Purpose Test
The purpose test is the first step in assessing whether an organisation can rely on the legitimate interests legal basis to process personal data under the GDPR. In this step, the organisation identifies the interest it is pursuing and considers whether that interest is genuine and legitimate. It is generally followed by further steps that weigh that interest against the rights of the individuals concerned.
Within the three-part legitimate interests assessment (commonly framed as the purpose, necessity, and balancing tests) used to substantiate reliance on the legitimate interests basis, the purpose test is the initial stage in which the controller identifies and articulates the specific interest pursued and evaluates whether it qualifies as a legitimate interest. Based on the evidence provided, this term is described as the first step of a GDPR three-step test verifying whether a processing activity serves a legitimate interest; the evidence does not detail the specific criteria applied, and practitioners should note that the framing of this assessment derives substantially from regulator and supervisory authority guidance rather than being set out as a discrete labelled test in the Regulation text. The precise structure and terminology can vary between EU and UK GDPR guidance and between supervisory authorities, and this definition should be verified against current official guidance.
Why it matters
The legitimate interests basis under Article 6 of the GDPR is one of six lawful bases for processing personal data, and it is often chosen precisely because it does not require consent. However, reliance on it is not automatic. The purpose test acts as the gateway to this basis: before an organisation can weigh its interests against the rights of individuals, it must first be able to identify and articulate a specific interest and confirm that it is genuine and legitimate. Getting this step wrong can undermine the entire justification for a processing activity.
Documenting the purpose test matters for accountability. Because the three-part assessment (purpose, necessity, and balancing) derives substantially from supervisory authority guidance rather than from a discrete labelled test in the Regulation text, organisations that record their reasoning are better placed to demonstrate their thinking if a regulator or affected individual later questions the basis. A vague or unstated purpose makes it difficult to run the necessity and balancing steps that generally follow, and can leave a controller unable to show why the interest justified the processing.
The framing and terminology of this assessment can vary between EU GDPR and UK GDPR guidance and between individual supervisory authorities, so readers should treat the purpose test as a widely used practical structure rather than a fixed statutory formula. The evidence available does not detail the specific criteria applied within the test, and organisations should verify the current expectations against official guidance from the relevant supervisory authority before relying on it.
Who it's relevant to
Inside Purpose Test
Common questions
Answers to the questions practitioners most commonly ask about Purpose Test.