Legitimate interests is one of the GDPR's six lawful bases. It is the most commonly used, as it is the most widely applicable and flexible of the lawful bases. Legitimate interests applies when personal data is used in a way that people would reasonably expect, and when there is little to no risk of privacy infringement with the processing.