Legitimate Interest vs Consent
Date: 2026-08-17
Which lawful basis you rely on to process personal data under UK GDPR. The common error is treating them as interchangeable options to pick between — they carry different obligations, different user rights, and one of them can’t be swapped in when the other fails.
The two, side by side
| Consent | Legitimate interests | |
|---|---|---|
| What it requires | Freely given, specific, informed, unambiguous, opt-in | A documented balancing test |
| The user can | Withdraw — and it must be as easy as giving | Object — and you must stop unless you show compelling grounds |
| Records needed | Who consented, when, to what, how | A legitimate interests assessment (LIA) |
| If challenged | Show the consent record | Show the LIA and your reasoning |
| Fails when | Bundled, pre-ticked, or refusing is harder than accepting | The individual’s rights outweigh your interest |
| Suits | Marketing, profiling, sharing with third parties | Fraud prevention, security, core service analytics |
They’re not a hierarchy. Consent isn’t “safer” — a consent you can’t evidence is worse than a well-documented legitimate interest, and consent that isn’t freely given is no basis at all.
PECR bites first, and this is the part people miss
Before the lawful-basis question arises, there’s a separate regime governing the device itself.
Q1 are you reading or writing ANYTHING on the user's device?
(cookies, localStorage, device fingerprinting, pixels)
│
├── YES → PECR applies. CONSENT is required, with a narrow
│ "strictly necessary" exemption.
│ legitimate interests is NOT available here.
│ ↓
└── NO ──→ ────┴──→ Q2 what are you doing with the data?
→ UK GDPR. now choose a lawful basis,
and legitimate interests IS available
This is the single most consequential point. Analytics cookies need consent under PECR regardless of how good your legitimate interests argument is — you cannot legitimate-interest your way onto someone’s device. The lawful basis question only governs what you do with data once lawfully obtained.
So the frequently-heard “we use legitimate interests for our analytics cookies” is confusing the two regimes — UK GDPR and PECR for Analytics covers the split in full.
The three-part balancing test
Where legitimate interests is available, an LIA has three parts and all three must pass:
1 PURPOSE is there a real, specific, lawful interest?
✓ "detect fraudulent orders"
✗ "improve the business" ← too vague to assess
2 NECESSITY is this processing actually needed for it?
could a less intrusive method work?
✗ fails if aggregate data would have sufficed
3 BALANCING do the individual's rights override your interest?
consider: would they reasonably expect this?
what's the impact if it goes wrong?
are they a child or otherwise vulnerable?
is the data sensitive?
Step 3 is the one that fails, and it fails on reasonable expectation. A customer expects you to record that they placed an order; they don’t expect their browsing to be combined with third-party data to infer their income bracket. The more surprising the processing, the weaker the balance.
Write the LIA down. An undocumented legitimate interest is indistinguishable from not having considered it, and the document is the entire defence if challenged.
Where each lands for analytics work
CONSENT NEEDED (PECR and/or GDPR)
· analytics cookies and similar storage ← almost always
· advertising pixels and remarketing
· sharing identifiers with ad platforms
· profiling for personalisation
· email marketing to individuals
· session replay and heatmap tools
LEGITIMATE INTERESTS PLAUSIBLE (no device access, or exempt)
· server-side logs for security and fraud
· aggregate reporting from data already lawfully held
· order and delivery processing analytics
· internal service-quality measurement
Note the pattern: legitimate interests works for things a customer would expect and that don’t involve tracking them across contexts. It stops working the moment third parties or cross-context profiling appear.
Consequences for the data
- Consented traffic is a biased sample. If 60% consent, your analytics describe those 60% — and they differ systematically from the rest. Every rate computed from consented data needs that caveat, and comparing periods across a consent-rate change compares two different populations — Consent Management, Modelled Conversions
- Withdrawal must propagate. To every destination the data was forwarded to, not just your own store — Customer Data Platforms
- Objection is not withdrawal. Under legitimate interests, an objection can in principle be refused with compelling grounds — but for direct marketing, an objection is absolute and must always be honoured
- You can’t switch bases when one fails. Falling back to legitimate interests after someone declines consent is specifically not permitted, and it’s a recognisable pattern that attracts enforcement
The commercial reality
Consent rates materially affect what you can measure, and the pressure to improve them is constant. The line: optimising the clarity and design of a banner is legitimate; optimising it by making refusal harder is not. Equal prominence for accept and reject, no pre-ticked boxes, no “legitimate interest” toggles buried a layer deeper than the accept button — Deceptive Design, Testing and Compliance.
[CHECK: enforcement positions on banner design and the treatment of analytics cookies have been the subject of active regulatory attention. Confirm the current ICO position before making changes to a consent flow, and take advice on any LIA that would be load-bearing.]
Where it interacts
- UK GDPR and PECR for Analytics — the two-regime split this note sits inside
- Consent Management — the mechanism that records and enforces the decision
- Pseudonymisation and Anonymisation — genuinely anonymous data needs no lawful basis at all, which is the only clean exit from this entirely
- Privacy-Preserving Measurement — approaches designed to need less of this