← Back to context

Comment by freehorse

2 days ago

If it is based on legitimate interest, under gdpr you don't.

Legitimate interest of the user, not yours. Rule of thumb, if its not a legal requirement, you need consent.

  • That’s not true. From the law as written:

    > legitimate interests pursued by the controller or by a third party

    There are six lawful bases for processing, consent is only one of them.