Skip to content
Privacy and law

What is Legitimate interest?

Legitimate interest is one of six lawful bases for processing personal data under the GDPR. It permits processing necessary for interests of the controller or a third party, provided those interests are not overridden by the individual's rights. It requires a documented balancing test, and it does not exempt anything from the separate ePrivacy consent requirement.

Explanatory, not legal advice. A balancing assessment is specific to your processing and should be reviewed by someone qualified.

The three-part test

A legitimate interests assessment has to answer all three, in writing, before the processing starts:

  1. Purpose — is there a real, articulable interest? “Understanding which pages our audience reads” qualifies. “It might be useful later” does not.
  2. Necessity — is the processing actually needed for that purpose, and is there no less intrusive way to achieve it? If aggregate counts would answer the question, per-person tracking is not necessary.
  3. Balancing — do the individual’s rights and reasonable expectations override the interest? Visitors do not expect to be profiled across sites; they may reasonably expect a site to count its own traffic.

Necessity is where most analytics arguments fail. It is hard to argue a durable cross-visit identifier is necessary to know how many people read an article.

The mistake that matters

Legitimate interest is frequently offered as the reason a site needs no cookie banner. It is not, and the two rules operate independently:

GovernsLegitimate interest helps?
GDPRProcessing personal dataYes — it can be the lawful basis
ePrivacy / PECRStoring or reading data on a deviceNo — that rule requires consent

So a site can have a perfectly sound legitimate interests assessment for its analytics processing and still be required to show a banner, because it sets a cookie. The lawful basis and the storage permission are separate questions.

When it becomes straightforward

If nothing is stored on the device, the ePrivacy trigger never fires. And if no personal data is processed, there is nothing for a lawful basis to apply to. Both questions dissolve rather than being answered — which is a more comfortable position than winning either argument.

Questions

Frequently asked.

Cookies, install and pricing, answered. Still stuck? Ask us anything .

01 Can sonex show revenue next to my traffic?

Yes. Connect Stripe or Polar with a read-only key and sonex reads revenue straight from your payment provider, per website. Revenue then appears as a focusable series on the Overview chart and as its own report, beside the traffic that earned it. No tracked event is needed for it to work.

02 Does sonex use cookies?

No. sonex sets no cookies and needs no consent banner. It counts visits without cookies, fingerprinting, or any personal data, so it is GDPR, PECR and CCPA-ready by default.

03 How do I install sonex?

Add one script tag to your site's <head> with your website id. It is a single lightweight tracker — no build step and no SDK required.

04 Is sonex a Google Analytics alternative?

Yes. sonex gives you the reports that matter — visitors, pages, referrers, funnels, revenue and a world map — without surveilling your audience or drowning you in configuration.

05 How is sonex priced?

By monthly tracked events. Free covers 2k events, Pro is $20/mo for 200k events, and Business is $200/mo for 2M events with team seats.

See what your traffic actually earns.

Revenue beside the visitors that produced it. No cookies, no credit card, no consent banner.

Get started