PDPA Insights: Building Effective Privacy Governance
PDPA: Legitimate Interest Is No Longer a Shortcut
For many organizations implementing Thailand’s Personal Data Protection Act (PDPA), legitimate interest has become the preferred legal basis whenever obtaining consent appears impractical. Marketing activities, CCTV surveillance, fraud prevention, internal investigations, customer analytics, vendor due diligence, and employee monitoring are frequently justified on the basis that the organization has a legitimate business interest in processing personal data.
Yet legitimate interest is often misunderstood.
Some organizations treat it as a convenient alternative to consent, while others avoid relying on it altogether for fear that regulators may later disagree with their assessment. Both approaches overlook the purpose of legitimate interest within the PDPA.
The Personal Data Protection Committee’s recent consultation on legal bases provides an important indication of how the regulator expects organizations to approach legitimate interest. Rather than treating it as a residual category available whenever consent cannot be obtained, the consultation emphasizes a structured decision-making process requiring organizations to identify the processing purpose, assess necessity, balance competing interests, and document their reasoning. Although the consultation remains subject to revision, it reflects a broader movement toward accountability-based compliance rather than checklist compliance.
Legitimate interest is a legal analysis—not a business preference:
One of the most common misconceptions is that organizations may choose whichever legal basis they prefer.
The PDPA does not permit such flexibility.
Instead, the legal basis should reflect the actual purpose of the processing activity. Organizations should therefore begin by asking why the processing is taking place before considering whether legitimate interest is available.
For example, processing customer contact details to deliver purchased goods differs fundamentally from processing the same information to analyze purchasing behavior for future marketing campaigns. Likewise, operating CCTV to protect premises serves a different purpose from monitoring employee productivity.
Each processing activity should therefore be assessed independently.
Legitimate interest becomes relevant only after organizations have clearly identified the processing purpose and determined that no more appropriate legal basis applies.
Legitimate interest requires necessity:
The consultation suggests that organizations should demonstrate that the processing is genuinely necessary to achieve the identified purpose rather than merely convenient.
Necessity does not require the organization to prove that no alternative exists. However, it should be able to explain why the processing contributes meaningfully to the legitimate objective and why less intrusive alternatives would not achieve substantially the same result.
For example, a shopping mall operating CCTV in public areas for security purposes may reasonably conclude that surveillance is necessary to deter crime and investigate incidents. By contrast, continuous monitoring of employees in low-risk office environments may require a much more persuasive justification.
Organizations should therefore avoid assuming that every commercially useful processing activity automatically satisfies the necessity requirement.
Balancing interests requires more than common sense:
Perhaps the most significant aspect of legitimate interest is the balancing exercise.
Organizations should evaluate not only their own commercial interests but also the likely impact on individuals.
Relevant considerations may include:
- the nature of the personal data;
- the reasonable expectations of the individuals concerned;
- the relationship between the organization and the individual;
- the potential consequences of the processing;
- whether adequate safeguards have been implemented; and
- whether individuals can reasonably object to the processing.
This balancing exercise is particularly important where organizations undertake customer profiling, behavioral analytics, fraud detection, or other activities involving continuous monitoring.
Importantly, the outcome is not predetermined. Two organizations undertaking similar processing activities may legitimately reach different conclusions depending upon their operational context and safeguards.
Documentation is becoming as important as the decision itself:
One of the clearest messages emerging from the PDPC’s recent consultation is that organizations should be able to explain how they reached their legal conclusions.
Historically, many organizations simply recorded “Legitimate Interest” in their Records of Processing Activities or privacy notices without documenting the underlying reasoning.
That approach is becoming increasingly difficult to justify.
Organizations should instead maintain contemporaneous records explaining:
- the legitimate interest pursued;
- why the processing is necessary;
- how competing interests were balanced;
- what safeguards were implemented; and
- when the assessment will be reviewed.
These records not only support regulatory accountability but also improve internal governance by ensuring that legal basis assessments remain consistent across different business units.
Legitimate interest should evolve with the processing:
A legal basis assessment should not be regarded as a one-time exercise.
Business practices evolve. New technologies are introduced. AI systems become more sophisticated. Customer expectations change.
Processing that was originally assessed as proportionate may become significantly more intrusive over time.
Organizations should therefore periodically review Legitimate Interest Assessments, particularly where processing activities involve profiling, AI-assisted decision-making, large-scale analytics, or new categories of personal data.
Periodic review is consistent with the broader accountability framework underpinning the PDPA and helps ensure that legal basis assessments remain aligned with actual business practices.
Legitimate interest is ultimately about governance:
Perhaps the most important lesson emerging from the PDPC’s consultation is that legitimate interest should not be viewed primarily as a legal exception to consent.
Instead, it should be understood as a governance framework requiring organizations to demonstrate thoughtful decision-making.
Organizations that simply declare legitimate interest without documented analysis are unlikely to satisfy increasing regulatory expectations.
By contrast, organizations capable of demonstrating why processing is necessary, how competing interests were balanced, and what safeguards were implemented will be better positioned to justify their decisions if questioned by regulators or affected individuals.
The emphasis is therefore shifting from selecting a legal basis to demonstrating why that legal basis remains appropriate throughout the lifecycle of the processing activity.
Looking ahead:
As organizations increasingly deploy AI, customer analytics, fraud detection systems, behavioral advertising, and other data-driven technologies, reliance on legitimate interest is likely to become more common rather than less.
This makes governance increasingly important.
The PDPC’s consultation suggests that future enforcement may focus less on whether organizations selected legitimate interest and more on whether they can demonstrate the quality of the assessment supporting that decision.
Organizations that treat Legitimate Interest Assessments as living governance documents rather than compliance paperwork will be better prepared as Thailand’s privacy regime continues to mature.
Key takeaways:
- Legitimate interest is not an alternative chosen for convenience but a legal basis that should reflect the actual purpose of processing.
- Organizations should identify each processing activity separately before determining whether legitimate interest is appropriate.
- Necessity and balancing are substantive assessments that should be documented rather than assumed.
- Legitimate Interest Assessments should evolve alongside changes in technology, business practices, and customer expectations.
- Increasingly, regulatory scrutiny is likely to focus on the quality of governance and documentation supporting legitimate interest rather than the mere assertion that it applies.
Author: Panisa Suwanmatajarn, Managing Partner.
Related Articles in the “PDPA Insights: Building Effective Privacy Governance” Series
- PDPA: Data Breach Governance Is More Than a 72-Hour Deadline
- PDPA: PDPC Clarifies the Scope of “Health Data”
- PDPA: The PDPC Is Redefining Marketing Compliance
- PDPA: Legitimate Interest Is No Longer a Shortcut
- PDPA: ROPA Is Becoming the Organization’s Privacy Blueprint
- PDPA: The DPO Is Not Responsible for Compliance—Your Organization Is