Legitimate interests examples are the quickest way to see where Article 6(1)(f) of the GDPR works and where it breaks down, because the same purpose can pass the test for one organization and fail it for another. The GDPR’s recitals name a handful of interests that may be legitimate, and the regulators and courts have added more. This guide goes through the common legitimate interests examples, what usually tips the balance, and where each one runs into trouble.

How to Read These Legitimate Interests Examples
No purpose is legitimate interests by label alone. Every example below still needs the three-part test: a legitimate interest (the purpose test), processing that is necessary for it (the necessity test), and a balance that is not overridden by the interests, rights and freedoms of the people concerned (the balancing test). The UK ICO says the same about the examples the Data (Use and Access) Act 2025 added to the UK GDPR: they may be legitimate interests, but you must still do the test.
Legitimate Interests Examples Named in the GDPR
| Example | Where it comes from | What usually decides the balance |
|---|---|---|
| Fraud prevention | Recital 47: processing strictly necessary to prevent fraud | Proportion: checks focused on real fraud signals, not blanket profiling |
| Direct marketing | Recital 47: may be regarded as a legitimate interest | ePrivacy consent rules, expectations, and an absolute right to object |
| Intra-group administration | Recital 48: transmission within a group for internal administrative purposes | Kept to administration, not each company’s own marketing |
| Network and information security | Recital 49: strictly necessary and proportionate security | Logs and monitoring limited to what security needs |
| Reporting possible crimes | Recital 50: indicating possible criminal acts to a competent authority | Specific concerns, not routine disclosure |
Recital 47 adds the test that runs through all of them: whether the people concerned can reasonably expect, at the time and in the context of the collection, that processing for this purpose may take place. A relevant and appropriate relationship, such as being your customer or employee, makes that more likely.
Everyday Legitimate Interests Examples
Postal marketing to existing customers
Usually passes, because customers expect it and no consent rule applies to post. It fails when it relies on sensitive inferences, ignores objections, or goes to people who never dealt with you. Email and text marketing are different: where the ePrivacy rules (PECR in the UK) require consent, legitimate interests cannot be used. Our legitimate interests assessment example works through a retailer’s personalised offers.
Fraud and payment checks
Usually passes where checks target fraud risk and people are told about them. Watch for automated refusals: a decision based solely on automated processing with legal or similarly significant effects brings in Article 22, which legitimate interests does not unlock on its own.
CCTV and building security
Usually passes for entrances, car parks and stock areas with clear signs. It fails in places people expect privacy, such as toilets or changing rooms, and when footage is kept long after any incident would have come to light.
Employee monitoring
Often uses legitimate interests, because consent at work is rarely freely given (Recital 43). The balance is hard: continuous or covert monitoring, keystroke logging or tracking outside working hours rarely passes. Tell staff what is monitored and why, and monitor as little as the purpose allows. Systematic monitoring of staff may also need a DPIA.
Analytics and product improvement
Aggregated or pseudonymised analytics of your own service usually passes. Tracking across other sites does not, and the cookies and similar technology behind analytics have their own ePrivacy rules, whatever the GDPR basis.
Debt recovery and legal claims
Pursuing a debt or defending a claim is a recognised interest. Keep disclosures to what the claim needs, and use collection agencies under contract.
Research and service improvement using customer feedback
Usually passes when feedback is used to improve the service it came from. Reusing it for a new purpose calls for a compatibility check and, often, a new assessment.
Legitimate Interests Examples That Usually Fail
| Purpose | Why it usually fails | Usual alternative |
|---|---|---|
| Behavioural advertising across sites and apps | People do not reasonably expect it; the Court of Justice said so for a social network in Meta v Bundeskartellamt (C-252/21) | Consent |
| Selling customer data to data brokers | Unexpected, and people lose control of their data | Consent, or do not do it |
| Marketing emails without the soft opt-in | The ePrivacy rules require consent | Consent |
| Profiling children for marketing | Children’s interests weigh heavily, and Recital 38 singles out marketing and profiling | Do not do it, or consent with strong safeguards |
| Processing by a public authority for its tasks | Article 6(1) excludes it | Public task |
UK Recognised Legitimate Interests
Since 5 February 2026, the UK GDPR has a separate basis, recognised legitimate interests, for five purposes in its Annex 1: disclosures to bodies that need the data for their public tasks, national security and defence, emergencies, crime, and safeguarding vulnerable people. No balancing test is needed, though the processing must still be necessary. It does not exist under the EU GDPR. See our guide to recognised legitimate interests.
What Turns an Example Into a Pass
Across these legitimate interests examples, the same safeguards keep appearing:
- telling people, and naming the interest in the privacy notice (Article 13(1)(d));
- an easy way to object, which always works for direct marketing (Article 21);
- using as little data as the purpose needs, for as short a time as it needs;
- keeping out special category data and children’s data, or protecting them specifically;
- human review of decisions that matter to people.
Frequently Asked Questions
Are these legitimate interests examples enough to rely on without an assessment?
No. They show where legitimate interests often works. The accountability principle in Article 5(2) still means you must be able to show the three-part test for your own processing.
Can a commercial interest be a legitimate interest?
Yes. In October 2024 the Court of Justice confirmed, in the Royal Dutch Lawn Tennis Association case (C-621/22), that a purely commercial interest can be legitimate, provided it is lawful. It must still pass necessity and balancing.
What is the most common reason legitimate interests fails?
Reasonable expectations. If people would be surprised by the processing, the balance usually tips against it, as the EDPB Guidelines 1/2024 on legitimate interest explain.
Legitimate interests or consent?
See our comparison of legitimate interests vs consent.
To test your own purpose, use our free legitimate interests assessment template, which screens the basis, runs the three tests and rates the impact on the people concerned. Our guide to the legitimate interests assessment covers the method, and the GDPR Toolkit has the privacy notices, records and policies around it.