Skip to main content
The state of ai impact assessment
Category: TCF and Vendors

Legitimate Interest Signal

Also known as: LI Signal, Legitimate Interest Flag
Simply put

A legitimate interest signal is a technical indicator, typically passed between a consent management platform and the vendors it works with, that communicates whether a business is relying on 'legitimate interest' rather than user consent as its justification for certain data processing. Legitimate interest is a legal basis under EU data protection law that can, in some cases, permit processing without asking the user to opt in, provided the business's interests are balanced against the individual's rights. It is important to note that this basis does not apply universally: separate ePrivacy rules often still require consent before cookies or similar technologies can be placed on or read from a user's device, and the user's ability to object must be respected.

Formal definition

A legitimate interest signal is a machine-readable value used within consent management infrastructure (for example, within the IAB Transparency and Consent Framework) to indicate that a controller or vendor is asserting legitimate interests as its GDPR Article 6(1)(f) lawful basis for a given processing purpose, as distinct from consent under Article 6(1)(a). Legitimate interests is one of the six lawful bases enumerated in Article 6(1) GDPR and requires a documented balancing assessment weighing the controller's or a third party's interests against the data subject's interests, rights, and freedoms; the data subject also retains a right to object under Article 21. Practitioners should note key limitations: reliance on legitimate interests for GDPR-level processing does not by itself satisfy the separate ePrivacy Directive (and national implementations) requirement of prior consent for storing or accessing information on a user's device, so a legitimate interest signal cannot lawfully substitute for consent where device access or certain marketing activities require it. The permissibility of legitimate interest for specific purposes, particularly targeted advertising, is contested and subject to evolving regulatory and enforcement positions across EU and other jurisdictions; this definition does not resolve those questions and does not address non-EU frameworks, which use different constructs.

Why it matters

The legitimate interest signal sits at a fault line between two distinct legal regimes, and misunderstanding it can lead to significant compliance exposure. Under the GDPR, legitimate interests is one of six lawful bases for processing personal data, and it can in some circumstances support processing without asking the user to opt in. However, the ePrivacy Directive and its national implementations impose a separate requirement of prior consent before cookies or similar technologies are stored on or read from a user's device. A legitimate interest signal that asserts a lawful basis under the GDPR does not, on its own, satisfy that separate ePrivacy consent requirement. Treating the two as interchangeable is a common source of error.

Who it's relevant to

Privacy officers and data protection professionals
Those responsible for lawful basis decisions need to ensure that any reliance on legitimate interests reflected in a signal is backed by a documented balancing assessment under Article 6(1)(f), and that the data subject's right to object under Article 21 is respected. They should verify that the signal is not being used to bypass ePrivacy consent requirements for device access or certain marketing activities.
Legal counsel and compliance teams
Counsel advising on cookie and tracking practices must assess whether legitimate interests can lawfully support each specific purpose, recognizing that this is contested for purposes such as targeted advertising and that regulatory and enforcement positions continue to evolve across EU and other jurisdictions. They should flag where a legitimate interest signal cannot substitute for the prior consent that ePrivacy rules may require.
Web developers and CMP implementers
Teams configuring consent management platforms and integrating with frameworks such as the TCF need to understand how legitimate interest signals are set, passed to vendors, and interpreted alongside consent signals, so that the technical implementation accurately reflects the legal basis chosen by the business and does not conflate a GDPR basis with ePrivacy consent.
Marketing and adtech compliance teams
Those managing vendor relationships and advertising activity should be aware that a legitimate interest signal communicates a claimed lawful basis rather than a guarantee that processing is permissible, and that its acceptability for advertising purposes is unsettled. They should coordinate with legal and privacy functions before relying on the signal for marketing use cases.

Inside Legitimate Interest Signal

Legitimate interest as a lawful basis under the GDPR
Legitimate interests is one of the six lawful bases for processing personal data set out in Article 6 GDPR. A legitimate interest signal, in the context of consent management, communicates that a party is relying on this basis rather than on consent for a given processing purpose. It concerns the GDPR layer of personal data processing and is distinct from the ePrivacy rules governing the placing of or access to information on a user's device.
Signalling within consent frameworks
Within frameworks such as the IAB Transparency and Consent Framework (TCF), a legitimate interest signal is a machine-readable indicator that a vendor or purpose is being processed under legitimate interests rather than under consent. It typically travels alongside consent signals and is intended to be read by downstream parties such as ad tech vendors and CMPs.
Relationship to the balancing test
Reliance on legitimate interests generally requires a balancing exercise weighing the controller's or third party's interests against the rights and freedoms of the individual. A legitimate interest signal reflects a claimed reliance on this basis but does not itself demonstrate that a valid balancing test was performed or documented.
The right to object
Where processing relies on legitimate interests, individuals generally have a right to object. A legitimate interest signal is often paired with mechanisms allowing users to object to or opt out of the relevant processing, and the signal may be updated to reflect such an objection.
Interaction with ePrivacy and device access
The signal addresses the GDPR lawful basis for processing personal data. It does not, on its own, satisfy separate ePrivacy requirements that in most EU jurisdictions call for prior consent to place or access information on a user's device, such as with analytics or advertising cookies. Legitimate interests cannot generally be substituted for consent where the applicable national ePrivacy implementation requires consent.

Common questions

Answers to the questions practitioners most commonly ask about Legitimate Interest Signal.

