Legitimate Interests vs Consent in the UK: How to Choose
Legitimate interests vs consent in the UK: use the purpose, necessity and balancing tests, check PECR, and record why the chosen lawful basis fits.

A sales team wants to email people who downloaded a pricing sheet. One colleague asks for consent; another says legitimate interests. The legitimate interests vs consent UK decision cannot be settled by choosing the label that feels more cautious. It starts with the exact purpose, the person's real choice, whether the activity must continue and any channel-specific rule 1,3.
Quick Answer. For legitimate interests vs consent in the UK, use consent for genuine choice where processing can stop. Ordinary legitimate interests needs purpose, necessity and balancing tests. Recognised legitimate interest is separate for five statutory public-interest conditions. Check PECR separately for marketing and record the decision before processing 2,4,5,8,9.
Begin with the operation, not the preferred label
A single product can contain several processing operations. An account may need an email address to deliver login links, an audit trail to prevent fraud, analytics to improve a service and a newsletter to promote another product. Those purposes do not inherit one lawful basis merely because they share a database.
Describe each operation as a verb with an outcome: send a requested download, detect repeated failed logins, measure feature use, send a weekly offer. Name the data, people, source, recipients, timing and consequence. This prevents a broad phrase such as “customer engagement” from hiding activities with different necessity and expectations.
| Processing operation | First question | Why it matters |
|---|---|---|
| Deliver a requested service | Is processing necessary for the contract or request? | Consent may falsely imply an optional choice |
| Prevent account fraud | Is a defined interest served by necessary, proportionate processing? | A legitimate-interests assessment may fit |
| Send promotional email | What does PECR permit for this recipient and channel? | UK GDPR alone cannot permit the message |
| Publish a customer story | Can the person genuinely refuse publication? | Consent may fit a genuinely optional use |
| Keep evidence of an opt-out | What minimum record is needed to honour the choice? | Suppression is different from continued marketing |
The lawful basis is fixed for the defined purpose before processing begins and appears in privacy information. It is not an explanation invented when a complaint arrives. If the purpose or method changes, reassess the new operation rather than stretching the old record 1,3.
Consent is a choice, not a permission screen
Valid consent requires a freely given, specific, informed and unambiguous indication, expressed through a clear affirmative action 1,2,4. Each word changes the design. Bundling optional marketing into service terms is not specific. Pre-ticked boxes are not affirmative. A choice that blocks an unrelated service may not be freely given.
The decisive operational question is what happens after “no”. If the organisation will continue the activity anyway, consent is not describing reality. If refusal means a worker loses an ordinary workplace benefit, or a customer cannot buy a product that does not need the optional data, the choice may be impaired.
Consent also has to remain usable after collection. The organisation needs evidence of who consented, when, what they were told, which action they took and which purposes were covered. It needs a withdrawal route that is as easy as giving consent and reaches campaign tools, spreadsheets, agencies and future uploads 2,4.
Consent fits best where the optional choice is part of the purpose itself: publishing an identifiable customer story, enabling a non-essential feature, or sending a marketing message where the channel rule requires consent. In each case, refusal leaves the ordinary service intact. That is different from adding a consent box to fraud prevention, payroll or another activity the organisation intends or is required to perform regardless of the answer.
Withdrawal stops future processing that depends on that consent. It does not make earlier lawful processing unlawful 2. This distinction matters when a campaign report already exists or a photograph was used during the consent period. The organisation stops the future activity, updates recipients where necessary and records the change; it does not rewrite history.
Ordinary legitimate interests uses a written three-part test
UK law now provides seven lawful bases. Recognised legitimate interest is a separate basis, not a lighter version of ordinary legitimate interests. It applies only where processing is necessary for one of five specified public-interest conditions: disclosing personal data when another organisation requests it because it needs the information for a public task or official functions; national security, public security or defence; emergencies; crime; or safeguarding vulnerable people 8,9.
The recognised basis removes the balancing part of an ordinary legitimate interests assessment, but necessity remains. It is not an exemption from the UK GDPR: purpose limitation, data minimisation, transparency, security, retention and applicable rights continue to apply. People must still receive clear privacy information about the processing 8,9.
Outside those five conditions, ordinary legitimate interests begins with a specific interest that is lawful, sufficiently clear and real. Preventing fraud, securing premises or following up a genuine business enquiry may be interests. “Growing revenue” or “using our data” is too broad to expose what the processing does to people 5.
The necessity test asks whether the processing is a targeted and proportionate way to achieve that purpose. Necessary does not mean indispensable, but it does exclude methods chosen merely for convenience. If aggregated information, a shorter period, a smaller audience or a non-tracking method would work reasonably well, the more intrusive option is harder to defend.
