Outlook got updated on my iPhone last night and now they want me to agree to having my data shared with 807 partners.
Important note: I don’t use outlook as my primary email provider. I use Proton with a custom domain but I keep outlook for some old emails.
I was also curious about this and just had a chat with gpt 3.5 about it, and it gave an example of “a bank collecting data to detect and prevent fraud” as a valid legitimate interest and “a company collecting data to sell to advertisers” as an invalid legitimate interest.
It also said that legitimate interests must be explained, as on what interests they are, why they are considered legitimate, how the processing of that data accomplishes that interest and any potential impact it has on the user’s privacy and freedom.
Based on this, I think “legitimate interest” is being used as a reason instead of a category that covers genetic legitimate reasons that should still be explained, not hand waved as “legitimate interest”.
Though I believe this only applies in the context of the GPDR (because the bot specifically mentioned it), and might vary in other jurisdictions.