Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

Legitimate interests vs consent compared: who decides, what the law requires and a two-question test

Legitimate Interests vs Consent: The Essential 2026 Guide to Choosing

Legitimate interests vs consent is the lawful basis choice most organizations get wrong, usually by asking for consent they do not need or by relying on legitimate interests where the law requires consent. Both are lawful bases under Article 6(1) of the GDPR, and neither ranks above the other. They work very differently, though: consent hands control to the individual, while legitimate interests puts the responsibility on you to show the processing is fair. This guide sets out the differences and how to choose.

Legitimate interests vs consent compared: who decides, what the law requires and a two-question test

Use consent when you want to give people real choice and control, when you can let them say no without consequence, and when another law requires it, such as the ePrivacy rules for most marketing emails and non-essential cookies. Use legitimate interests when the processing is something people would reasonably expect, has a minimal privacy impact or a compelling justification, and you can offer a genuine right to object. If you would carry on processing after someone refused consent, consent was never the right basis.

Consent (Art 6(1)(a))Legitimate interests (Art 6(1)(f))
Who decidesThe individualYou, after a three-part test
What it takesFreely given, specific, informed and unambiguous agreement by a clear affirmative act (Art 4(11), 7)A legitimate interest, necessity, and a balance that favours the processing
Record to keepWho consented, when, to what, and howA legitimate interests assessment
Can people stop it?Withdraw at any time, as easily as they gave it (Art 7(3))Object (Art 21); you must stop unless you show compelling grounds, and always for direct marketing
Data portability (Art 20)AppliesDoes not apply
Public authoritiesRarely suitable because of the imbalance of powerNot available for their tasks
EmployeesRarely freely givenOften more suitable, with a careful balance
ChildrenParental consent under 16 (or the national age, 13 in the UK) for online services (Art 8)Children’s interests weigh heavily in the balance

The GDPR does not make consent the default for anything, but other rules do. The ePrivacy Directive, implemented in the UK as PECR, requires consent for:

  • marketing emails and texts to individuals, unless the soft opt-in applies (your own customers, similar products, with a chance to refuse at collection and in every message);
  • storing or reading information on a device, such as cookies and similar trackers, unless strictly necessary or covered by a narrow exemption;
  • automated marketing calls.

Where those rules require consent, the UK ICO says you must not use legitimate interests as your lawful basis for that processing, and that consent obtained under PECR is also the appropriate lawful basis under the UK GDPR. Postal marketing, and some live phone marketing to numbers not on the preference register, carry no consent requirement, so legitimate interests can be used there.

Article 9 adds another layer: special category data needs a condition as well as a lawful basis, and for many commercial uses the only condition available is explicit consent.

Legitimate interests is often the more honest basis where consent would not be a real choice:

  • Fraud prevention and network security. Recitals 47 and 49 name both. You would not stop because someone said no.
  • Employee data. Recital 43 warns that consent is unlikely to be freely given where there is a clear imbalance, which is typical at work.
  • Postal marketing to existing customers. Recital 47 says direct marketing may be a legitimate interest, and no consent rule applies to post.
  • Intra-group administration. Recital 48 recognises sharing within a group for internal administration.

In the UK, the Data (Use and Access) Act 2025 wrote those examples into the UK GDPR from 5 February 2026. The ICO is clear that this does not mean legitimate interests automatically applies to them: you must still do the three-part test.

Consent is the better choice where the processing is intrusive, unexpected, or something people should be able to refuse:

  • tracking people across websites or apps for advertising;
  • sharing or selling data to third parties for their own marketing;
  • processing that people would find surprising, however useful it is to you.

The Court of Justice showed where the line can fall in Meta Platforms v Bundeskartellamt (C-252/21, July 2023): it held that users of a free social network could not reasonably expect their data to be processed for personalised advertising without their consent, so their interests overrode the company’s.

The right basis depends on the facts, but these are the usual answers:

PurposeUsual basisWhy
Marketing emails to prospectsConsentThe ePrivacy rules require it
Marketing emails to existing customers (soft opt-in)Legitimate interestsNo consent required, and customers can opt out in every message
Postal marketing to customersLegitimate interestsExpected, and no consent rule applies
Non-essential cookies and advertising trackersConsentThe ePrivacy rules require it
Fraud checks on ordersLegitimate interestsRefusal would defeat the purpose
Security loggingLegitimate interestsNamed in Recital 49
Staff monitoringLegitimate interestsConsent at work is rarely free; the balance needs care
Health data for a wellness appExplicit consentArticle 9 needs a condition, and explicit consent is usually the one available

When the legitimate interests vs consent answer is not obvious, ask two questions: would people be surprised by the processing, and would you stop if they said no? A yes to either points to consent.

Common Mistakes

  • Asking for consent “to be safe”. If you would process anyway, consent is misleading, and a withdrawal leaves you with no basis to fall back on.
  • Switching bases after the event. You cannot swap to legitimate interests when consent is withdrawn; the basis must be chosen, and stated in the privacy notice, before you start.
  • Legitimate interests for emails that need consent. A strong balancing test cannot fix a PECR breach.
  • No written LIA. Without one you cannot show the test was done, which is what Article 5(2) requires.
  • Bundled consent. Consent tied to a service, or pre-ticked, is not freely given.

Frequently Asked Questions

Legitimate interests vs consent: which is safer?

Neither. Each is safe when it fits. Consent is weaker than it looks, because it can be withdrawn at any time; legitimate interests is weaker where the balance is doubtful.

Can I rely on both for the same processing?

Not for the same purpose. You can use consent for one purpose and legitimate interests for another, but each purpose needs one clear basis.

Do I need an LIA if I use consent?

No. You need records of the consent instead. The LIA is the record for legitimate interests.

What about cookies for analytics?

Under the ePrivacy rules they generally need consent in the EU. The UK now exempts some analytics cookies if people are told and can opt out; check the conditions before relying on it.

If legitimate interests is your answer, record the test with our free legitimate interests assessment template, and see a finished one in our legitimate interests assessment example. Our guide to the legitimate interests assessment covers the test in depth, and cookie consent covers the ePrivacy side. For privacy notices, consent records and the policies around them, see the GDPR Toolkit.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.