Privacy & regulation · also called LI
Legitimate interest
Legitimate interest is one of the GDPR's six lawful bases for processing personal data, allowing processing without consent when it is necessary for a genuine interest not overridden by the individual's rights.
Consent is not the only way to lawfully process data under the GDPR. Article 6(1)(f) allows processing when it is necessary for the legitimate interests of the company or a third party, unless those interests are overridden by the person's rights and freedoms. It requires a three-part test: a real, lawful interest; necessity; and a balancing test against the individual's expectations and potential harm.
In advertising, legitimate interest has been used for purposes such as fraud prevention, security and some measurement. Fraud prevention is widely accepted as a legitimate interest. For personalised advertising, it is contested: regulators and courts have been sceptical that tracking-based profiling passes the balancing test, and the EU Court of Justice's 2023 ruling in the Meta v Bundeskartellamt case reinforced that scepticism for large-scale profiling.
The IAB IAB TCF v2.2 removed legitimate interest as an option for ad and content personalisation purposes. Also note that the ePrivacy rules on accessing information on a device (such as cookies) require consent regardless of GDPR's legal bases, except where strictly necessary.
Think of it like this
Legitimate interest is like a shop's right to check your bag for security reasons without asking permission, but not a right to read your diary.
An example
A verification vendor processes IP addresses and device signals to detect invalid traffic on EU campaigns, relying on legitimate interest in fraud prevention after documenting a balancing assessment.
Related terms
GDPR
The GDPR (General Data Protection Regulation) is the European Union's data protection law, applying since May 2018, which governs how organisations collect and use personal data about people in the EU.
IAB TCF (Transparency & Consent Framework)
The IAB TCF (Transparency & Consent Framework) is IAB Europe's standard for collecting users' GDPR consent and objections through CMPs and passing those choices to ad tech vendors in a consent string.
CMP (consent management platform)
A CMP (consent management platform) is software that shows users privacy choices, such as a cookie banner, records their consent or opt-outs, and passes them to the site's partners.
Data minimization
Data minimization is the privacy principle that organisations should collect and keep only the personal data that is adequate, relevant and necessary for a specific, stated purpose.
Fraud detection
Fraud detection in advertising is the process and technology of identifying invalid or fraudulent impressions, clicks, installs and conversions, so they can be blocked in advance or excluded from billing.
Sources: GDPR Article 6: lawfulness of processing, IAB Europe: TCF v2.2