Introduction
On Oct. 4, 2024, the Court of Justice of the European Union (the "Court") issued an important ruling on the application of the General Data Protection Regulation (AVG). This ruling provides more clarity on how organizations in the Netherlands can invoke legitimate interest as a legal basis for processing personal data, for example, in situations where explicit consent of data subjects is not possible.
The ruling emphasizes that invoking legitimate interest should not be taken lightly; organizations must thoroughly substantiate it and be able to demonstrate that the processing meets strict conditions. At the same time, the ruling provides opportunities for organizations, when all conditions are met and sufficient measures are in place, to process personal data lawfully.
A few days after the ruling, on Oct. 8, 2024, the European Data Protection Board (EDPB) published new guidelines on processing personal data based on legitimate interest. In this article, we discuss the Court's key considerations, share practical examples for correctly implementing this legal basis, and provide a five-step plan for applying legitimate interest within your organization based on the EDPB guidelines.
KNLTB v. Personal Data Authority, C-621/22
What was the case about? - legitimate interest and the sale of personal data
The proceedings before the Court revolved around a dispute between the Royal Dutch Lawn Tennis Association (KNLTB) and the Personal Data Authority (AP). The KNLTB had sold the personal data of 350,000 members, including names, addresses, telephone numbers and e-mail addresses, to sponsors, including the largest gaming provider in the Netherlands, without permission. This led to a fine from the AP for violation of the AVG, as the AP ruled that sharing this data was not allowed without explicit consent from members.
According to the AP, a legitimate interest under Article 6(1)(f) of the AVG can only be based on an interest that is explicitly defined in the law. The KNLTB disagreed. The KNLTB argued that the sale of the personal data served the interest of strengthening the relationship with its members by offering them additional benefits through partners. According to the KNLTB, this interest justified the use of legitimate interest as the legal basis for processing personal data under the AVG. Questions on this point of contention were referred to Hof, a body whose tasks include ensuring the correct and uniform application of EU law in all member states.
What did the Court rule? - commercial interest a legitimate interest under the AVG
The Court held that the AP gave too narrow an interpretation to the term "legitimate interest" in Article 6(1)(f) of the AVG. The Court clarified that commercial interests can in principle qualify as a legitimate interest, provided certain criteria are met. For example, the processing of personal data must be strictly necessary to achieve the intended purpose, and there must be no other, less intrusive way to achieve the same purpose. Moreover, the rights and freedoms of the data subjects must not outweigh the interest of the organization, taking into account the reasonable expectations of the data subjects and the nature and extent of the data processing.
Although the Court recognized the possibility of commercial interests as a legitimate interest, this does not mean that the fine imposed on the KNLTB is automatically unjustified or waived. Indeed, the Court did not rule on the specific lawfulness of the KNLTB's data processing, but merely provided clarification on the interpretation of "legitimate interest" under the AVG. It is now up to the Amsterdam Court to decide whether the interest invoked by the KNLTB can actually be considered a legitimate interest and whether the processing complied with the requirements of the AVG.
EDPB guidelines on legitimate interest as a legal basis
What do the EDPB guidelines say about legitimate interest in the AVG?
The European Data Protection Board (EDPB) published a set of guidelines four days after the Court's ruling in the KNLTB case. These guidelines provide further clarification on how organizations can apply the concept of "legitimate interest" as a legal basis for data processing. Consistent with the Court's ruling, the guidelines state that organizations must meet three cumulative conditions to properly use legitimate interest:
- Legitimate interest: there must be a legitimate interest of the controller or a third party. This interest must be concrete and not contrary to law.
- Necessity and subsidiarity of processing: the processing must be necessary to achieve the intended interest. This means that no less intrusive alternatives should be available that could achieve the same goal. The principle of minimal data processing must be observed.
- Balance of interests: the interests, rights and freedoms of data subjects must not override the interests of the data controller. Organizations must make a thorough balancing of interests that takes into account the reasonable expectations of data subjects, such as whether they could have foreseen that their data would be used for the specific purpose.
