Legitimate Interests Under the GDPR and International Human Rights Law: A Proportionality Critique
DOI:
https://doi.org/10.22437/jfbbec84Keywords:
legitimate interests, informational self-determination, proportionality, data colonialism, global south.Abstract
Background: The concept of legitimate interests as a basis for the lawful processing of personal data occupies a unique and vulnerable position in international data protection law. The GDPR formally adopts this concept under Article 6(1)(f); however, its operationalization raises fundamental questions regarding the adequacy of the doctrine of proportionality in protecting informational self-determination as a human right under Article 17 of the ICCPR and regional human rights instruments. Methodology: This article employs a normative juridical method integrating international human rights law analysis, the doctrine of proportionality, comparative legal analysis, and doctrinal analysis of judicial decisions. Purpose: This study critically examines whether the formal proportionality model underlying the legitimate interests framework in the GDPR can protect fundamental rights under conditions of radical informational asymmetry, surveillance capitalism, and data colonialism that characterize the global digital economy. Findings: The analysis shows that the GDPR proportionality model, although sophisticated, contains structural weaknesses when applied to diverse socio-economic contexts. The proposed framework consists of a mandatory three-step test, a Legitimate Interests Assessment (LIA), an anti-catch-all doctrine, and an allocation of the burden of proof based on international human rights law. Originality/Novelty: This article advances three arguments: first, the normative uncertainty of the GDPR legitimate interests clause challenges its adequacy as an international model; second, the transplantation of a proportionality-based balancing model without adequate institutional prerequisites risks creating accountability gaps; third, in the context of surveillance capitalism as data colonialism, a rights-first proportionality framework is required.
References
Alexy, Robert. A Theory of Constitutional Rights. Oxford University Press, 2002.
Article 29 Data Protection Working Party. Opinion 06/2014 on the Notion of Legitimate Interests of the Data Controller under Article 7 of Directive 95/46/EC (WP217). Brussels: European Commission, 2014. https://ec.europa.eu/justice/article-29/documentation/opinion-recommendation/files/2014/wp217_en.pdf.
Barak, Aharon. Proportionality: Constitutional Rights and Their Limitations. 1st ed. Cambridge Studies in Constitutional Law. Cambridge, U.K. ; New York: Cambridge University Press, 2012. https://doi.org/10.1017/CBO9781139035293.
Bundesverband Der Verbraucherzentralen Und Verbraucherverbände v. Planet49 GmbH (October 1, 2019). https://curia.europa.eu/juris/liste.jsf?num=C-673/17.
Cavoukian, Ann. Privacy by Design: The 7 Foundational Principles. Information and Privacy Commissioner of Ontario, 2009.
Couldry, Nick, and Ulises A. Mejias. The Costs of Connection: How Data Is Colonizing Human Life and Appropriating It for Capitalism. Culture and Economic Life. Stanford, California: Stanford University Press, 2019. https://doi.org/10.1515/9781503609754.
Data Protection Commissioner v. Facebook Ireland Ltd and Maximillian Schrems (Schrems II) (July 16, 2020). https://curia.europa.eu/juris/liste.jsf?num=C-311/18.
De Hert, Paul, and Vagelis Papakonstantinou. “The Proposed Data Protection Regulation Replacing Directive 95/46/EC: A Sound System for the Protection of Individuals.” Computer Law & Security Review 28, no. 2 (April 2012): 130–42. https://doi.org/10.1016/j.clsr.2012.01.011.
European Data Protection Board. Binding Decision 01/2023 on the Dispute Submitted by the Irish Supervisory Authority Regarding Meta Platforms Ireland Limited (Facebook). European Data Protection Board, 2023. https://www.edpb.europa.eu/our-work-tools/consistency-findings/binding-decisions_en.
———. Guidelines 06/2020 on the Interplay of the Second Payment Services Directive and the GDPR. Brussels: European Data Protection Board, 2020. https://www.edpb.europa.eu/our-work-tools/our-documents/guidelines/guidelines-062020-interplay-second-payment-services_en.
European Data Protection Board (EDPB). Guidelines 06/2020 on the Interplay of the Second Payment Services Directive and the GDPR; See Also EDPB Recommendations on Legitimate Interests. EDPB, 2020.
Floridi, Luciano. “Open Data, Data Protection, and Group Privacy.” Philosophy & Technology 27, no. 1 (March 2014): 1–3. https://doi.org/10.1007/s13347-014-0157-8.
Fuller, Lon L. The Morality of Law. Yale University Press, 1964.
Google Spain SL and Google Inc. v Agencia Española de Protección de Datos (AEPD), Case C-131/12 (2014).
Greenleaf, G. “The Influence of European Data Privacy Standards Outside Europe: Implications for Globalization of Convention 108.” International Data Privacy Law 2, no. 2 (May 2012): 68–92. https://doi.org/10.1093/idpl/ips006.
Hart, H. L. A. The Concept of Law. Oxford University Press, 1961.
Indonesian 1945 Constitution.
