Legitimate Interests (Article 6(1)(f) GDPR)
Balancing of interests under Article 6(1)(f) GDPR: the three-step test (interest, necessity, balancing), the exclusion of public authorities under Article 6(1), second subparagraph, GDPR, and case groups.
Under Article 6(1)(f) GDPR, processing is lawful where it is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data. Point (f) is the most important open-ended legal basis in Article 6 GDPR and covers a large share of private-sector data processing.
Key takeaways
- Point (f) is the most important open-ended legal basis, but it is neither a catch-all nor a preferred ground, and like every legal basis it must be interpreted restrictively.
- The assessment proceeds in three cumulative steps: legitimate interest, necessity (no less intrusive means), and the balancing of interests.
- Public authorities are excluded from relying on point (f) in the performance of their tasks (Article 6(1), second subparagraph, GDPR).
- Data subjects have a right to object under Article 21 GDPR, which is even absolute in the case of direct marketing (Article 21(2) GDPR).
- The controller bears the burden of demonstration and proof for all three steps and must document the balancing exercise before processing begins.
1 Overview
1.1 Legal effect and function
Point (f) legitimizes processing operations that cannot be based on consent, contract, a legal obligation, vital interests, or a public interest task. The central function of the provision is to reconcile the legitimate interests of the controller with the data subject's interest in data protection.
The GDPR places point (f) on an equal footing with the other legal bases in Article 6(1) GDPR. There is no hierarchy among the legal bases (EDPB, Guidelines 1/2024 of 8 October 2024 on processing of personal data based on Article 6(1)(f) GDPR, para. 1).
1.2 Neither a catch-all nor a preferred ground
Point (f) is neither a "last resort" for rare or unexpected processing operations nor a preferred ground on the assumption that its requirements are less demanding than those of consent, for example. Its open-ended structure does not mean that every processing operation which cannot be brought under one of the other legal bases is automatically caught by point (f). Like every legal basis in Article 6(1) GDPR, point (f) must be interpreted restrictively (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, para. 92 et seq.; EDPB Guidelines 1/2024, para. 9).
1.3 Three-step test
The CJEU has developed a three-step test for point (f) (CJEU, judgment of 4 May 2017, C-13/16, Rīgas satiksme, para. 28; CJEU, judgment of 11 December 2019, C-708/18, Asociaţia de Proprietari, para. 40; CJEU, judgment of 7 December 2023, C-26/22 and C-64/22, SCHUFA Holding (Libération), para. 75):
- Is there a legitimate interest of the controller or of a third party?
- Is the processing necessary in order to achieve that interest?
- Do the interests, fundamental rights or fundamental freedoms of the data subject override the legitimate interest?
All three steps must be satisfied cumulatively. Steps two and three may overlap: in some constellations, whether a less intrusive means exists cannot be determined independently of the balancing exercise (CJEU, judgment of 7 December 2023, C-26/22 and C-64/22, SCHUFA Holding (Libération), para. 92). The assessment must be carried out and documented before processing begins; where a data protection officer has been designated, that officer must be involved (Article 38(1) GDPR).
Where several purposes are pursued, a separate legal basis must be identified for each individual purpose (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, para. 90). A blanket justification of several processing purposes by means of a single balancing exercise is not permissible.
The three steps build on one another: if the assessment fails at any one step, the processing cannot be based on point (f); only where all three steps are satisfied is the processing lawful.
1.4 Exclusion of public authorities under Article 6(1), second subparagraph, GDPR
Public authorities cannot rely on point (f) in so far as they act in the performance of their tasks (Article 6(1), second subparagraph, GDPR). This follows from the exhaustive regulatory scheme of Article 6(1) GDPR for the public sector: public authorities require a specific legal basis under point (c) or point (e) for their processing operations. Where a public authority acts commercially outside its sovereign tasks and the legal order of the Member State permits that activity, reliance on point (f) remains possible in narrow exceptional cases, but must be documented internally (EDPB Guidelines 1/2024, paras. 98 et seq.). The following applies to requests made by private parties to public authorities: the authority itself must be entitled and obliged to transmit the data on the basis of a sufficiently specific statutory processing provision; it is not sufficient that the requesting private party has a legitimate interest within the meaning of point (f).
