Luma relies on 'legitimate interests' — a broad legal justification under GDPR — to process your personal data for product development and analytics without requiring your consent, including potentially for AI model improvement.
This analysis describes what Luma AI's agreement states, permits, or reserves. It does not constitute a legal determination about enforceability. Regulatory applicability and practical outcomes may vary by jurisdiction, enforcement context, and individual circumstances. Read our methodology
This clause establishes legitimate interests as a lawful basis for data processing under GDPR and similar frameworks, enabling the entity to process data for operational purposes without explicit user consent when a balancing test favors the processing.
Removal of the high-severity 'Legitimate Interests' legal basis provision eliminates transparency around broad processing justifications, potentially obscuring reliance on legitimate interests for data use.
View full change record →Luma processes your personal data for product development and analytics under 'legitimate interests' without asking for your consent, but EU/UK users have the right under GDPR Art. 21 to object to this processing at any time.
Cross-platform context
See how other platforms handle Legitimate Interests as Legal Basis for Processing and similar clauses.
Compare across platforms →Monitoring
Luma AI has changed this document before.
Receive same-day alerts, structured change summaries, and monitoring for up to 25 platforms.
"Legitimate Interests. We may process your personal information where we or a third party have a legitimate interest in processing your personal information. Specifically, we have a legitimate interest in using your personal information for product development and internal analytics purposes, and otherwise to improve the safety, security, and performance of our Services. We only rely on our or a third party's legitimate interests to process your personal information when these interests are not overridden by your rights and interests.— Excerpt from Luma AI's Luma AI Privacy Policy
(1) REGULATORY FRAMEWORK: This provision directly implicates GDPR Art. 6(1)(f) (legitimate interests as legal basis), GDPR Art. 21 (right to object to legitimate interests processing), EDPB Guidelines 06/2020 on legitimate interests, and Recital 47 of the GDPR. The legal basis must be supported by a documented legitimate interests assessment (LIA). Enforced by EU national supervisory authorities and the EDPB. UK GDPR Art. 6(1)(f) and ICO's legitimate interests guidance apply in the UK. (2)
Full compliance analysis
Regulatory citations, enforcement risk, and due diligence action items.
Free: track 1 platform + weekly digest. Monitor: 25 platforms + same-day alerts. No credit card required.
Compliance Governance Intelligence
Need to monitor specific governance provisions?
Compliance includes provision-level monitoring, governance timelines, regulatory mapping, and audit-ready analysis.
Built from archived source documents, structured governance mappings, and historical version tracking.
This clause establishes legitimate interests as a lawful basis for data processing under GDPR and similar frameworks, enabling the entity to process data for operational purposes without explicit user consent when a balancing test favors the processing.
Luma processes your personal data for product development and analytics under 'legitimate interests' without asking for your consent, but EU/UK users have the right under GDPR Art. 21 to object to this processing at any time.
ConductAtlas has identified this type of provision across 1 platforms. See the full comparison.
No. ConductAtlas is an independent monitoring service. We are not affiliated with, endorsed by, or sponsored by Luma AI.