Skip to content

Legitimate Interests vs Consent in the UK: How to Choose

Legitimate interests vs consent in the UK: use the purpose, necessity and balancing tests, check PECR, and record why the chosen lawful basis fits.

Two isometric routes compare purpose, necessity and balance with choice and withdrawal, while an objection lever remains attached to the legitimate-interest route.
By AI Priority Map Editorial

A sales team wants to email people who downloaded a pricing sheet. One colleague asks for consent; another says legitimate interests. The legitimate interests vs consent UK decision cannot be settled by choosing the label that feels more cautious. It starts with the exact purpose, the person's real choice, whether the activity must continue and any channel-specific rule 1,3.

Quick Answer. For legitimate interests vs consent in the UK, use consent for genuine choice where processing can stop. Ordinary legitimate interests needs purpose, necessity and balancing tests. Recognised legitimate interest is separate for five statutory public-interest conditions. Check PECR separately for marketing and record the decision before processing 2,4,5,8,9.

Begin with the operation, not the preferred label

A single product can contain several processing operations. An account may need an email address to deliver login links, an audit trail to prevent fraud, analytics to improve a service and a newsletter to promote another product. Those purposes do not inherit one lawful basis merely because they share a database.

Describe each operation as a verb with an outcome: send a requested download, detect repeated failed logins, measure feature use, send a weekly offer. Name the data, people, source, recipients, timing and consequence. This prevents a broad phrase such as “customer engagement” from hiding activities with different necessity and expectations.

Processing operationFirst questionWhy it matters
Deliver a requested serviceIs processing necessary for the contract or request?Consent may falsely imply an optional choice
Prevent account fraudIs a defined interest served by necessary, proportionate processing?A legitimate-interests assessment may fit
Send promotional emailWhat does PECR permit for this recipient and channel?UK GDPR alone cannot permit the message
Publish a customer storyCan the person genuinely refuse publication?Consent may fit a genuinely optional use
Keep evidence of an opt-outWhat minimum record is needed to honour the choice?Suppression is different from continued marketing

The lawful basis is fixed for the defined purpose before processing begins and appears in privacy information. It is not an explanation invented when a complaint arrives. If the purpose or method changes, reassess the new operation rather than stretching the old record 1,3.

Valid consent requires a freely given, specific, informed and unambiguous indication, expressed through a clear affirmative action 1,2,4. Each word changes the design. Bundling optional marketing into service terms is not specific. Pre-ticked boxes are not affirmative. A choice that blocks an unrelated service may not be freely given.

The decisive operational question is what happens after “no”. If the organisation will continue the activity anyway, consent is not describing reality. If refusal means a worker loses an ordinary workplace benefit, or a customer cannot buy a product that does not need the optional data, the choice may be impaired.

Consent also has to remain usable after collection. The organisation needs evidence of who consented, when, what they were told, which action they took and which purposes were covered. It needs a withdrawal route that is as easy as giving consent and reaches campaign tools, spreadsheets, agencies and future uploads 2,4.

Consent fits best where the optional choice is part of the purpose itself: publishing an identifiable customer story, enabling a non-essential feature, or sending a marketing message where the channel rule requires consent. In each case, refusal leaves the ordinary service intact. That is different from adding a consent box to fraud prevention, payroll or another activity the organisation intends or is required to perform regardless of the answer.

Withdrawal stops future processing that depends on that consent. It does not make earlier lawful processing unlawful 2. This distinction matters when a campaign report already exists or a photograph was used during the consent period. The organisation stops the future activity, updates recipients where necessary and records the change; it does not rewrite history.

Ordinary legitimate interests uses a written three-part test

UK law now provides seven lawful bases. Recognised legitimate interest is a separate basis, not a lighter version of ordinary legitimate interests. It applies only where processing is necessary for one of five specified public-interest conditions: disclosing personal data when another organisation requests it because it needs the information for a public task or official functions; national security, public security or defence; emergencies; crime; or safeguarding vulnerable people 8,9.

The recognised basis removes the balancing part of an ordinary legitimate interests assessment, but necessity remains. It is not an exemption from the UK GDPR: purpose limitation, data minimisation, transparency, security, retention and applicable rights continue to apply. People must still receive clear privacy information about the processing 8,9.

