What is a Legitimate Interests Assessment?
Legitimate interests is the most flexible lawful basis in GDPR, and the flexibility is exactly why it demands the most discipline. The other bases are largely matters of fact: either a contract needs the data or it does not, either the law requires it or it does not. Legitimate interests is a judgement, and GDPR requires the judgement to be made properly: a genuine interest, a necessary means, and a balance that does not sacrifice the person in the data. The Legitimate Interests Assessment is where that judgement gets made and, crucially, written down. (This entry is a practical explainer, not legal advice.)
The three-part test in plain English
Purpose. Name the interest and check it is real. Commercial interests count, so do operational and societal ones: keeping the network secure, preventing fraud, coaching a team, keeping clients informed. What fails the test is vagueness. An interest you cannot state in one concrete sentence is not yet an interest; it is an inclination.
Necessity. Check the processing actually serves the interest, and that nothing less intrusive would serve it as well. This is where data minimisation enters through the side door: if sampling would do, blanket collection is not necessary; if aggregates would do, individual records are not necessary. Necessary means needed, not convenient.
Balance. Weigh the interest against the people it touches. Whose data is it, what would they reasonably expect given their relationship with you, what could the processing cost them, and which safeguards reduce that cost: transparency, limits, retention, a way to object. If their rights and freedoms override your interest, the basis fails, no matter how genuine the interest was. The balancing test is the conscience of the exercise, and it only works when the organisation is willing to lose.
An unwritten LIA is an undefended decision
Everything above could, in principle, happen in someone’s head. That is precisely the problem. A judgement with no record is indistinguishable from a hunch, and legitimate interests is the basis most likely to be challenged: by a data subject exercising the right to object, by a regulator asking questions, by a client’s procurement team working through a due-diligence list. In each case what matters is the reasoning as it stood before the processing began. When someone objects, the organisation must show compelling grounds that override theirs; with a written LIA that is an exercise in retrieval, and without one it is reconstruction under pressure, paying the re-derivation tax at the worst possible moment and hoping the answer comes out the same. An unwritten LIA is an undefended decision: the judgement may have been sound, but the organisation cannot prove it was ever made.
One concrete example
Clearly illustrative, with no customer implied. A consultancy wants to email contacts at past clients about a new service line. It has no consent for that, so the honest question is whether legitimate interests can carry it. Purpose: keeping established business relationships informed of relevant services, a genuine commercial interest, stated in one sentence. Necessity: does the interest require emailing every contact ever collected? No. Recent relationships, business addresses, one message with a clear route to decline. Balance: a contact from a live or recent engagement would plausibly expect to hear from a current supplier; a contact from many years ago would not, so the old list stays out. The firm records the assessment with a date and an owner, and notes that marketing email also has its own rules beyond GDPR for counsel to confirm. Months later a recipient objects and asks why they were contacted. The answer takes a day, quotes the assessment, and the objection is honoured immediately. The same email sent without the LIA would have been the same processing with no defence behind it.
The LIA and decision intelligence
The LIA is a balancing decision, and it rewards being treated the way decision intelligence treats any consequential call. Its inputs have quality: a claim about what people would expect might be measured (you asked), inferred from behaviour, or simply asserted, and the evidence hierarchy makes that difference visible instead of flattening it. Its outcome deserves a decision audit trail: who weighed the balance, when, against what evidence, over what alternatives. And it has a lifecycle: purposes drift, datasets grow, and an assessment made for one shape of processing does not silently cover the next, so the record is what makes the drift visible. Where the LIA sits among a people business’s wider obligations is covered in GDPR for BPOs.
Common questions
What is a Legitimate Interests Assessment?
A Legitimate Interests Assessment, or LIA, is the recorded three-part test an organisation performs before relying on legitimate interests as its lawful basis under GDPR. It asks whether there is a genuine, lawful interest behind the processing (the purpose test), whether the processing is actually needed to achieve it (the necessity test), and whether the interest is overridden by the rights and freedoms of the people concerned (the balancing test). If any part fails, legitimate interests is not available as a basis.
What are the three parts of the test?
Purpose: name the interest and check it is real and lawful, whether commercial, operational or societal. Necessity: check the processing genuinely serves that interest and that no less intrusive route would achieve the same end. Balance: weigh the interest against the impact on the people in the data, considering what they would reasonably expect, what the processing could cost them, and what safeguards reduce that cost. The interest must survive all three, and the balancing test is where most weak cases fail.
Does an LIA have to be written down?
GDPR’s accountability principle requires organisations to be able to demonstrate that their processing is lawful, and regulators expect the assessment behind a legitimate-interests claim to be documented. An unwritten LIA is nearly impossible to evidence after the fact: when someone objects or a regulator asks, what counts is the reasoning as it stood before the processing began, and only a record can show that.
When does the balancing test fail?
When the people in the data would not reasonably expect the processing, when the potential harm to them outweighs the interest pursued, when a less intrusive route exists, or when no safeguard can bring the impact down to something proportionate. Covert monitoring is the classic failure: however genuine the interest, secrecy defeats reasonable expectation, and the balance tips against the organisation.
Related reading
See a decision run live
Watch evidence land, options reorder against the binding constraint, and the outcome get scored.