Can we rely on a legitimate interest signal instead of getting consent to place cookies?
Generally not for the placing of or access to information on a user's device. In most EU jurisdictions the ePrivacy Directive (as nationally implemented) requires prior consent for non-essential cookies and similar technologies, regardless of whether a legitimate interest basis exists under the GDPR. Legitimate interests is a GDPR lawful basis for processing personal data; it does not by itself override the separate ePrivacy consent requirement for device access. Where a signal indicates reliance on legitimate interests, it typically concerns downstream data processing rather than the initial storage or reading of cookies. The precise interaction depends on national law and evolving regulatory guidance.
Is legitimate interests one of the seven lawful bases in the GDPR?
Article 6 of the GDPR sets out six lawful bases, not seven. Legitimate interests is one of these six. It permits processing that is necessary for the legitimate interests pursued by the controller or a third party, except where those interests are overridden by the interests or fundamental rights of the data subject. Reliance on this basis generally requires a documented balancing assessment, and it does not remove separate obligations such as consent for device access under ePrivacy rules where those apply.
Where does a legitimate interest signal appear within a consent management setup?
A legitimate interest signal is typically transmitted as part of a structured consent or preference record produced by a consent management platform (CMP), and it may be expressed within frameworks such as the IAB Transparency and Consent Framework (TCF), which allows some purposes to be flagged as based on legitimate interests rather than consent. The signal communicates the asserted lawful basis to downstream vendors. Its presence does not by itself establish that the basis is valid; that depends on the underlying balancing assessment and on whether ePrivacy consent requirements also apply.
What records should we keep when relying on a legitimate interest signal?
Organizations relying on legitimate interests generally maintain documentation of the balancing assessment (often called a legitimate interests assessment) identifying the interest pursued, the necessity of the processing, and the outcome of weighing it against the individual's rights. Where a legitimate interest signal is transmitted through a CMP or a framework such as the TCF, retaining logs of the signals sent and received supports accountability. What specific records are required, and for how long, can vary by jurisdiction and by regulatory guidance, so legal review of your record-keeping approach is advisable.
How should we handle a user objection when we are relying on legitimate interests?
Under the GDPR, data subjects generally have a right to object to processing based on legitimate interests, and for direct marketing that objection must typically be honored without a balancing test. Implementations should be able to receive and act on an objection, update the relevant signal or preference record, and stop or restrict the affected processing and any onward transmission to vendors. Whether an equivalent mechanism is required in a given US state depends on that state's law, which often centers on opt-out rights rather than legitimate interests. The exact handling should be confirmed against applicable law.
How does a legitimate interest signal interact with an opt-out mechanism such as Global Privacy Control?
These operate under different logics and legal frameworks. A legitimate interest signal typically asserts a GDPR lawful basis for certain processing, while Global Privacy Control is a browser-level opt-out signal relevant chiefly under some US state privacy laws, where it may be treated as a request to opt out of sale or sharing. An organization may need to reconcile both: honoring an applicable opt-out signal even where a legitimate interest basis is asserted, depending on which jurisdiction's rules govern the user. How these signals should be prioritized in a given deployment depends on the applicable legal regime and is a matter for legal assessment rather than technical configuration alone.

Common misconceptions

A legitimate interest signal means the user does not need to be asked for anything.
Even where legitimate interests is a valid basis for processing personal data under the GDPR, separate ePrivacy rules in most EU jurisdictions still require prior consent to store or access information on a user's device (for example, non-essential cookies, pixels, local storage, or SDKs). Legitimate interests addresses the GDPR processing layer and does not by itself displace those device-access consent obligations.
Declaring legitimate interests through a signal is sufficient to make the processing lawful.
A signal only communicates a claimed reliance on this basis. Reliance on legitimate interests generally requires a documented balancing test and respect for the individual's right to object. The presence of a signal does not demonstrate that these steps were carried out, and it does not guarantee compliance.
The rules around legitimate interest signals apply the same way everywhere.
The concept of legitimate interests as described here derives from the GDPR and applies in the EU, with a closely aligned regime in the UK. Other jurisdictions, including individual US states such as California under the CCPA and CPRA, structure their obligations differently and often rely on opt-out mechanisms rather than lawful bases in the GDPR sense. Scope should always be stated when applying this concept.

Best practices

Treat the GDPR lawful basis and ePrivacy device-access consent as separate questions; do not assume a legitimate interest signal removes any requirement for prior consent to place or access cookies and similar technologies where national ePrivacy rules require it.
Where you rely on legitimate interests, carry out and document a balancing test weighing your interests against the rights and freedoms of individuals before configuring any signal to that effect.
Ensure that any purpose flagged under legitimate interests offers a clear and accessible way for users to exercise their right to object, and that objections are reflected in the signals passed to downstream parties.
When using a framework such as the IAB TCF, review how legitimate interest signals are configured for each vendor and purpose, and confirm they align with your own legal analysis rather than accepting vendor defaults.
State the geographic and legal scope of your reliance on legitimate interests, recognising that EU and UK rules differ from US state frameworks that generally use opt-out models.
Remember that CMPs and signalling frameworks support compliance but do not replace legal judgment; keep records of your basis, balancing tests, and objection handling to demonstrate accountability.
Promotional banner graphic asking if you are ready for PCI DSS 4.0 with a call-to-action to get the guide