Compliance

Voice AI recognised legitimate interests: a DUAA guide

Recognised legitimate interest is a new UK GDPR lawful basis added by the Data (Use and Access) Act 2025, in force from 5 February 2026. It covers a closed public-interest list, so most enterprise voice AI still needs a full legitimate interests assessment. Dilr Voice maps each call purpose to a defensible basis.

DILR.AI ENGINEERING · UK GDPR · DUAA 2025 Recognised legitimate interests Article 6(1)(ea) · Annex 1 · in force 5 February 2026 No balancing test but necessity still applies a closed list of five A narrow public-interest basis, not a shortcut around the legitimate interests assessment.

On 5 February 2026 the UK gained a seventh lawful basis for processing personal data. The Data (Use and Access) Act 2025 inserted a new "recognised legitimate interest" into Article 6(1)(ea) of the UK GDPR, and for the narrow set of purposes it covers, a controller no longer has to run the legitimate interests balancing test. For anyone deploying a voice AI agent that handles inbound calls, this looked, at first glance, like a simpler route to a lawful basis.

It is not. The recognised list is short, it is closed, and almost nothing an ordinary enterprise voice agent does falls inside it. A renewal reminder, an appointment booking, an outbound sales call: none of those are recognised legitimate interests. Read the wrong way, Article 6(1)(ea) becomes a compliance trap, a basis a firm claims because it sounds convenient rather than because the processing genuinely qualifies. Getting the lawful basis wrong sits in the higher enforcement tier, up to £17.5 million or 4% of global annual turnover under Article 83(5), so the stakes are not academic.

This guide sets out what the recognised legitimate interests list actually contains, why most voice AI processing still needs a full legitimate interests assessment, and the narrow safeguarding, crime and emergency cases where a voice programme can rely on the new basis. It is written for the person who has to defend the lawful basis to the ICO, not the person who wants the quickest tick in a box.

This guide is shipped by the team behind Dilr Voice, enterprise voice AI built for regulated deployments. Or see DATS, our five-stage AI consulting system.

What is a recognised legitimate interest under the DUAA?

A recognised legitimate interest is a lawful basis in UK GDPR Article 6(1)(ea), added by the Data (Use and Access) Act 2025, that lets a controller process personal data for a fixed set of public-interest purposes without running a balancing test. New Article 6(5) states the limit plainly: processing qualifies "only if it meets a condition in Annex 1". The ICO published its guidance on it on 23 March 2026.

The Act received Royal Assent on 19 June 2025, and the recognised legitimate interests provision came fully into force on 5 February 2026. Unlike the ordinary legitimate interests basis in Article 6(1)(f), which lets an organisation define its own purpose and then justify it, recognised legitimate interest is a closed list that Parliament pre-approved. You cannot reason your way into it. Either your processing meets one of the Annex 1 conditions word for word, or it does not, and if it does not, you are back on one of the other six bases. That distinction shapes every lawful-basis decision a voice deployment makes, which is why the lawful-basis mapping our AI execution office runs treats it as a gate rather than a footnote.

Which processing does the recognised legitimate interests list actually cover?

The recognised legitimate interests are set out in the new Annex 1 to the UK GDPR, inserted by Schedule 4 of the DUAA. The ICO summarises it as five conditions of pre-approved public-interest purposes: crime detection and prevention, public security, national security or defence, safeguarding vulnerable individuals, emergencies, and disclosures that help another body carry out a public task. Nothing about ordinary commercial call handling appears anywhere on that list.

Read the conditions in full and the pattern is unmistakable. They point outward, toward the state and toward harm, not toward a business running its own operations:

The five recognised legitimate interest conditions (Annex 1, UK GDPR)
01Disclosure for a public taskSharing data so another body can act under Article 6(1)(e)02National security, public security and defenceSafeguarding national or public security, or defence purpose…03EmergenciesResponding to an emergency as defined in the Civil Contingen…04CrimeDetecting, investigating or preventing crime; apprehending o…05Safeguarding vulnerable individualsProtecting a person under 18, or 18 and over and at risk, fr…
The closed statutory list added by the DUAA; each condition still requires the processing to be necessary.

