Luma AI · Luma AI Privacy Policy

Legitimate Interests as Legal Basis for Processing

High severity
Share 𝕏 Share in Share 🔒 PDF

What it is

Luma relies on 'legitimate interests' — a broad legal justification under GDPR — to process your personal data for product development and analytics without requiring your consent, including potentially for AI model improvement.

Consumer impact (what this means for users)

Luma processes your personal data for product development and analytics under 'legitimate interests' without asking for your consent, but EU/UK users have the right under GDPR Art. 21 to object to this processing at any time.

What you can do

⚠️ These actions may provide transparency or partial mitigation but may not fully address the underlying issue. Effectiveness varies by jurisdiction and individual circumstances.
  • Delete Your Data
    EU/UK users can exercise their GDPR Art. 21 right to object to legitimate interests processing by emailing hello@lumalabs.ai. State that you are objecting to processing of your personal data based on legitimate interests, including for AI model training and product development purposes.

Cross-platform context

See how other platforms handle Legitimate Interests as Legal Basis for Processing and similar clauses.

Compare across platforms →
Need full compliance memos? See Professional →

Why it matters (compliance & risk perspective)

Legitimate interests is the most flexible GDPR legal basis and requires a balancing test; using it for AI training data purposes is currently subject to active regulatory challenge across Europe, meaning this legal basis may not withstand scrutiny.

View original clause language
Legitimate Interests. We may process your personal information where we or a third party have a legitimate interest in processing your personal information. Specifically, we have a legitimate interest in using your personal information for product development and internal analytics purposes, and otherwise to improve the safety, security, and performance of our Services. We only rely on our or a third party's legitimate interests to process your personal information when these interests are not overridden by your rights and interests.

Institutional analysis (Compliance & legal intelligence)

(1) REGULATORY FRAMEWORK: This provision directly implicates GDPR Art. 6(1)(f) (legitimate interests as legal basis), GDPR Art. 21 (right to object to legitimate interests processing), EDPB Guidelines 06/2020 on legitimate interests, and Recital 47 of the GDPR. The legal basis must be supported by a documented legitimate interests assessment (LIA). Enforced by EU national supervisory authorities and the EDPB. UK GDPR Art. 6(1)(f) and ICO's legitimate interests guidance apply in the UK. (2)

🔒

Compliance intelligence locked

Regulatory citations, enforcement risk, and due diligence action items.

Watcher $9.99/mo Professional $149/mo

Watcher: regulatory citations. Professional: full compliance memo.

Applicable agencies

  • FTC
    The FTC has jurisdiction over unfair or deceptive data processing practices under Section 5 of the FTC Act, including use of broad legal justifications to process user data without adequate disclosure.
    File a complaint →

Provision details

Document information
Document
Luma AI Privacy Policy
Entity
Luma AI
Document last updated
April 29, 2026
Tracking information
First tracked
April 30, 2026
Last verified
April 30, 2026
Record ID
CA-P-004297
Document ID
CA-D-00497
Evidence Provenance
Source URL
Wayback Machine
SHA-256
67674aa1a904b7c68bd20d464b6be4c1e518b1fe7e03c01dfdb4e87cfd26cb78
Verified
✓ Snapshot stored   ✓ Change verified
How to Cite
ConductAtlas Policy Archive
Entity: Luma AI | Document: Luma AI Privacy Policy | Record: CA-P-004297
Captured: 2026-04-30 07:54:18 UTC | SHA-256: 67674aa1a904b7c6…
URL: https://conductatlas.com/platform/luma-ai/luma-ai-privacy-policy/legitimate-interests-as-legal-basis-for-processing/
Accessed: May 2, 2026
Classification
Severity
High
Categories

Other provisions in this document