1. Introduction

Last October 8, 2024 the European Data Protection Board (hereinafter referred to as “EDPB“) published its Guidelines 1/2024, providing detailed instructions on using legitimate interest as a legal basis for processing personal data. This publication serves as an essential reference for both private and public entities, clarifying the fundamental requirements for a compliant application of Article 6(1)(f) of the GDPR. Among its key points, the document emphasizes the importance of the balancing test, a crucial tool to balance the legitimate interests of the data controller with the fundamental rights and freedoms of data subjects.


2. Why it is relevant?

The importance of legitimate interest lies in its flexibility: it allows data controllers to process personal data without explicit consent from data subjects, provided strict conditions are met. However, this flexibility can also entail risks of abuse or misinterpretation. Guidelines 1/2024 offer a structured framework to mitigate such risks, ensuring a balanced and proportionate use of this legal basis.

Moreover, the EDPB highlights that Article 6(1)(f) of the GDPR should not be treated as a “last resort” for rare or unforeseen situations, nor should it be automatically chosen or excessively used based on a perception that it is less restrictive than other legal bases. This approach aims to preserve the integrity and effectiveness of the protections offered by the GDPR.

3. Criteria

According to the EDPB, using legitimate interest requires compliance with three conditions:

  • The Interest: The pursued interest must be lawful, clearly defined, and current. For example, a company may invoke legitimate interest to monitor access to its IT systems to ensure corporate security. However, this basis would not be acceptable for processing that violates national or EU laws.
  • Necessity of Processing: The processing must be strictly necessary to achieve the declared interest. This implies that the controller must assess whether less invasive alternatives exist. For instance, an employer may monitor corporate emails to prevent security breaches, but only if other methods, such as staff training, prove insufficient.
  • Balancing of Interests: The controller’s interest must not override the fundamental rights and freedoms of data subjects. For example, behavioral tracking technologies may be justified to improve user experience on a website, but they must respect visitors’ privacy and provide opt-out options.

4. The balancing test: how does it work?

The balancing test is a methodological tool that allows the controller to assess whether the processing is genuinely justified. This process must consider several factors:

  • Fundamental Rights of Data Subjects: These include data protection, privacy, and other constitutionally relevant freedoms, such as freedom of expression or association. For example, in a workplace context, employee monitoring must be limited and proportionate to avoid violations of personal dignity.
  • Impact of Processing: The controller must carefully analyze the nature and sensitivity of the data processed. A common example involves health data: processing such data may be justified for scientific research purposes but requires robust security measures to protect the individuals involved.
  • Expectations of Data Subjects: It is crucial to consider what data subjects expect. For instance, a customer providing their data to purchase a product might expect it to be used solely to complete the transaction, not for undisclosed marketing purposes.

The EDPB underscores that the balancing test should not aim to avoid any impact on the rights and interests of data subjects but rather to prevent disproportionate impact by evaluating the relative weight of conflicting interests.

5. Sectors of application.

The guidelines provide specific recommendations for various sectors, highlighting the importance of case-by-case assessment:

  • Data of Minors: The best interest of the child must always prevail. For example, schools may process student data for educational purposes but should avoid uses that could expose minors to risks, such as commercial profiling.
  • Direct Marketing: Companies can rely on legitimate interest to send promotional communications to their customers, provided these are relevant and non-intrusive. For example, a regular customer might expect to receive offers related to previously purchased products.
  • Information Security: In an era of increasing cyber threats, using legitimate interest to ensure the security of corporate systems is often justified. However, transparent measures must be adopted to inform data subjects.
  • Fraud Prevention: Processing personal data to prevent, detect, and prosecute fraud can be based on legitimate interest, provided adequate measures are in place to protect the rights of the data subjects.
  • Scientific and Historical Research: Though less common, legitimate interest may be used in research contexts, provided the principles of data minimization and subject protection are rigorously observed. 


6. Practical Guidelines for Businesses.

To ensure compliance, organizations must adopt a rigorous approach:

  • Document the Balancing Test: Every decision related to legitimate interest must be supported by accurate documentation demonstrating how the processing meets the defined criteria. This documentation must be maintained and regularly updated.
  • Ensure Transparency: Companies must clearly inform data subjects about the purposes of processing, using detailed and accessible privacy notices. It is important to specify the pursued interests and the rights of data subjects in an understandable manner.
  • Respect Data Subjects’ Rights: It is essential to enable data subjects to exercise their rights, such as data access, objection to processing, and data deletion. Companies must implement efficient procedures to manage such requests promptly.
  • Evaluate Less Invasive Alternatives: Before proceeding with processing based on legitimate interest, companies must examine whether alternative methods achieve the same objectives with a lesser impact on the rights of data subjects.


7. Conclusions

Guidelines 1/2024 represent a crucial reference point for any business activity that involves processing personal data. These guidelines provide a clear and detailed framework for balancing the legitimate interests of data controllers with the protection of fundamental rights of data subjects, ensuring that the use of legitimate interest complies with GDPR principles.

For further insight into how these guidelines can be applied to your business activities, we invite you to contact our firm. Adhering to these guidelines not only ensures compliance with the GDPR but also strengthens customer trust and enhances your company’s reputation.