Compare LIA vs consent basis with a practical test for purpose, necessity, balancing and evidence so your lawful basis holds up under scrutiny.
Topics: LIA, Consent, GDPR, Lawful Basis, Privacy Operations
A lawful-basis decision can look straightforward in a processing register and become difficult under scrutiny. The choice between LIA vs consent basis affects what individuals are told, which rights apply, how teams configure workflows, and whether the organisation can demonstrate that its processing is necessary and proportionate. It should therefore be treated as an operational decision, not a box to tick in a ROPA.
The first correction is an important one: an LIA is not itself a lawful basis. Legitimate interests is the lawful basis under Article 6(1)(f) of the GDPR and UK GDPR. A Legitimate Interests Assessment documents why an organisation believes it may rely on that basis. Consent, by contrast, is a separate lawful basis under Article 6(1)(a), with its own threshold and ongoing obligations.
LIA vs consent basis: start with the processing purpose
The right question is not which basis is easier to administer. It is whether the proposed processing has a clear, lawful purpose and whether the chosen basis accurately reflects the relationship with the individual.
Consent may be appropriate where an individual has a genuine, informed choice and can refuse without suffering a detriment. It is often relevant for optional activities where the person would reasonably expect to make an active decision, such as particular marketing communications or the use of optional data features. Valid consent must be freely given, specific, informed and unambiguous. It must also be as easy to withdraw as it was to give.
Legitimate interests may be appropriate where the organisation has a real and lawful interest, the processing is necessary for that interest, and the impact on individuals does not override it. Common examples can include fraud prevention, network security, certain business-to-business relationship management, internal administration and carefully targeted direct marketing. None of these examples is automatic. The context, data types, audience, reasonable expectations and safeguards determine the outcome.
A decision to rely on legitimate interests should never be a way to avoid consent because consent rates may be lower. If individuals are being asked to accept something optional, unexpected or potentially intrusive, a carefully written LIA will not cure the underlying mismatch.
What an LIA needs to establish
A defensible LIA is usually structured around three questions: purpose, necessity and balancing. It should be specific to the processing activity, rather than a generic statement copied across multiple records.
1. Is there a legitimate interest?
The organisation must identify the interest precisely. “Business interests” alone is too broad to be useful. A clearer statement might be protecting customer accounts from fraudulent access, maintaining the security of corporate systems, or contacting existing business customers about related services.
The interest must be lawful and sufficiently defined. It may belong to the organisation, a third party or society more broadly, but it cannot conflict with data protection principles or other applicable legal obligations.
2. Is the processing necessary?
Necessary does not mean absolutely indispensable. It means the purpose cannot reasonably be achieved through a less intrusive means. Teams should test this honestly. Could the same outcome be achieved with less data, a shorter retention period, aggregation, pseudonymisation, narrower audiences or an alternative communication channel?
This is where operational teams often need input from security, product, marketing, HR or procurement. The privacy lead can assess the legal framework, but the business owner must explain why the processing design is needed and what alternatives were considered.
3. Do individuals’ interests override yours?
The balancing test is the centre of the LIA. It considers the likely impact on the individual, including both tangible and less obvious effects such as loss of control, unwanted contact, discrimination, reputational harm or distress.
Reasonable expectations matter. A customer is more likely to expect limited account-security monitoring than extensive profiling based on unrelated behaviour. A worker may have less freedom to object in an employment relationship, which can make legitimate interests harder to rely on for monitoring. Children, vulnerable people and individuals whose data is used in unexpected ways require particular caution.
Safeguards can alter the balance. Data minimisation, access controls, opt-outs, short retention periods, pseudonymisation, frequency limits and clear privacy information may reduce risk. However, safeguards should reduce a defined risk, not act as generic reassurance added after the decision has been made.
When consent is the stronger basis
Consent is strongest when it matches the reality of the interaction. The individual should understand what they are agreeing to, why, and what will happen if they say no. The request should not be bundled with unrelated terms, hidden in a privacy notice or designed to steer the individual towards acceptance.
For organisations operating across multiple jurisdictions, consent also needs consistent evidence. Teams must be able to show when and how it was obtained, the wording presented at the time, the purposes covered and any subsequent withdrawal. If consent is withdrawn, downstream systems must stop the relevant processing without delay, unless another lawful basis independently applies to a separate purpose.
Consent becomes fragile where there is an imbalance of power. In employment, education, public services or any situation where access to a necessary service depends on agreement, people may not be able to refuse freely. In those circumstances, a different lawful basis may be more appropriate, provided it genuinely fits the processing.
Consent should also not be recycled casually. A change in purpose, material change in data use or expansion to a new recipient group may require fresh consent. Relying on old permissions without version control creates a weak evidential position.
Rights and transparency do not disappear under legitimate interests
A frequent error is to treat legitimate interests as less demanding because it does not require an opt-in. In practice, it creates different controls. Individuals have the right to object to processing based on legitimate interests. For direct marketing, that right is absolute. The organisation must stop processing for that purpose when an objection is received.
Privacy notices must explain the legitimate interests being pursued in clear language. An individual should not need to infer the organisation’s reasoning from vague statements about service improvement or commercial needs. Where the processing involves profiling, monitoring or less obvious data use, clarity becomes even more important.
The lawful basis must also align with the rest of the privacy programme. The ROPA should identify the purpose, categories of personal data, recipients, retention periods, security measures and lawful basis. A DPIA may be required where processing is likely to result in high risk to individuals, even if the organisation has completed an LIA. The two assessments answer different questions: an LIA supports the lawful-basis decision, while a DPIA examines broader privacy risks and mitigations.
Avoid basis shopping and retrospective paperwork
The most defensible lawful-basis decisions are made before processing begins. Retrospectively selecting legitimate interests after consent has failed, or describing an existing activity as necessary without testing alternatives, creates inconsistency across notices, contracts, system configurations and audit evidence.
This risk increases when privacy records sit in separate spreadsheets and teams manage decisions independently. Marketing may record consent, security may rely on legitimate interests, and procurement may capture vendor assurances without a shared view of where personal data flows. The result is not merely administrative friction. It makes it difficult to prove that processing is controlled throughout its lifecycle.
A structured governance process should connect the LIA to the relevant processing record, privacy notice, vendor assessment, DPIA where applicable, and review cycle. It should assign a business owner, record the decision date, capture safeguards and flag changes that require reassessment. New AI uses, expanded data sources, new recipients, altered profiling logic or an increased impact on individuals can all change the original balance.
Privacy360 supports this discipline by bringing Legitimate Interest Assessments, ROPA records, DPIAs, vendor reviews and evidence collection into one operational system. That makes the decision traceable across the teams responsible for designing, approving and running the processing.
A practical decision standard for governance teams
Before selecting either route, ask whether the individual has a real choice, whether the activity is optional, and whether the organisation could reasonably deliver the purpose in a less intrusive way. If the answer points to a clear, voluntary choice, consent may be appropriate. If the purpose is necessary for a legitimate operational interest and the impact is carefully controlled, legitimate interests may be viable.
Neither basis is a permanent label. Review it when the purpose, data, audience, technology or risk profile changes. A well-maintained LIA does more than justify a decision: it gives privacy, legal, security and business teams a shared record of the limits they must continue to respect.