Guide

GDPR Consent vs Legitimate Interest: A Decision Guide

A practical decision framework for choosing between consent and legitimate interest as your GDPR lawful basis, for any kind of processing, not just cookies.

Published May 11, 2026·Last updated August 18, 2026

We’ve written before about consent vs. legitimate interest specifically for cookies, where the answer is almost always consent. This piece is broader: a decision framework for choosing a lawful basis for any processing activity, customer data, employee monitoring, fraud prevention, marketing lists, where the answer is genuinely more of a judgment call.

Start here: what is the processing actually for

Before picking a basis, write down, specifically, what you’re processing and why. “Marketing” is too vague. “Sending a monthly product newsletter to people who bought from us in the last 12 months” is specific enough to evaluate.

Question 1: Would a reasonable person expect this?

Legitimate interest works best when the processing is something the individual would reasonably expect, given their relationship with you. A returning customer expecting an order-related email is reasonable. A first-time website visitor being added to a marketing list without asking is not, that’s a consent situation.

Question 2: Can you do the balancing test honestly?

Legitimate interest requires a genuine three-part test: you have a real interest, the processing is necessary to achieve it (not just convenient), and that interest isn’t overridden by the individual’s rights and interests. If you’re rationalizing your way to “yes” on all three to avoid building a consent flow, that’s a signal you should probably use consent instead.

Question 3: Is this special category data, or a high-risk context?

Health data, biometric data, and similar special categories almost always require explicit consent (with narrow exceptions), regardless of how compelling your legitimate interest argument is. Similarly, contexts widely recognized as sensitive, health-adjacent sites are a good example, covered in our piece on healthcare risk for a related but distinct legal theory, deserve a more conservative default.

Our recommendation

CookieYes

Whichever basis you land on, you need a way to actually record and manage it, CookieYes handles both consent capture and the underlying cookie inventory that most of these decisions turn on.

Try CookieYes

Question 4: Do you need an easy opt-out either way?

Even where legitimate interest is the correct basis, individuals still have a right to object to processing based on it, and for direct marketing specifically, that objection right is absolute, no balancing test required. If you’re not prepared to honor an opt-out request immediately and without argument, that’s a practical reason to prefer consent instead, where the opt-out is already built into the flow.

A simple rule of thumb

If you can clearly explain to the individual, in one sentence, why the processing serves their own reasonable expectations rather than just your business goals, legitimate interest is worth considering. If the explanation only makes sense from your side of the relationship, use consent.

Document the decision either way

Whichever basis you choose, write down why. Under the accountability principle (see our overview of GDPR’s seven core principles), being able to show your reasoning matters as much as getting the decision right.

This guide is educational and not legal advice. The legitimate interest balancing test is fact-specific and outcomes vary. For your specific situation, consult a privacy attorney.