Outside those five conditions, ordinary legitimate interests begins with a specific interest that is lawful, sufficiently clear and real. Preventing fraud, securing premises or following up a genuine business enquiry may be interests. “Growing revenue” or “using our data” is too broad to expose what the processing does to people 5.

The necessity test asks whether the processing is a targeted and proportionate way to achieve that purpose. Necessary does not mean indispensable, but it does exclude methods chosen merely for convenience. If aggregated information, a shorter period, a smaller audience or a non-tracking method would work reasonably well, the more intrusive option is harder to defend.

The balancing test brings the person into the decision. Consider the nature of the data, source, relationship, reasonable expectations, scale, frequency, vulnerability, likely benefit and possible harm. An existing business contact may reasonably expect a limited follow-up about the same request; a person whose details were copied from an unrelated public page may not expect a sustained sales sequence.

Balancing factorEvidence to capture
RelationshipCustomer, prospect, worker, visitor or no prior relationship
ExpectationWhat was said at collection and what the context implies
Data and sourceOrdinary contact details, observed behaviour, inferred interests or sensitive data
ImpactAnnoyance, loss of control, exclusion, financial effect or exposure
Scale and frequencyOne response, periodic service message or persistent campaign
SafeguardsNarrow audience, short retention, easy objection, human review and suppression

Safeguards can change the balance, but they do not erase a fundamentally unexpected activity. Record the negative factors as well as the supportive ones. An assessment that lists only business benefits is not a balancing exercise.

Compare the two bases by their consequences

Consent and ordinary legitimate interests create different controls. Under consent, the organisation proves the choice and stops the dependent activity after withdrawal. Under ordinary legitimate interests, it proves the three-part test, explains the interest and handles the right to object. The selection should match which set of facts is true.

Decision pointConsentLegitimate interests
Person's choiceMust be genuine and informedImpact can occur without prior agreement
Core recordConsent wording, action, time and versionPurpose, necessity and balancing assessment
Main controlRefusal and withdrawal must workObjection and reassessment must work
If challengedProve valid consentProve the interest, necessity and balance
FragilityChoice can be withdrawn at any timeFacts or objections can change the balance

Neither column is a shortcut. Consent is not stronger merely because a person clicked. Legitimate interests is not easier merely because no click is needed. Both depend on purpose limitation, minimisation, transparency, security, retention and rights 1,3.

A useful stress test is to write the rejection path. If consent is refused, does the feature still work? If a person objects to legitimate-interests processing, who receives it, what pauses, which grounds are reconsidered and how is the outcome explained? A basis that cannot survive its own rights mechanism is not ready.

Keep the lawful basis separate from other conditions

Choosing between consent and legitimate interests answers only one part of the UK GDPR analysis. It does not decide whether the organisation may process special-category data, use criminal-offence data, make a solely automated decision, send a message under PECR or transfer data internationally. Each additional condition has its own facts and record 1,3.

This separation prevents a common false conclusion: “the person consented, so every use is permitted.” Consent covers specified purposes described at the time of choice. It does not waive minimisation, accuracy, security or retention, and it does not silently extend to a later recipient or incompatible purpose. The same limit applies to legitimate interests.

The decision works in layers. The processing operation and purpose come first, followed by the UK GDPR lawful basis that genuinely fits them. Data types and automated decisions are then checked for additional UK GDPR conditions, while the communication channel receives its own PECR analysis where relevant.

Transparency, rights, recipients, security, retention and transfer controls remain separate checks. Finally, system configuration must make refusal, withdrawal and objection produce the recorded outcome across the original application, connected services, audience exports and any processor that receives the preference.

A sales platform that infers a prospect's health condition from browsing and sends a tailored email exposes the layers clearly. A legitimate commercial interest does not answer the special-category issue. Consent to receive one newsletter does not necessarily cover the inference. A privacy notice cannot substitute for the PECR analysis. Keeping those questions apart stops one positive answer from being treated as permission for the whole design, even when the data and message travel through the same vendor.

The layered record also makes later change manageable. If the team changes only the email cadence, it can locate the PECR and balancing effects. If it adds inference, it opens the data-condition analysis. If it changes purpose, it returns to the basis. One broad “consent versus legitimate interest” checkbox cannot show which part moved.

