Legitimate Interest vs Consent: Why It Matters for Cookies
Legitimate interest and consent are both valid GDPR lawful bases, but they're not interchangeable for cookies. Here's when each actually applies, and where sites get it wrong.
GDPR gives you six possible lawful bases for processing personal data, but for cookies and website tracking specifically, the practical choice almost always comes down to two: consent, or legitimate interest. They’re both legitimate legal bases in the abstract, the mistake is treating them as interchangeable, which they’re not, especially for cookies.
What each one actually means
Consent is exactly what it sounds like: the visitor affirmatively agrees before processing begins. It has to be freely given, specific, informed, and unambiguous, the standard covered in our piece on what a compliant cookie banner requires.
Legitimate interest is a different lawful basis entirely: you can process data without consent if you have a genuine business reason, that reason isn’t overridden by the individual’s rights and freedoms, and you can document a “balancing test” showing you weighed your interest against their privacy expectations.
Why legitimate interest mostly doesn’t work for cookies
This is the part that trips people up. Legitimate interest can be a valid basis for some processing, fraud prevention, basic network security, certain first-party analytics in specific circumstances. But for most cookie-based tracking, advertising pixels, third-party analytics, cross-site tracking, European regulators and the ePrivacy Directive framework have been consistently clear: consent, not legitimate interest, is the required basis. The reasoning is that visitors don’t reasonably expect this kind of tracking, and their privacy interest generally outweighs a business’s marketing interest in the balancing test.
Usercentrics
Getting the lawful basis right per tracker category, not just having a banner, is exactly the kind of granular configuration Usercentrics supports, distinguishing cookies that can rely on legitimate interest from those that genuinely require consent.
Where legitimate interest can legitimately apply
A narrower set of cases where legitimate interest is more defensible:
- Strictly necessary cookies technically don’t need a lawful-basis debate at all, they’re exempt from consent requirements because the site can’t function without them (session cookies, security tokens, load balancing).
- First-party analytics in limited configurations, some regulators have accepted narrowly scoped, privacy-preserving analytics under legitimate interest, though this varies by jurisdiction and isn’t a safe default assumption for most standard analytics setups.
- Direct marketing to existing customers in some circumstances, subject to an opt-out being clearly available.
The practical takeaway
Don’t reach for “legitimate interest” as a way to avoid asking for cookie consent, for the tracking categories most sites actually run (analytics, ads, chat, session replay), it’s very unlikely to hold up, and using it incorrectly can be worse than a straightforward consent gap, because it suggests the operator considered the requirement and got it wrong rather than simply missed it. When in doubt, default to consent for anything beyond strictly necessary cookies.
For choosing a lawful basis outside of cookies specifically, customer data, marketing lists, employee monitoring, see our broader consent vs. legitimate interest decision guide.
This guide is educational and not legal advice. The legitimate interest balancing test is fact-specific. For your specific situation, consult a privacy attorney.