Home / Blog / Legitimate interest is not a consent shortcut: the claims that fail audits

Legitimate interest is not a consent shortcut: the claims that fail audits

Published 2026-10-03

Most privacy notices read like they were written by someone who has never had to defend them. The phrase that fails most often is "legitimate interest." It sounds like a legal shield. In practice, regulators treat it as a claim you have to prove, and consent banners that lean on it usually cannot.

What legitimate interest actually requires

Legitimate interest is one of the lawful bases under GDPR, but it is not a shortcut around consent for tracking. To rely on it, a site must identify a specific interest, show the processing is necessary for it, and pass a balancing test against the visitor's rights. For advertising cookies, analytics that build profiles, or any cross-site tracking, the balancing test almost always fails. Data protection authorities have said so repeatedly: routine marketing tracking does not survive it.

The balancing test is also documented, not declared. If you claim legitimate interest, you are expected to have a written assessment showing your work. A banner that says "we process data based on legitimate interest" with no assessment behind it is a finding waiting to happen.

The three claims banners make that do not hold up

First, "essential cookies" that are not essential. A cookie is strictly necessary only if the service the visitor explicitly requested would not work without it. A preference cookie, an A/B testing cookie, and especially any analytics or ad cookie do not qualify. Labeling them essential to avoid asking for consent is one of the most common violations regulators flag.

Second, legitimate interest for analytics. Some vendors ship default configurations that set analytics cookies before consent, justified by legitimate interest. Regulators in France, Germany, and Italy have fined companies for exactly this. If your analytics tool drops cookies before the visitor chooses, the vendor's default is your liability.

Third, the bundled "accept all" with no real reject path. A banner with a bright accept button and a reject option buried three clicks deep is not freely given consent. Several authorities have ruled that refusing must be as easy as accepting. The design of the banner is part of the legal test, not decoration around it.

Where the claim usually enters the site

In most audits, nobody on the team chose these claims deliberately. They arrived through defaults: the consent platform's template text, the tag manager's vendor preset, the analytics tool's installation guide. Each default was written to make onboarding easy, not to survive an audit. The fix is to treat every pre-filled lawful basis as a draft, not a decision.

Run a simple inventory. For every cookie and tracker on the site, write down the claimed basis and who made the claim. Anything marked legitimate interest or strictly necessary gets a second look. Ask two questions: would the requested service break without this, and do we have a written assessment? If the answer to either is no, the claim does not survive.

What to put in the banner instead

Ask for consent for anything that is not genuinely necessary, and make the request specific. Separate categories for analytics, marketing, and functional tracking let visitors choose, and granular choice is exactly what the rules require. A single "accept all" button with fine print underneath is the pattern regulators keep striking down.

Keep the receipt. When a visitor consents, record what they consented to, when, and which version of the banner they saw. Consent records are the evidence that the choice was real. Without them, even a well-designed banner is just a screenshot.

The bottom line

Legitimate interest is a real lawful basis for a narrow set of processing. For the tracking that most banners are trying to justify, it is a shortcut that fails on contact with an auditor. The sites that pass audits are not the ones with the cleverest legal theory. They are the ones that asked for consent plainly, recorded the answer, and never let a vendor default make the decision for them.

Get a free consent audit of your website

Free consent audit