The EDPB emphasizes that legitimate interest should not be used as a "safety net" when other legal grounds, such as consent or performance of a contract, do not apply. Organizations should carefully document why this legal ground is used and be able to demonstrate that they have made the appropriate trade-offs to comply with the AVG, in order to minimize the risk of fines and other penalties.
Conducting a Legitimate Interest Assessment (LIA).
Meeting the conditions for a legitimate interest claim requires a thorough and detailed analysis, which is developed and documented in a so-called Legitimate Interest Assessment (LIA).1 In an LIA, the three conditions mentioned above are systematically assessed and recorded to substantiate the lawfulness of data processing. By conducting an LIA, organizations can:
- Assess whether the requirement for a legitimate interest claim is met.
- Identify and assess privacy risks to data subjects.
- Implement appropriate measures to mitigate risks.
Practice
Below are some practical examples showing how legitimate interest can be applied. Please note that no rights can be derived from the examples below; they are for illustrative purposes only and do not constitute legal advice. Each situation must be assessed individually, where careful balancing of interests and appropriate safeguards are essential to meet the requirements of the AVG.
Case study - digital direct marketing to existing customers
A retail chain sends emails with offers to customers who have recently made a digital purchase. This can be seen as a legitimate interest, because i) the store owner has a legitimate interest to maintain customer contact with existing customers, ii) it cannot reach its existing customers other than through the email address they have left, and iii) the impact for existing customers is low if they receive an email that they can also immediately unsubscribe from. Another factor is that customers can reasonably expect to receive such messages. However, the ability to unsubscribe must be provided in order for the processing to be AVG compliant.
Case study - camera surveillance for security
A company places security cameras at the entrance to its office to prevent theft. This may be justified because i) the company has a legitimate interest in protecting its property and the safety of employees and visitors, ii) the camera surveillance is a direct, necessary means to ensure security (there are no less intrusive alternatives available), and iii) appropriate measures have been taken, such as limiting filming to public areas and clearly informing visitors and employees about the camera surveillance. In addition, additional measures are taken to protect employee and visitor privacy, such as maintaining retention periods and restricting access to the camera system.
Case study - selling customer files in a business acquisition
In a business acquisition, the customer base is transferred to the new owner. This can be considered legitimate interest because i) the new owner has a legitimate interest in retaining the customers and continuing the business activities, ii) the transfer of the customer base is necessary to ensure continuity of services, and iii) appropriate measures have been taken to safeguard the rights of the customers, such as informing the customers in a timely manner and updating the privacy statement. In addition, customers will be given the opportunity to have their data deleted if they wish.
Roadmap for correctly conducting a Legitimate Interest Assessment
Based on the EDPB guidelines, we have developed a practical roadmap to help your organization apply legitimate interest as the legal basis for processing personal data. This roadmap leads to a documented LIA, which your organization can use to substantiate the lawfulness of its processing.
Step 1: identify the legitimate interest
The first step is to clearly define what interest your organization intends to pursue by processing personal data. This interest must not conflict with other laws, be specifically stated and actually present. Examples of legitimate interests include commercial purposes (such as direct marketing), security (e.g., camera surveillance), fraud and abuse prevention, or internal administrative purposes within a group of companies.
It is important to be able to demonstrate why this interest is justified, such as by referring to business purposes, legal obligations or scientific purposes.
Step 2: assess the necessity of the processing
In this step, the organization must assess whether the processing of personal data is necessary to serve the identified interest. Here, a distinction must be made between data that is need to have and nice to have.
Also, under the principle of minimum data processing, it must be assessed whether no less intrusive alternatives are available that could achieve the same goal.
