Legal · May 17, 2026 · 10 min read

What is legitimate interest? Art. 6(1)(f) GDPR for B2B marketers

A plain-language explainer of the three-step balancing test, with a worked example for company-level website-visitor identification, what your documentation should contain, and when consent is actually the lawful basis you need.

Editorial illustration of scales of justice, one side heavier, with a legal document silhouette.

Legitimate interest — Art. 6(1)(f) GDPR — is the most useful and the most misunderstood lawful basis in the regulation. Marketers reach for it because it does not require a consent banner; regulators scrutinise it because it must not become a blanket permission slip. This piece walks you through what the article actually says, the three-step test regulators expect you to run, a worked example for company-level visitor identification, and where the boundaries are.

What Art. 6(1)(f) actually says

The article permits processing of personal data when it is "necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject." Two words carry most of the weight — "necessary" and "overridden" — and the third pillar is unwritten but expected: your legitimate interest must itself be lawful. Any of the three failing means the basis fails.

The regulator does not decide for you. You perform the analysis, you record the analysis, and if you are challenged you produce the analysis. There is no filing, no registration and no approval — but there is also no defence if the balancing was not actually done.

The three-step balancing test

European data protection authorities converge on the same three-step framework, sometimes called the LIA (Legitimate Interests Assessment). Every step must pass.

  1. Purpose test — is the interest lawful, specific and real? A generic "we want to sell more" does not qualify. "Identifying companies visiting our B2B website in order to reach the right decision-maker with relevant information" does.
  2. Necessity test — is the processing the least-intrusive way to achieve the purpose? If a less-invasive method would work (aggregate analytics, opt-in newsletter, a form), it should be preferred. Necessity means you cannot reasonably do it another way.
  3. Balancing test — do the data subject’s interests, rights and freedoms override yours? Consider their reasonable expectations, the nature of the data, the sensitivity, the context in which it was collected, and any safeguards you apply.

Worked example: company-level visitor identification

Assume a B2B SaaS company operating in the EU wants to identify the organisations behind visits to its website — company-level identification, no cookies, no personal identifiers. Here is what a defensible LIA looks like, step by step.

Step 1 — Purpose

The purpose is to identify companies that are actively researching a B2B service in order to send them relevant, targeted information (a personalised email, a case study, an invitation to a fifteen-minute call). The purpose is lawful, specific, and real. It is not "just in case" data collection.

Step 2 — Necessity

Could the purpose be achieved less-invasively? Aggregate analytics answers "how many?" but not "who?" — it cannot fulfil the purpose. A generic newsletter reaches self-selected subscribers but not the companies actively researching now. A form only captures the small fraction of visitors who volunteer their details. Company-level identification, which resolves the IP to an organisation without touching a personal identifier, is a proportionate and necessary means for the stated purpose.

Step 3 — Balancing

Reasonable expectations: business visitors browsing a B2B service’s website while at work generally expect the site operator to know that a business (not necessarily an individual) has visited. Nature of the data: the identified entity is a legal person (an organisation), not a natural person. Sensitivity: no special-category data is involved. Context: the data was collected on the controller’s own website in the ordinary course of business. Safeguards: no cookies, no fingerprinting, no cross-site tracking, no profile of the individual visitor; an accessible opt-out for the identified company; a public privacy notice explaining exactly what happens.

On that balance, the controller’s interest in reaching a decision-maker with relevant information is not, in the ordinary B2B case, overridden by the interests, rights and freedoms of the data subject. A different processing (say, individual-level tracking, or repurposing the data to sell to third parties) would flip the balance the other way — the analysis is specific to what you actually do.

What the documentation actually looks like

A defensible LIA is a short, dated document — usually two to four pages — signed off by a named person. Below is the structure most European DPAs accept.

SectionContentsLength
HeaderController name, controller address, DPO contact if any, effective date1 line each
PurposeSpecific, lawful, real interest — one paragraph~100 words
NecessityAlternatives considered and why they do not meet the purpose~150 words
BalancingReasonable expectations, nature, sensitivity, context, safeguards~300 words
SafeguardsConcrete measures: opt-out, retention, no personal identifiers, DPA with processors~150 words
ReviewSigned off by (name, role); next review date (annual)2 lines
Minimum sections of a Legitimate Interests Assessment.

What differs by country

Art. 6(1)(f) is uniform across the EU, but the ePrivacy dimension (in Germany, § 25 TDDDG) governs whether you may place or read information on the terminal equipment — cookies, local storage, fingerprinting. Company-level identification without any client-side storage falls outside § 25’s consent requirement; introducing any client-side identifier moves you into consent territory regardless of your Art. 6 basis.

Legitimate interest is not a universal replacement for consent. The right basis flips to consent (Art. 6(1)(a)) in at least three common B2B situations.

  1. Whenever information is stored on or read from the visitor’s device beyond what is strictly necessary — a tracking cookie, a localStorage identifier, a fingerprint — ePrivacy/§ 25 TDDDG requires consent regardless of your Art. 6 basis.
  2. Processing of personal data of natural persons for behavioural advertising, cross-site profiling, or resale to third parties. These fall well outside a proportionate B2B contact interest.
  3. Sensitive-category data (Art. 9) — health, political opinions, biometrics — is never covered by ordinary legitimate interest; a specific Art. 9 basis is required in addition to Art. 6.

An operational checklist

  • You have a written, dated LIA covering the specific processing.
  • Your privacy notice explains, in plain language, that you identify companies (not individuals) and why.
  • You have an accessible opt-out and you honour it — companies removed within a defined window and not re-identified.
  • You have a signed DPA with any processor that touches the data.
  • You review the LIA annually or when the processing materially changes.

This article is written for education, not legal advice. For a binding assessment of your own processing, consult qualified counsel in your jurisdiction.

lead.box Team

Published by

lead.box Team

More articles

See lead.box on your own traffic

Start free — no card, no sales call required. Or book a 20-minute walk-through if you want the guided tour.

Start free trial

Notes on GDPR B2B lead intelligence

B2B Lead Identification Platform

lead.box — Identify the companies visiting your website

lead.box turns anonymous B2B website visitors into named companies. GDPR-first, first-party only, with EU data processing.

What lead.box does

How it works

  1. Add a single lightweight tracking snippet to your website.
  2. lead.box identifies the companies behind each visit using first-party IP intelligence.
  3. Hot leads are scored, enriched with contact data and exported as a file for your sales team.

Quick links