1.5 Burden of demonstration and proof
The controller bears the burden of demonstration and proof that all three steps are satisfied. This follows from the general accountability obligation under Article 5(2) GDPR and Article 24(1) GDPR and has been confirmed repeatedly by the CJEU (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, para. 95).
2 Step 1: Legitimate interest
2.1 Concept and distinction from the purpose
Purpose and interest are not the same thing. The purpose within the meaning of Article 5(1)(b) GDPR is the specific occasion for the processing; the interest is the underlying economic, legal, or non-material motive. A company may have an interest in promoting its products; the purpose derived from that interest is, for example, sending marketing emails to existing customers.
In principle, any interest that is legally unobjectionable qualifies as legitimate: economic, legal, non-material, or factual interests may all be relevant. The threshold for recognition as an interest is low; the interest need not be named in legislation.
2.2 Three cumulative requirements
An interest qualifies as "legitimate" within the meaning of point (f) only where three requirements are met cumulatively (EDPB Guidelines 1/2024, para. 17):
- Lawful. The interest must not infringe Union or Member State law. A purely commercial interest may suffice provided it is not unlawful (CJEU, judgment of 4 October 2024, C-621/22, Koninklijke Nederlandse Lawn Tennisbond, paras. 40, 49). Where the intended processing is prohibited by a specific provision (such as electronic advertising for e-cigarettes under the Tobacco Products Directive), reliance on point (f) already fails at the first step.
- Clearly and precisely articulated. The controller must describe the interest specifically enough for it to be assessed at the subsequent steps. Formulas such as "our own business interest" or "protection for the good of the general public" are too vague. A neighborhood initiative that wishes to install video surveillance "to protect the community" without naming any specific incidents already fails the precision requirement.
- Real and present. A fictitious, hypothetical, or merely speculative interest is not sufficient (CJEU, judgment of 11 December 2019, C-708/18, Asociaţia de Proprietari, para. 44). A newspaper that builds a database of former subscribers for a future relaunch that is still merely hypothetical is not processing in pursuit of a real interest. Nor is an impairment that has already materialized required: the controller may pursue its interest preventively, provided that interest is tangible and present.
The interest must also already exist at the time of the processing. Interests established after the fact cannot justify processing retroactively (CJEU, judgment of 11 December 2019, C-708/18, Asociaţia de Proprietari, para. 44).
2.3 Own interests and third-party interests
Point (f) covers both the controller's own interests and the interests of third parties to whom the data are transmitted. The lawfulness of the third-party interest is assessed against the same criteria as that of the controller's own interest.
Typical contexts for third-party interests are:
- Establishment, exercise, or defense of legal claims. The interest of third parties in learning the identity of a tortfeasor in order to pursue civil law claims is recognized as a legitimate interest (CJEU, judgment of 4 May 2017, C-13/16, Rīgas satiksme, para. 29; CJEU, judgment of 17 June 2021, C-597/19, M.I.C.M., para. 108).
- Disclosure for transparency and accountability purposes. Where, for example, the salaries of senior management are disclosed without any statutory obligation to do so, this occurs primarily in the interest of employees or shareholders.
- Scientific or historical research. Third-party interests in research results may be taken into account under point (f).
- Information requests under company law. The interest of a shareholder in the data of the other shareholders, in order to make contact with them or to acquire their shares, may be legitimate (CJEU, judgment of 12 September 2024, C-17/22 and C-18/22, HTB Neunte Immobilien v Ökorenta, paras. 56 et seq.).
In practice, necessity is harder to demonstrate for third-party interests than for the controller's own interests; the processing is as a rule less foreseeable for data subjects.
2.4 Distinction from the public interest
Interests of the general public (such as public security or the protection of health) are as a rule to be covered by point (c) or point (e), not by point (f). Point (f) remains applicable only where a specific interest of the controller or of a third party can be identified which at the same time indirectly serves the public interest. Point (f) must not be used to circumvent the statutory requirements applicable to public interest tasks.
