Balancing test under GDPR – how to document legitimate interest
Share
Short answer: A legitimate interest assessment (LIA) according to GDPR Article 6(1)(f) can be used when there is a legitimate interest, the processing is necessary to achieve that interest, and the interests or fundamental rights of the data subject do not override it. The assessment should be documented before the processing begins.
What is a legitimate interest assessment?
A legitimate interest assessment is one of the legal bases under the GDPR. It is often used in private operations when processing is not appropriately based on a contract, legal obligation, or consent. However, it is not a general fallback basis. The organization must be able to demonstrate why this specific processing passes the test.
The three-part test in an LIA
1. Is there a legitimate interest?
Describe the specific interest and who holds it. Examples include preventing fraud, maintaining network and information security, or conducting certain types of direct marketing.
2. Is the processing necessary?
Ask whether the purpose can be achieved in a less privacy-intrusive way. If the same result can be reached with less data, shorter storage, or anonymized information, this should be taken into account.
3. Whose interests carry the most weight?
Assess the nature of the data, the relationship with the data subject, reasonable expectations, the scope, protective measures, and potential consequences. Children and other vulnerable groups require special caution.
What should the documentation contain?
- the purpose and a description of the legitimate interest
- what personal data and data subjects are affected
- a necessity assessment and possible alternatives
- a balancing of the organization’s interests against those of the data subject
- protective measures, storage periods, and access restrictions
- information on the right to object and how objections are handled
- the decision, the person responsible, and the date for reassessment
Direct marketing and objection
Direct marketing is often mentioned in the context of legitimate interest, but this does not mean that all marketing is automatically permitted. Other rules may also be relevant, and if an individual objects to processing for direct marketing purposes, that processing must cease.
When is an LIA not enough?
A legitimate interest assessment does not replace a DPIA when the processing is likely to result in a high risk. Nor does it replace the requirements for information, data minimization, storage limitation, security, and other GDPR principles.
Common mistakes
- describing the interest too abstractly, for example, just as “business value”
- skipping the necessity assessment
- assuming that a customer relationship automatically means that the data subject should expect the processing
- not documenting protective measures
- never reassessing an old evaluation when the processing changes
See the Template Store's template package for legitimate interest assessments / LIA.
FAQ
Is consent always better than a legitimate interest assessment?
No. The legal basis should be chosen based on the actual processing. Consent has specific requirements and must, among other things, be voluntary and capable of being withdrawn.
Can authorities use Article 6(1)(f)?
Not when the authority is processing personal data as part of the performance of its tasks. For private actors, however, Article 6(1)(f) may be relevant if the conditions are met.
How often should an LIA be reviewed?
There is no simple universal timeframe. If the purpose, data volume, technology, recipients, or risk profile change, the assessment should be reconsidered.
Official guidance: The Swedish Authority for Privacy Protection (IMY) and the European Data Protection Board provide guidance on Article 6(1)(f) and the three criteria for legitimate interest assessments.
This article provides general information and does not constitute legal advice.