This guidance outlines how organizations can lawfully process personal data under GDPR Article 6(1)(f), which allows for processing based on legitimate interests. It details three key conditions: identifying a legitimate interest, ensuring processing is necessary for that interest, and balancing it against the rights and freedoms of data subjects. The guidelines provide a framework for conducting this assessment and offer examples, including areas like fraud prevention and marketing. The guidance is subject to public consultation and might be amended.
Author: European Data Protection Board
Status: Draft
Adoption date: 2024-10-08
Last updated: 08 Aug 2025
Category: Guidance
Subcategory: Other official document