2.5 Interests recognized in the case law
The CJEU has recognized as legitimate interests, among others: access to online information (CJEU, judgment of 13 May 2014, C-131/12, Google Spain, para. 81; CJEU, judgment of 24 September 2019, C-136/17, GC and Others v CNIL, para. 53), the proper functioning of publicly accessible websites (CJEU, judgment of 19 October 2016, C-582/14, Breyer, para. 60), the protection of the property, health, and life of the co-owners of a residential building (CJEU, judgment of 11 December 2019, C-708/18, Asociaţia de Proprietari, para. 42), product improvement (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, para. 122), and creditworthiness assessment (CJEU, judgment of 7 December 2023, C-26/22 and C-64/22, SCHUFA Holding (Libération), para. 83).
2.6 Examples named in the recitals
Recital 47 names as examples of legitimate interests processing for direct marketing purposes, the prevention of fraud, and the transmission of personal data within a group of undertakings for internal administrative purposes. Recital 49 adds ensuring network and information security. Recital 50 names the reporting of possible criminal acts or threats to public security to the competent authority in individual cases.
3 Step 2: Necessity
3.1 "Necessary", not "useful"
The processing must be necessary in order to achieve the legitimate interest. Necessity is an autonomous concept of Union law and does not extend to everything that is merely useful for the interest. It must be interpreted in the light of the fundamental rights to privacy and data protection and of the principles laid down in Article 5 GDPR (CJEU, judgment of 16 December 2008, C-524/06, Huber, para. 52).
3.2 Strict standard and link to data minimization
The CJEU has tightened the standard considerably: processing is necessary only where it remains within "the limits of what is strictly necessary" (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, paras. 106, 126; CJEU, judgment of 7 December 2023, C-26/22 and C-64/22, SCHUFA Holding (Libération), para. 88). Necessity must be assessed together with the principle of data minimization under Article 5(1)(c) GDPR: only data that are "adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed" may be processed.
3.3 No less intrusive means
Where less intrusive, equally suitable alternatives exist, the processing is ruled out. The controller must examine whether it can achieve the interest with less data or with different data, with pseudonymized or aggregated data sets, or with processing limited in time. If the result can be achieved just as effectively by a less intrusive means, point (f) cannot be relied on (CJEU, judgment of 4 October 2024, C-621/22, Koninklijke Nederlandse Lawn Tennisbond, paras. 42 et seq., 51 et seq.).
3.4 The right to object plays no role
The right to object under Article 21 GDPR is left out of account when necessity is assessed. Whether the data subject is able to object to the processing at a later stage does not make the processing any more necessary or any less intrusive; necessity is to be assessed against objective criteria, irrespective of the options for reacting available to the data subject at a later point (CJEU, judgment of 9 January 2025, C-394/23, Mousse, paras. 65 et seq.).
4 Step 3: Balancing of interests
4.1 Four assessment steps
The EDPB recommends a structured balancing exercise in four steps: first, the interests, fundamental rights, and fundamental freedoms of the data subjects are identified. Next, the impact of the processing is to be established, on the basis of the nature of the data, the context of the processing, and the further consequences. In the third step, the reasonable expectations of the data subjects are determined. Finally, the balancing exercise proper is carried out, where appropriate with additional mitigating measures (EDPB Guidelines 1/2024, para. 32).
The balancing exercise does not aim to avoid every impact on data subjects, but to rule out disproportionate consequences. It is carried out on a case-by-case basis and must be documented.
4.2 Fundamental rights positions of the data subject
The following in particular are to be taken into account:
- the right to the protection of personal data (Article 8 of the Charter of Fundamental Rights of the European Union),
- the right to respect for private and family life (Article 7 of the Charter, Article 8 ECHR),
- the presumption of innocence (Article 6(2) ECHR),
- the freedom to choose an occupation (Article 15 of the Charter),
- human dignity (Article 1 of the Charter),
- freedom of expression, of assembly, and of religion, the prohibition of discrimination, the right to property, and physical and mental integrity, in so far as they are directly or indirectly affected by the processing.
In addition to fundamental rights, the "interests" of data subjects are expressly to be taken into account as well: financial, social, and personal concerns affected by the processing.
4.3 Fundamental rights positions of the controller
On the controller's side, the following in particular are to be taken into account:
- the freedom to conduct a business (Article 16 of the Charter),
- freedom of expression and information (Article 11 of the Charter), although only to a limited extent for purely commercially oriented online providers (German Federal Constitutional Court (BVerfG), order of 6 November 2019, 1 BvR 276/17, Recht auf Vergessen II, para. 105; CJEU, judgment of 24 September 2019, C-136/17, GC and Others v CNIL).
