Compelling Legitimate Grounds
Compelling legitimate grounds are the strong reasons an organisation may need to show in order to keep processing someone's personal data after that person has objected to the processing. If the organisation can demonstrate these grounds outweigh the individual's interests, rights and freedoms, it may generally continue the processing despite the objection. This term arises in the context of the right to object and is not precisely defined in the GDPR itself.
"Compelling legitimate grounds" is a threshold referenced in the right to object (Article 21 GDPR / UK GDPR) where personal data is processed on the basis of legitimate interests (or the public task basis). Where a data subject exercises the right to object, the controller must cease processing unless it can demonstrate either compelling legitimate grounds for the processing that override the interests, rights and freedoms of the data subject, or that the processing is for the establishment, exercise or defence of legal claims. The notion is not defined in the GDPR; per the EDPB Guidelines 1/2024 and ICO guidance, it is understood from the wording of Article 21 as requiring a strong justification that is assessed on the facts of each case, and the burden of demonstrating such grounds rests on the controller. It should be distinguished from the balancing test conducted when initially relying on legitimate interests under Article 6(1)(f): here the controller must actively demonstrate grounds that override the objecting individual, rather than the individual having to show their interests prevail. The precise content of what qualifies remains subject to assessment and evolving guidance, and readers should verify the current position against the official text and applicable regulator guidance, noting possible divergence between EU and UK approaches.
Why it matters
The right to object under Article 21 GDPR / UK GDPR shifts the burden of justification onto the organisation in a way that many other rights do not. When an individual objects to processing based on legitimate interests or the public task basis, the default position is that the controller must stop. Processing may generally continue only where the controller can actively demonstrate compelling legitimate grounds that override the individual's interests, rights and freedoms, or that the processing is for the establishment, exercise or defence of legal claims. Getting this threshold wrong exposes an organisation to a rights infringement, because continuing to process without a defensible justification can amount to unlawful processing.
The practical significance lies in the reversal of the balancing exercise. When first relying on legitimate interests under Article 6(1)(f), the balance is assessed at the outset. Once a valid objection is received, the controller must go further and show a strong justification that outweighs the specific objecting individual, taking account of their particular circumstances. This is a higher bar than the initial legitimate interests assessment, and the EDPB and ICO both make clear that the notion is not defined in the GDPR and must be assessed on the facts of each case. Organisations that treat an objection as a routine formality, or that rely on the same generic justification used at the outset, risk being unable to meet this threshold if challenged.
Because the content of what qualifies as compelling remains subject to assessment and evolving guidance, and because EU and UK approaches may diverge, organisations should document their reasoning carefully and verify the current position against the official text and applicable regulator guidance rather than assuming a fixed answer.
Who it's relevant to
Inside Compelling Legitimate Grounds
Common questions
Answers to the questions practitioners most commonly ask about Compelling Legitimate Grounds.