Skip to main content
Category: Consent Principles

Necessity Test

Also known as: Necessity Requirement, Erforderlichkeit, Less Restrictive Means Test
Simply put

The necessity test is a check used to decide whether an organisation's use of personal data is genuinely needed to achieve its stated purpose, or whether that purpose could reasonably be met in a way that interferes less with people's rights. In the context of the GDPR, it typically forms the second step of the three-part Legitimate Interest Assessment. In broader legal analysis, it is also one stage of the wider proportionality assessment used when a measure limits a fundamental right.

Formal definition

Under the GDPR, the necessity test is generally the second stage of the three-step Legitimate Interest Assessment (LIA), following the identification of a legitimate interest and preceding the balancing test. It asks whether the proposed processing is necessary to achieve the identified legitimate aim, or whether a less intrusive means could reasonably accomplish the same purpose; where a less restrictive alternative exists, the processing may not satisfy the requirement. More broadly, the necessity test (in German doctrine, Erforderlichkeit) is one component of the proportionality assessment used to scrutinise measures that limit fundamental rights, and is commonly framed as the requirement of the 'less restrictive means.' The precise scope and interpretation of the necessity requirement remains subject to legal and academic debate, and its application in any given case depends on facts not addressed by this definition.

Why it matters

The necessity test sits at the heart of two related but distinct legal exercises, and getting it wrong can undermine the lawful basis for an entire processing activity. Within the GDPR's Legitimate Interest Assessment (LIA), necessity is the gate that a controller must pass through after identifying a legitimate interest but before reaching the balancing test. If the same purpose could reasonably be achieved by a less intrusive means, the processing may fail this stage, and reliance on legitimate interests as a lawful basis may not hold up under scrutiny from a supervisory authority.

The concept also matters beyond data protection compliance narrowly defined. In broader legal analysis, the necessity test (in German doctrine, Erforderlichkeit) forms one component of the wider proportionality assessment applied whenever a measure limits a fundamental right. This means the same analytical discipline that a privacy team applies within an LIA reflects a deeper legal tradition of asking whether a rights-limiting measure goes further than it needs to. Understanding both framings helps privacy officers and legal counsel articulate why a particular data use is defensible, or recognise when it is not.

Because the precise scope and interpretation of the necessity requirement remains subject to legal and academic debate, teams should treat the test as a documented, reasoned judgement rather than a mechanical checkbox. Its application depends heavily on facts specific to each processing operation, and what counts as a reasonably available less restrictive alternative can be contested. Recording the reasoning behind a necessity conclusion supports accountability and provides a basis for defending decisions if they are later questioned.

Who it's relevant to

Privacy officers and data protection professionals
Those conducting Legitimate Interest Assessments must apply and document the necessity test as the second step, evaluating whether a stated purpose could reasonably be met by a less intrusive means before moving on to the balancing test. Recording the reasoning supports accountability and helps defend the chosen lawful basis if questioned.
Legal counsel and compliance teams
Advisers who structure lawful bases for processing rely on the necessity test to assess whether legitimate interests can be sustained, and may also encounter the same concept as part of the broader proportionality analysis applied to measures limiting fundamental rights. Given ongoing academic and legal debate over its scope, counsel should frame necessity conclusions as reasoned, fact-dependent judgements.
Product and engineering teams designing data uses
Teams that determine what data a feature or system collects benefit from understanding the necessity test, since choosing a less intrusive design that still achieves the purpose can be what allows a processing activity to satisfy the requirement. Involving these teams early helps surface whether reasonable less restrictive alternatives exist.

Inside Necessity Test

Strict Necessity Standard
The core assessment of whether a cookie or similar technology is genuinely essential to provide a service explicitly requested by the user. Under the ePrivacy Directive and its national implementations, the exemption from consent applies only where storage or access is strictly necessary for a service the user has actively asked for, not merely useful or commercially convenient for the operator.
User-Requested Service Anchor
The requirement that necessity be judged from the perspective of the user's request, not the provider's interests. A cookie that enables a shopping cart or maintains a login session during a browsing session is typically necessary, whereas one that supports analytics or advertising generally is not, even if the operator considers it important to its business.
Scope of Covered Technologies
The test applies not only to HTTP cookies but to functionally similar technologies such as pixels, local storage, SDKs, and fingerprinting, since the ePrivacy rules govern any storage of, or access to, information on a user's device regardless of the mechanism used.
Separation from GDPR Lawful Basis
The necessity test under ePrivacy addresses whether consent is required to place or read a cookie; it is distinct from the separate GDPR question of whether any personal data subsequently processed has a lawful basis. Passing the necessity test does not by itself resolve GDPR obligations.
Case-by-Case Evaluation
Necessity is assessed per cookie and per purpose rather than by broad category labels. A cookie serving multiple purposes may be exempt for its essential function but require consent for any additional, non-essential purpose bundled with it.