4.4 Nature of the data
The more sensitive the data, the stronger the data subjects' interest in protection. Special categories of personal data under Article 9 GDPR cannot in principle be based on point (f) (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, para. 90). A data set containing at least one sensitive data item is regarded as sensitive in its entirety where the data elements are not separable from one another at the time of collection (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, para. 89). Data are also sensitive where information within the meaning of Article 9(1) GDPR can objectively be inferred from them, irrespective of whether that information is accurate and of whether the controller intends the inference at all (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, paras. 68 et seq.).
Data under Article 10 GDPR (criminal offenses) likewise enjoy heightened protection. Data subjects typically perceive financial and location data as more private than occupational data; this affects the weight accorded to them in the balancing exercise.
4.5 Context of the processing
The context includes in particular:
- the scale of the processing and the number of data subjects affected,
- the position of the controller in relation to the data subject (employer, service provider, platform operator),
- combination with other data sets,
- the accessibility and degree of publicity of the data: the mere fact that data are publicly accessible does not render their further processing lawful (CJEU, judgment of 24 November 2011, C-468/10 and C-469/10, ASNEF, para. 44; CJEU, judgment of 4 May 2017, C-13/16, Rīgas satiksme, para. 32),
- any particular need for protection on the part of the data subjects (children, vulnerable persons).
4.6 Further consequences of the processing
Beyond the immediate effect of the processing, further consequences are to be taken into account: decisions by third parties that build on the data, legal consequences, discrimination, reputational damage, financial loss, exclusion from a service without any alternative, and risks to liberty, security, and physical or mental integrity.
In addition, there are the emotional consequences of losing control over one's own data and the chilling effect on protected forms of conduct, such as research, expression of opinion, or political activity. Continuous observation by a platform may create in data subjects the feeling that their private life is under constant surveillance; this weighs considerably in favor of the data subjects (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, para. 118). Where high risks are involved, a data protection impact assessment under Article 35 GDPR must be considered.
4.7 Reasonable expectations of data subjects
Recital 47 highlights the reasonable expectations of data subjects as a central balancing factor. What is to be expected is what the data subject could reasonably assume at the time of, and in the context of, the collection. The following in particular are to be taken into account:
- the nature of the relationship with the controller (existing customer, former customer, mere prospect),
- the closeness between the undertakings involved (a single unified brand vs. group companies that are merely linked economically),
- the place and context of the collection (video surveillance in a bank is to be expected, in sanitary or sauna areas it is not),
- the professional position, age, and status of the data subjects (minors, public figures).
Common industry practice and reasonable expectation are not the same thing. The mere fact that a practice is widespread in a sector does not automatically make it something to be expected. Conversely, merely complying with the information obligations under Articles 12, 13, and 14 GDPR does not substitute for reasonable expectation; a detailed privacy notice does not turn a surprising processing operation into an expected one (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, paras. 117, 123).
The assessment is made from the perspective of an "average" data subject within the relevant group, unless the processing affects different groups differently or there are specific indications of divergent individual interests, in particular in the employment relationship.
4.8 Child as data subject
Article 6(1)(f) GDPR expressly refers to the case where the data subject is a child. In that case, the interests in protection are given particularly strong weight. Children are often not aware of the implications of disclosing their data; this increases the weight of their fundamental rights positions in the balancing exercise (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, para. 111). The best interests of the child under Article 24(2) of the Charter are to be taken into account as a primary consideration.
The GDPR contains no separate definition of a child for the purposes of the balancing of interests. A workable reference point follows a contrario from Article 8(1), third sentence, GDPR: below the completed age of 13 (the minimum age below which Member States may under no circumstances go in relation to consent to information society services), it can as a rule be assumed that the interests of the data subject prevail. Above that age, minority remains a significant, but not automatically decisive, balancing factor; depending on maturity, the processing context, and the intensity of the interference, the balancing exercise may turn out differently.
Certain types of processing will be difficult to reconcile with the duties of protection owed to children: these include, in particular, extensive profiling and targeted advertising. In any event, the Digital Services Act (Article 28(2) of Regulation (EU) 2022/2065) prohibits targeted advertising based on profiling of minors.
