| name | legitimate-interest-lia |
| title | Performing Legitimate Interest Assessment |
| description | Guides the three-part Legitimate Interest Assessment (LIA) required under GDPR Article 6(1)(f): purpose test, necessity test, and balancing test. Activate when evaluating legitimate interest as a lawful basis, conducting LIA reviews, or documenting proportionality analysis. Keywords: LIA, legitimate interest, balancing test, necessity test, purpose test, Article 6(1)(f). |
| author | mukul975 |
| author_url | https://github.com/mukul975/Privacy-Data-Protection-Skills/tree/main/skills/privacy/legitimate-interest-lia |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | general |
| practice | data-protection |
| language | en |
Performing Legitimate Interest Assessment
Overview
When a controller relies on Art. 6(1)(f) as the lawful basis for processing, a Legitimate Interest Assessment (LIA) must be conducted and documented before processing begins. The LIA consists of three sequential tests derived from the wording of Art. 6(1)(f) and elaborated in WP29 Opinion 06/2014. If any test fails, legitimate interest cannot be relied upon, and an alternative lawful basis must be found or processing must not proceed.
Part 1: Purpose Test
The purpose test establishes whether the controller (or a third party) has a legitimate interest that is real, lawful, and clearly articulated.
Assessment Criteria
-
Identify the interest: What specific interest does the controller or third party pursue? The interest must be concrete and articulated, not vague or hypothetical.
-
Verify legitimacy: The interest must be:
- Lawful (not prohibited by any law)
- Sufficiently specific to be assessed
- Real and present (not speculative or future)
- Consistent with what data subjects would reasonably expect
-
Common legitimate interests recognised by the GDPR:
- Fraud prevention (Recital 47)
- Direct marketing to existing customers (Recital 47)
- Network and information security (Recital 49)
- Intra-group transfers for internal administrative purposes (Recital 48)
- Reporting possible criminal acts or threats to public security (Recital 50)
-
Document the interest: State the interest in a single clear sentence that could be understood by a non-expert.
Purpose Test Outcome
- PASS: A legitimate interest has been clearly identified and is lawful.
- FAIL: No legitimate interest can be articulated, or the interest is prohibited by law. Stop the assessment — Art. 6(1)(f) cannot be relied upon.
Part 2: Necessity Test
The necessity test determines whether the specific processing is necessary to achieve the identified legitimate interest. This is not a test of whether the interest itself is necessary, but whether the processing is necessary for the interest.
Assessment Criteria
-
Could the interest be achieved without processing personal data? If the same outcome can be reached without personal data, the processing fails the necessity test.
-
Could the interest be achieved with less personal data? Apply data minimisation — only the minimum data necessary should be processed.