Legitimate Interests Under UK GDPR: A Business Guide
Two pieces on this site have circled the same underlying issue without quite landing on it directly. In our look at HubSpot's withdrawn enrichment terms, the sticking point was whether "legitimate interests" could really justify pooling customer contact data across accounts. In our piece on data sovereignty, the question was whose laws govern your data once it sits inside a vendor's platform. Both pieces kept bumping into the same legal mechanic: lawful basis, and specifically, the legitimate interests basis that most CRM and marketing processing actually relies on.
This piece goes into that mechanic properly. Not as legal advice, and not as a substitute for your own data protection officer or solicitor, but as a plain-language explanation of how the legitimate interests balancing test actually works, what changed in UK data protection law earlier this year, and where the right to object fits in. If your business runs CRM, marketing automation, or enrichment tools of any kind, this is the test sitting underneath most of what you do with contact data day to day.
The Lawful Bases at a Glance
UK GDPR requires a lawful basis before you process any personal data. There are now seven, following a change earlier in 2026, and most CRM-related processing sits on one of three.
| Lawful basis | What it requires | Typical fit for CRM data |
|---|---|---|
| Consent | A freely given, specific, informed, unambiguous opt-in | Email marketing to individuals, where required by PECR |
| Contract | Processing necessary to perform a contract with the person | Order processing, account administration, support tickets |
| Legal obligation | A specific legal requirement to process the data | Tax, employment, and regulatory record-keeping |
| Vital interests | Necessary to protect someone's life | Rarely relevant to routine CRM use |
| Public task | Necessary for a task in the public interest or official authority | Public sector and some regulated bodies only |
| Legitimate interests | A genuine business reason, that is necessary, and does not override the person's rights, judged by the three-part test | B2B prospecting, enrichment, most day-to-day CRM processing |
| Recognised legitimate interest | One of five narrow, pre-approved public-interest conditions set out by the ICO, with no balancing test required | Specific scenarios such as responding to another organisation's public task request, not general commercial use |
That seventh basis, recognised legitimate interest, is new. It was introduced by the Data (Use and Access) Act 2025, came into force on 5 February 2026, and the ICO published its final guidance on it on 23 March 2026. It is worth knowing it exists, but its five pre-approved conditions are narrow and mostly public-interest focused, so most commercial CRM and marketing processing will still sit on the ordinary legitimate interests basis and its three-part test, not this new one.
How the Legitimate Interests Balancing Test Works
The ICO breaks ordinary legitimate interests down into three stages, sometimes called a Legitimate Interests Assessment or LIA. You need to satisfy all three before you rely on this basis, not just one.
The Purpose Test
First, identify the actual interest you are pursuing, and check it is legitimate. This can be a broad commercial interest, such as running effective sales prospecting, provided it is a genuine and specific reason rather than a vague catch-all.
The Necessity Test
Second, check that the processing is actually necessary to achieve that purpose, not merely convenient. If there is a less intrusive way to achieve the same result, the necessity test becomes harder to satisfy.
The Balancing Test
Third, and usually the hardest, weigh your interest against the rights and reasonable expectations of the person whose data it is. The ICO's own guidance points to a key question here: would this person reasonably expect their data to be used this way? Data collected in the context of one customer relationship being pooled into a shared enrichment dataset for other companies' benefit is exactly the kind of use that tends to fail this expectation test, which is broadly what played out in the HubSpot episode covered in our earlier piece.
Legitimate interests is not a free pass. It is a test you have to actually pass, on all three counts, before you rely on it.
Where the Right to Object Fits In
If someone objects to direct marketing, including profiling connected to it, you must stop immediately. There is no balancing test and no exception here.
For legitimate-interests processing outside direct marketing, an objection can be resisted only if you can show compelling legitimate grounds that override the person's interests.
UK GDPR requires you to bring this right to a person's attention clearly, and separately from other information, at the point of first contact.
You have one calendar month to respond to an objection, whether it arrives by email, phone, or in writing, so this needs a defined workflow, not an ad hoc reply.
Four Steps to Run Your Own Legitimate Interests Assessment
Name the actual business reason for the processing in concrete terms, not as a general statement about "improving our services."
If you could achieve the same outcome with less data or a narrower use, the necessity test likely fails as things stand.
Ask whether the person would reasonably expect this specific use, and document the answer, including where it is uncomfortable.
Keep the assessment on file for accountability, and make sure your privacy notice states the right to object clearly and separately, not buried in general terms.
What This Means for UK and Irish Businesses
None of this is exotic. Most UK and Irish businesses running a CRM already rely on legitimate interests for a good chunk of their day-to-day processing, and in most cases that is entirely appropriate. The HubSpot episode did not fail because legitimate interests can never justify enrichment, it failed the balancing test specifically, because pooling one customer's contact data to benefit other customers is not something most people would reasonably expect when they first handed over their details.
The practical takeaway is the same one raised in our sovereignty piece: ask the specific question rather than accepting a vendor's general assurance. Does your CRM vendor's enrichment or AI training feature rely on legitimate interests, and if so, has that balancing test actually been documented anywhere you can see it? Zoho, like any vendor, expects customers to configure consent and legitimate interest settings correctly themselves. Reading the current settings and the current Data Processing Addendum is still your responsibility as data controller, whichever platform you use.
If you would like a plain-language walkthrough of your current lawful basis position across your CRM and marketing tools, we are happy to talk it through with you, no obligation attached.
