Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

recognised legitimate interests — Recognised Legitimate Interests: The New UK GDPR Lawful Basis Explained

Recognised Legitimate Interests: The New UK GDPR Lawful Basis Explained

Recognised legitimate interests are a new lawful basis in the UK GDPR. Since 5 February 2026, Article 6(1)(ea) makes processing lawful where it is necessary for one of the purposes listed in a new Annex 1, and, unlike ordinary legitimate interests under Article 6(1)(f), it requires no balancing test against the individual’s rights. The basis was inserted by section 70 of the Data (Use and Access) Act 2025. This guide explains the five categories of recognised legitimate interests, what “necessary” still requires, the one thing the basis can never be used for, and how to record it so the decision holds up.

What this guide covers

recognised legitimate interests explained
Recognised Legitimate Interests: The New UK GDPR Lawful Basis Explained

What recognised legitimate interests are

Ordinary legitimate interests, Article 6(1)(f), has three parts: a legitimate interest, processing necessary for it, and a balance in which the individual’s interests, rights and freedoms do not override it. The balancing test is the part that takes the time and produces the legitimate interests assessment. Parliament’s view in the 2025 Act was that for a short list of purposes the balance has already been struck by the legislature, so the controller should not have to strike it again. That is what a recognised legitimate interest is: a purpose in Annex 1 for which the balancing test is dispensed with.

The necessity test is not dispensed with. The processing must still be necessary for the Annex 1 purpose, and “necessary” keeps its data protection meaning: more than useful, less than indispensable; a targeted and proportionate way of achieving the purpose, where a less intrusive means would not do. And the other principles still apply in full: transparency, minimisation, accuracy, storage limitation and security. The basis removes one test, not the rest of the regulation.

The five categories of recognised legitimate interests

Annex 1 to the UK GDPR, as inserted by Schedule 4 to the 2025 Act, lists the conditions. They group into five categories.

Annex 1 purpose What it covers Typical use
Disclosure for another’s public task Disclosing data to a person who has asked for it and needs it for a task carried out in the public interest or in the exercise of official authority under Article 6(1)(e) A regulator, a local authority or a public body writes asking for records about an individual
National security, public security and defence Processing necessary for those purposes Rare for private-sector controllers
Emergencies Responding to an emergency in the Civil Contingencies Act 2004 sense Sharing locations or contact details with emergency responders during an incident
Crime Detecting, investigating or preventing crime, or apprehending or prosecuting offenders Fraud detection; sharing evidence with the police
Safeguarding vulnerable individuals Protecting a person under 18, or an adult at risk, from neglect or physical, mental or emotional harm Safeguarding referrals; welfare checks

The first category is the one most private-sector organisations will meet. Note its structure: the disclosure must be to a person who needs the data for their own public task, and that person must have asked for it. It covers responding to a request from a public body; it does not cover volunteering data to one, and it does not cover the organisation’s own processing for its own purposes. Our guide to the Data (Use and Access) Act 2025 sets the basis in the context of the other changes.

What recognised legitimate interests cannot be used for

Article 22B(4), inserted in the same amendment, provides that a significant decision may not be based solely on automated processing where the processing relies on Article 6(1)(ea). A fraud model that declines transactions with no human review cannot rest on the crime condition; it needs another basis, and the safeguards in Article 22C. Our guide to UK GDPR automated decision-making explains the rest of that regime.

Two further limits are practical rather than statutory. The first Annex 1 condition is written for the organisation that discloses; the public body receiving the data relies on its own public task under Article 6(1)(e), not on (ea). And special category data still needs an Article 9 condition. A recognised legitimate interest is an Article 6 basis only; safeguarding processing involving health data needs Article 9(2)(g) and the substantial public interest condition at Data Protection Act 2018 Schedule 1 paragraph 18 as well.

Recognised legitimate interests vs the Article 6(11) examples

The same section of the 2025 Act inserted Article 6(11), which is often confused with the new basis. Article 6(11) says that processing for direct marketing, transmission within a group of undertakings for internal administration, and ensuring network and information security are examples of processing that may be necessary for a legitimate interest under Article 6(1)(f). Those are not recognised legitimate interests. They still require the balancing test and a legitimate interests assessment; Article 6(11) confirms they can pass it, which was previously said only in recitals.

