Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Category: TCF and Vendors

Vendor Legitimate Interest Encoding

Also known as: Vendor Legitimate Interest Declaration, LI Encoding
Simply put

Vendor Legitimate Interest Encoding refers to how a consent management system records that a particular third-party vendor is relying on "legitimate interests" rather than user consent as its legal justification for processing personal data. Legitimate interests is one of several lawful bases available under data protection law, where an organization processes data to pursue a legitimate purpose without asking the user to opt in first. In this arrangement, the publisher is generally expected to provide transparency to the user about the vendor's activity, though the user experience differs from consent-based processing.

Formal definition

Vendor Legitimate Interest Encoding is the technical recording, within a consent framework, of a vendor's declaration that legitimate interests serves as its lawful basis for a given data processing purpose, as distinct from consent. Under frameworks such as the IAB Europe Transparency and Consent Framework, a vendor may declare legitimate interest for certain purposes, in which case, per IAB Europe guidance, the framework treats this as requiring the publisher to provide transparency rather than a user opt-in. Legitimate interests is one of the lawful bases recognized under the (UK) GDPR and can encompass the controller's own interests or those of third parties, including commercial interests. Practitioners should note that whether legitimate interests is validly relied upon in a specific case depends on a fact-specific assessment (typically a balancing of the organization's interests against the individual's rights), which the encoding itself does not perform or guarantee. It is also important to distinguish this GDPR-level lawful basis question from the separate ePrivacy rules governing the placing of and access to cookies and similar technologies on a user's device, which in most EU jurisdictions generally require prior consent for non-essential technologies regardless of any legitimate interest declaration; this definition does not resolve how those two regimes interact in any given deployment, and enforcement positions on the use of legitimate interests for advertising-related purposes remain contested.

Why it matters

How a consent management system encodes a vendor's reliance on legitimate interests matters because it changes what the user is asked and what the publisher is obligated to provide. When a vendor declares legitimate interest as its lawful basis rather than consent, the arrangement generally shifts from an opt-in interaction to one where, per IAB Europe guidance, the publisher is expected to provide transparency about the vendor's processing. This distinction has direct consequences for how banners are designed, what controls users see, and how publishers document the legal justification for third-party data processing across their vendor stack.

The encoding itself is a record of a declaration; it is not proof that reliance on legitimate interests is valid in a given case. Under the (UK) GDPR, whether legitimate interests can be relied upon depends on a fact-specific assessment that typically balances the organization's interests (which may include commercial interests, and may extend to third parties) against the rights and interests of the individual. A consent framework can capture that a vendor has asserted legitimate interest, but it does not perform that balancing test or guarantee its outcome. Treating the encoded declaration as a substitute for a documented assessment is a common source of compliance risk.

Equally important, this GDPR-level lawful basis question is separate from the ePrivacy rules governing the placing of and access to cookies and similar technologies on a user's device, which in most EU jurisdictions generally require prior consent for non-essential technologies regardless of any legitimate interest declaration. Enforcement positions on relying on legitimate interests for advertising-related purposes remain contested, so publishers and privacy teams should treat the encoding as one input into a broader compliance analysis rather than a settled answer.

Who it's relevant to

Privacy and data protection officers
DPOs and privacy leads need to understand that a vendor's encoded legitimate interest declaration is an assertion, not a validated lawful basis. They are typically responsible for ensuring that any reliance on legitimate interests is backed by a documented, fact-specific assessment balancing the organization's or third party's interests against individual rights, and for confirming that ePrivacy consent obligations are handled separately.
Legal and compliance counsel
Counsel advising on vendor arrangements should note that enforcement positions on using legitimate interests for advertising-related purposes remain contested, and that requirements differ across the EU, the UK, and other regimes. The encoding does not resolve how the GDPR lawful basis question interacts with ePrivacy rules on placing and accessing information on a device, which in most EU jurisdictions generally require prior consent for non-essential technologies.
Web developers and CMP implementers
Those integrating consent management platforms and framework signals need to correctly capture and propagate the distinction between consent-based and legitimate-interest-based processing per vendor and purpose. They should recognize that the technical encoding supports transparency and record-keeping but does not, on its own, perform the legal balancing test or guarantee compliance.
Marketing and adtech compliance teams
Teams managing vendor relationships and advertising technology should understand how a legitimate interest declaration changes the user experience, generally shifting toward transparency rather than an opt-in for the affected purposes. Given the contested enforcement landscape for advertising-related legitimate interest claims, they should coordinate closely with legal and privacy teams before relying on these declarations.

Inside Vendor Legitimate Interest Encoding

Legitimate Interest Signal in the TCF
Within the IAB Transparency and Consent Framework (TCF), a vendor's reliance on legitimate interest as a legal basis is encoded in the Transparency and Consent (TC) String. This is distinct from the consent signal, and it records whether a vendor has declared legitimate interest for a given purpose and whether the user has objected.
Purpose-Level Encoding
Legitimate interest is expressed per purpose (for example, certain measurement or personalization purposes) rather than globally. A vendor may declare legitimate interest for some purposes while relying on consent for others, and the TC String encodes these positions separately.
Right to Object Representation
Because legitimate interest under the GDPR carries a data subject right to object, the encoding must capture whether a user has exercised that objection. An object signal for a vendor or purpose indicates the user has withdrawn the legitimate interest basis for that processing.
Vendor Declarations in the Global Vendor List (GVL)
Which legal basis a vendor may claim for each purpose is constrained by that vendor's declarations in the framework's vendor list. The encoding in the TC String is read in conjunction with these declarations to determine the applicable basis.
Interaction Between ePrivacy and GDPR Layers
Legitimate interest encoding concerns the GDPR legal basis for processing personal data. It does not by itself address the separate ePrivacy Directive requirement for consent to store or access information on a device, which generally still requires prior consent for non-essential cookies and similar technologies.

