Skip to content
UK GDPR

UK Legitimate Interest Assessment: Template and Guide

5 min readUpdated 9 September 2026

A UK Legitimate Interest Assessment (LIA) is the documented analysis an organisation must complete before relying on legitimate interest as a lawful basis under UK GDPR. Without a completed LIA, legitimate interest cannot be relied upon as a basis — the ICO has been clear that documentation is required, not optional.

The process mirrors EU GDPR's legitimate interest assessment closely, but with some UK-specific considerations following the DPDI Act.


When You Need a UK LIA

You need an LIA when you plan to rely on legitimate interest (UK GDPR Article 6(1)(f)) for any processing activity. Common use cases:

  • Direct marketing to existing B2B customers
  • Fraud prevention and security monitoring
  • Intra-group data transfers for administrative purposes
  • Processing for analytics and product improvement
  • Employee monitoring (where proportionate)
  • Profiling and personalisation where consent is not the basis

You do not need an LIA for processing based on other grounds (contract, legal obligation, vital interests). You only document the legitimate interest analysis when Article 6(1)(f) is the claimed basis.


The Three-Part Test

The UK legitimate interest test has three elements:

Part 1 — The Purpose Test

Is there a legitimate interest?

The interest must be:

  • Legal — not contrary to law or public policy
  • Real and present — not speculative or hypothetical
  • Specific enough to identify

Examples of legitimate interests:

  • Preventing fraud
  • Ensuring network and information security
  • Direct marketing to existing customers
  • Intra-group transfers for administrative efficiency
  • Improving products and services through analytics

The DPDI Act introduced a list of purposes for which legitimate interest applies without a full balancing test (see below). For purposes not on this list, the full three-part assessment is required.

Part 2 — The Necessity Test

Is the processing necessary for that interest?

Necessity means the processing is required — not just convenient or helpful. Ask:

  • Can the interest be achieved with less personal data?
  • Can the interest be achieved with less intrusive processing?
  • Is the proposed processing proportionate to the interest?

If the answer to any of these is "yes, a less intrusive approach exists," the necessity test fails.

Part 3 — The Balancing Test

Do the data subject's interests override?

Weigh the organisation's interest against the individual's privacy interests and fundamental rights. Factors to consider:

In favour of the processing:

  • The individual would reasonably expect this processing
  • The processing does not involve sensitive data
  • The impact on individuals is minimal
  • The processing benefits the individual or society, not only the organisation

Against the processing:

  • The individual would not expect this processing
  • The data is sensitive or of a type that causes harm if misused
  • The processing only benefits the organisation commercially
  • Children or vulnerable individuals are affected
  • The processing could cause embarrassment, discrimination, or other harm

If the balance is genuinely unclear, lean against legitimate interest — the burden is on the controller to demonstrate the balance tips in favour of processing.


UK LIA Template

LEGITIMATE INTEREST ASSESSMENT

Processing activity: [Description]
Date: [Date]
Completed by: [Name and role]
Reviewed by: [Name and role]

─────────────────────────────────────────────────────

PART 1 — PURPOSE TEST

What is the legitimate interest claimed?
[Describe specifically — e.g., "Direct marketing to existing business 
customers about similar services"]

Is the interest legitimate?
☐ Legal — not contrary to law or public policy: Yes / No
☐ Real and present (not speculative): Yes / No
☐ Specific (not vague): Yes / No

Conclusion — Part 1: Legitimate interest identified ☐ Not identified ☐

─────────────────────────────────────────────────────

PART 2 — NECESSITY TEST

Is the processing necessary for the interest?
Describe what processing is proposed: [e.g., "Sending monthly email 
newsletters to opted-in customer contacts at business email addresses"]

Is there a less privacy-intrusive way to achieve the interest?
[If yes, describe it and explain why it is not used]
[If no, state that no less intrusive alternative exists]

Conclusion — Part 2: Processing is necessary ☐ Not necessary ☐

─────────────────────────────────────────────────────

PART 3 — BALANCING TEST

What are the data subject's reasonable expectations?
[Would they expect this processing? Context of the relationship?]

What is the likely impact on data subjects?
Severity of potential harm: ☐ Low  ☐ Medium  ☐ High

Factors in favour of processing:
□ Data subjects would reasonably expect this processing
□ The data is not sensitive
□ The impact on individuals is minimal or low
□ The processing benefits the individual or society, not only the organisation

Factors against processing:
□ Data subjects would not expect this processing
□ The data includes sensitive information
□ Only the organisation benefits commercially
□ Vulnerable individuals are affected

Are there safeguards that reduce impact?
[e.g., easy opt-out, data minimisation, no third-party sharing]

Conclusion — Part 3: Balance tips in favour of processing ☐ Against ☐

─────────────────────────────────────────────────────

OVERALL CONCLUSION

Legitimate interest applies: ☐ Yes  ☐ No

If yes — safeguards and opt-out mechanism:
[Describe the opt-out mechanism and any additional safeguards]

Review date: [Date — minimum 12 months, or when processing changes]

─────────────────────────────────────────────────────

DPDI Act — Simplified Legitimate Interest for Listed Purposes

The DPDI Act introduced a shortlist of purposes where a full balancing test is not required. For these purposes, legitimate interest can be used without completing Part 3 of the above assessment:

  • Democratic engagement activities
  • Safeguarding vulnerable people
  • Research, journalism, and education
  • Emergency response
  • Internal administrative purposes
  • Security and crime prevention

For purposes not on this list, the full three-part LIA is required.


Where to Store LIAs

Each processing activity relying on legitimate interest should have a completed LIA:

  • Stored in a central compliance document library
  • Referenced in the Article 30 RoPA for the relevant processing activity
  • Available for ICO review on request

ComplyOne covers UK GDPR and EU GDPR in one platform — identifying the specific gaps between the two frameworks.

Check your UK GDPR compliance →