The distinction matters in the register. An entry for “marketing to existing customers” cites Article 6(1)(f) with an LIA reference. An entry for “disclosure to HMRC on request” cites Article 6(1)(ea) with an Annex 1 paragraph reference and no LIA. Mixing the two, either by skipping the LIA for marketing or by writing one for a police disclosure, is a finding either way.

Deciding whether recognised legitimate interests apply

A short, recorded decision is enough, and it should answer four questions in order.

  • Which Annex 1 paragraph? Name it. If the purpose does not fit a paragraph, the basis does not apply, however reasonable the processing.
  • Is the processing necessary for that purpose? Could less data, or a less intrusive method, achieve it? If so, the processing is not necessary in the required sense.
  • Is any of it special category or criminal offence data? If so, name the Article 9 or 10 condition and the Schedule 1 condition, and check the appropriate policy document is in place.
  • Is a solely automated significant decision involved? If so, stop; Article 22B(4) forbids the combination.

Record the answers with the date, the decider and the request that prompted the disclosure where there was one. The record goes in the lawful basis register against the activity, and in the record of processing, which under Data Protection Act 2018 Schedule 1 paragraph 41 must state how Article 6 is satisfied. Our guide to records of processing covers what that register needs.

Transparency still applies

Individuals must be told the lawful basis in the privacy notice under Articles 13 and 14. A notice that lists the six familiar bases and stops is now incomplete for a controller that relies on the new one. The recommended wording names the basis and the purposes: “where necessary for a recognised legitimate interest, such as responding to a request from a public body, preventing crime, or safeguarding a vulnerable person”. For one-off disclosures prompted by a request, the notice’s general wording covers it; a systematic sharing arrangement with a public body should be named as a recipient. Our guide to the UK GDPR privacy notice covers the rest of the content.

Because the basis dispenses with the balancing test, the individual’s interests are not weighed at the point of decision, which is a further reason to use it only where the purpose plainly fits an Annex 1 paragraph. Where there is doubt, Article 6(1)(f) with a legitimate interests assessment is the safer route, and it reaches the same lawful result for any disclosure that would have qualified.

Recognised legitimate interests in practice: three cases

A police request for CCTV footage. The police need it to investigate an offence; the crime condition fits; the footage of the relevant period is necessary; no special category data is involved unless the footage reveals it; the disclosure is recorded with the request reference. Basis: Article 6(1)(ea), Annex 1 crime condition. No LIA.

A school raises a safeguarding concern about a pupil with a social services team. The safeguarding condition fits; the data shared is limited to what the concern requires; health information involved needs Article 9(2)(g) and Schedule 1 paragraph 18 as well. Basis: Article 6(1)(ea) plus the Article 9 route. Recorded.

An online retailer wants to screen orders against a fraud model that automatically declines high-risk transactions. The crime condition would fit the purpose, but the decision is solely automated and significant, so Article 22B(4) rules out (ea). The retailer uses Article 6(1)(f) with an LIA, and puts the Article 22C safeguards in place. The basis is not available.

Building it into the programme

A lawful basis procedure that includes the four-question decision; a register with an Annex 1 column; a privacy notice paragraph; and a note in the automated decision-making procedure that (ea) is excluded. The UK GDPR Toolkit ships each of those: a recognised legitimate interests procedure, a lawful basis register that carries the Annex 1 paragraph and the Article 9 condition side by side, notices that name the basis, and an automated decision-making procedure that checks for it. For how the basis fits the wider set of 2026 differences, see UK GDPR vs EU GDPR.

Frequently asked questions about recognised legitimate interests

Do recognised legitimate interests replace ordinary legitimate interests?

No. Article 6(1)(f) continues unchanged for every other purpose, with its balancing test. The new basis covers only the Annex 1 purposes.

Do I still need a legitimate interests assessment?

Not for a recognised legitimate interest; that is the point of the basis. You do need a short necessity record naming the Annex 1 paragraph. For Article 6(11) purposes such as marketing, yes, the LIA is still required.

Can a public authority use the new basis?

For its own tasks it relies on Article 6(1)(e). The disclosure condition in Annex 1 is aimed at the organisation that discloses to a public body, not at the body that receives.

Does the EU GDPR have recognised legitimate interests?

No. The basis exists only in the UK text. Processing of EU data for the same purposes still needs an EU lawful basis with a balancing test where Article 6(1)(f) is used.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.