4.8Top Rated Service 2026verified by TrustindexTrustindex verifies that the company has a review score above 4.5, based on reviews collected on Google over the past 12 months, qualifying it to receive the Top Rated Certificate.
Recognised legitimate interest is a new lawful basis under the UK GDPR for certain specified public-interest purposes. Businesses need to understand when it can be used, why it is separate from ordinary legitimate interests, and what this change means when choosing the right basis for processing personal data.
Recognised legitimate interest is one of the seven lawful bases under the UK GDPR. It allows organisations to process personal data where the processing is necessary for one of five specific public-interest purposes set out in law. Unlike ordinary legitimate interests, organisations do not need to carry out the usual balancing test, but they must still show that the processing is necessary and comply with the rest of data protection law.
New basis
Added to UK GDPR by the Data (Use and Access) Act 2025
Five conditions
Public tasks, security and defence, emergencies, crime, and safeguarding
Key difference
No ordinary legitimate interests balancing test is required
The Data (Use and Access) Act 2025 added recognised legitimate interest to Article 6 of the UK GDPR. The new basis is designed for a limited number of activities that Parliament has already recognised as serving important public interests.
Recognised legitimate interest is not a variation of ordinary legitimate interests. It is a separate Article 6 lawful basis alongside consent, contract, legal obligation, vital interests, public task and legitimate interests.
Organisations cannot invent their own recognised legitimate interest. The processing must fall within one of the specific conditions listed in Annex 1 of the UK GDPR.
The new basis does not give organisations unrestricted permission to use personal data. The processing must be a targeted and proportionate way of achieving the relevant recognised purpose.
For the wider framework, see our guide to the seven lawful bases under UK GDPR. The ICO's recognised legitimate interest guidance also provides practical guidance on applying the new basis.
There are five recognised legitimate interest conditions. An organisation can only rely on this lawful basis where its purpose meets the requirements of at least one of them and the processing is necessary for that purpose.
This condition can apply where another organisation asks for personal data because it needs the information to carry out a public task or official function, provided the detailed statutory requirements are met.
Processing may fall within this condition where it is necessary to safeguard national security, protect public security or support defence purposes.
The emergencies condition can apply where personal data needs to be used to respond to or deal with an emergency situation, subject to the requirements set out in law.
This condition covers necessary processing for preventing, detecting or investigating crime, including activities connected with apprehending or prosecuting offenders.
Safeguarding can apply where processing is necessary to protect the physical, mental or emotional wellbeing of people who need additional support, or to protect them from harm or neglect.
The full statutory framework appears in Schedule 4 of the Data (Use and Access) Act 2025. Businesses should check the detailed requirements rather than relying on the headline description of a condition.
The similar names can cause confusion, but recognised legitimate interest and legitimate interests are separate lawful bases with different tests. Understanding that distinction is essential before relying on either one.
The purpose must fit one of the five statutory conditions and the processing must be necessary. Because Parliament has already recognised these purposes as being in the public interest, organisations do not carry out the usual balancing exercise against the individual's interests, rights and freedoms.
Ordinary legitimate interests can potentially apply to a much wider range of activities. Organisations must identify a legitimate purpose, show the processing is necessary, and balance the interest against the individual's rights, freedoms and interests. This is normally documented through a legitimate interests assessment.
If an organisation already relies appropriately on ordinary legitimate interests for processing that now falls within a recognised legitimate interest condition, the ICO says it does not have to change its lawful basis. It may choose recognised legitimate interest for qualifying processing in future. See the ICO's detailed comparison for further guidance.
Recognised legitimate interest removes one part of the ordinary legitimate interests assessment, but it is not a general exemption from UK GDPR. Businesses still need to meet the wider data protection requirements that apply to the processing.
The proposed use of personal data must genuinely help achieve the recognised purpose. If the same result can reasonably be achieved in a less intrusive way, the processing may not satisfy the necessity requirement.
A formal legitimate interests assessment is not required, but organisations remain accountable. They should document which recognised legitimate interest condition applies and why the processing is necessary.
People generally need to be told that recognised legitimate interest is being relied on and which condition is being used, unless a relevant exemption from the transparency requirements applies.
Special category data requires an Article 9 condition in addition to an Article 6 lawful basis. Criminal offence data also has additional requirements, and high-risk processing may require a data protection impact assessment.
The right to object applies when recognised legitimate interest is used. An objection does not automatically require the organisation to stop in every case, but continuing the processing requires compelling legitimate grounds that override the individual's interests, rights and freedoms. The ICO explains these continuing obligations in its detailed recognised legitimate interest guidance. This also links closely to wider accountability and transparency obligations.
Recognised legitimate interest is deliberately narrower than ordinary legitimate interests. For most routine commercial processing, businesses will continue to use one of the other lawful bases. The new basis becomes relevant where the purpose genuinely falls within one of the five statutory conditions.
A business investigating suspected fraudulent activity may be able to rely on the crime condition where using the relevant personal data is necessary to prevent, detect or investigate crime.
A private organisation receiving a qualifying request from a body that needs personal data for a public task or official function may be able to use the public task disclosure response condition.
Where the statutory safeguarding requirements are met, an organisation may be able to use personal data where this is necessary to protect someone who needs additional support from harm or neglect.
An emergency may create a need to use or share personal information quickly. The emergency condition can provide a lawful basis where its requirements are met and the processing is necessary.
Recognised legitimate interest is not a general basis for routine marketing. Businesses may instead need to consider ordinary legitimate interests or consent, together with any separate rules under PECR.
Using customer or employee information for everyday commercial purposes does not become a recognised legitimate interest simply because the processing benefits the business. Another lawful basis will normally need to be identified.
Start with the purpose rather than the name of the lawful basis. If the purpose clearly falls within one of the five recognised legitimate interest conditions, assess whether the processing is genuinely necessary and document the decision. If it does not, choose another appropriate lawful basis. The government's Data (Use and Access) Act UK GDPR factsheet provides a useful overview of the reform.
This article is based on the UK GDPR changes introduced by the Data (Use and Access) Act 2025 and current ICO guidance on recognised legitimate interest. It also connects to the wider rules around lawful basis, legitimate interests, accountability, and transparency.
Use the glossary for clear explanations of key GDPR concepts, or download the checklist if you want a practical starting point for reviewing lawful basis decisions, privacy information, records, accountability, and how your organisation handles personal data.
We use cookies and similar technologies to make our website work and to provide optional features such as live chat.
Some cookies are strictly necessary for the website to function. Optional cookies support tools such as live chat and will only be used if you choose to allow them.
We also use privacy-friendly, cookieless website analytics to understand aggregated website usage. This does not use cookies or track you across websites.
You can choose to accept all cookies, reject non-essential cookies, or manage your preferences.