The 3-part LIA test

Regulators and the EDPB frame legitimate interest as a three-part test. All three parts have to be satisfied, a strong answer on one doesn't compensate for a weak answer on another.

Part 1: Purpose test

What's the specific purpose, and why is it legitimate? "We want more customers" is too vague to be useful here; the purpose needs to be specific enough that you could defend it to a regulator.

Example fill: "B2B prospecting for our SaaS product. Targeting professionals whose public role (title, industry, seniority) indicates relevance to our service. Ordinary, lawful commercial activity, not targeted at vulnerable individuals or sensitive categories of data."

Part 2: Necessity test

Is this specific processing necessary for the purpose, or could you reasonably achieve the same result with less data, or a less intrusive method?

Example fill: "Yes, contact data is needed to make initial contact. We minimize to job title, company, and public profile URL only. We don't enrich with data unrelated to prospecting relevance, and we don't purchase third-party data broker files to supplement what we extract."

Part 3: Balance test

Does your interest outweigh the data subject's rights and freedoms once you actually weigh them against each other? Consider:

  • Is the data sensitive? (Generally no for standard B2B contact info: name, title, company, public profile)
  • Would the subject reasonably expect this kind of contact? (B2B professionals with public profiles generally expect occasional, relevant cold outreach)
  • How do you minimize impact? (Honor opt-out immediately, no resale, defined retention limits, no dark patterns in the unsubscribe flow)

Example fill: "Our interest in commercial outreach to B2B contacts is balanced against minimal realistic harm: no financial, physical, or reputational risk to the individual. Contacts can opt out at the first message. No data resale to third parties. 12-month retention with automatic review. Right to erasure and right to object honored within 30 days."

Documenting a GDPR legitimate interest assessment for LinkedIn prospecting
A documented LIA is your defensible paper trail if the basis is ever challenged.

Worked example for LinkedIn prospecting

Applied specifically to LinkedIn-sourced B2B data, the assessment usually looks like this: purpose is targeted outreach to decision-makers whose public role matches your product's buyer profile; necessity is that public profile data (name, title, company, industry) is the minimum needed to personalize and qualify outreach, and nothing beyond that is collected; balance favors the business because the data is already public, professionally self-published by the individual, low-sensitivity, and the contact retains full control via opt-out at any time. Where the balance tips the other way is usually volume and persistence: repeated unsolicited contact after no response, or outreach that ignores an earlier opt-out, weakens the necessity and balance legs even if the original purpose was sound.

When an LIA isn't enough

An LIA is a defensible starting position, not a permanent shield. It stops protecting your processing the moment a data subject raises a valid, specific objection under Article 21, at which point you either have to show a compelling overriding legitimate ground (rare in ordinary prospecting) or stop and delete. It also doesn't apply at all to special category data (health, political opinions, and similar), which needs a different, stricter legal basis entirely and has no place in ordinary B2B contact records regardless. Treat the LIA as your reasoning on file for the ordinary case, not as something that survives every specific challenge automatically.

Document and save

Save the completed LIA in your data protection records, alongside your privacy policy and any DPA with vendors. Update it at least annually, and immediately whenever your processing changes materially, a new data source, a new use of the data, or a meaningful jump in scope or volume.

Frequently asked questions

Is a Legitimate Interest Assessment legally required?

GDPR doesn't mandate a specific document format, but the accountability principle in Article 5(2) requires you to be able to demonstrate compliance, and in practice that means having a written LIA on file. If a regulator or a data subject challenges your basis for processing and you have nothing documented, you're relying entirely on being able to reconstruct your reasoning after the fact, which is a much weaker position.

Who has to sign off on an LIA?

There's no universal legal requirement for a specific signatory, but best practice is review by whoever holds data protection responsibility in your organization, a DPO if you have one, otherwise the person accountable for compliance decisions. The point of the sign-off is a second, independent look at the balancing test, not a rubber stamp.

Does a completed LIA guarantee my processing is compliant?

No. An LIA documents your reasoning and shows you did the assessment in good faith, but it doesn't override a data subject's valid objection under Article 21, and it doesn't help if the processing itself is disproportionate. Think of it as your defensible paper trail, not a compliance guarantee.

How often does the LIA need updating?

At least annually, and immediately whenever your processing changes materially, a new data source, a new use of the data, or a significant increase in volume or scope all warrant revisiting the balance test rather than assuming the original assessment still holds.

General information only, not legal advice; confirm current requirements with counsel for your specific situation.

GDPR-positioned tooling.

Leadsforlinked operates under a documented LIA framework. Free 100 leads on signup.

Start free