5 | The new recognised legitimate interests lawful basis

By Jon Bartley and Kiran Dhoot

What is happening?

The Data (Use and Access) Act 2025 (DUAA) introduced the new lawful basis “recognised legitimate interests” (RLI). In summary, organisations can now use RLI to handle and share personal data with greater confidence and less administrative burden in certain specific situations. Annex 1 of the UK GDPR identifies the following 5 RLIs:

  • public task disclosure
  • national security/defence
  • emergencies
  • crime
  • safeguarding.

RLI is intended to reduce compliance burden and provide greater certainty where businesses process personal data for defined public interest purposes. Businesses no longer need to carry out the usual legitimate interests balancing test. However, the new concept is not a blanket permission. Businesses must still be able to show the processing, or disclosure, is necessary for the relevant purpose and comply with wider UK GDPR obligations.

How might it impact professional and financial services firms?

Requests for personal data

Professional and financial services firms stand to benefit from the new RLI, in particular when responding to requests from regulators for personal data.

An accounting firm may, for example, receive a request for personal data from a third-party organisation such as HMRC or the Serious Fraud Office (SFO). The requesting body may assert that it requires the information although there is no clear legal obligation on the firm to make the disclosure, such as under a court order. In those circumstances, the firm may nonetheless be able to disclose the relevant personal data under the public task disclosure RLI, provided the requesting organisation confirms that the data is required for a public task laid down by UK law (or relevant international law).

However, RLI is not a green light to disclose everything that is requested. Criminal offence and special category personal data still needs a relevant condition to justify disclosure. Further, even if an RLI is identified, businesses still need to be comfortable that the processing (or disclosure) is:

  • necessary for that purpose, rather than just helpful
  • limited in scope, meaning “whole file” disclosures should not be made unless clearly necessary for the RLI
  • transparent such as through updating privacy notices so data subjects know what lawful basis applies, unless there is an applicable exemption to this requirement, and
  • documented to comply with the principle of accountability.

In regulated sectors, there are typically other obligations in play and care should be taken to ensure that the RLI does not conflict with these, such as legal professional privilege.

Firms may also stand to benefit similarly from the crime RLI when responding to requests from law enforcement.

Compatible purposes

Businesses must generally carry out a compatibility assessment before reusing personal data for a new purpose, to determine whether the new purpose is compatible with the original one for which the data was collected. This usually involves a complex assessment weighing a number of factors.

DUAA also introduces a new Article 8A, which removes the need for that compatibility assessment where the further processing is necessary for a purpose listed in the new Annex 2 to the UK GDPR and is therefore deemed compatible. These purposes overlap with the RLIs, including where the processing necessary for: (i) responding to disclosure requests made in connection with tasks carried out in the public interest; and (ii) detecting or preventing crime. In those circumstances, no separate compatibility assessment is required.

What actions should you consider?

Businesses should review existing processing activities to identify where they currently rely on legitimate interests and consider whether any could fall within the new RLI framework.

In particular, they should consider:

  • mapping RLI to key workflows – create a short inventory of routine and time-sensitive processing disclosure activities to identify where the RLI conditions are most likely to apply
  • updating external notices and internal policies – this is to ensure operational reality matches the transparency information provided in privacy notices and any internal request-handling procedures. Where practical it may be helpful to draft or update playbooks addressing how to respond to requests.

For professional and financial services firms, RLI provides an opportunity to simplify decision-making around disclosures and investigations whilst maintaining compliance with data protection obligations.

Jon Bartley

Partner

Profile

Cavan Fabris

Partner, Head of Data & Cyber

Profile
Return to top