Common questions

Answers to the questions practitioners most commonly ask about Necessity Test.

Does labelling a cookie as 'necessary' in a CMP mean it is automatically exempt from consent?
No. A label applied within a consent management platform does not, by itself, determine the legal status of a cookie. The necessity test is an objective assessment of whether the cookie is strictly necessary to provide a service the user has explicitly requested. In most EU jurisdictions, a cookie only falls within the ePrivacy exemption if it genuinely meets that threshold, regardless of how it is categorised in a tool. Mislabelling a non-essential cookie as necessary does not remove the consent obligation, and the classification may be challenged by a data protection authority.
If a cookie is useful or important for the business, does that make it 'necessary' under the necessity test?
Not generally. Business usefulness, commercial value, or operational convenience are different from strict necessity. The exemption in most EU jurisdictions is assessed from the perspective of the user and the service they have requested, not the interests of the website operator. Analytics, advertising, and many functional cookies may be valuable to the business but typically still require prior consent because they are not strictly necessary to deliver the requested service. The necessity test is narrow, and being important is not the same as being essential.
How do we actually apply the necessity test to an individual cookie?
A common approach is to ask whether the service the user explicitly requested could function without that cookie or similar technology. If the requested functionality would fail or be materially impaired without it, it may fall within the strictly necessary category in most EU jurisdictions. If the service still works and the cookie serves analytics, advertising, personalisation, or other secondary purposes, it typically requires consent. This assessment should be documented per cookie or technology, and note that the analysis applies equally to non-cookie technologies such as pixels, local storage, and SDKs. Because interpretations of the exemption can be contested, legal judgment is usually needed for borderline cases.
Who within an organisation should carry out and sign off the necessity assessment?
The necessity test generally requires input from several roles because it combines technical and legal analysis. Developers or engineers can describe what each cookie or technology does and whether functionality depends on it, while privacy, legal, or data protection colleagues assess whether that meets the strict necessity threshold under the applicable framework. A CMP or scanning tool can support the inventory and evidence gathering but does not replace this judgment. Documented sign-off helps demonstrate accountability, though the appropriate governance structure will depend on the organisation.
How often should the necessity test be repeated?
It is generally advisable to reassess when circumstances change rather than treating the test as a one-time exercise. Triggers may include adding or updating third-party scripts, changing SDKs or tag configurations, launching new features, or changes in guidance from a relevant data protection authority. Because cookies and technologies can be introduced by vendors without notice, periodic re-scanning and review are commonly used to keep the assessment current. The appropriate frequency depends on how frequently the site or app changes.
Should the outcome of a necessity test be recorded, and if so how?
Maintaining records is generally considered good practice because it supports the accountability expectations under frameworks such as the GDPR and can help respond to regulator or user queries. A record typically identifies each cookie or technology, its purpose, the reasoning for classifying it as necessary or consent-requiring, and who made the determination. This documentation supports, but does not guarantee, a defensible position, and the format and level of detail may vary depending on the jurisdiction and the organisation's risk approach.

Common misconceptions

If a cookie is important to the website operator's business, it qualifies as necessary and is exempt from consent.
The necessity test is judged from the user's request for a service, not the operator's commercial interests. In most EU jurisdictions, cookies for analytics, advertising, or business optimization are generally not considered strictly necessary and typically require prior consent, however valuable they may be to the operator.
The necessity test only concerns traditional HTTP cookies.
Because the underlying ePrivacy rules govern any storage of or access to information on a user's device, the same necessity analysis generally applies to pixels, local storage, SDKs, and fingerprinting techniques, not just cookies in the literal sense.
Passing the necessity test means no further privacy compliance is needed for that cookie.
The necessity test addresses only whether consent is required to place or read information on the device under ePrivacy rules. Any personal data processed through the cookie may still trigger separate GDPR obligations, including the need for a lawful basis, transparency, and data subject rights.

Best practices

Assess necessity cookie by cookie and purpose by purpose, rather than exempting entire categories, and document the specific user-requested service each exempt cookie supports.
Frame the necessity question from the user's perspective, asking whether the cookie is essential to deliver a service the user actively requested, not whether it benefits the operator.
Extend the necessity analysis to non-cookie technologies such as pixels, local storage, SDKs, and fingerprinting, since these generally fall within the same ePrivacy rules.
Keep the ePrivacy necessity determination separate from the GDPR lawful basis analysis, and address both where a cookie also involves processing of personal data.
Where a cookie serves both essential and non-essential purposes, treat only the essential function as exempt and obtain consent for the additional purposes.
Record the reasoning behind each necessity determination and revisit it periodically, as regulatory guidance and enforcement positions on strict necessity in the EU and UK may evolve.