The Annex defines its own terms tightly. "Emergency" borrows the meaning from Part 2 of the Civil Contingencies Act 2004. A "vulnerable individual" means someone under 18, or aged 18 and over and "at risk", which the Annex ties to a person who has needs for care and support and cannot protect themselves. These are not loose descriptions a marketing team can stretch. A voice agent that reminds a member their subscription lapses next week is not preventing crime, responding to an emergency, or safeguarding anyone, and no amount of framing changes that.

Can a voice AI programme rely on recognised legitimate interests?

For most of what enterprise voice AI does, no. The recognised legitimate interests list covers public-interest processing: crime prevention, safeguarding, emergencies, national security, and disclosures to public bodies. Routine voice AI work, such as booking appointments, chasing renewals, qualifying leads or answering billing questions, sits outside every one of those conditions, so a controller cannot rely on Article 6(1)(ea) for it and must choose consent, contract or ordinary legitimate interests instead.

There is a genuine set of edge cases where a voice programme can rely on the new basis, and they are worth naming precisely. A voice AI agent that screens inbound calls for fraud, or that detects and routes a call from someone at risk of harm to a human safeguarding team, is processing for crime prevention or safeguarding respectively, both of which are Annex 1 conditions. A regulated firm that discloses caller data to a public authority in response to a lawful request may land on the public-task disclosure condition. Those are real, but they are the exception in a commercial deployment, not the default. Our AI operating model work maps each call purpose to its own basis rather than stretching one basis across the whole estate.

Recognised legitimate interest versus the legitimate interests balancing test: what changes?

The one thing recognised legitimate interest removes is the balancing test. Under ordinary legitimate interests in Article 6(1)(f), a controller must weigh its purpose against the rights, freedoms and interests of the data subject and document that in a legitimate interests assessment. Under Article 6(1)(ea), Parliament has already made that judgement for the listed purposes, so the balancing step falls away. Everything else, including the necessity test, stays exactly where it was.

That is the whole of the difference, and it is smaller than it sounds. The ICO is explicit that you must still show the processing is necessary, meaning there is no less intrusive way to achieve the purpose. As the regulator puts it in its March 2026 guidance:

Recognised legitimate interest is a lawful basis not an exemption. You must still comply with the rest of the UK GDPR and the DPA even if this basis applies.

So the recognised basis buys you one thing: it retires the balancing exercise for a short list of public-interest purposes. It does not retire transparency, data minimisation, security, retention limits, or the rights of the people on the call. For the ordinary legitimate interests that cover the rest of a voice estate, the three-part test and the written assessment remain mandatory.

Do you still need a legitimate interests assessment for voice AI?

For nearly every enterprise voice AI use case, yes. Because recognised legitimate interests only covers crime, safeguarding, emergencies, security and public-task disclosures, the everyday purposes a voice agent serves still rely on Article 6(1)(f) ordinary legitimate interests, contract or consent. Where you rely on ordinary legitimate interests, the balancing test and a documented legitimate interests assessment are still required before the first call connects.

The practical mistake we see teams about to make is treating the new basis as an upgrade path: "the DUAA gave us recognised legitimate interests, so we can drop the assessment." That reasoning fails at the first Annex 1 condition. A booking agent, a payment-reminder agent, an outbound qualification agent: each of these needs its lawful basis chosen on its own facts, and for most of them the honest answer is an ordinary legitimate interests assessment or consent, not the recognised list. The same discipline runs through our DATS methodology and, for firms that want the governance built and staffed, our AI execution office. Documenting the basis per purpose is what survives an ICO audit; a blanket claim does not.

The same diagnostic logic underpins our AI placement diagnostic, a fixed-fee assessment used before any deployment commitment, which is where the lawful-basis mapping for each call flow gets pinned down in writing.

What does recognised legitimate interest not remove?

