The organization must maintain a documented process to evaluate and justify the use of legitimate interest as a lawful basis for processing personal data. Before processing begins, a Legitimate Interest Assessment (LIA) must be conducted and retained as evidence of compliance.
- Identify the proposed processing, its purpose, the type of data involved, and the categories of data subjects.
- Confirm that the purpose is legitimate, necessary, and compliant with applicable laws.
- Assess whether processing is essential to achieve the intended purpose and proportionate to the organization’s objectives.
- Evaluate potential harm or impact on data subjects and their ability to exercise their rights.
- Identify and implement measures to mitigate risks or prevent possible harm.
Processing may proceed only when the assessment confirms that it is lawful, necessary, and does not infringe upon individuals’ rights or interests. If the assessment reveals any noncompliance, risks, or potential harm, the processing must be modified, reassessed, or based on an alternative lawful ground before continuation.