PECR can decide the channel first

For electronic mail, calls, cookies and similar technologies, PECR may impose a consent rule or another specific condition before the UK GDPR basis is considered 6,7. Direct marketing remains within ordinary legitimate interests rather than recognised legitimate interest, so any reliance on that basis still requires the full purpose, necessity and balancing test 5,9. Accordingly, “we use legitimate interests for marketing” is incomplete: it may describe personal-data processing while saying nothing about whether the message itself may be sent.

For an email campaign, identify the recipient type, how details were obtained, whether the message is direct marketing and whether any relevant PECR condition applies. The soft opt-in, where available, has its own conditions; it is not a general permission for any existing contact. Every marketing message also needs the applicable identification and opt-out controls 6,7.

If PECR requires consent and valid consent is absent, a legitimate-interests assessment cannot repair the channel. If PECR permits the message, the organisation still needs a UK GDPR basis for processing the address and campaign data. The two analyses sit together, not in competition.

Cookies create the same layered problem. A lawful-basis label in a privacy policy does not make a non-essential tracker fire lawfully before the required choice. Technical deployment must reflect the channel rule, not only the wording of the notice.

Work through one sales follow-up example

Suppose a finance manager downloads a detailed pricing guide after giving a work email address. The page promises the guide and says a specialist may answer questions. The sales team wants a three-message sequence over ten days, then to add the address to a monthly newsletter.

Split the operations. Sending the requested guide follows the request itself. A short, relevant follow-up may be assessed for necessity and expectations, but the team should not treat that conclusion as automatic. Record the relationship, wording at collection, message content, frequency, source, impact, easy objection and any PECR condition 5,7.

The monthly newsletter is another purpose and cadence. If the team wants consent, the choice must be separate and optional, with no pre-ticked box. The evidence must preserve the wording and action. If consent is not obtained, the address does not enter that stream merely because the earlier follow-up passed a different assessment.

Now change one fact: the address came from a conference attendee list supplied by another organiser, and the person did not ask this business for anything. Expectations and source change sharply. The same copy and frequency may now fail the balancing or channel analysis. A template cannot replace those facts.

Withdrawal and objection need different workflows

A withdrawal request is not an invitation to choose a new label. Stop future processing that relies on the withdrawn consent, update the consent record and send the preference to systems and recipients. Keep only what is needed to demonstrate and honour the withdrawal under an independently assessed purpose 2,4.

An objection to legitimate-interests processing triggers a different decision. For general processing, the organisation assesses whether compelling legitimate grounds override the person's interests, rights and freedoms, or whether legal claims require continuation. For direct marketing, the objection requires the direct-marketing processing to stop 1,5.

Incoming signalImmediate actionRecord
Consent refusedDo not start the optional operationChoice, wording and system outcome
Consent withdrawnStop dependent future processingTime, scope, systems and recipients updated
General objectionPause or contain while grounds are assessedFacts, impact, grounds and response
Marketing objectionStop direct-marketing processingSuppression route and campaign systems updated
New purpose proposedReassess before usePurpose, basis, notice and controls

Suppression is often necessary so a person is not re-imported. It should be minimal, secured and used only to respect the choice. Deleting every trace without preserving a suppression control can cause the very marketing the person asked to stop.

Record one decision that another person can operate

The final record should name the operation, purpose, data, people, source, recipients, frequency, lawful basis, PECR position, rights path, retention and reviewer. Attach the consent evidence design or legitimate-interests assessment rather than writing “GDPR compliant” in a spreadsheet cell.

Translate the record into system behaviour. Consent fields need version and timestamp evidence. Objection routes need an owner and response process. Marketing lists need suppression before each send. Vendors need instructions that preserve the same purposes and choices.

Use a decision register rather than isolated documents. One row can identify the processing operation, owner, live systems, basis, assessment link, privacy-notice version, PECR conclusion, relevant rights route and next review. Supporting evidence stays attached, but the register lets a new colleague find the decision before changing a campaign.

The owner should be able to demonstrate three tests without reconstructing them from memory. First, the legal test: why this basis applies. Second, the truth test: whether the product behaves as the record says. Third, the rights test: whether a real refusal, withdrawal or objection reaches every downstream system. A policy passes only the first and sometimes not even that.

