GDPR consent vs legitimate interest: pick the lawful basis you can defend
Article 6 is not a menu of convenience. Consent and legitimate interest have different tests, different UX, and different failure modes.

The GDPR requires a lawful basis before you process personal data. Marketing teams sometimes treat “consent” and “legitimate interest” as interchangeable. Supervisory authorities do not.
Consent under Article 4(11) must be freely given, specific, informed, and unambiguous. Pre-ticked boxes, bundled purposes, and “take it or leave it” cookie walls fail that test. Legitimate interest under Article 6(1)(f) requires a balancing test, documentation, and a real opt-out where the interest is not compelling.
Cookies, ads, and ePrivacy
For non-essential cookies and similar tracking technologies, the ePrivacy Directive (as implemented in Member States) generally pushes you toward prior consent. Legitimate interest is rarely a clean fit for third-party advertising cookies.
A consent manager should map each purpose to an explicit lawful basis so the banner, the preference center, and the vendor contracts tell the same story.
Operational takeaway
If you cannot explain the balancing test in writing, do not claim legitimate interest. If you cannot honor a withdrawal instantly, do not claim GDPR consent. Your CMP is the control plane that makes those claims true at runtime.
Educational overview only — not legal advice. Confirm requirements with counsel for your products and markets.