The balancing test brings the person into the decision. Consider the nature of the data, source, relationship, reasonable expectations, scale, frequency, vulnerability, likely benefit and possible harm. An existing business contact may reasonably expect a limited follow-up about the same request; a person whose details were copied from an unrelated public page may not expect a sustained sales sequence.
| Balancing factor | Evidence to capture |
|---|---|
| Relationship | Customer, prospect, worker, visitor or no prior relationship |
| Expectation | What was said at collection and what the context implies |
| Data and source | Ordinary contact details, observed behaviour, inferred interests or sensitive data |
| Impact | Annoyance, loss of control, exclusion, financial effect or exposure |
| Scale and frequency | One response, periodic service message or persistent campaign |
| Safeguards | Narrow audience, short retention, easy objection, human review and suppression |
Safeguards can change the balance, but they do not erase a fundamentally unexpected activity. Record the negative factors as well as the supportive ones. An assessment that lists only business benefits is not a balancing exercise.
Compare the two bases by their consequences
Consent and ordinary legitimate interests create different controls. Under consent, the organisation proves the choice and stops the dependent activity after withdrawal. Under ordinary legitimate interests, it proves the three-part test, explains the interest and handles the right to object. The selection should match which set of facts is true.
| Decision point | Consent | Legitimate interests |
|---|---|---|
| Person's choice | Must be genuine and informed | Impact can occur without prior agreement |
| Core record | Consent wording, action, time and version | Purpose, necessity and balancing assessment |
| Main control | Refusal and withdrawal must work | Objection and reassessment must work |
| If challenged | Prove valid consent | Prove the interest, necessity and balance |
| Fragility | Choice can be withdrawn at any time | Facts or objections can change the balance |
Neither column is a shortcut. Consent is not stronger merely because a person clicked. Legitimate interests is not easier merely because no click is needed. Both depend on purpose limitation, minimisation, transparency, security, retention and rights 1,3.
A useful stress test is to write the rejection path. If consent is refused, does the feature still work? If a person objects to legitimate-interests processing, who receives it, what pauses, which grounds are reconsidered and how is the outcome explained? A basis that cannot survive its own rights mechanism is not ready.
Keep the lawful basis separate from other conditions
Choosing between consent and legitimate interests answers only one part of the UK GDPR analysis. It does not decide whether the organisation may process special-category data, use criminal-offence data, make a solely automated decision, send a message under PECR or transfer data internationally. Each additional condition has its own facts and record 1,3.
This separation prevents a common false conclusion: “the person consented, so every use is permitted.” Consent covers specified purposes described at the time of choice. It does not waive minimisation, accuracy, security or retention, and it does not silently extend to a later recipient or incompatible purpose. The same limit applies to legitimate interests.
The decision works in layers. The processing operation and purpose come first, followed by the UK GDPR lawful basis that genuinely fits them. Data types and automated decisions are then checked for additional UK GDPR conditions, while the communication channel receives its own PECR analysis where relevant.
Transparency, rights, recipients, security, retention and transfer controls remain separate checks. Finally, system configuration must make refusal, withdrawal and objection produce the recorded outcome across the original application, connected services, audience exports and any processor that receives the preference.
A sales platform that infers a prospect's health condition from browsing and sends a tailored email exposes the layers clearly. A legitimate commercial interest does not answer the special-category issue. Consent to receive one newsletter does not necessarily cover the inference. A privacy notice cannot substitute for the PECR analysis. Keeping those questions apart stops one positive answer from being treated as permission for the whole design, even when the data and message travel through the same vendor.
The layered record also makes later change manageable. If the team changes only the email cadence, it can locate the PECR and balancing effects. If it adds inference, it opens the data-condition analysis. If it changes purpose, it returns to the basis. One broad “consent versus legitimate interest” checkbox cannot show which part moved.
PECR can decide the channel first
For electronic mail, calls, cookies and similar technologies, PECR may impose a consent rule or another specific condition before the UK GDPR basis is considered 6,7. Direct marketing remains within ordinary legitimate interests rather than recognised legitimate interest, so any reliance on that basis still requires the full purpose, necessity and balancing test 5,9. Accordingly, “we use legitimate interests for marketing” is incomplete: it may describe personal-data processing while saying nothing about whether the message itself may be sent.
For an email campaign, identify the recipient type, how details were obtained, whether the message is direct marketing and whether any relevant PECR condition applies. The soft opt-in, where available, has its own conditions; it is not a general permission for any existing contact. Every marketing message also needs the applicable identification and opt-out controls 6,7.
If PECR requires consent and valid consent is absent, a legitimate-interests assessment cannot repair the channel. If PECR permits the message, the organisation still needs a UK GDPR basis for processing the address and campaign data. The two analyses sit together, not in competition.
Cookies create the same layered problem. A lawful-basis label in a privacy policy does not make a non-essential tracker fire lawfully before the required choice. Technical deployment must reflect the channel rule, not only the wording of the notice.
Work through one sales follow-up example
Suppose a finance manager downloads a detailed pricing guide after giving a work email address. The page promises the guide and says a specialist may answer questions. The sales team wants a three-message sequence over ten days, then to add the address to a monthly newsletter.