Almost everything. Recognised legitimate interest is an Article 6 lawful basis and nothing more. It does not remove the duty to give people a privacy notice under Article 13, it does not remove data minimisation and redaction obligations, it does not remove security duties or the breach notification duty under Article 33, and it does not remove the individual rights that attach to every basis.

Two limits deserve particular care in a voice deployment. First, special category data. If a call reveals health, and many inbound calls to a clinic or an insurer do, then relying on recognised legitimate interest as the Article 6 basis still leaves you needing a separate Article 9 condition and, for most of them, an appropriate policy document. The recognised list handles the lawfulness limb, not the special category limb. Second, the right to object under Article 21 continues to apply to processing based on the recognised legitimate interest, so your voice flows still need a clean route for a caller to object and have that honoured. Recording the call does not change any of this; the EU AI Act transparency duty to tell people they are speaking to an AI system runs in parallel, independent of which UK lawful basis you pick.

What is the best lawful basis for enterprise voice AI in 2026?

There is no single best basis; the right one depends on the purpose of each call flow, and a serious deployment uses several. For fraud screening or safeguarding routing, recognised legitimate interest may be the cleanest fit. For a service call tied to a contract, Article 6(1)(b) is usually correct. For most other outbound and analytics purposes, ordinary legitimate interests with a documented assessment, or consent, is the defensible choice, which the ICO calls the most flexible basis.

The platform decision interacts with this more than teams expect. With build-your-own voice frameworks such as Vapi, Retell AI or Bland AI, you own the lawful-basis mapping, the assessments and the objection handling yourself, which suits an organisation with an in-house DPO and a single, well-scoped flow where build genuinely wins. With managed platforms such as Dilr Voice or PolyAI, the lawful-basis mapping, the assessment templates and the transparency scripts come as part of delivery, and Twilio or your own telephony sits underneath either model. The concession is real: if you have the privacy engineering capacity in-house and one narrow use case, a build platform lets you own the whole stack. For a regulated estate spanning many purposes, the managed route is usually where the governance actually gets staffed, and closing that gap is what our approach to placing AI in regulated systems is built for.

Is recognised legitimate interest available for special category data?

Only as the Article 6 basis. The ICO confirms recognised legitimate interest can apply where special category data is involved, but that covers lawfulness under Article 6, not the separate Article 9 requirement. A voice agent handling health or other special category data on a call still needs a valid Article 9 condition and, in most cases, an appropriate policy document under the Data Protection Act 2018 before processing begins.

Can a public authority use recognised legitimate interest?

Generally not for its own tasks. The ICO is clear that a public authority cannot rely on recognised legitimate interest to perform its official tasks or functions, where the public task basis in Article 6(1)(e) is likely to be appropriate instead. The recognised list is aimed at controllers outside that public-task frame, or at disclosures that help a public body act, which is why the direction of the basis matters when you map a voice flow.

Does recognised legitimate interest apply to outbound marketing calls?

No. Marketing and win-back calls are not on the Annex 1 list, and recognised legitimate interest does not touch the separate PECR rules on live and automated calls. An outbound campaign still needs its own lawful basis under Article 6, usually consent or ordinary legitimate interests, and must satisfy PECR and the Ofcom and TPS obligations that bind the caller. The DUAA changed the balancing test for a short public-interest list; it did not deregulate marketing.

Across 2026, roughly 88% of enterprises use AI but only about 6% capture material EBIT impact, on McKinsey's State of AI reading, and the firms pulling ahead are the ones that made the boring governance decisions early. Choosing the lawful basis per call purpose, rather than reaching for whichever basis sounds least effortful, is one of those decisions.

Want to see this in production? Try Dilr Voice live, book an AI placement diagnostic, see our DATS methodology, or read about our approach to placing AI inside regulated systems.

Service
AI Operating Model
Service
AI Execution Office
Product
Dilr Voice
Talk to the operators

Pick the lawful basis before you pick the vendor.

30-min scoping call · No deck · Confidential. We will tell you which of your voice flows can rely on recognised legitimate interest, and which still need a full assessment.

Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.

voice AI recognised legitimate interestsDUAA recognised legitimate interestsUK GDPR lawful basis voice AIrecognised legitimate interest redditbest lawful basis voice AI 2026voice AI complianceDilr Voice

Questions this article answers

What is a recognised legitimate interest under the DUAA?

A recognised legitimate interest is a lawful basis in UK GDPR Article 6(1)(ea), added by the Data (Use and Access) Act 2025, that lets a controller process personal data for a fixed set of public-interest purposes without running a balancing test. New Article 6(5) states the limit plainly: processing qualifies "only if it meets a condition in Annex 1". The ICO published its guidance on it on 23 March 2026.

Which processing does the recognised legitimate interests list actually cover?

The recognised legitimate interests are set out in the new Annex 1 to the UK GDPR, inserted by Schedule 4 of the DUAA. The ICO summarises it as five conditions of pre-approved public-interest purposes: crime detection and prevention, public security, national security or defence, safeguarding vulnerable individuals, emergencies, and disclosures that help another body carry out a public task. Nothing about ordinary commercial call handling appears anywhere on that list.

Can a voice AI programme rely on recognised legitimate interests?

For most of what enterprise voice AI does, no. The recognised legitimate interests list covers public-interest processing: crime prevention, safeguarding, emergencies, national security, and disclosures to public bodies. Routine voice AI work, such as booking appointments, chasing renewals, qualifying leads or answering billing questions, sits outside every one of those conditions, so a controller cannot rely on Article 6(1)(ea) for it and must choose consent, contract or ordinary legitimate interests instead.

Recognised legitimate interest versus the legitimate interests balancing test: what changes?

The one thing recognised legitimate interest removes is the balancing test. Under ordinary legitimate interests in Article 6(1)(f), a controller must weigh its purpose against the rights, freedoms and interests of the data subject and document that in a legitimate interests assessment. Under Article 6(1)(ea), Parliament has already made that judgement for the listed purposes, so the balancing step falls away. Everything else, including the necessity test, stays exactly where it was.

Do you still need a legitimate interests assessment for voice AI?

For nearly every enterprise voice AI use case, yes. Because recognised legitimate interests only covers crime, safeguarding, emergencies, security and public-task disclosures, the everyday purposes a voice agent serves still rely on Article 6(1)(f) ordinary legitimate interests, contract or consent. Where you rely on ordinary legitimate interests, the balancing test and a documented legitimate interests assessment are still required before the first call connects.

What does recognised legitimate interest not remove?

Almost everything. Recognised legitimate interest is an Article 6 lawful basis and nothing more. It does not remove the duty to give people a privacy notice under Article 13, it does not remove data minimisation and redaction obligations, it does not remove security duties or the breach notification duty under Article 33, and it does not remove the individual rights that attach to every basis.

What is the best lawful basis for enterprise voice AI in 2026?

There is no single best basis; the right one depends on the purpose of each call flow, and a serious deployment uses several. For fraud screening or safeguarding routing, recognised legitimate interest may be the cleanest fit. For a service call tied to a contract, Article 6(1)(b) is usually correct. For most other outbound and analytics purposes, ordinary legitimate interests with a documented assessment, or consent, is the defensible choice, which the ICO calls the most flexible basis.

Is recognised legitimate interest available for special category data?

Only as the Article 6 basis. The ICO confirms recognised legitimate interest can apply where special category data is involved, but that covers lawfulness under Article 6, not the separate Article 9 requirement. A voice agent handling health or other special category data on a call still needs a valid Article 9 condition and, in most cases, an appropriate policy document under the Data Protection Act 2018 before processing begins.

Compliance

Deploy voice AI without failing an audit

Dilr Voice ships per-country TCPA and GDPR rules, and the UK AI compliance changelog tracks ICO, FCA, and EU AI Act changes as they land.

Related articles

← Previous
Voice AI dead air: masking latency without faking it

One email, once a month. No hype. Just what we learned shipping.