4.9 Mitigating measures
Where the balancing exercise initially proves to be open or to fall against the data subjects, the controller may put additional safeguards in place in order to turn the balance in its favor. Such mitigating measures include, for example, additional access restrictions, more far-reaching pseudonymization, shortened retention periods, or the granting of enhanced data subject rights (such as a right to erasure without the limitations of Article 17(1) GDPR or a right to object without any requirement to state reasons).
Crucially, mitigating measures must go beyond the legal obligations that exist in any event. What is already owed under the GDPR (transparency, data security, data minimization, compliance with data subject rights) must not additionally be entered into the balancing exercise as a mitigating measure (EDPB Guidelines 1/2024, para. 57). Where mitigating measures are implemented, the balancing exercise must be carried out again.
5 Right to object under Article 21 GDPR
5.1 Objection and burden of proof
Under Article 21(1) GDPR, the data subject has a right to object to any processing based on point (e) or point (f). The objection must be based on grounds relating to the data subject's particular situation; a detailed explanation is not required, and the controller may ask for clarification in case of doubt. Where the data subject objects, the controller must cease the processing unless it demonstrates compelling legitimate grounds which override the interests of the data subject. The burden of proof lies with the controller (CJEU, judgment of 7 December 2023, C-26/22 and C-64/22, SCHUFA Holding (Libération), para. 111).
5.2 "Compelling legitimate grounds" as a higher threshold
The balancing exercise under Article 21(1) GDPR is not identical to the original balancing exercise under point (f). The controller must demonstrate that grounds exist which are compelling: not every legitimate interest qualifies, only those which are essential for the controller or the third party. Examples that may be considered include protecting the organization or its systems against serious, immediate harm, or averting severe sanctions. A mere advantage for the controller is not sufficient. The assessment is case-specific, relating to the particular situation of the objecting person, and must be documented.
5.3 Direct marketing
For direct marketing, Article 21(2) GDPR provides an absolute right to object. An objection leads to the immediate cessation of the marketing-related processing, without the controller being able to assert any countervailing interest. No reasons need be given. Exercising the right must be possible easily and free of charge (Article 12(2) GDPR).
5.4 Restriction and erasure following an objection
While an objection is being examined, the data subject may request restriction of processing under Article 18(1)(d) GDPR: the data may then only be stored and not processed further, subject to the exceptions in Article 18(2) GDPR. Where the objection succeeds, it as a rule also gives rise to a right to erasure under Article 17(1)(c) GDPR; the criteria for objection and for erasure are essentially congruent (CJEU, judgment of 7 December 2023, C-26/22 and C-64/22, SCHUFA Holding (Libération), paras. 111 et seq.).
Where it is unclear from the data subject's request whether they are objecting or seeking erasure, the controller must not simply treat the request as an objection. It must clarify the thrust of the request and, if necessary, ask.
6 Transparency and data subject rights
6.1 Information obligations
Where the controller relies on point (f), it must inform data subjects of the legal basis pursuant to Article 13(1)(c) and Article 14(1)(c) GDPR. In addition, Article 13(1)(d) and Article 14(2)(b) GDPR require the specific legitimate interests pursued to be stated: blanket formulas such as "our own business interests" are not sufficient (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, para. 107). That statement is a condition of lawfulness: if the interest pursued is not communicated at the time of collection, the processing can no longer be based on point (f) (CJEU, judgment of 9 January 2025, C-394/23, Mousse); the legal basis cannot be supplied after the fact. On the content and presentation of that statement in the privacy notice. The controller may make the balancing documentation accessible in advance or provide it on request; drawing attention to that option facilitates the exercise of rights and contributes to accountability.
6.2 Access and legal basis
Article 15 GDPR does not lay down any express obligation to state the legal basis when responding to an access request. The EDPB nevertheless recommends communicating it or at least referring to the relevant information. Without knowledge of the legal basis, the data subject cannot meaningfully assess which further rights (objection, erasure, restriction) are available.