Post-launch sampling should exercise the workflow. A test contact gives no consent and the optional field must remain empty; an existing consent is withdrawn and the event is traced through the customer platform and email service; a marketing objection must affect both active campaigns and the next audience import. Evidence from these deliberately different paths is more valuable than a screenshot of the preference centre because it proves the choice survived each integration.

Supplier contracts and instructions should preserve the distinction between operations. A processor should not treat every address in the platform as marketable, infer new consent from continued use or discard suppression data during a routine cleanup. Where several controllers receive a choice, the wording and withdrawal route need to explain who acts and how the signal reaches them 1,4.

Review is triggered by a new data source, audience, channel, frequency, profiling method, consequence or complaint pattern. It is also triggered when evidence changes reasonable expectations. Do not wait for an annual date if the processing has already changed.

The first action is to take one proposed message and write two sentences: the exact purpose, and what happens if the person says no. If the activity must continue, do not ask for consent. If the purpose is optional but the organisation cannot stop, repair the workflow before choosing any lawful-basis label.

Last updated: 26 August 2026.

Frequently Asked Questions

Is consent safer than legitimate interests under UK GDPR?
No lawful basis is automatically safer. Consent is appropriate only when the person has a genuine choice and the organisation can stop the processing if consent is refused or withdrawn. Legitimate interests can fit necessary, proportionate processing after a documented three-part test. The safer basis is the one that truthfully describes the activity and its consequences [1][3][4].
What is the three-part legitimate interests test?
Ordinary legitimate interests uses three parts. First identify a specific purpose, then ask whether the processing is necessary or a less intrusive method would work, and finally balance the interest against people's rights, interests and expectations. The separate recognised legitimate interest basis has no balancing test, but it is limited to five statutory public-interest conditions and still requires necessity [5][8][9].
Can we switch from consent to legitimate interests after withdrawal?
Not simply to avoid the withdrawal. A lawful basis should be selected before processing and communicated transparently. Re-labelling the same activity after a person withdraws consent can be unfair and misleading. If circumstances genuinely create a separate purpose or processing operation, assess that operation on its own facts and update the information given to people before relying on it [2][3][4].
What happens when someone withdraws consent?
Processing that depends on that consent must stop unless another independently established legal basis applies to a separate operation. Withdrawal does not make earlier lawful processing unlawful. It must be as easy to withdraw as to give consent, and the organisation needs an operational route that reaches every system and recipient relying on the choice [2][4].
What happens when someone objects to legitimate interests?
The organisation must consider the objection and stop unless it demonstrates compelling legitimate grounds that override the person's interests, rights and freedoms, or needs the processing for legal claims. Direct marketing is different: an objection to direct marketing requires that processing to stop. Suppression may still be needed so the preference is respected across future campaigns [1][5].
Does legitimate interests allow marketing emails?
Direct marketing is not a recognised legitimate interest. Where ordinary legitimate interests fits the personal-data processing, the full purpose, necessity and balancing test still applies. PECR may separately require consent for electronic mail unless a specific rule, such as the soft opt-in conditions, applies. Legitimate interests cannot turn a PECR-prohibited message into a permitted one [5][6][7][9].
Do we need to publish our legitimate interests assessment?
UK GDPR does not generally require publishing the whole internal assessment. People must still receive clear privacy information about the purpose, the legitimate interests relied on and their rights. A concise notice can describe the result while the underlying record preserves the evidence, alternatives, balancing factors, safeguards, reviewer and review trigger needed for accountability [1][5].

Sources

  1. 1.UK GDPR (retained)legislation.gov.uk · 2026
  2. 2.UK GDPR Article 7legislation.gov.uk · 2026
  3. 3.A guide to lawful basisInformation Commissioner's Office · 2026
  4. 4.ConsentInformation Commissioner's Office · 2026
  5. 5.Legitimate interestsInformation Commissioner's Office · 2026
  6. 6.Privacy and Electronic Communications Regulations 2003legislation.gov.uk · 2026
  7. 7.Electronic mail marketingInformation Commissioner's Office · 2026
  8. 8.Data (Use and Access) Act 2025legislation.gov.uk · 2025
  9. 9.Recognised legitimate interestInformation Commissioner's Office · 2026

Want this run on your business?

AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.

Start your audit

You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.