Step 3: perform a balancing of interests
The balancing of interests is the most important and intensive step in the process of applying legitimate interest as a legal basis. Here the organization must carefully weigh the interests, rights and freedoms of data subjects against its own legitimate interest. This must take into account:
- The interests, fundamental rights and freedoms of data subjects: the potential impact of the processing on the privacy and other rights of data subjects must be identified. This includes an evaluation of potential risks and negative impacts on them.
- The impact of the processing on data subjects, including:
- The nature of the data: is sensitive or special personal data being processed, such as information about race, health or finances? The more sensitive the data, the greater the potential impact on data subjects and the stricter the consideration must be.
- The context of the processing: for example, is there an existing relationship, such as that of customer-supplier or employer-employee? A close relationship can sometimes tip the balance of interests in the organization's favor because the data subjects may be more familiar with the processing.
- Other consequences: consider any financial, emotional or other consequences the processing may have on data subjects. The more serious the consequences, the more heavily this should weigh in the consideration.
- The reasonable expectations of data subjects: can data subjects reasonably expect their data to be processed for this specific purpose?
- The final balancing of conflicting rights and interests, including the possibility of additional restrictive measures: even if the legitimate interest is strong in itself, the organization should consider measures to limit the impact on data subjects. These can range from minimizing the amount of data being processed to implementing additional security measures.
Step 4: Apply appropriate safeguards
To safeguard the rights of data subjects, organizations must take appropriate measures. These safeguards ensure that the processing of personal data is in line with the AVG and that data subjects' rights are respected. Some key safeguards are described below:
- Transparency: ensure that data subjects are clearly informed about the processing of their data. This can be done, for example, through an understandable and accessible privacy statement that explains why and how the data is processed, and what the data subjects' rights are.
- Security measures: take both technical and organizational measures to ensure the security of personal data. These include encrypting data, setting up access controls and performing regular security checks to ensure data protection.
- Possibility to object: offer data subjects the opportunity to object to the processing of their data, this is especially important for processing based on legitimate interest. Organizations are required to offer this right to data subjects and clearly communicate how they can object.
- Other data subject rights: ensure that data subjects can exercise other rights available to them under the AVG, such as the right to access, rectification, restriction of processing, data erasure (right to oblivion), and data portability. It is important that organizations establish procedures to address these rights in a timely and adequate manner.
Step 5: documentation and accountability
The AVG requires organizations to be able to demonstrate compliance with the obligations of the AVG, also known as accountability. This means that organizations must maintain detailed documentation of all steps taken to comply with the AVG. Therefore, it is essential to properly document all of the above steps:
- Record the legal analysis: document the reasons why legitimate interest was chosen as the legal basis, including the legal considerations underlying this choice. This may refer, for example, to specific business objectives or legal requirements.
- Document the balancing of interests: keep a detailed record of the balancing of interests, considering all factors, such as the nature of the data, its sensitivity, the reasonable expectations of data subjects and any measures to minimize the impact on their rights.
- Note appropriate safeguards: describe the safeguards implemented to protect data subjects' rights, such as technical security measures, transparency obligations, and opportunities for data subjects to object.
- Update the privacy notice as needed: make sure the privacy notice is current and contains all required information about the processing, legal basis and data subjects' rights.
Organizations must be able to produce this documentation to the regulator, such as the Personal Data Authority, upon request to show that the processing meets the requirements of the AVG.
Conclusion - what does legitimate interest under the AVG mean for your organization?
The ECJ ruling clarifies that commercial interests can qualify as legitimate interest under the AVG under certain circumstances, provided organizations meet strict conditions. Organizations must ensure that the processing is necessary and that the rights of data subjects are respected. Complying with the AVG means not only that organizations must follow the EDPB's guidelines, but also that they must maintain thorough documentation of the balancing of interests undertaken.
Want to know more?
Are you curious about how your organization can correctly apply legitimate interest and remain compliant with the AVG? Or are you looking for legal support in performing a Legitimate Interest Assessment? Please feel free to contact Sven van Dooren or our team via our contact form.