GDPR's Article 6 lists six lawful bases a business can rely on to process personal data: consent, contract, legal obligation, vital interests, public task, and legitimate interests. In practice, most privacy policies lean on two of them for the bulk of their processing, consent and legitimate interest, and those two get confused with each other constantly. They're not interchangeable, they're not a matter of picking whichever sounds more comfortable, and getting the choice wrong isn't just a paperwork problem: under EDPB guidance, the lawful basis for a given processing activity generally has to be determined before that processing starts, and you can't quietly swap to a different basis later just because the first one stopped working out, for instance switching to legitimate interest after someone withdraws consent for the same purpose.
What consent actually requires
GDPR sets a genuinely high bar for consent, higher than "the visitor didn't object." To count as valid consent, it has to be freely given, specific to one purpose, informed, and given through a clear affirmative action, not implied by silence, pre-ticked boxes, or continued use of a site. A few consequences follow directly from that definition:
- It has to be granular. Bundling "I agree to receive marketing emails" into the same checkbox as "I agree to the Terms of Service" invalidates the consent for marketing, because it wasn't a specific, separate choice.
- Withdrawal has to be as easy as giving it. If signing up takes one click, unsubscribing or opting out needs to be roughly that easy too, not buried behind a support ticket.
- A real power imbalance can invalidate it. Consent from an employee to their employer, for example, is treated skeptically by regulators, since an employee may not feel free to refuse.
Consent's biggest practical strength is also its biggest weakness: the individual can withdraw it at any time, for any reason, and processing has to stop. That makes it a poor fit for anything your business genuinely needs to keep doing regardless of one person's preference, fraud prevention being the clearest example.
What legitimate interest actually requires
Legitimate interest isn't a shortcut for "we didn't want to ask." It has its own real test, commonly called the three-part test, and regulators expect it to be documented in a Legitimate Interests Assessment (LIA), not just asserted in a privacy policy:
- Purpose test. Is there a genuine, legitimate reason for the processing, your own business interest, a third party's interest, or a broader societal interest?
- Necessity test. Is this processing actually necessary to achieve that purpose, or is there a less intrusive way to get the same result?
- Balancing test. Does your interest in processing outweigh the individual's rights, freedoms, and reasonable expectations, taking into account whether they'd reasonably expect this processing given the context?
Unlike consent, legitimate interest doesn't require an upfront yes from the individual. What it requires instead is that you've done the assessment, can produce it if asked, and give the individual a standing right to object under Article 21, at which point you have to stop unless you can demonstrate compelling legitimate grounds that override their interests, or the processing is needed for a legal claim.
Consent vs legitimate interest
| Consent | Legitimate Interest | |
|---|---|---|
| Upfront requirement | Affirmative opt-in before processing | No opt-in, documented assessment instead |
| Withdrawal | Individual can withdraw anytime | Individual can object, not withdraw |
| Documentation needed | Consent records, timestamp, wording used | Legitimate Interests Assessment (LIA) |
| Direct marketing by email/SMS | Generally required under ePrivacy rules | Generally not sufficient on its own |
| Typical fit | Marketing emails, non-essential cookies | Fraud prevention, security logging |
The rule that overrides both: ePrivacy and marketing
One case resolves itself before you even reach the three-part test: direct marketing by electronic means, email and SMS campaigns being the common examples, is governed by the ePrivacy Directive on top of GDPR, and ePrivacy's default position generally requires consent for that specific channel, regardless of how strong a legitimate-interest argument you could otherwise build. This is the same reason non-essential cookies need consent under Article 5(3) of the ePrivacy Directive even in cases where a legitimate-interest argument for the underlying data use might otherwise hold up under GDPR alone: a separate rule, layered on top of GDPR, closes off legitimate interest as an option for that specific activity.
A simple way to triage which one applies
The other four bases, briefly
Consent and legitimate interest dominate this conversation because most website and product data processing falls into one or the other, but the remaining four bases in Article 6 cover situations where the choice isn't really a choice at all. Contract applies when processing is genuinely necessary to deliver something you agreed to provide, shipping a physical order to the address a customer gave you, for instance. Legal obligation applies when a law requires the processing regardless of anyone's preference, retaining certain financial records for tax purposes being the common example. Vital interests covers processing necessary to protect someone's life, rare outside emergency and healthcare contexts. Public task applies to processing carried out by a public authority or in the exercise of official government functions, which is why it almost never shows up in a commercial privacy policy. None of the four require the balancing exercise consent or legitimate interest do, because the law or the contract itself already settles the question.
Where each one actually fits in practice
A few concrete pairs make the split easier to hold onto than the abstract test alone:
Marketing newsletter relies on consent, both because it's the individual's inbox and because ePrivacy's marketing rule requires it directly. Fraud detection and account-security logging typically rests on legitimate interest, since asking a user to consent to having their login attempts monitored for suspicious activity defeats the purpose, and withdrawing that consent shouldn't be an option a compromised account can exercise.
First-party analytics that doesn't set non-essential cookies, aggregate server-log statistics with no individual profiling, can often rely on legitimate interest, since it's a narrower, more defensible use than behavioral ad targeting. Third-party advertising and retargeting cookies, by contrast, need consent, both under ePrivacy's cookie rule and because a balancing test rarely favors a business's interest in cross-site ad targeting over an individual's reasonable expectations.
Getting this right in your privacy policy means naming the actual basis for each real category of processing you do, not defaulting to "legitimate interest" everywhere it feels convenient or "consent" everywhere it feels safe. Regulators have pushed back specifically on legitimate interest being used as a catch-all for processing that should have required consent, and an LIA that doesn't survive a real balancing test doesn't protect you just because it exists on paper.
A useful gut check when the choice feels genuinely unclear: would a reasonable person be surprised to learn this processing was happening. Order confirmation emails, fraud checks, and basic security logging rarely surprise anyone, they're the ordinary, expected mechanics of using a service, which is exactly the territory legitimate interest is built for. Being added to a marketing list, having behavior tracked across other websites, or having data shared with an unrelated third party are the kinds of processing people reasonably want a say in beforehand, which is exactly the territory consent is built for. The three-part test formalizes this intuition, but the intuition itself is usually a fast, reliable first pass before working through the formal assessment.
Our Privacy Policy Generator builds a policy that states the correct lawful basis for each category of processing your business actually does, rather than one blanket basis applied to everything. For the specific case of cookie-based tracking, which almost always needs consent regardless of what basis covers the underlying data use, see our GDPR vs CCPA cookie consent guide for how the opt-in requirement plays out in practice.
The information in this article is for informational purposes only and should not be construed as legal advice on any matter, and does not create a lawyer-client relationship.