The 3-part LIA test

Part 1: Purpose

What's the specific purpose? Why is it legitimate?

Example fill: "B2B prospecting for our SaaS product. Targeting professionals whose role indicates relevance to our service. Lawful commercial activity."

Part 2: Necessity

Is this processing necessary for the purpose? Could you achieve the same with less data?

Example fill: "Yes, contact data is needed to make initial contact. We minimize to job title, company, public profile only. We don't enrich beyond what's necessary for personalization."

Part 3: Balance test

Does our interest outweigh the data subject's rights and freedoms? Consider:

  • Is the data sensitive? (No for B2B contact info)
  • Would the subject reasonably expect this contact? (B2B professionals expect cold reach occasionally)
  • How can we minimize impact? (Honor opt-out, no resale, retention limits)

Example fill: "Our interest in commercial outreach to B2B contacts is balanced against minimal harm. Contacts can opt out at first message. No data resale. 12-month retention. Right to erasure honored within 30 days."

Document and save

Save the LIA in your DPO records. Update annually or when processing changes materially.

GDPR-positioned tooling.

Lead4Linked operates under documented LIA framework. Free 100 leads on signup.

Start free