The 3-part LIA test
Part 1: Purpose
What's the specific purpose? Why is it legitimate?
Example fill: "B2B prospecting for our SaaS product. Targeting professionals whose role indicates relevance to our service. Lawful commercial activity."
Part 2: Necessity
Is this processing necessary for the purpose? Could you achieve the same with less data?
Example fill: "Yes, contact data is needed to make initial contact. We minimize to job title, company, public profile only. We don't enrich beyond what's necessary for personalization."
Part 3: Balance test
Does our interest outweigh the data subject's rights and freedoms? Consider:
- Is the data sensitive? (No for B2B contact info)
- Would the subject reasonably expect this contact? (B2B professionals expect cold reach occasionally)
- How can we minimize impact? (Honor opt-out, no resale, retention limits)
Example fill: "Our interest in commercial outreach to B2B contacts is balanced against minimal harm. Contacts can opt out at first message. No data resale. 12-month retention. Right to erasure honored within 30 days."
Document and save
Save the LIA in your DPO records. Update annually or when processing changes materially.
GDPR-positioned tooling.
Lead4Linked operates under documented LIA framework. Free 100 leads on signup.
Start free