Skip to main content
Category: Lawful Basis for Processing

Purpose Test

Simply put

The purpose test is the first step in assessing whether an organisation can rely on the legitimate interests legal basis to process personal data under the GDPR. In this step, the organisation identifies the interest it is pursuing and considers whether that interest is genuine and legitimate. It is generally followed by further steps that weigh that interest against the rights of the individuals concerned.

Formal definition

Within the three-part legitimate interests assessment (commonly framed as the purpose, necessity, and balancing tests) used to substantiate reliance on the legitimate interests basis, the purpose test is the initial stage in which the controller identifies and articulates the specific interest pursued and evaluates whether it qualifies as a legitimate interest. Based on the evidence provided, this term is described as the first step of a GDPR three-step test verifying whether a processing activity serves a legitimate interest; the evidence does not detail the specific criteria applied, and practitioners should note that the framing of this assessment derives substantially from regulator and supervisory authority guidance rather than being set out as a discrete labelled test in the Regulation text. The precise structure and terminology can vary between EU and UK GDPR guidance and between supervisory authorities, and this definition should be verified against current official guidance.

Why it matters

The legitimate interests basis under Article 6 of the GDPR is one of six lawful bases for processing personal data, and it is often chosen precisely because it does not require consent. However, reliance on it is not automatic. The purpose test acts as the gateway to this basis: before an organisation can weigh its interests against the rights of individuals, it must first be able to identify and articulate a specific interest and confirm that it is genuine and legitimate. Getting this step wrong can undermine the entire justification for a processing activity.

Documenting the purpose test matters for accountability. Because the three-part assessment (purpose, necessity, and balancing) derives substantially from supervisory authority guidance rather than from a discrete labelled test in the Regulation text, organisations that record their reasoning are better placed to demonstrate their thinking if a regulator or affected individual later questions the basis. A vague or unstated purpose makes it difficult to run the necessity and balancing steps that generally follow, and can leave a controller unable to show why the interest justified the processing.

The framing and terminology of this assessment can vary between EU GDPR and UK GDPR guidance and between individual supervisory authorities, so readers should treat the purpose test as a widely used practical structure rather than a fixed statutory formula. The evidence available does not detail the specific criteria applied within the test, and organisations should verify the current expectations against official guidance from the relevant supervisory authority before relying on it.

Who it's relevant to

Data Protection Officers and compliance leads
DPOs and compliance teams typically oversee whether legitimate interests is an appropriate lawful basis for a given processing activity. The purpose test is where they confirm and document that a genuine, legitimate interest exists before the necessity and balancing steps are carried out, supporting the accountability expectations under the GDPR.
Privacy lawyers and advisers
Lawyers advising on lawful bases need to distinguish legitimate interests from the other Article 6 bases such as consent and contract, and to advise on how the purpose test should be framed. Because the three-part structure draws substantially on supervisory authority guidance, advisers should flag where EU and UK GDPR positions may diverge and verify against current official guidance.
Product and engineering teams
Teams designing systems and features that process personal data are often the ones who can articulate the specific interest a processing activity serves. Their input helps the organisation identify and describe the purpose clearly at the first step of the assessment, which in turn feeds the necessity and balancing analysis that generally follows.

Inside Purpose Test

Purpose Identification
The first component requires the controller to articulate the specific, legitimate interest being pursued. In the context of the legitimate interests legal basis under Article 6(1)(f) GDPR, this generally means clearly naming the interest of the controller or a third party rather than describing it in vague or overly broad terms.
Legitimacy Assessment
This element evaluates whether the identified interest is lawful and genuine. An interest that is contrary to law, or that cannot be pursued in a way that respects data protection principles, would typically fail this stage. The interest must be real and present, not speculative.
Articulation and Documentation
The purpose test is generally expected to be recorded so the controller can demonstrate accountability. This involves setting out the interest with enough clarity that it can be weighed at the later balancing stage.
Relationship to the Wider Legitimate Interests Assessment
The purpose test is typically understood as the first of a three-part legitimate interests assessment, commonly framed alongside a necessity test and a balancing test. It establishes the interest that the subsequent stages examine, and it does not by itself determine lawfulness.

Common questions

Answers to the questions practitioners most commonly ask about Purpose Test.

