Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Legitimate interests examples grouped into those that usually pass, need care or usually fail

Legitimate Interests Examples: 12 Proven Cases and Where They Fail (2026)

Legitimate interests examples are the quickest way to see where Article 6(1)(f) of the GDPR works and where it breaks down, because the same purpose can pass the test for one organization and fail it for another. The GDPR’s recitals name a handful of interests that may be legitimate, and the regulators and courts have added more. This guide goes through the common legitimate interests examples, what usually tips the balance, and where each one runs into trouble.

Legitimate interests examples grouped into those that usually pass, need care or usually fail

How to Read These Legitimate Interests Examples

No purpose is legitimate interests by label alone. Every example below still needs the three-part test: a legitimate interest (the purpose test), processing that is necessary for it (the necessity test), and a balance that is not overridden by the interests, rights and freedoms of the people concerned (the balancing test). The UK ICO says the same about the examples the Data (Use and Access) Act 2025 added to the UK GDPR: they may be legitimate interests, but you must still do the test.

Legitimate Interests Examples Named in the GDPR

ExampleWhere it comes fromWhat usually decides the balance
Fraud preventionRecital 47: processing strictly necessary to prevent fraudProportion: checks focused on real fraud signals, not blanket profiling
Direct marketingRecital 47: may be regarded as a legitimate interestePrivacy consent rules, expectations, and an absolute right to object
Intra-group administrationRecital 48: transmission within a group for internal administrative purposesKept to administration, not each company’s own marketing
Network and information securityRecital 49: strictly necessary and proportionate securityLogs and monitoring limited to what security needs
Reporting possible crimesRecital 50: indicating possible criminal acts to a competent authoritySpecific concerns, not routine disclosure

Recital 47 adds the test that runs through all of them: whether the people concerned can reasonably expect, at the time and in the context of the collection, that processing for this purpose may take place. A relevant and appropriate relationship, such as being your customer or employee, makes that more likely.

Everyday Legitimate Interests Examples

Postal marketing to existing customers

Usually passes, because customers expect it and no consent rule applies to post. It fails when it relies on sensitive inferences, ignores objections, or goes to people who never dealt with you. Email and text marketing are different: where the ePrivacy rules (PECR in the UK) require consent, legitimate interests cannot be used. Our legitimate interests assessment example works through a retailer’s personalised offers.

Fraud and payment checks

Usually passes where checks target fraud risk and people are told about them. Watch for automated refusals: a decision based solely on automated processing with legal or similarly significant effects brings in Article 22, which legitimate interests does not unlock on its own.

CCTV and building security

Usually passes for entrances, car parks and stock areas with clear signs. It fails in places people expect privacy, such as toilets or changing rooms, and when footage is kept long after any incident would have come to light.

Employee monitoring

Often uses legitimate interests, because consent at work is rarely freely given (Recital 43). The balance is hard: continuous or covert monitoring, keystroke logging or tracking outside working hours rarely passes. Tell staff what is monitored and why, and monitor as little as the purpose allows. Systematic monitoring of staff may also need a DPIA.

Analytics and product improvement

Aggregated or pseudonymised analytics of your own service usually passes. Tracking across other sites does not, and the cookies and similar technology behind analytics have their own ePrivacy rules, whatever the GDPR basis.

Debt recovery and legal claims

Pursuing a debt or defending a claim is a recognised interest. Keep disclosures to what the claim needs, and use collection agencies under contract.

Research and service improvement using customer feedback

Usually passes when feedback is used to improve the service it came from. Reusing it for a new purpose calls for a compatibility check and, often, a new assessment.

Legitimate Interests Examples That Usually Fail

PurposeWhy it usually failsUsual alternative
Behavioural advertising across sites and appsPeople do not reasonably expect it; the Court of Justice said so for a social network in Meta v Bundeskartellamt (C-252/21)Consent
Selling customer data to data brokersUnexpected, and people lose control of their dataConsent, or do not do it
Marketing emails without the soft opt-inThe ePrivacy rules require consentConsent
Profiling children for marketingChildren’s interests weigh heavily, and Recital 38 singles out marketing and profilingDo not do it, or consent with strong safeguards
Processing by a public authority for its tasksArticle 6(1) excludes itPublic task

UK Recognised Legitimate Interests

Since 5 February 2026, the UK GDPR has a separate basis, recognised legitimate interests, for five purposes in its Annex 1: disclosures to bodies that need the data for their public tasks, national security and defence, emergencies, crime, and safeguarding vulnerable people. No balancing test is needed, though the processing must still be necessary. It does not exist under the EU GDPR. See our guide to recognised legitimate interests.

What Turns an Example Into a Pass

Across these legitimate interests examples, the same safeguards keep appearing:

  • telling people, and naming the interest in the privacy notice (Article 13(1)(d));
  • an easy way to object, which always works for direct marketing (Article 21);
  • using as little data as the purpose needs, for as short a time as it needs;
  • keeping out special category data and children’s data, or protecting them specifically;
  • human review of decisions that matter to people.

Frequently Asked Questions

Are these legitimate interests examples enough to rely on without an assessment?

No. They show where legitimate interests often works. The accountability principle in Article 5(2) still means you must be able to show the three-part test for your own processing.

Can a commercial interest be a legitimate interest?

Yes. In October 2024 the Court of Justice confirmed, in the Royal Dutch Lawn Tennis Association case (C-621/22), that a purely commercial interest can be legitimate, provided it is lawful. It must still pass necessity and balancing.

What is the most common reason legitimate interests fails?

Reasonable expectations. If people would be surprised by the processing, the balance usually tips against it, as the EDPB Guidelines 1/2024 on legitimate interest explain.

Legitimate interests or consent?

See our comparison of legitimate interests vs consent.

To test your own purpose, use our free legitimate interests assessment template, which screens the basis, runs the three tests and rates the impact on the people concerned. Our guide to the legitimate interests assessment covers the method, and the GDPR Toolkit has the privacy notices, records and policies around it.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.