Legitimate Interest vs Consent: Choosing the Right Legal Basis for Ads

Reading time: 1 minutes | Compliance Guide | Updated: 9/3/2026

Choosing correctly between legitimate interest vs consent GDPR bases is the first decision in any compliance analysis this guide is a practical framework for getting it right.

Legal basis is the first decision in any GDPR compliance analysis, and marketing teams often default to whichever one seems most convenient rather than the one that actually fits the activity. This guide is a practical framework for choosing correctly between the two bases that come up most often in marketing: consent and legitimate interest.

1. The two bases are not interchangeable

Consent and legitimate interest solve different problems, and switching between them retroactively relying on legitimate interest because consent wasn't obtained, or vice versa is a compliance red flag, not a fallback option. The choice has to be made deliberately, before processing starts, and documented.

2. When consent is the right (or only) basis

Consent is required, not just preferred, for:

  • Cookie-based tracking and similar technologies, under the ePrivacy rules this sits alongside GDPR and generally can't be replaced with legitimate interest.
  • Email marketing to individual consumers in most EU jurisdictions, under national ePrivacy implementations of the "soft opt-in" rules.
  • Processing that involves special category data, or profiling with legal or similarly significant effects.

Consent's advantage is clarity if properly obtained, it's hard to challenge. Its cost is friction: opt-in rates are lower than assumed reach, and consent has to be genuinely revocable at any time.

3. When legitimate interest can apply

GDPR Recital 47 explicitly names direct marketing as a potential legitimate interest, particularly relevant for:

  • B2B outreach to existing business contacts, where the relationship creates a reasonable expectation of continued communication.
  • Postal or non-electronic direct marketing (email/SMS still generally needs consent under ePrivacy rules regardless of the GDPR legal basis chosen).
  • Retargeting or personalization based on a genuine existing customer relationship, where the individual would reasonably expect this.

Legitimate interest is not a shortcut around consent requirements that exist for other reasons (like the cookie consent rule) — it only ever applies to the GDPR legal-basis question, not to ePrivacy's separate tracking-technology consent requirement.

4. The three-part test behind "legitimate interest"

Relying on legitimate interest isn't just asserting it Article 6(1)(f) and EDPB guidance describe a three-part test:

  • Purpose test is there a genuine, specific, legitimate interest being pursued (not just "because it benefits us")?
  • Necessity test is this processing actually necessary to achieve that interest, and is there a less intrusive way to achieve the same goal?
  • Balancing test do the individual's interests, rights, and reasonable expectations override your interest? This is where factors like the individual's relationship to you, whether they'd reasonably expect this use, and the potential impact on them all get weighed.

5. Documenting a Legitimate Interest Assessment (LIA)

If you rely on legitimate interest, write the three-part test down a short, specific document for each distinct processing activity, not a generic template reused unchanged across every campaign. A real LIA names the specific interest, explains why the processing is necessary, and honestly weighs the individual's perspective, including what would change the balance (for example, a much more sensitive data category, or a data subject who has an existing relationship with a competitor rather than with you). This document is what you'd need to produce if a regulator or the individual challenges your basis.

6. The right to object always applies

Unlike consent (which the individual grants or withholds up front), legitimate interest comes with a standing right to object at any time (Article 21) and for direct marketing specifically, that objection must be honored absolutely, with no balancing test on your side. Your process needs a clear, easy opt-out mechanism, and honoring an objection has to actually stop the processing, not just log the request.

7. A practical decision framework

  • Does the activity involve cookies or similar tracking technology? → Consent, no exceptions.
  • Is it email/SMS marketing to a consumer with no prior soft-opt-in relationship? → Consent.
  • Is it B2B outreach to an existing business contact, non-electronic, or based on a genuine prior relationship? → Legitimate interest may apply — complete and document an LIA.
  • Does it involve special category data or high-risk profiling? → Consent (or another explicit Article 9 basis), not legitimate interest.
  • Whichever basis applies, is the opt-out/right-to-object mechanism actually easy to use and honored promptly?
This guide is general information, not legal advice. Legitimate interest is one of the most fact-specific areas of GDPR — have a qualified data protection professional review your LIA before relying on it for anything with real scale or risk.

See how Adverizeo handles GDPR compliance across legal bases, or view pricing.

Loading full guide...