6.3 Rectification, restriction, erasure
The right to rectification under Article 16 GDPR applies irrespective of the legal basis. It is particularly relevant in the case of point (f), because the data are often not collected directly from the data subject, which increases the susceptibility to error. The benchmark for accuracy and completeness is always the purpose of the processing (CJEU, judgment of 20 December 2017, C-434/16, Nowak, para. 53); subjective value judgments or subsequent "corrections" of examination answers do not fall within its scope.
In addition, data subjects may seek restriction under Article 18 GDPR (in particular while an objection is being examined) and erasure under Article 17 GDPR, especially where the purpose has ceased to exist, the objection has succeeded, or the processing should never have been based on point (f) in the first place.
6.4 Automated decisions and profiling
Point (f) is not a "Union law" provision within the meaning of Article 22(2)(b) GDPR and therefore does not authorize automated individual decision-making (CJEU, judgment of 7 December 2023, C-634/21, SCHUFA Holding (Scoring), para. 70). For profiling that does not lead to an automated decision within the meaning of Article 22 GDPR, point (f) is in principle available. The balancing exercise must then take into account in particular: the level of detail and the scope of the profile, its effects on the data subject, possible later combinations with further data, and the safeguards for fairness, non-discrimination, and accuracy.
7 Case groups
The following overview classifies the most important case groups; the sections that follow examine them in more depth. This classification does not replace the case-by-case balancing exercise.
| Case group | Tendency under Article 6(1)(f) GDPR |
|---|---|
| Credit reference agencies | Viable where §§ 30 et seq. of the German Federal Data Protection Act (BDSG) and strict necessity standards are observed; the balancing exercise usually favors the agency. |
| Fraud prevention | Recognized (Recital 47), but only where the processing is narrowly tailored and strictly necessary. |
| Publication of images | Balancing against the right to one's own image; the German Act on Copyright in Works of Fine Art and Photography (KUG) continues to apply via Article 85 GDPR; self-published photographs may not be freely reused. |
| Direct marketing | Possible for marketing to existing customers; observe the absolute right to object (Article 21(2) GDPR) and the German Act Against Unfair Competition (UWG); cross-context tracking usually fails. |
| Requests from third countries | Viable only exceptionally; the balancing exercise frequently falls against the controller; Chapter V GDPR applies in addition. |
| Reports to law enforcement authorities | Case-specific reporting is recognized (Recital 50); systematic preventive disclosure is not. |
| IT security | As a rule recognized (Recital 49); the processing must be narrowly tailored to the security purposes. |
| Intra-group data processing | Internal administrative purposes are recognized (Recital 48); for employee data, point (b) or (c) often applies instead of point (f). |
| Rating portals for individuals | Viable as long as the portal remains a neutral information intermediary; the interests of reviewers and of users must be included. |
| Search engines | Possible; in the case of name-based searches, however, the fundamental rights of the data subject generally prevail. |
| Tracking and personalized advertising in social networks | Personalization cannot be based on point (f); as a rule, only consent remains available. |
| Business acquisition (asset deal) | Only limited data transfer without consent; an opportunity to object must be provided. |
| Video surveillance by private parties | Strict requirements: a specific interest, limited in space and time, transparent; dashcams are usually unlawful. |
| Warning and alert services | Viable where inclusion criteria are narrow, purpose limitation is clear, and the records are reviewed regularly. |
7.1 Credit reference agencies
The processing of creditworthiness data by credit reference agencies can be based on point (f) in so far as the strict requirements of §§ 30 et seq. BDSG, of the data protection case law, and of the relevant codes of conduct are observed. The balancing of interests as a rule favors the agency where the credit industry depends on the information; the inclusion criteria, retention periods, and updating must, however, withstand the strict necessity and proportionality standards of the CJEU (CJEU, judgment of 7 December 2023, C-26/22 and C-64/22, SCHUFA Holding (Libération), paras. 75, 88).
7.2 Fraud prevention
Recital 47 GDPR expressly names the prevention of fraud as a possible application of point (f). At the same time, the requirements are strict: the processing must be "strictly necessary", narrowly tailored to the specific type of fraud, and bound by the principles of data minimization and storage limitation. A blanket reference to "combating fraud" in the privacy notice is not sufficient (EDPB Guidelines 1/2024, paras. 104-106).
