skip to content

Under GDPR Art. 6(1)(f), how does a bank justify fraud-screening card payments on legitimate interests, and what must it record?

level: middleimportance: must knowfreq 60%

answer

  1. three cumulative conditions
  2. interest, necessity, balance
  3. reasonable expectations
  4. Recital 47 names fraud prevention

basics

~20 s

Under GDPR Art. 6(1)(f), the bank must show a legitimate interest (Recital 47 names fraud prevention), that the screening is necessary for it, and that customers' interests and rights do not override it, and document that assessment before screening starts.

solid answer

~50 s

Under GDPR `Art. 6(1)(f)`, processing is lawful when *necessary for the legitimate interests* of the controller or a third party, *except where* the data subject's interests or fundamental rights override them. EDPB draft Guidelines 1/2024 break this into **three cumulative conditions**: a **legitimate interest** that is lawful and precisely articulated, **necessity**, meaning the data processed are needed for that interest and no less intrusive means would do, and a **balancing test** in which the customer's interests, rights and reasonable expectations do not take precedence. Recital 47 says processing *strictly necessary* for preventing fraud constitutes a legitimate interest, which helps with step one but does not settle steps two and three. The bank should record a **legitimate interests assessment** covering the specific fraud types, the data used, retention, safeguards and the balancing outcome, disclose the interest in its notice (`Art. 13(1)(d)`), and be ready for objections under `Art. 21(1)`.

go deeper

for a junior

Recall that legitimate interests is one of six bases and that Recital 47 names fraud prevention as a legitimate interest, subject to conditions.

for a middle

Walk through the three cumulative steps (interest, necessity, balancing) and apply each to fraud screening, naming what the LIA records.

for a senior

Show where the test fails in practice: vague interests, excess data, missing retention limits, and no route for Art. 21(1) objections.

for a principal

Own the rule that a legitimate interests assessment is written before launch and revisited when the model's data inputs change.

## The text `Art. 6(1)(f)` of the GDPR makes processing lawful where it is *necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child*. Public authorities cannot use it for processing in the performance of their tasks. Recital 47 adds context used in every assessment: - a legitimate interest needs **careful assessment**, including whether the data subject can **reasonably expect**, at the time and in the context of collection, that processing for that purpose may take place; - the data subject's interests could in particular override where people **do not reasonably expect** the processing; - *the processing of personal data strictly necessary for the purposes of preventing fraud also constitutes a legitimate interest of the data controller concerned*. ## The three-step test EDPB Guidelines 1/2024 on legitimate interests (adopted 8 October 2024 as a **version for public consultation**, so draft regulator guidance) structure the assessment as three cumulative conditions: 1. **A legitimate interest.** The interest must be lawful, precisely articulated and real and present, not speculative. "Preventing card-payment fraud against our customers and the bank" is specific; the draft warns that a generic reference to "combating fraud" is not sufficient for the transparency and documentation obligations (para. 106). 2. **Necessity.** The processing must be needed for that interest, and the interest must not be reasonably achievable by less intrusive means. This is where data minimisation (`Art. 5(1)(c)`) bites: which transaction fields, device signals and history does the model actually need? 3. **Balancing.** The interest must not be overridden by the data subject's interests or rights, weighing the impact on them, their reasonable expectations and the safeguards in place. The draft says the assessment should be **documented** and **done before** the processing starts. ## Applying it to card-payment fraud screening | Step | What the bank shows | |---|---| | Interest | Preventing specific fraud types, such as stolen-card use and account takeover; Recital 47 supports it and customers also benefit | | Necessity | Each data item used has a stated role in detection; retention is limited (`Art. 5(1)(e)`); cruder or less intrusive means would not work | | Balancing | Customers reasonably expect a bank to screen payments; safeguards such as access control, limited retention and human review of blocks reduce impact | The EDPB draft adds points specific to fraud (paras. 100-105): Recital 47 does not make every fraud-related processing automatically lawful; the fraud targeted should be of **substantial importance**; controllers should be **specific** about the type of fraud and the data really needed; and storage limitation applies to fraud data. ## Other bases that may apply Legitimate interests is not the only candidate: - **Legal obligation (`Art. 6(1)(c)`)** where applicable law specifically requires the bank to perform certain checks; the EDPB draft (para. 107) says that basis is then the appropriate one, and EDPB Guidelines 2/2019 (para. 50) also mention it. - **Contract (`Art. 6(1)(b)`)** is generally *not* suitable: the same para. 50 says fraud-prevention monitoring and profiling is likely to go beyond what is objectively necessary for the contract. Each purpose gets the basis that actually fits it. ## What the bank must record and disclose A **legitimate interests assessment (LIA)** is the usual name for the documented test. It should contain: - the precisely stated interest and the fraud types in scope; - the data categories used and why each is needed; - alternatives considered and why they were insufficient; - the balancing: impact on customers, their expectations, safeguards, and the outcome; - retention periods and review dates. Around it, the GDPR requires: - disclosure of the legal basis and of the **legitimate interests pursued** at collection (`Art. 13(1)(c)` and `(d)`); - the ability to demonstrate compliance (`Art. 5(2)`); - handling of **objections**: under `Art. 21(1)` a data subject may object to processing based on (f), and the controller must stop unless it demonstrates compelling legitimate grounds that override the data subject's interests, or needs the data for legal claims. ## Common mistakes - Treating Recital 47 as a blanket licence for any fraud-related processing. - Writing the LIA after the system is live. - Stating the interest so broadly that necessity cannot be tested. - Forgetting that an automated block on a card can also raise questions about automated decision-making, which is a separate subject.

  • Under GDPR Art. 21(1), what happens when a customer objects to fraud screening based on legitimate interests?
    The controller must stop that processing unless it demonstrates compelling legitimate grounds that override the customer's interests, rights and freedoms, or needs the data for establishing, exercising or defending legal claims. For well-scoped fraud screening a bank may be able to show compelling grounds, but it has to demonstrate them for that customer's situation rather than simply refuse.
  • Under the GDPR, why is contract necessity usually the wrong basis for fraud screening?
    EDPB Guidelines 2/2019 (para. 50) say fraud-prevention monitoring and profiling is likely to go beyond what is objectively necessary to perform the contract with the customer. They point instead to legitimate interests, for processing strictly necessary to prevent fraud, and to legal obligation where law requires the checks.
  • Under GDPR Recital 47, what role do the data subject's reasonable expectations play?
    They feed the balancing step. Recital 47 says the assessment must consider whether the person can reasonably expect, at the time and in the context of collection, that processing for that purpose may take place, and that their interests can override the controller's where they do not. Bank customers generally expect payment screening; they would not expect the same data reused for unrelated profiling.

saying these in an interview costs you the question

  • Recital 47 makes any fraud-related processing automatically lawful.
  • Legitimate interests needs no documentation because nothing is signed.
  • Fraud screening is necessary for the card contract, so Art. 6(1)(b) covers it.
  • Once legitimate interests is chosen, customers have no right to object.
  • The legitimate interests assessment can be written after the system goes live.