Recognised Legitimate Interest under the Data (Use and Access) Act: A narrow Lawful Basis for Public Interest Scenarios
Introduction
Recognised legitimate interest is a new lawful basis introduced by the Data (Use and Access) Act 2025, designed for specific public‑interest scenarios – not an exemption from GDPR obligations (i.e., not a shortcut).
It is a distinct lawful basis, separate from the existing legitimate interest basis.
The ICO has published detailed guidance [1] on the new lawful basis of recognised legitimate interest, introduced by the Data (Use and Access) Act 2025 [2].
The ICO’s guidance positions recognised legitimate interest as a helpful, but tightly limited, lawful basis designed for specific public‑interest scenarios where the law has already struck the balance between organisational needs and individuals’ rights.
It offers clarity, not a shortcut. Organisations must still demonstrate necessity, proportionality and full compliance with all UK data protection principles.
This basis allows organisations to process personal data for a small number of specific, pre‑defined activities that the ICO considers to be in the public interest.
As stated above, the ICO emphasises that this basis operates separately from the existing “legitimate interests” basis and still requires organisations to meet the core principles of lawfulness, fairness and transparency.
Recognised Legitimate Interest vs Legitimate Interest
In its guidance, the ICO explains that recognised legitimate interest sits alongside, rather than replaces, legitimate interests.
Legitimate interests remain broad in scope but requires organisations to carry out the familiar three‑part balancing test (the Legitimate Interest Assessment).
Recognised legitimate interest is far narrower. It can only be used where one of the five conditions in Annex 1 of the Data (Use and Access) Act 2025 applies [3]. If one of these conditions’ fit, the ICO states that organisations do not need to complete a balancing test, as the law has already determined that the balance is appropriate against people’s rights interests and freedoms.
The five conditions are:
- Public task disclosure response
- National security, public security and defence
- Emergencies
- Crime
- Safeguarding
The ICO guidance notes that more than one condition may apply if the organisation meets the requirements for each and records its decision. It may also cover processing involving children’s data, and in principle can apply to special category and criminal offence data, provided all other relevant UK GDPR conditions are met.
Public Task Disclosure Response Condition
According to the ICO guidance, the public task disclosure response condition applies only when:
- Another organisation asks for personal data;
- They confirm the request relates to a public task set out in law; and
- Sharing the data is necessary to respond.
The ICO states that if legal obligation is available as the lawful basis, organisations should rely on that instead. Where the request is lawful but not mandatory, this condition may be used, and organisations may still choose not to share.
If the request is accepted, the ICO stresses the need to ensure the sharing is necessary, proportionate, limited to the minimum data required, and supported by appropriate checks on the requester. This basis covers the disclosure only and any further processing requires a separate lawful basis.
National Security, Public Security and Defence Condition
The ICO explains that the national security, public security and defence condition applies where using personal data is necessary to protect national security, public security or defence. Although these terms are not defined in the UK GDPR, the ICO describes them broadly as protecting the UK, its people, institutions and armed forces from threats such as terrorism, crime or major safety risks.
The ICO guidance also notes that this condition is likely to be used more by private organisations supporting security‑related activity, as public authorities often rely on public task, legal obligation as their legal basis, or the law enforcement/intelligence frameworks. Organisations must be able to show that the processing is reasonable, proportionate and the least intrusive available option.
Emergency Condition
Under the ICO guidance, this condition applies only when the situation meets the definition of an “emergency” in Part 2 of the Civil Contingencies Act 2004 [4]. This includes significant events posing serious harm to human welfare, the environment or national security. For example, this condition could include events such as major accidents, pandemics, severe weather, terrorist incidents or large‑scale disruption to essential services.
The ICO is clear that not every urgent issue qualifies; everyday incidents such as medical events at work or data breaches do not meet the statutory threshold.
If an emergency does exist, organisations may process personal data in a targeted and proportionate way for the duration of the emergency. When the situation stabilises, the ICO states that organisations must switch to another lawful basis if ongoing processing is required.
Crime Condition
The ICO guidance states that this condition applies when processing is necessary for:
- detecting, investigating or preventing crime; or
- apprehending or prosecuting offenders.
It covers activities such as fraud prevention, responding to police requests or sharing CCTV footage linked to suspected criminal activity. Public authorities and regulated bodies usually rely on public task or legal obligation as their lawful basis, and police generally use the law enforcement regime rather than this basis.
As with any use of criminal offence data, relevant Article 10 and Schedule 1 of UK GDPR conditions [5] must also be met, and processing must be limited to the minimum necessary.
Safeguarding Condition
The ICO defines a vulnerable person as a child under 18 or an adult who is at risk, requires care or support, is experiencing or at risk of harm, and cannot protect themselves. The safeguarding condition applies where using personal data is necessary to safeguard that person or group.
The ICO stresses the need for an objective assessment of vulnerability and appropriate records. If circumstances later change, such as when a child reaches adulthood, the organisation must reassess whether recognised legitimate interest still applies and, if not, identify another lawful basis.
Other Considerations
The ICO guidance makes clear that recognised legitimate interest does not reduce an organisation’s wider data protection responsibilities. The usual principles still apply, including fairness, transparency, data minimisation, purpose limitation and security. Individuals also retain the right to object.
Organisations must tell people when they rely on recognised legitimate interest and identify the specific condition used. While updates to privacy information may not be possible in fast‑moving scenarios such as emergencies, the ICO encourages preparing template notices in advance.
If the purpose of processing later changes, it can continue only if the new purpose is compatible and supported by its own lawful basis as stated in Annex 2 of Data (Use and Access) Act 2025 [6].
Please contact Jose Saras for detailed advice on the above
The material contained in this article is only for general review of the topics covered and does not constitute any legal advice. No legal or business decision should be based on its content.
This article is written in the English language. Preiskel & Co LLP is not responsible for any translation of all or part of its content into any language.
[1] ICO – Recognised Legitimate Interest
[2] Data (Use and Access) Act 2025
[3] Annex 1 Data (Use and Access) Act 2025