Common questions

Answers to the questions practitioners most commonly ask about Vendor Legitimate Interest Encoding.

Does encoding a vendor's legal basis as legitimate interest in a consent string mean users have consented to that processing?
No. Legitimate interest and consent are distinct legal bases under the GDPR, and encoding a purpose as legitimate interest specifically signals that the vendor is relying on legitimate interest rather than on the user's consent. The two should not be treated as interchangeable. Where the underlying activity involves placing or accessing information on a user's device, note that the ePrivacy rules in most EU jurisdictions generally require prior consent regardless of how the legal basis is encoded downstream, so a legitimate interest signal for GDPR processing does not by itself satisfy those separate ePrivacy obligations.
If a vendor is registered as relying on legitimate interest, does that mean the reliance is automatically valid and unchallengeable?
No. Encoding legitimate interest in a technical signal records a claimed legal basis; it does not establish that the basis is lawful for the specific processing. Legitimate interest generally requires a balancing assessment weighing the vendor's interests against the individual's rights and reasonable expectations, and some purposes may not be permissible on that basis. Data protection authorities in the EU have questioned the use of legitimate interest for certain advertising-related activities, and interpretations continue to evolve. The encoding is a declaration, not a determination of validity.
How should we review which vendors are asserting legitimate interest in the consent strings our CMP generates?
Most consent management platforms expose the per-vendor and per-purpose legal basis assertions, allowing you to see which vendors are flagged as relying on legitimate interest versus consent. Reviewing this typically involves examining the vendor and purpose configuration in your CMP and, where a framework such as the IAB TCF is used, the applicable vendor list and its declared bases. Because these declarations originate from vendors and framework policies rather than from your own legal analysis, they should be reviewed against your organization's own assessment of what is appropriate. This entry does not cover the internal configuration steps of any specific CMP.
Can we restrict or override the legitimate interest basis that individual vendors assert?
Many CMPs and frameworks allow publishers to restrict a vendor's declared purposes or to disallow reliance on legitimate interest for particular purposes, effectively narrowing what is encoded. Whether and how you can do this depends on your CMP's capabilities and any framework policies you have adopted. Applying such restrictions is generally an organizational and legal decision that should follow from your assessment of each purpose, rather than a purely technical exercise. The availability and effect of specific restriction controls vary by tool and are outside the scope of this definition.
What should we log or retain regarding vendor legitimate interest encoding?
Because record-keeping obligations under the GDPR extend to the legal bases relied upon, it is generally advisable to retain evidence of how legal bases, including legitimate interest, were encoded and communicated for the vendors and purposes in question. This may include the consent string values, the applicable vendor list version, and the configuration in effect at a given time. The specific retention practices and what constitutes adequate records depend on facts not addressed here, including your jurisdiction and the guidance of the relevant data protection authority, and should be confirmed through your own legal assessment.
How does vendor legitimate interest encoding interact with a user's choice to object?
Where processing is based on legitimate interest, individuals generally have a right to object, and frameworks that encode legitimate interest typically also provide a mechanism to record such objections separately from consent signals. Implementers should ensure that an objection is captured, transmitted to the relevant vendors, and acted upon, since honoring the objection is what gives effect to the user's right. The technical encoding supports this but does not by itself guarantee that downstream vendors process or respect the objection; verifying that behavior is a separate operational and contractual matter not covered by this definition.

Common misconceptions

A vendor's legitimate interest signal removes the need for consent to place cookies.
The two regimes operate on different layers. Even where legitimate interest may be a valid GDPR basis for subsequent processing, the ePrivacy rules in most EU jurisdictions generally still require prior consent to store or access information on a user's device for non-essential purposes. Legitimate interest encoding does not substitute for that consent.
Encoding legitimate interest makes the processing automatically lawful.
The encoding merely records a vendor's claimed basis and the user's objection status. Whether legitimate interest is actually a valid basis depends on a case-by-case assessment (including a balancing test) and is a legal judgment, not something the TC String or a CMP can guarantee. Enforcement positions on using legitimate interest for advertising-related purposes have been contested.
The same legitimate interest encoding applies uniformly across all jurisdictions.
The TCF legitimate interest mechanism is built around the EU/GDPR framework. Other regimes, such as the UK or various US state laws like the CCPA and CPRA, rely on different concepts and often opt-out models, so the encoding does not map directly onto those requirements.

Best practices

Treat consent and legitimate interest as separate signals, and confirm that your CMP correctly encodes each per vendor and per purpose rather than collapsing them into a single flag.
Do not rely on a legitimate interest signal to satisfy the ePrivacy consent requirement for storing or accessing information on a device; obtain prior consent for non-essential cookies and similar technologies where required in EU jurisdictions.
Ensure the user's right to object is honored in practice, so that an object signal in the TC String actually stops the corresponding processing downstream.
Cross-check each vendor's declared legal bases against the framework's vendor list, and verify that claimed legitimate interest purposes are consistent with those declarations.
Document a legitimate interest assessment, including the balancing test, for any purpose where a vendor relies on that basis, and treat this as a legal determination rather than a technical configuration.
Recognize that requirements differ across the EU, UK, and US state regimes, and avoid assuming TCF legitimate interest encoding maps onto opt-out frameworks such as the CCPA or CPRA.
a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.