ICO Data Protection Register

What is a 'recognised legitimate interest' — and should we switch our lawful basis to it?

Recognised legitimate interest is a seventh lawful basis, added to the UK GDPR on 5 February 2026. It covers five pre-approved purposes: crime, safeguarding, emergencies, national security and public security and defence, and disclosing information to a body that has asked for it for its public task. You skip the balancing test, but not the necessity test — and if you already use ordinary legitimate interests for one of those purposes, the ICO says you do not have to change.

Last updated 31 July 2026. This page explains the law as it stands on that date. It is general information, not legal advice.

The bottom line

Recognised legitimate interest is a lawful basis, not an exemption. It became available on 5 February 2026. It covers five pre-approved purposes and nothing else. There is no balancing test, but you still have to show the processing is necessary, and every other UK GDPR duty still applies. Most organisations already relying on ordinary legitimate interests do not need to switch.

What the seventh lawful basis is, and when it arrived

Section 70 of the Data (Use and Access) Act 2025 inserted a new point into Article 6(1) of the UK GDPR. Article 6(1)(ea) now reads: processing is necessary for the purposes of a recognised legitimate interest.

Section 70 and Schedule 4 came into force on 5 February 2026 under regulation 2 of SI 2026/82, the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026. Nothing about this basis was available before that date.

A new Article 6(5) sets the limit: processing is necessary for a recognised legitimate interest "only if it meets a condition in Annex 1". So this is not a general-purpose basis. It is a closed list.

No basis outranks another

The ICO's position is that recognised legitimate interest is "one of the seven lawful bases" and that "no single basis is 'better' or more important than the others". Adding a seventh option did not demote consent, contract, legal obligation, vital interests, public task or legitimate interests.

The five conditions, and where the list is in law

The conditions sit in a new Annex 1 to the UK GDPR, inserted by Schedule 4 to the DUAA. Annex 1 runs to eight numbered paragraphs, but several are definitions. There are five conditions.

Condition (ICO shorthand) What Annex 1 covers Paragraph
Public task disclosure response Disclosing personal data to another person in response to their request, where the request states they need it for Article 6(1)(e) public task processing with a legal basis satisfying Article 6(3) 1
National security, public security and defence Safeguarding national security, protecting public security, or defence purposes 2
Emergencies Responding to an emergency — 'emergency' has the same meaning as in Part 2 of the Civil Contingencies Act 2004 3–4
Crime Detecting, investigating or preventing crime, or apprehending or prosecuting offenders 5
Safeguarding Safeguarding a vulnerable individual — a child under 18, or an adult who is 'at risk' 6–8

For adults, 'at risk' has a tight statutory meaning. You need reasonable cause to suspect the person needs care and support, is experiencing or at risk of neglect or physical, mental or emotional harm, and as a result cannot protect themselves. A child qualifies automatically.

Article 6(6) lets the Secretary of State amend Annex 1 by regulations, and Article 6(10) makes those regulations subject to the affirmative resolution procedure. Before adding a case, Article 6(9) requires the Secretary of State to consider that processing in that case is necessary to safeguard an objective listed in Article 23(1)(c) to (j). No amending regulations were recorded against Annex 1 on legislation.gov.uk when this page was written, and the ICO's guidance still describes five conditions — but check Annex 1 before treating the list as closed.

Is it true there's no balancing test?

Broadly, yes — and the ICO is explicit about why. Its detailed guidance says recognised legitimate interest "presumes that your interests and those of the person whose information you want to use are balanced. Therefore, there's no requirement for you to do a balancing test of the type required by the legitimate interests basis." There is no three-part test, so no legitimate interests assessment (LIA).

What survives is the necessity test, and the ICO does not treat it as a formality: necessary "doesn't mean it has to be absolutely essential, but you must ensure it is a targeted and proportionate way of achieving the pre-approved purpose". If a less intrusive route achieves the same purpose, the more intrusive one is not necessary.

Accountability also survives. The ICO says "you must still be accountable and you should record why recognised legitimate interest applies".

