The Practical Role of Legitimate Interest under the GDPR
The Practical Role of Legitimate Interest under the GDPR AI, Operational Constraints, and the Limits of Regulatory Simplification Among the six legal bases for processing personal data under Article 6 GDPR, legitimate interest was not originally designed to support large-scale or continuous data processing as a primary mechanism. Its role was limited and functional: to cover processing activities that cannot realistically rely on consent, do not fall under a legal obligation or the exercise of public authority, yet occur as part of ordinary organisational operations. Such activities are common in large organisations. They include internal administration, cybersecurity measures, fraud prevention, system maintenance, and basic operational analytics. The GDPR deliberately retained legitimate interest for these situations. Article 6(1)(f) does not provide a general authorisation. It conditions its use on whether the processing is necessary for the purposes of a specific legitimate...