What are “legitimate interests” under Data Protection legislation, and can your washing machine rely on them?

October 2, 2023

By Ciara O’Brien

When a company wants to process personal data, it must be able to rely on one of the six lawful bases to do so under Article 6(1)(f) of the UK General Data Protection Regulation (UK GDPR). One lawful basis is the “legitimate interests” ground, where processing of personal data is necessary for the legitimate interests of the company. Whilst it sounds like a convenient catch all, this basis should not be used as a blanket approach for all data processing.

Triggered by security cameras sending data to Tik Tok, consumer champion Which? recently investigated common home device companies for their collection of consumers’ personal data via so-called “smart products”. Many consumers may be surprised at the information their home appliances are collecting about them. For example, data tracking is programmed into smart washing machines and some providers require individuals set up an account and provide their name, date of birth or even their location. Under the UK GDPR, businesses should not collect any more data than the minimum required to carry out their function. In light of that, it is difficult to understand on what basis a washing machine is legitimately collecting that information.

Which? has called for the Information Commissioner’s Office (ICO), the organisation responsible for upholding information rights and data privacy for individuals within the UK, to “crack down on data collection by manufacturers and marketing firms that appears to go beyond legitimate interests”.

Whilst “legitimate interests” is the most flexible of the bases for processing personal data, it can’t be relied on as a blanket authority for all data processing.

So how do you ensure your business is not falling foul of the UK GDPR? We’ve re-capped the three-part test when undertaking a legitimate interest assessment, as found in Article 6(1)(f) of the UK GDPR to help you in your decision-making:

  1. Purpose

Is there a genuine legitimate interest behind the processing?

This can be a commercial purpose or an individual interest. Examples included in the UK GDPR include use of client or employee data, which would involve regular processing, or fraud prevention, which might include one-off processing by sharing the data with a third party.

As a general rule of thumb, consider whether the individual who has given you their data would reasonably expect you to use their data in the way you are proposing.

It is useful to consider what benefits your company is expecting to get from the processing including any specific business objectives, whether such processing is common for your type of business, and whether any third parties’ benefit from the processing. Also consider how important those benefits are, and whether there are any wider, ethical concerns as to processing the data.

  1. Necessity

Is it necessary to process the personal data in order to achieve your intended goals? Could you achieve the same goal by different means?

An overarching principle in the data protection legislation is that all processing of personal data must not go further than is necessary to achieve the purpose. In particular, be mindful of any legacy data-gathering forms you provide to customers and clients and ensure that you are not obtaining information which you don’t need to fulfil your purpose.

The ICO notes that if you find it difficult to explain how the processing achieves your objective or there are alternative methods available to you, then you may need to revisit whether you have a genuine legitimate interest in the proposed data processing.

  1. Balancing interests

Is your legitimate interest overridden by the individual’s interests, rights or freedoms?

Will it cause the individual, whose personal data is being processed, any unjustified harm or cause them to lose control over their personal data?

This final step of the test does not mean that the interests of the business and individual must match or be simultaneously achieved, just that if there is any conflict, the business must be able to clearly justify why its interests prevail. It is a balancing act. If there is a conflict to a large extent, the individual’s interests may take priority.

The more significant the risks to the individual, the more compelling the justification for relying on the “legitimate interests” ground should be and the more a business should consider documenting the decision and risk mitigation measures.

If you’re unsure whether your intended data processing can be justified under the legitimate interest’s ground, please contact a member of our corporate team, Stephen Thompson via email on sthompson@darwingray.com or via telephone on 029 2082 9136 for a free initial chat to see how we can help you.

 

Contact Our Team
Fflur Jones
Managing Partner
View Profile
Owen John
Partner
View Profile
Rachel Ford-Evans
Senior Associate
View Profile
Rhodri Evans
Senior Associate
View Profile
Siobhan Williams
Senior Associate
View Profile
Stephen Thompson
Partner
View Profile

I have worked with Darwin Gray for a number of years and the level of service, professionalism and timely response is second to none. I would highly recommend Darwin Gray to any business.”

Becs Beslee
Dice FM Ltd

Darwin Gray have provided us with a first-class service for many years now. They really take the time to understand our business and develop relationships which results in advice and support that is contextualised and effective.”

Rebecca Cooper
ACT Training

We have worked with Darwin Gray for several years and have always found their services and advice to be first class.”

Karen Gale
Stepping Stones Group

An extremely professional and sincere company who make time for your queries and understand the need to break down certain facts and information to ensure everything is understood perfectly. I would highly recommend the company to anyone looking for any type of legal advice”

Gwawr Booth
Portal Training Ltd

PSS has worked with Darwin Gray for many years. We have always received an excellent service. Prompt and professional advice and support.”

Ledia Shabani
Property Support Services UK Ltd

We have used several departments within DG recently and we have been very pleased with an effective, efficient and down to earth service. Very happy thus far and I expect that we will continue to use DG.”

Guto Bebb
Farmers’ Union of Wales

Darwin Gray offer us truly superb services. Very professional, quick and services available bilingually which is very important to us, highly recommend.”

Iwan Hywel
Mentrau Iaith Cymru

My “go to” in urgent and time sensitive cases for direction, support and advice. The team are quick to respond to calls or emails for advice and support on all matters. Always explain complex matters in a way a lay person can easily understand.”

Margot Adams
Guarding UK Ltd