New ICO Guidance on Recognised Legitimate Interests

ICO on Mobile

The Information Commissioner’s Office (ICO) has issued new guidance explaining how organisations can use the recently introduced Recognised Legitimate Interests (RLI) as a lawful basis for processing personal data under the UK GDPR. RLI was created by the Data (Use and Access) Act 2025 and applies only to a defined set of public‑interest purposes listed in Annex 1 of the UK GDPR.

A key clarification from the ICO is that organisations relying on RLI do not need to complete a Legitimate Interests Assessment (LIA). This exemption, however, does not remove the broader compliance duties that apply to all processing activities. Organisations must still demonstrate that the processing is necessary, proportionate, transparent, and supported by appropriate governance records.

When RLI Can Be Used

RLI may be relied upon when processing is necessary for one of the following recognised purposes:

  • Preventing, detecting, or investigating crime
  • Protecting national security, public security, or defence
  • Responding to emergencies
  • Safeguarding children or vulnerable individuals
  • Sharing data with bodies carrying out public or official functions, where disclosure is requested

If a processing activity fits within one of these categories, organisations do not need to balance their interests against the rights and freedoms of individuals. They must still be able to justify why the processing is necessary and ensure that only relevant data is used.

Ongoing Compliance Expectations

Even where RLI applies, organisations must continue to meet core UK GDPR requirements, including:

  • Identifying and documenting the specific RLI condition being used
  • Maintaining clear accountability and governance records
  • Providing individuals with transparent information about the processing
  • Applying data minimisation and appropriate retention periods

The ICO emphasises that RLI cannot be used as a shortcut to avoid an LIA. Using RLI incorrectly may still result in regulatory action.

Immediate Actions for Organisations

  • Review processing activities currently based on legitimate interests to determine whether RLI is more appropriate
  • Update Records of Processing Activities where the lawful basis changes
  • Amend privacy notices to reflect reliance on RLI
  • Ensure teams involved in safeguarding or data sharing understand the new basis

Longer‑Term Considerations

  • Integrate RLI into internal data protection policies and templates
  • Monitor future ICO updates, particularly if more recognised purposes are added
  • Provide ongoing training to help staff distinguish between legitimate interests and RLI

 

If you need support assessing whether RLI applies to your processing or updating your governance framework, Hope and May can assist.

Website Asset

Get in touch

Login / Register
If you would like to manage your Organisations access to our courses and invite members via group code.

If you want to take courses as an individual.