A distinction must be drawn between fraud prevention in the narrower sense (preventing fraud) and fraud detection (identifying fraud): detection is in principle also covered by point (f) in so far as it likewise serves to prevent further incidents. Where a specific statutory obligation to process data exists (for example, in the financial sector to combat money laundering), point (c) applies, not point (f).
7.3 Publication of images
The relationship with the German Act on Copyright in Works of Fine Art and Photography (§§ 22, 23 KUG) is disputed. The prevailing view treats the KUG as continuing to apply by virtue of the opening clause in Article 85 GDPR, at any rate in the journalistic and editorial sphere. Otherwise, the balancing standards of point (f) apply; the right to one's own image is included in the balancing exercise. Publicly accessible photographs (for example from social networks) may not simply be used for other purposes (such as printed advertising); the mere fact that the data subject published the images themselves does not create a reasonable expectation of further processing by third parties.
7.4 Direct marketing
Recital 47 GDPR characterizes processing for direct marketing purposes as a possible case of a legitimate interest. That does not mean that every form of direct marketing can be justified under point (f). According to the case law of the CJEU, personalized advertising is a form of direct marketing (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, para. 115); advertising inserted into an email inbox and disguised as ordinary messages also falls within that concept (CJEU, judgment of 25 November 2021, C-102/20, StWL Städtische Werke Lauf a.d. Pegnitz, paras. 47-51).
Marketing to existing customers is possible under point (f), but is subject to the absolute right to object under Article 21(2) GDPR and to the requirements of competition law (in particular § 7 UWG). Electronic marketing to new customers as a rule requires consent under the ePrivacy Directive and § 7(2) no. 2 UWG. Exceptions apply to advertising for the controller's own similar products directed at existing customers, subject to the conditions of Article 13(2) of the ePrivacy Directive / § 7(3) UWG. Setting cookies or comparable technologies for advertising purposes as a rule requires consent under § 25 of the German Telecommunications Digital Services Data Protection Act (TDDDG) / Article 5(3) of the ePrivacy Directive; a subsequent analysis based on point (f) is then usually no longer possible.
For intrusive tracking and profiling practices spanning several websites, devices, or services, the balancing exercise under point (f) will scarcely produce a positive outcome.
7.5 Requests from third countries
Requests from authorities in third countries for the release of personal data first require an examination of the framework of international law. Where the request is based on an internationally applicable agreement that creates an obligation of disclosure in the EU or in the Member State, point (c) applies. Where cooperation is merely permitted, point (e) may be considered; where there is a danger to the life or limb of the data subject, point (d) applies.
Point (f) can only be considered where the controller is subject to the law of the third country and must expect sanctions if it refuses. The balancing exercise frequently falls against the controller, however, in particular because in such a scenario data subjects as a rule do not expect a transmission and because the fundamental rights position may not be protected to an equivalent standard in third countries. Irrespective of the legal basis, the requirements for transfers to third countries under Chapter V GDPR must additionally be met.
7.6 Reports to law enforcement authorities
Recital 50 GDPR names the reporting of possible criminal acts or threats to public security to the competent authority in individual cases as a possible application of point (f). The condition is that the report is made on a case-by-case basis and relates to specific incidents.
By contrast, the systematic, preventive collection of personal data for the purpose of passing them on to law enforcement authorities across the board cannot be justified under point (f), at any rate not where the controller is primarily engaged in commercial activity. Such activities require a specific statutory basis (point (c)) (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, paras. 124, 132). Professional or official secrecy obligations may additionally bar disclosure.
7.7 IT security
Measures to ensure network and information security, in particular to fend off cyberattacks and to log and analyze suspicious access, are as a rule supported by a legitimate interest under Recital 49 GDPR (CJEU, judgment of 19 October 2016, C-582/14, Breyer, para. 60). The same applies to security measures within a corporate group. The processing must be narrowly tailored to the security purposes; particularly intrusive techniques such as deep packet inspection may tip the balance (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, paras. 119 et seq.). The processing of data from sources outside the controller's own network is permissible only in so far as it is genuinely necessary for the security of the network and cannot be replaced by less intrusive means.
