Legitimate interest — Art. 6(1)(f) GDPR — is the most useful and the most misunderstood lawful basis in the regulation. Marketers reach for it because it does not require a consent banner; regulators scrutinise it because it must not become a blanket permission slip. This piece walks you through what the article actually says, the three-step test regulators expect you to run, a worked example for company-level visitor identification, and where the boundaries are.
What Art. 6(1)(f) actually says
The article permits processing of personal data when it is "necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject." Two words carry most of the weight — "necessary" and "overridden" — and the third pillar is unwritten but expected: your legitimate interest must itself be lawful. Any of the three failing means the basis fails.
The regulator does not decide for you. You perform the analysis, you record the analysis, and if you are challenged you produce the analysis. There is no filing, no registration and no approval — but there is also no defence if the balancing was not actually done.
The three-step balancing test
European data protection authorities converge on the same three-step framework, sometimes called the LIA (Legitimate Interests Assessment). Every step must pass.
- Purpose test — is the interest lawful, specific and real? A generic "we want to sell more" does not qualify. "Identifying companies visiting our B2B website in order to reach the right decision-maker with relevant information" does.
- Necessity test — is the processing the least-intrusive way to achieve the purpose? If a less-invasive method would work (aggregate analytics, opt-in newsletter, a form), it should be preferred. Necessity means you cannot reasonably do it another way.
- Balancing test — do the data subject’s interests, rights and freedoms override yours? Consider their reasonable expectations, the nature of the data, the sensitivity, the context in which it was collected, and any safeguards you apply.
Worked example: company-level visitor identification
Assume a B2B SaaS company operating in the EU wants to identify the organisations behind visits to its website — company-level identification, no cookies, no personal identifiers. Here is what a defensible LIA looks like, step by step.
Step 1 — Purpose
The purpose is to identify companies that are actively researching a B2B service in order to send them relevant, targeted information (a personalised email, a case study, an invitation to a fifteen-minute call). The purpose is lawful, specific, and real. It is not "just in case" data collection.
Step 2 — Necessity
Could the purpose be achieved less-invasively? Aggregate analytics answers "how many?" but not "who?" — it cannot fulfil the purpose. A generic newsletter reaches self-selected subscribers but not the companies actively researching now. A form only captures the small fraction of visitors who volunteer their details. Company-level identification, which resolves the IP to an organisation without touching a personal identifier, is a proportionate and necessary means for the stated purpose.
Step 3 — Balancing
Reasonable expectations: business visitors browsing a B2B service’s website while at work generally expect the site operator to know that a business (not necessarily an individual) has visited. Nature of the data: the identified entity is a legal person (an organisation), not a natural person. Sensitivity: no special-category data is involved. Context: the data was collected on the controller’s own website in the ordinary course of business. Safeguards: no cookies, no fingerprinting, no cross-site tracking, no profile of the individual visitor; an accessible opt-out for the identified company; a public privacy notice explaining exactly what happens.
On that balance, the controller’s interest in reaching a decision-maker with relevant information is not, in the ordinary B2B case, overridden by the interests, rights and freedoms of the data subject. A different processing (say, individual-level tracking, or repurposing the data to sell to third parties) would flip the balance the other way — the analysis is specific to what you actually do.
What the documentation actually looks like
A defensible LIA is a short, dated document — usually two to four pages — signed off by a named person. Below is the structure most European DPAs accept.
| Section | Contents | Length |
|---|---|---|
| Header | Controller name, controller address, DPO contact if any, effective date | 1 line each |
| Purpose | Specific, lawful, real interest — one paragraph | ~100 words |
| Necessity | Alternatives considered and why they do not meet the purpose | ~150 words |
| Balancing | Reasonable expectations, nature, sensitivity, context, safeguards | ~300 words |
| Safeguards | Concrete measures: opt-out, retention, no personal identifiers, DPA with processors | ~150 words |
| Review | Signed off by (name, role); next review date (annual) | 2 lines |
What differs by country
Art. 6(1)(f) is uniform across the EU, but the ePrivacy dimension (in Germany, § 25 TDDDG) governs whether you may place or read information on the terminal equipment — cookies, local storage, fingerprinting. Company-level identification without any client-side storage falls outside § 25’s consent requirement; introducing any client-side identifier moves you into consent territory regardless of your Art. 6 basis.
When consent — not legitimate interest — is the right basis
Legitimate interest is not a universal replacement for consent. The right basis flips to consent (Art. 6(1)(a)) in at least three common B2B situations.
- Whenever information is stored on or read from the visitor’s device beyond what is strictly necessary — a tracking cookie, a localStorage identifier, a fingerprint — ePrivacy/§ 25 TDDDG requires consent regardless of your Art. 6 basis.
- Processing of personal data of natural persons for behavioural advertising, cross-site profiling, or resale to third parties. These fall well outside a proportionate B2B contact interest.
- Sensitive-category data (Art. 9) — health, political opinions, biometrics — is never covered by ordinary legitimate interest; a specific Art. 9 basis is required in addition to Art. 6.
An operational checklist
- You have a written, dated LIA covering the specific processing.
- Your privacy notice explains, in plain language, that you identify companies (not individuals) and why.
- You have an accessible opt-out and you honour it — companies removed within a defined window and not re-identified.
- You have a signed DPA with any processor that touches the data.
- You review the LIA annually or when the processing materially changes.
This article is written for education, not legal advice. For a binding assessment of your own processing, consult qualified counsel in your jurisdiction.
Published by
lead.box Team
More articles
See lead.box on your own traffic
Start free — no card, no sales call required. Or book a 20-minute walk-through if you want the guided tour.