Split the operations. Sending the requested guide follows the request itself. A short, relevant follow-up may be assessed for necessity and expectations, but the team should not treat that conclusion as automatic. Record the relationship, wording at collection, message content, frequency, source, impact, easy objection and any PECR condition 5,7.
The monthly newsletter is another purpose and cadence. If the team wants consent, the choice must be separate and optional, with no pre-ticked box. The evidence must preserve the wording and action. If consent is not obtained, the address does not enter that stream merely because the earlier follow-up passed a different assessment.
Now change one fact: the address came from a conference attendee list supplied by another organiser, and the person did not ask this business for anything. Expectations and source change sharply. The same copy and frequency may now fail the balancing or channel analysis. A template cannot replace those facts.
Withdrawal and objection need different workflows
A withdrawal request is not an invitation to choose a new label. Stop future processing that relies on the withdrawn consent, update the consent record and send the preference to systems and recipients. Keep only what is needed to demonstrate and honour the withdrawal under an independently assessed purpose 2,4.
An objection to legitimate-interests processing triggers a different decision. For general processing, the organisation assesses whether compelling legitimate grounds override the person's interests, rights and freedoms, or whether legal claims require continuation. For direct marketing, the objection requires the direct-marketing processing to stop 1,5.
| Incoming signal | Immediate action | Record |
|---|---|---|
| Consent refused | Do not start the optional operation | Choice, wording and system outcome |
| Consent withdrawn | Stop dependent future processing | Time, scope, systems and recipients updated |
| General objection | Pause or contain while grounds are assessed | Facts, impact, grounds and response |
| Marketing objection | Stop direct-marketing processing | Suppression route and campaign systems updated |
| New purpose proposed | Reassess before use | Purpose, basis, notice and controls |
Suppression is often necessary so a person is not re-imported. It should be minimal, secured and used only to respect the choice. Deleting every trace without preserving a suppression control can cause the very marketing the person asked to stop.
Record one decision that another person can operate
The final record should name the operation, purpose, data, people, source, recipients, frequency, lawful basis, PECR position, rights path, retention and reviewer. Attach the consent evidence design or legitimate-interests assessment rather than writing “GDPR compliant” in a spreadsheet cell.
Translate the record into system behaviour. Consent fields need version and timestamp evidence. Objection routes need an owner and response process. Marketing lists need suppression before each send. Vendors need instructions that preserve the same purposes and choices.
Use a decision register rather than isolated documents. One row can identify the processing operation, owner, live systems, basis, assessment link, privacy-notice version, PECR conclusion, relevant rights route and next review. Supporting evidence stays attached, but the register lets a new colleague find the decision before changing a campaign.
The owner should be able to demonstrate three tests without reconstructing them from memory. First, the legal test: why this basis applies. Second, the truth test: whether the product behaves as the record says. Third, the rights test: whether a real refusal, withdrawal or objection reaches every downstream system. A policy passes only the first and sometimes not even that.
Post-launch sampling should exercise the workflow. A test contact gives no consent and the optional field must remain empty; an existing consent is withdrawn and the event is traced through the customer platform and email service; a marketing objection must affect both active campaigns and the next audience import. Evidence from these deliberately different paths is more valuable than a screenshot of the preference centre because it proves the choice survived each integration.
Supplier contracts and instructions should preserve the distinction between operations. A processor should not treat every address in the platform as marketable, infer new consent from continued use or discard suppression data during a routine cleanup. Where several controllers receive a choice, the wording and withdrawal route need to explain who acts and how the signal reaches them 1,4.
Review is triggered by a new data source, audience, channel, frequency, profiling method, consequence or complaint pattern. It is also triggered when evidence changes reasonable expectations. Do not wait for an annual date if the processing has already changed.
The first action is to take one proposed message and write two sentences: the exact purpose, and what happens if the person says no. If the activity must continue, do not ask for consent. If the purpose is optional but the organisation cannot stop, repair the workflow before choosing any lawful-basis label.
Last updated: 26 August 2026.
Frequently Asked Questions
Is consent safer than legitimate interests under UK GDPR?
What is the three-part legitimate interests test?
Can we switch from consent to legitimate interests after withdrawal?
What happens when someone withdraws consent?
What happens when someone objects to legitimate interests?
Does legitimate interests allow marketing emails?
Do we need to publish our legitimate interests assessment?
Sources
- 1.UK GDPR (retained) — legislation.gov.uk · 2026
- 2.UK GDPR Article 7 — legislation.gov.uk · 2026
- 3.A guide to lawful basis — Information Commissioner's Office · 2026
- 4.Consent — Information Commissioner's Office · 2026
- 5.Legitimate interests — Information Commissioner's Office · 2026
- 6.Privacy and Electronic Communications Regulations 2003 — legislation.gov.uk · 2026
- 7.Electronic mail marketing — Information Commissioner's Office · 2026
- 8.Data (Use and Access) Act 2025 — legislation.gov.uk · 2025
- 9.Recognised legitimate interest — Information Commissioner's Office · 2026
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.