Kumm, Mattias. Political Liberalism and the Structure of Rights: On the Place and Limits of the Proportionality Requirement. 2007.
Kuner, Christopher. “The European Commission’s Proposed Data Protection Regulation: A Copernican Revolution in European Data Protection Law.” Bloomberg BNA Privacy and Security Law Report (2012) February 6, no. 2012 (2012): 1–15.
Kusniati, Retno. “Free, Prior, and Informed Consent Principles as Indigenous Peoples’ Right: Soft Law or Hard Law?” Jambe Law Journal 7, no. 1 (July 2024): 169–93. https://doi.org/10.22437/home.v7i1.350.
Law Number 27 of 2022 on Personal Data Protection (2022). https://peraturan.bpk.go.id/Home/Details/229798/uu-no-27-tahun-2022.
Lynskey, Orla. The Foundations of EU Data Protection Law. Oxford Studies in European Law. Oxford, GB: Oxford University Press, 2015.
Ministry of Communication and Informatics of the Republic of Indonesia. Report on Data Breach Incidents and Failures in Electronic System Protection for 2024. Ministry of Communication and Informatics of the Republic of Indonesia, 2025.
Möller, Kai. The Global Model of Constitutional Rights. Oxford University Press, 2012.
Natamiharja, Rudi, Febryani Sabatira, Muhammad Fakih, Orima Melati Davey, and Haidir Anam. “Patient Rights During the Covid-19 Pandemic: The Dilemma between Data Privacy and Transparency in Indonesia.” The Age of Human Rights Journal, no. 19 (December 2022): 121–36. https://doi.org/10.17561/tahrj.v19.7004.
Nissenbaum, Helen. “Privacy in Context: Technology, Policy, and the Integrity of Social Life.” In Privacy in Context. Stanford University Press, 2009.
Pavlakos, George, and Robert Alexy, eds. Law, Rights and Discourse: The Legal Philosophy of Robert Alexy. Oxford ; Portland, Or: Hart Pub, 2007.
Purtova, Nadezhda. “The Law of Everything. Broad Concept of Personal Data and Future of EU Data Protection Law.” Law, Innovation and Technology 10, no. 1 (January 2018): 40–81. https://doi.org/10.1080/17579961.2018.1452176.
Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data, and Repealing Directive 95/46/EC (General Data Protection Regulation), L119 Official Journal of the European Union 1 (2016). https://eur-lex.europa.eu/eli/reg/2016/679/oj.
Rosadi, Sinta Dewi. Pembahasan UU Pelindungan Data Pribadi (UU RI No. 27 Tahun 2022). Sinar Grafika, 2023.
Rubinstein, Ira. “Regulating Privacy by Design.” Berkeley Technology Law Journal 26 (2012): 1409.
Rudy, Rudy, Rudi Natamiharja, Jalil Alejandro Magaldi Serna, and Ahmad Syofyan. “Implementation of Civil Rights against Vulnerable Groups in the Legal and Constitutional System in Indonesia.” Hasanuddin Law Review 8, no. 3 (February 2023): 299. https://doi.org/10.20956/halrev.v8i3.4229.
Ryngaert, Cedric, and Mistale Taylor. “The GDPR as Global Data Protection Regulation?” AJIL Unbound 114 (2020): 5–9. https://doi.org/10.1017/aju.2019.80.
Salim, Andi Agus, Maulidina Sari, Nova Bela Dhyta, Ahmad Sholihin Muttaqin, and Try Hardyanthi. “Protecting Critical National Infrastructure Against Cyber Operations Under International Humanitarian Law: Lessons for Southeast Asia.” International Law Discourse in Southeast Asia 5, no. 1 (July 2026): 296–329. https://doi.org/10.15294/ildisea.v5i1.42796.
Solove, Daniel J. Understanding Privacy. Harvard University Press, 2008.
Sujadmiko, Bayu, Iskardo P. Panggar, Ade Sofyansah, and Intan Fitri Meutia. “The Concept of E-Voting Mechanism Based on Law of General Election and Information Security.” Jambe Law Journal 3, no. 1 (November 2020): 19–36. https://doi.org/10.22437/jlj.3.1.19-36.
United Nations Human Rights Committee. General Comment No. 16 (1988): Article 17 (Right to Privacy), The Right to Respect of Privacy, Family, Home and Correspondence, and Protection of Honour and Reputation. General Comment. New York: United Nations, 1988. https://www.refworld.org/docid/453883f922.html.
Voigt, Paul, and Axel Von Dem Bussche. The EU General Data Protection Regulation (GDPR). Cham: Springer International Publishing, 2017. https://doi.org/10.1007/978-3-319-57959-7.
Westin, Alan Furman. Privacy and Freedom. New edition. New York: IG Publishing, 2015.
Downloads
Published
Issue
Section
License
Copyright (c) 2026 Febrida Himni Ilmi, Johni Najwan, Akbar Kurnia Putra

This work is licensed under a Creative Commons Attribution 4.0 International License.