Is the purpose test the same as obtaining consent for legitimate interests?
No. The purpose test is the first stage of the three-part legitimate interests assessment (identifying and articulating the interest pursued), not a consent mechanism. Legitimate interests and consent are separate legal bases under Article 6, and where you rely on legitimate interests you are not seeking the data subject's agreement. Confusing the two can undermine your accountability position, because the analytical steps and the records you must keep differ. The purpose test simply asks whether there is a genuine, lawful, and sufficiently articulated interest; it does not authorise processing on its own and does not substitute for the necessity and balancing stages.
Does passing the purpose test mean the processing is lawful?
Not by itself. The purpose test is only one of three cumulative elements of the legitimate interests assessment; the necessity test and the balancing test must also be satisfied before legitimate interests can be relied on. Identifying a legitimate purpose establishes that there is an interest worth considering, but the processing can still fail at necessity or where the data subject's interests, rights, and freedoms override the interest pursued. Lawfulness is therefore context and risk dependent, and passing the purpose test should be treated as a starting point rather than a conclusion.
How specifically should we articulate the purpose when documenting the purpose test?
Generally, the purpose should be described concretely enough that a reader can understand what is being pursued and why, rather than in broad or generic terms. A purpose framed only as improving the business or security purposes typically gives too little to assess against necessity and balancing. In most cases it is advisable to state who benefits from the interest (the controller, a third party, or the wider public), the concrete outcome sought, and how the processing connects to it. This specificity supports the accountability principle and makes the later balancing stage easier to conduct and defend.
Who within an organisation should carry out and sign off the purpose test?
This depends on internal governance and is not prescribed by the Regulation text. Typically the business owner who understands the intended processing articulates the interest, while a data protection function, DPO where one is appointed, or legal reviews it for adequacy. Because the assessment forms part of the wider legitimate interests assessment and supports accountability, it is generally advisable to have clear ownership and a review step rather than leaving it to a single unreviewed author. The involvement of a DPO, where designated, should reflect their advisory role and independence.
Should the purpose test be recorded, and if so, where?
Recording the assessment is generally advisable to demonstrate compliance with the accountability principle, even though the specific documentary form is not dictated by the Regulation. Many organisations capture the purpose test as part of a documented legitimate interests assessment, and may cross-reference it in the record of processing activities and in privacy information provided to data subjects. Keeping a dated record helps show the reasoning applied at the time and supports later review. Retention and format of such records may be shaped by internal policy and any applicable national or regulator guidance, which you should verify.
When should the purpose test be revisited?
In most cases it should be reviewed whenever the processing changes materially, for example if the purpose, the categories of data, the recipients, or the context of use shift, since a change may affect both necessity and balancing. A purpose that was appropriately articulated for one activity may not cover a new or expanded use. Periodic review is also generally sensible for ongoing processing, so that the assessment continues to reflect actual practice. Where regulator guidance or case law develops, revisiting the analysis may be prudent; the appropriate cadence is a matter of risk and internal policy rather than a fixed legal interval.

Common misconceptions

Passing the purpose test means the processing is lawful under legitimate interests.
The purpose test is generally only the first stage of the assessment. Even a legitimate interest must still satisfy the necessity test and the balancing test against the rights and freedoms of the data subject before processing can rely on Article 6(1)(f). Passing one stage does not establish overall lawfulness.
The purpose test is a formal requirement stated as such in the text of the GDPR.
The three-part framing, including the label purpose test, derives largely from regulatory guidance and commentary interpreting Article 6(1)(f) rather than from an express provision using those words. Readers should verify the specific approach against current official guidance, which can vary between regulators.
The purpose test applies to any legal basis for processing.
This structured assessment is associated specifically with the legitimate interests basis. Other Article 6 bases, such as consent, contract, legal obligation, vital interests, and public task, have their own distinct conditions and are not established through a legitimate interests purpose test.

Best practices

State the interest specifically and concretely, avoiding broad or generic descriptions such as improving the business, so that it can be meaningfully assessed at the balancing stage.
Document the purpose test contemporaneously to support accountability, retaining a record of the interest identified and why it is considered legitimate.
Treat the purpose test as only the opening stage and proceed to complete the necessity and balancing stages before concluding that legitimate interests is available.
Confirm the interest is genuine and present rather than speculative, and check that pursuing it does not conflict with applicable law or data protection principles.
Consult current regulatory guidance for the relevant jurisdiction, noting that the framing and expectations may differ between EU regulators and under the UK GDPR.
Revisit the purpose test where the processing activity or its context changes, since the underlying interest and its assessment can shift over time.