Services
Consultancy Project-Based Approach Support Training Academy
Accelerators
AI Data Analyst Artificial Intelligence CDP as a Service Customer Data Architecture Data Ideation Workshops Data Maturity Assessment Job Analytics Server Side Tracking
Cases
News
Events
About
Our Values Our Team Our Toolkit Careers
Contact Us
  • News
21 November 2024
2 min read

New GDPR Guidelines on Legitimate Interest

In October 2024, The European Data Protection Board (EDPB) adopted new Guidelines on processing personal data based on legitimate interest, providing a clearer path for data controllers to lawfully process data under Article 6(1)(f) of the GDPR.

Peter Vertongen
Head of Omni-Channel Strategy Peter Vertongen

In our opinion, it’s about time to address this issue, especially considering how frequently we encounter “legitimate interest” as a legal basis in cookie consent banners.

Some websites use legitimate interest as a legal basis to pre-check consent boxes for various types of cookies (see example below). A particularly concerning example is a Dutch online community that claims legitimate interest to place cookies for gambling-related ads. A justification that seems questionable under GDPR standards.

Data preferences dialogue with options for personalized ad profiles and ad selection, featuring consent toggles and Back/Submit buttons.

So, what exactly is legitimate interest under GDPR?

In short, legitimate interest is a legal basis that allows organisations to process personal data when it’s necessary for a legitimate business purpose, provided it does not override the individual’s rights and freedoms. This means that no consent is required. A company may rely on legitimate interest to send marketing e-mails to existing customers, believing they have a reasonable expectation of receiving such communications.

The broad and flexible nature of the term allows websites to claim legitimate interest for various data processing activities, such as targeted advertising and user profiling, without fully disclosing these actions to users.

However, the main concern is that it can sometimes be applied in ways that may not fully align with user consent and transparency standards.

Key Takeaways from the new guidelines for legitimate interest as a legal basis
To address concerns around using legitimate interest as a legal basis for cookies, the latest guidelines outline when controllers can rely on this approach for data processing.

Controllers must meet three cumulative conditions:

  • The controller or third party pursues a legitimate interest.

  • Processing the data is necessary for this interest.

  • Balancing the legitimate interest with the rights and freedoms of individuals is essential.

The update also reflects the recent ECJ ruling (C-621/22, Oct 2024), which provides further clarity on how legitimate interest should be evaluated.

Controllers must carefully assess:

  • Whether their interest is lawful, specific, and real.

  • If there are less intrusive alternatives.

  • Safeguards that can protect the individual’s rights.

These updates are important for any organisation considering relying on legitimate interest to process personal data. The new framework helps ensure compliance while balancing business needs with protecting individual rights.

Ready to activate your data?

Ready to embark on a journey of success? Contact us today to discuss your needs. Let's work together to turn your vision into reality.

Reach out, and let's chat.
pencil drawing of two men
  • Contact us
  • Hertshage 10
    9300 Aalst, Belgium
  • welcome@multiminds.eu
  • +32 491 33 11 11
  • Our services
  • Consultancy
  • Project-Based Approach
  • Support
  • Training
  • Our accelerators
  • CDP as a Service
  • Customer Data Architecture
  • Data Ideation Workschops
  • Data Maturity Assessment
  • Server Side Tracking
  • Job Analytics
  • AI Data Analyst
  • Artificial Intelligence
  • Our newsletter
  • Subscribe to our newsletter for the latest news and upcoming workshops.
  • Thank you for subscribing!

©2026 MultiMinds. All rights reserved.

Cookie Policy Privacy Policy

We’re an analytics agency. You know what’s coming.

Honestly? We just want to see how you move through our site so we can make our charts look beautiful and our insights even sharper. It's like a science experiment, and you're our favourite variable.

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

anonymous
2 year | HTTP Cookie
Stores the user's cookie consent state for the current domain.
_cfuvid
Session | HTTP Cookie
This cookie is a part of the services provided by Cloudflare - Including load-balancing, deliverance of website content and serving DNS connection for website operators.
_cfuvid
Persistent | HTML Local Storage
This cookie is used to distinguish between humans and bots.

Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in.

Analytical cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

_ga#
1 year | HTTP Cookie
This cookie is a Google Analytics persistent cookie which is used to distinguish unique users.

Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.