7.8 Intra-group data processing
The transmission of data within a group of undertakings for internal administrative purposes is in principle a legitimate interest under Recital 48 GDPR. The limit lies where the processing goes beyond necessary administrative purposes and interferes with the economic activity of the individual company. For employee data, the special national rules under Article 88 GDPR must be observed, in Germany above all § 26 BDSG and collective agreements; the transmission is then often supported by point (b) or point (c) rather than point (f). Employees must be informed of the legal basis pursuant to Articles 13 and 14 GDPR.
7.9 Rating portals for individuals
Rating portals as a rule rely on point (f). The balancing exercise depends on the individual case; in the Jameda case, the German Federal Court of Justice (BGH) made classification as a "neutral information intermediary" the central criterion. As long as the portal maintains a neutral position, the public's interest in information prevails; if that neutrality is abandoned, the balance tips in favor of the data subject (BGH, judgment of 20 February 2018, VI ZR 30/17, Ärztebewertung III).
Moreover, the balancing exercise is not to be conducted purely bipolarly between the portal operator and the person rated. The interests of the reviewers (in particular their interest in anonymity and their freedom of expression and information) and of the users who consult the portal for information must also be included. Reviewers' interests in anonymity are legitimate, but are themselves subject to balancing; the factors to be considered include the likely extent of abusive reviews, deterrent and self-censorship effects, and procedural safeguards against abuse (such as identity checks, complaint channels, and deletion mechanisms).
7.10 Search engines
Search engines may rely on point (f). In its Google Spain case law, however, the CJEU established a rule-and-exception mechanism: in the case of name-based searches, the fundamental rights of the data subject generally override the operator's economic interest and the public's interest in information (CJEU, judgment of 13 May 2014, C-131/12, Google Spain; CJEU, judgment of 24 September 2019, C-136/17, GC and Others v CNIL). These principles also apply under the GDPR.
7.11 Tracking and personalized advertising in social networks
In Germany, tracking by means of cookies or comparable technologies is additionally subject to § 25 TDDDG, which as a rule requires consent. For the subsequent analysis of the data, point (f) is available only to a very limited extent, because the CJEU attaches considerable weight to the intrusiveness of commercial processing.
For the personalization of advertising in social networks, the CJEU has expressly held that the balancing exercise falls against the operator: a platform operator does in principle have a legitimate interest in structuring its business model on an advertising-financed basis. Where the processing is particularly extensive, concerns potentially unlimited data, and makes users' online activities largely traceable, however, the interests and fundamental rights of the data subjects prevail. A contributing factor is that users may be given the feeling that their private life is under continuous surveillance (CJEU, judgment of 4 July 2023, C-252/21, Meta Platforms v Bundeskartellamt, paras. 115 et seq.). Personalization therefore cannot be based on point (f); as a rule, consent is the only legal basis that remains.
7.12 Business acquisition (asset deal)
In an asset deal (transfer of the business operation without the legal entity), the transfer of customer data to the acquirer must be justified under data protection law. Without the consent of the customers concerned, only a very limited data transfer is possible under point (f); an opportunity to object must be provided.
7.13 Video surveillance by private parties
Private video surveillance of publicly accessible spaces is to be assessed under point (f). The requirements are strict: there must be a specific legitimate interest (such as protection against criminal offenses or a history of incidents); the surveillance must be limited in space and time and must be made transparent by means of signage. Dashcams are predominantly unlawful.
7.14 Warning and alert services
Warning and alert services (for example in the insurance industry) may rely on point (f) in so far as they serve fraud prevention. This presupposes narrow inclusion criteria, clear purpose limitation, and regular review of the records.
The balancing of interests is the most common point of attack in data protection proceedings. Anyone relying on point (f) should document the three assessment steps (interest, necessity, balancing), not least in order to comply with the accountability obligation under Article 5(2) GDPR. The documentation should be made accessible on request or at least be addressable by means of a reference in the privacy notice.
About the author
About the author
This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.
Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.
According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.
Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.
His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.
For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.
Public Interest and Official Authority (Article 6(1)(e) GDPR)
Lawfulness of processing for the performance of a task carried out in the public interest or in the exercise of official authority; requirements for the legal basis under Article 6(3) GDPR and practical examples.
Change of Purpose (Article 6(4) GDPR)
Compatibility test for further processing for new purposes: the function of Article 6(4) GDPR, the criteria of the compatibility test, and the special case of archiving, research, and statistical purposes.