Duty

A simpler reason to use data: recognised legitimate interests

There is an additional lawful reason to use personal data, and for a short list of purposes it skips the usual balancing test. Here is what 'recognised legitimate interests' covers and where the shortcut does and does not apply.

TheDutyDesk Editorial23 March 20263 min readReviewed 7 June 2026

Every time you use someone's personal data, you need a lawful reason for it. One of the most common reasons, "legitimate interests", has always come with homework: a balancing test where you weigh your interest against the person's rights and write down the result.

The Data (Use and Access) Act has added a new option that removes that homework for a defined set of purposes. It is called "recognised legitimate interests".[1]

What is different

The law lists a small number of pre-approved purposes that count as recognised legitimate interests.[1] [21] When your use of data genuinely falls within one of them, you do not have to carry out the usual balancing test before you proceed. The case has, in effect, already been made for you.

The pre-approved list focuses on clear public-interest situations rather than everyday marketing.[21] It is deliberately narrow. The point is to make a handful of important, well-understood uses of data quicker, not to wave through anything a business would like to do.

This matters because the balancing test, done properly, takes time and judgement. Removing it for the right cases is a genuine saving.

Where the shortcut stops

Outside the pre-approved list, nothing has changed. Ordinary legitimate interests still need the balancing test and the written record.[3] If you are not certain your purpose sits inside the recognised list, assume it does not and do the test as before.

It is also not a free pass on everything else. You still have to be fair and transparent, tell people how you use their data, and respect their rights. The new option simplifies one step; it does not switch off the rest.

What this means for you

For most small businesses, day-to-day work will not change much, because the recognised list is narrow.

The practical move is to check the ICO's list against the reasons you actually rely on.[21] If one of your uses fits, you can simplify your paperwork for it. If it does not fit, carry on with the balancing test you already use. Either way, knowing which lawful reason you rely on, and writing it down, is the habit that keeps you safe.

Sources used in this article

  • [1]Data (Use and Access) Act 2025
  • [21]ICO guidance on recognised legitimate interests, March 2026
  • [3]UK GDPR (retained EU regulation)

Source verification and SHA-256 hashes are maintained in our sources index.

Last reviewed: 7 June 2026. Next review: 23 September 2026, or sooner if relevant guidance changes.

TheDutyDesk helps you manage data protection complaints with a structured process and an audit trail.