Blog

Recognised Legitimate Interests Under UK GDPR: What Businesses Need to Know

Recognised legitimate interest is a new lawful basis under the UK GDPR for certain specified public-interest purposes. Businesses need to understand when it can be used, why it is separate from ordinary legitimate interests, and what this change means when choosing the right basis for processing personal data.

Estimated reading time: 7 minutesTopic: Lawful processingRelated terms: Lawful basis and Legitimate interests
Quick answer

What recognised legitimate interest means in practice

Recognised legitimate interest is one of the seven lawful bases under the UK GDPR. It allows organisations to process personal data where the processing is necessary for one of five specific public-interest purposes set out in law. Unlike ordinary legitimate interests, organisations do not need to carry out the usual balancing test, but they must still show that the processing is necessary and comply with the rest of data protection law.

New basis

Added to UK GDPR by the Data (Use and Access) Act 2025

Five conditions

Public tasks, security and defence, emergencies, crime, and safeguarding

Key difference

No ordinary legitimate interests balancing test is required

Section one

Why recognised legitimate interest was introduced

The Data (Use and Access) Act 2025 added recognised legitimate interest to Article 6 of the UK GDPR. The new basis is designed for a limited number of activities that Parliament has already recognised as serving important public interests.

Seven lawful bases

It is a separate lawful basis

Recognised legitimate interest is not a variation of ordinary legitimate interests. It is a separate Article 6 lawful basis alongside consent, contract, legal obligation, vital interests, public task and legitimate interests.

Pre-approved purposes

Its purposes are defined in law

Organisations cannot invent their own recognised legitimate interest. The processing must fall within one of the specific conditions listed in Annex 1 of the UK GDPR.

Necessity remains

The processing still has to be necessary

The new basis does not give organisations unrestricted permission to use personal data. The processing must be a targeted and proportionate way of achieving the relevant recognised purpose.

For the wider framework, see our guide to the seven lawful bases under UK GDPR. The ICO's recognised legitimate interest guidance also provides practical guidance on applying the new basis.

Section two

The five recognised legitimate interest conditions

There are five recognised legitimate interest conditions. An organisation can only rely on this lawful basis where its purpose meets the requirements of at least one of them and the processing is necessary for that purpose.

National security, public security and defence

Processing may fall within this condition where it is necessary to safeguard national security, protect public security or support defence purposes.

Emergencies

The emergencies condition can apply where personal data needs to be used to respond to or deal with an emergency situation, subject to the requirements set out in law.

Crime

This condition covers necessary processing for preventing, detecting or investigating crime, including activities connected with apprehending or prosecuting offenders.

Safeguarding

Safeguarding can apply where processing is necessary to protect the physical, mental or emotional wellbeing of people who need additional support, or to protect them from harm or neglect.

The full statutory framework appears in Schedule 4 of the Data (Use and Access) Act 2025. Businesses should check the detailed requirements rather than relying on the headline description of a condition.

Section three

How it differs from ordinary legitimate interests

The similar names can cause confusion, but recognised legitimate interest and legitimate interests are separate lawful bases with different tests. Understanding that distinction is essential before relying on either one.

Recognised legitimate interest

Limited purposes but no balancing test

The purpose must fit one of the five statutory conditions and the processing must be necessary. Because Parliament has already recognised these purposes as being in the public interest, organisations do not carry out the usual balancing exercise against the individual's interests, rights and freedoms.

Legitimate interests

Broader purposes but more assessment

Ordinary legitimate interests can potentially apply to a much wider range of activities. Organisations must identify a legitimate purpose, show the processing is necessary, and balance the interest against the individual's rights, freedoms and interests. This is normally documented through a legitimate interests assessment.

You do not automatically need to switch basis

If an organisation already relies appropriately on ordinary legitimate interests for processing that now falls within a recognised legitimate interest condition, the ICO says it does not have to change its lawful basis. It may choose recognised legitimate interest for qualifying processing in future. See the ICO's detailed comparison for further guidance.

Section five

What this could look like in practice

Recognised legitimate interest is deliberately narrower than ordinary legitimate interests. For most routine commercial processing, businesses will continue to use one of the other lawful bases. The new basis becomes relevant where the purpose genuinely falls within one of the five statutory conditions.

Responding to suspected fraud

A business investigating suspected fraudulent activity may be able to rely on the crime condition where using the relevant personal data is necessary to prevent, detect or investigate crime.

Sharing information for a public task

A private organisation receiving a qualifying request from a body that needs personal data for a public task or official function may be able to use the public task disclosure response condition.

Protecting a vulnerable person

Where the statutory safeguarding requirements are met, an organisation may be able to use personal data where this is necessary to protect someone who needs additional support from harm or neglect.

Responding to an emergency

An emergency may create a need to use or share personal information quickly. The emergency condition can provide a lawful basis where its requirements are met and the processing is necessary.

Routine customer marketing

Recognised legitimate interest is not a general basis for routine marketing. Businesses may instead need to consider ordinary legitimate interests or consent, together with any separate rules under PECR.

Ordinary business administration

Using customer or employee information for everyday commercial purposes does not become a recognised legitimate interest simply because the processing benefits the business. Another lawful basis will normally need to be identified.

The practical takeaway

Start with the purpose rather than the name of the lawful basis. If the purpose clearly falls within one of the five recognised legitimate interest conditions, assess whether the processing is genuinely necessary and document the decision. If it does not, choose another appropriate lawful basis. The government's Data (Use and Access) Act UK GDPR factsheet provides a useful overview of the reform.

Grounded in

What this article is grounded in

This article is based on the UK GDPR changes introduced by the Data (Use and Access) Act 2025 and current ICO guidance on recognised legitimate interest. It also connects to the wider rules around lawful basis, legitimate interests, accountability, and transparency.

Next step

Keep building your understanding

Use the glossary for clear explanations of key GDPR concepts, or download the checklist if you want a practical starting point for reviewing lawful basis decisions, privacy information, records, accountability, and how your organisation handles personal data.

Future Implementation Support Waitlist