Recognised legitimate interest Legitimate interests
Suitable for a wide variety of purposes No — five conditions only Yes
Assess impact on people's rights, interests and freedoms No Yes
Assess necessity Yes Yes
Documented LIA needed No Yes
Right to object applies Yes Yes
Available for significant solely automated decisions No — barred by Article 22B(4) Yes, subject to the Article 22C safeguards

That last row is a statutory bar, not a matter of judgement. Article 22B(4) says a significant decision may not be taken based solely on automated processing where the processing for that decision is carried out entirely or partly in reliance on Article 6(1)(ea). The ICO puts it flatly: you can't use recognised legitimate interest if you want to take significant decisions about someone based solely on automated processing.

Section 70(5) amended Article 21(1) so the right to object extends to processing under point (ea). The right is not absolute here: if someone objects, you must stop unless you can show compelling legitimate grounds that override their interests, rights and freedoms. The ICO warns that simply restating that you have a recognised legitimate interest is not enough.

It does not cover direct marketing, and it does not cover democratic engagement

This is the most common misreading. Direct marketing is not a recognised legitimate interest. Section 70 dealt with marketing separately, by adding a new Article 6(11) listing examples of what *may* be an ordinary Article 6(1)(f) legitimate interest:

Those are illustrations under the ordinary basis. They still require the full three-part test, including the balancing test, and still require an LIA. They also do not touch PECR — if you send electronic marketing, PECR consent rules apply regardless of your UK GDPR lawful basis.

Democratic engagement is not on the Annex 1 list either. A democratic engagement provision featured in the predecessor Data Protection and Digital Information Bill, which did not become law. It was not carried into the DUAA. Political parties and candidates are in exactly the position they were in before 5 February 2026.

When the police or a public body asks you for information

The public task disclosure response condition exists to make this kind of sharing easier — the ICO says it "recognises the need to facilitate data sharing when an organisation needs the personal information for their public tasks and official functions". In practice it reaches schools, charities, employers, landlords and anyone else who gets an official-looking request. Recognised legitimate interest gives you a lawful basis to say yes voluntarily. It does not give the requester a right to the data.

  1. Step 1 Check whether you are actually being compelled If a statutory power requires you to hand the information over, your lawful basis is legal obligation, not recognised legitimate interest. This condition is only for voluntary disclosure. And if you are yourself a public authority — many schools and NHS bodies are — the ICO says to check first whether responding is covered by your own public task, because if it is, you cannot rely on recognised legitimate interest.
  2. Step 2 Get it in writing The ICO says the requester should put the request in writing and specify what personal information it seeks. If a request is verbal, tell them to put it in writing. If it is vague, ask for more detail.
  3. Step 3 Pick the right condition Do not assume every public body request falls under the public task disclosure response condition. The ICO says the crime condition is likely to be more appropriate for a police request tied to a criminal investigation, safeguarding for a social services request about a safeguarding issue, and emergencies for an emergency response.
  4. Step 4 Satisfy yourself the request is genuine Make further checks if you are unsure about the authenticity of the request, or whether the person sending it has authority to act for their organisation.
  5. Step 5 Send only what is proportionate The ICO's worked example: a public authority asks whether an employee was at work on specific days. Sharing the clocking-in and out records for those days is necessary. Sharing a whole year of records, or every employee's records for those days, is not — that is likely to breach data minimisation.
  6. Step 6 Record it, and remember you can refuse Log the disclosure in your record of processing activities and note which condition you relied on. The ICO is clear: "It's your choice whether or not to share the personal information the organisation has asked for."

The one point people get wrong — in the ICO's own words

On the public task disclosure response condition, the ICO says: "The UK GDPR says the requesting organisation must tell you that it needs this personal information for a specified public task or another power in law. This means you can rely on that declaration. You don't need to know or be able to demonstrate the information they request is actually necessary to perform their task or function." That removes one judgement call. It does not remove the other: "you must consider whether the information you want to disclose is proportionate and is actually necessary to meet the organisation's request."

Can public authorities rely on it for their own functions?

No. Section 70(2)(c) changed the closing words of Article 6(1) so that points (ea) and (f) do not apply to processing carried out by public authorities in the performance of their tasks. The ICO says public task is likely to be the appropriate basis instead. A public authority can use recognised legitimate interest only when it is genuinely acting outside its tasks and functions.

