TL;DR for the DPO
Legitimate interest is the legal basis controllers choose when they have no consent and nothing better. It is also the only one that requires writing down a piece of reasoning before you use it. If that reasoning does not exist on paper, then in front of a regulator the legal basis simply is not there.
What the Court decided
In Case C-621/22, decided on 4 October 2024, the Dutch tennis federation had passed its members' data to two sponsors for marketing purposes. The question put to the Court was blunt: can a purely commercial interest qualify as a legitimate interest under Article 6(1)(f)? The answer was yes, provided the interest is not contrary to law. That is the part of the judgment that went round the conference circuit.
The part almost nobody read
Accepting that the interest is legitimate means clearing the first of three conditions. Two remain, and that is where everything is decided: the processing must be necessary for that interest - meaning no less intrusive means exists to achieve the same result - and the controller's interest must not be overridden by the interests or fundamental rights and freedoms of the data subject. The Court left the balancing to the national court, but pointed clearly at the criterion that weighs most: the reasonable expectations of the person who provided the data.
The criterion that sinks most cases
A member joining a sports federation expects their data to be used to run the membership. They do not expect commercial offers from a company they have no relationship with. Once the processing steps outside what the data subject could reasonably expect at the time of collection, the balance tips - and no amount of commercial interest tips it back.
Why this matters even if your clients do not sell lists
Legitimate interest supports processing nobody considers controversial: workplace CCTV, fraud prevention, information security, debt recovery, communications to existing customers. In all of them the legal basis is probably right, and in almost all of them the document proving it is missing. The difference between the two situations only becomes visible when an access request or a complaint arrives.
What the assessment has to contain
It does not need to be long: it needs to answer three questions and carry a date. The EDPB Guidelines 1/2024 on legitimate interest follow the same three-step structure, and they are the benchmark against which a regulator will measure your work.
- Which interest the controller pursues, described concretely and not as a formula: not 'commercial purposes' but 'contacting customers who purchased in the last twenty-four months to offer a renewal'.
- Why the processing is necessary for that interest, and which less intrusive alternative was considered and rejected: this is the step almost nobody writes down, and it is the one that shows a choice was actually made.
- What the data subject could reasonably expect at the time of collection, and which safeguards reduce the impact on them: a clear notice, short retention, an objection that is easy to exercise.
Two duties that follow the choice, and get forgotten
The first is Article 13(1)(d): where the basis is legitimate interest, the privacy notice must state WHICH interest. Writing 'the legitimate interest of the controller' and stopping there does not discharge the obligation, and it is an easy finding to make by reading the website alone. The second is Article 21: legitimate interest is the only legal basis that comes with a right to object, and for direct marketing that objection is absolute - no balancing, no exceptions.
The acid test
Ask the client to show you, for one processing operation based on legitimate interest, the document in which the three conditions were assessed. If it does not exist, this is not a formality to fix when there is time: it is the only thing that, if a complaint lands, distinguishes a reasoned choice from a legal basis picked by elimination.
Looking for a workspace for your DPO work?
DPO Workspace is built by a certified DPO. 30-day free trial.
Start free