Then ask whether processing is necessary for that interest or a less intrusive effective method exists. Finally balance the interest against people's interests, rights and freedoms, considering impact and reasonable expectations. All three cumulative conditions must be met and documented before processing [3][5].
Can we switch from consent to legitimate interests after withdrawal?
Not simply to avoid the withdrawal. A lawful basis should be selected before processing and communicated transparently. Re-labelling the same activity after a person withdraws consent can be unfair and misleading. If circumstances create a genuinely separate purpose or operation, assess it on its own facts and update the information given to people before processing [1][2][3].
What happens when someone withdraws consent?
Future processing that depends on that consent must stop unless an independently established legal basis applies to a separate operation. Withdrawal does not make earlier lawful processing unlawful. It must be as easy to withdraw as to give consent, and the organisation needs an operational route that reaches every system and recipient relying on the choice [1][2].
What happens when someone objects to legitimate interests?
The organisation must stop unless it demonstrates compelling legitimate grounds that override the person's interests, rights and freedoms, or needs processing for legal claims. Direct marketing is stricter: an objection requires that processing for direct marketing stop. Minimal suppression may still be needed so the preference survives future audience imports [1][3].
Does legitimate interests allow marketing emails?
Not by itself. Article 6(1)(f) still requires the full three-part test, while the ePrivacy Directive and the national law implementing it may require prior consent for electronic direct marketing. The Directive contains a defined existing-customer exception with its own conditions. A legitimate-interests assessment cannot turn a prohibited message into a permitted one [3][4].
Do we need to publish our legitimate interests assessment?
EU GDPR does not generally require publication of the whole internal assessment. People must still receive clear privacy information about the purpose, the legitimate interests pursued and their rights. A concise notice can state the result while the internal record preserves the interest, alternatives, balancing factors, safeguards, reviewer and review trigger needed to demonstrate accountability [1][3].

Sources

  1. 1.Regulation (EU) 2016/679 (General Data Protection Regulation)EUR-Lex · 2016
  2. 2.Guidelines 05/2020 on consent under Regulation 2016/679European Data Protection Board · 2020
  3. 3.Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPREuropean Data Protection Board · 2024
  4. 4.Directive 2002/58/EC on privacy and electronic communicationsEUR-Lex · 2026
  5. 5.One-Stop-Shop case digest on the legal basis of legitimate interestEuropean Data Protection Board · 2026

Want this run on your business?

AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.

Start your audit

You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.