There is a related change worth knowing if you handle freedom of information requests. Section 70 amended section 40(8) of the Freedom of Information Act 2000 — and the equivalents in FOI (Scotland), the EIRs, the Civil Contingencies Act 2004 (Contingency Planning) Regulations and the INSPIRE Regulations — so that when a public authority assesses whether disclosure would breach the lawfulness principle, Article 6(1) is read as disapplying only the point (ea) gateway. In plain terms: you can still weigh ordinary legitimate interests when deciding an FOI request, but you cannot use recognised legitimate interest to justify an FOI disclosure.

Privacy notices, ROPAs and organisations that also process EU data

If you do adopt the new basis, transparency gets slightly more demanding, not less. The ICO says you must tell people your lawful basis is recognised legitimate interest and which of the five conditions you are using. A generic reference to 'legitimate interests' in a privacy notice will not do.

Four practical consequences:

If you also process EU personal data

This is a point of UK–EU divergence. Article 6(1)(ea) exists only in the UK GDPR. There is no equivalent in the EU GDPR, so you cannot rely on recognised legitimate interest for processing governed by EU law. Organisations running one policy across both regimes will need either a basis that works in both — usually ordinary legitimate interests with a full LIA — or two documented positions.

So should you switch?

Usually not, and the ICO says so directly: "If you're currently using legitimate interests as your lawful basis for a purpose which meets a recognised legitimate interest condition, you don't have to change basis (unless you want to)." There is no deadline and no transitional obligation.

Switching tends to be worth considering if you are a non-public-authority organisation doing fraud investigation, safeguarding or emergency response, where an LIA feels artificial and the reduced paperwork is genuinely useful. It is not worth considering for marketing, analytics, general data sharing, significant solely automated decisions, or anything a public authority does in the course of its functions — those purposes are simply outside the list.

This page is general information about what the law says, not legal advice about your situation. Check the statute and the ICO's guidance before you change a lawful basis, and take advice if the disclosure is contested.

Common questions

Is recognised legitimate interest the same as legitimate interests?

No, despite the names. Legitimate interests (Article 6(1)(f)) is open-ended but needs a three-part test and a documented legitimate interests assessment. Recognised legitimate interest (Article 6(1)(ea)) only covers five pre-approved purposes in Annex 1, but needs no balancing test and no LIA. Both require you to show the processing is necessary, and the right to object applies to both.

Can we use recognised legitimate interest for direct marketing?

No. Direct marketing is not one of the five Annex 1 conditions. Section 70 of the DUAA separately added direct marketing as an example of what may be an ordinary Article 6(1)(f) legitimate interest, in Article 6(11) — which still needs the full three-part test including balancing. PECR consent rules for electronic marketing are unaffected either way.

The police have asked our school for a pupil's details. What lawful basis do we use?

It depends. If a statutory power requires disclosure, your basis is legal obligation. If your school is itself a public authority — most state-funded schools are — check next whether responding falls within your own public task, because a public authority cannot rely on recognised legitimate interest for processing in the performance of its tasks. If neither applies and the request is voluntary and tied to a criminal investigation, the ICO says the crime condition is likely to be the appropriate condition; if it concerns a child at risk of harm, the safeguarding condition may fit. You still decide what is proportionate to send, and you can decline — the basis gives no right of access to the requester.

We're a local authority. Can we use this for our safeguarding work?

Not for your own tasks and functions. Article 6(1) as amended says points (ea) and (f) do not apply to public authorities processing in the performance of their tasks. The ICO says public task is likely to be the appropriate basis. You could only use recognised legitimate interest for something genuinely outside your public functions.

Do we have to update our privacy notice if we start using it?

Yes. The ICO says you must state that your lawful basis is recognised legitimate interest and identify which of the five conditions applies. It also suggests preparing privacy wording in advance for emergency or safeguarding situations you cannot anticipate.

Could the government add more conditions to the list later?

Yes. Article 6(6) of the UK GDPR lets the Secretary of State amend Annex 1 by regulations, and Article 6(10) makes those regulations subject to the affirmative resolution procedure. Under Article 6(9), before adding a case the Secretary of State must consider that processing in it is necessary to safeguard an objective in Article 23(1)(c) to (j). No such regulations were recorded against Annex 1 when this page was written, so five conditions is the current position — check Annex 1 on legislation.gov.uk for the live text.

Sources

This page summarises the following primary sources. Where they disagree with this summary, they take precedence.

Related guidance