Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

DPIA vs LIA: legitimate interests assessment under Article 6(1)(f) compared with a DPIA under Article 35

DPIA vs LIA: The Essential 2026 Guide to Which You Need (and When You Need Both)

DPIA vs LIA is one of the most common points of confusion in GDPR compliance, because both documents weigh your organization’s plans against the interests of the people whose data you use. They answer different questions. A legitimate interests assessment (LIA) asks whether you can rely on legitimate interests as your lawful basis at all. A data protection impact assessment (DPIA) asks whether processing that is likely to be high risk can go ahead, and with which measures. This guide sets out the differences, where the two overlap and when you need both.

DPIA vs LIA: legitimate interests assessment under Article 6(1)(f) compared with a DPIA under Article 35

DPIA vs LIA: The Short Answer

An LIA is about lawfulness: it supports your choice of Article 6(1)(f) as the lawful basis for a processing activity. A DPIA is about risk: Article 35 requires one before any processing that is likely to result in a high risk to people’s rights and freedoms, whatever the lawful basis. An LIA can exist without a DPIA, a DPIA can exist without an LIA, and for some processing you need both.

DPIA vs LIA: Side-by-Side Comparison

Legitimate interests assessment (LIA)Data protection impact assessment (DPIA)
Legal sourceArticle 6(1)(f), plus the accountability principle in Article 5(2)Article 35, with prior consultation under Article 36
TriggerYou choose legitimate interests as your lawful basisProcessing is likely to result in a high risk to individuals
Is it mandatory?Not named in the GDPR, but you need to show the test was met, and regulators expect a recordYes, where the high-risk test is met, and before the processing starts
ScopeOne purpose relying on legitimate interestsOne processing operation, or a set of similar operations
Core testPurpose, necessity and balancingDescription, necessity and proportionality, risks to individuals, measures
OutputA decision that the lawful basis applies, or does notA decision to proceed, change the design, consult the authority or stop
DPO involvementGood practiceThe DPO’s advice must be sought where one is designated (Article 35(2))
Regulator involvementNone requiredPrior consultation if high risk remains after measures (Article 36)
Typical lengthA few pagesLonger, with a risk register

What an LIA Covers

Article 6(1)(f) allows processing that is necessary for the legitimate interests of the controller or a third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the individual, in particular where the individual is a child. The European Data Protection Board’s Guidelines 1/2024 on legitimate interests, adopted in October 2024, describe three cumulative conditions, and the UK Information Commissioner’s Office uses the same three parts:

  1. Purpose test. Is there a legitimate interest? It must be lawful, clearly stated and real, not speculative.
  2. Necessity test. Is the processing necessary for that interest, or could you achieve it in a less intrusive way?
  3. Balancing test. Do the individual’s interests, rights and freedoms override yours? This is where reasonable expectations, the nature of the data, the relationship and any safeguards come in.

Three limits shape every LIA. Public authorities cannot rely on legitimate interests for processing in the performance of their tasks. Individuals can object under Article 21(1), and you must then stop unless you can show compelling legitimate grounds that override their interests. And for direct marketing the right to object is absolute: once someone objects, the marketing stops. Our legitimate interests assessment guide walks through each part with a template.

What a DPIA Covers

Article 35(7) sets the minimum content of a DPIA: a systematic description of the processing and its purposes, including, where applicable, the legitimate interest pursued; an assessment of necessity and proportionality; an assessment of the risks to individuals; and the measures to address them. Around that core sit the DPO’s advice, the views of the people concerned where appropriate, and prior consultation with the supervisory authority if high risk remains. Our DPIA guide covers the full method, and when is a DPIA required explains the screening.

Note the phrase “including, where applicable, the legitimate interest pursued”. The GDPR itself links the two documents: where legitimate interests is the lawful basis for high-risk processing, the DPIA has to describe that interest.

Where the DPIA vs LIA Question Overlaps

Both documents test necessity, and both weigh the effect on individuals. The difference is depth and purpose. The LIA balancing test asks whether the individual’s interests override yours, which decides the lawful basis. The DPIA risk assessment rates specific harms by likelihood and severity and asks which measures bring them down, which decides whether and how the processing goes ahead.

Free legitimate interests assessment

Can you rely on legitimate interests for this processing?

Check whether legitimate interests is available, set out the purpose, test necessity, weigh the impact on people from 25 scenarios and choose the safeguards that tip the balance. Built to GDPR Article 6(1)(f), free.

Start the free LIA →  or  View premium report sample

Regulators draw the connection explicitly. The EDPB guidelines say that where high risks come to light in the balancing test, the controller should consider a DPIA under Article 35. The ICO’s guidance on applying legitimate interests in practice says an LIA that shows potential for high risk is likely to mean you need a DPIA, and that you can build on or adapt the LIA into the DPIA rather than duplicating the work.

When You Need Both

This is where DPIA vs LIA stops being a choice. You need both when the lawful basis is legitimate interests and the processing is likely to be high risk. Common examples:

  • Employee monitoring. Telematics, email monitoring or productivity tracking justified by security or safety. Employees are treated as vulnerable in the relationship, and monitoring is systematic. Our DPIA example works through a telematics case built on legitimate interests.
  • Fraud prevention and profiling. Scoring customers or transactions using data from several sources.
  • Large-scale tracking or analytics. Location data, device tracking or combining datasets beyond what customers would expect.
  • CCTV and access control. Especially where it covers publicly accessible areas or uses biometrics.

In these cases, do the LIA first, or at least the purpose and necessity parts. If the balancing test turns up high risk, carry it into the DPIA screening and let the DPIA hold the detailed risk rating and measures. Cross-reference the two so a reader can follow the reasoning from one to the other.

When You Need Only One

ProcessingLawful basisLIA?DPIA?
Postal marketing to existing customersLegitimate interestsYesUsually not
Network security loggingLegitimate interestsYesUsually not, unless it becomes monitoring of staff
New patient records system in a hospitalPublic task and health care conditionsNoYes
AI shortlisting of job applicantsOften legitimate interestsYesYes
Payroll processingContract and legal obligationNoUsually not

The DPIA vs LIA decision is therefore two separate questions: which lawful basis applies (an LIA only if it is legitimate interests), and whether the processing is likely to be high risk (a DPIA if it is).

A Note on the UK: Recognised Legitimate Interests

UK GDPR now includes a list of recognised legitimate interests, such as certain safeguarding, crime prevention and emergency purposes, where the balancing test is not needed. That changes the LIA side of the comparison for those purposes, but not the DPIA side: if the processing is likely to be high risk, Article 35 still applies. Our guide to recognised legitimate interests covers the list and its conditions.

Common Mistakes

Most DPIA vs LIA mistakes come from treating the two as interchangeable:

  • Treating an LIA as a DPIA. A balancing test that says “our interests win” does not rate the risks or set measures, and will not satisfy Article 35.
  • Skipping the LIA because a DPIA exists. The DPIA should still show the purpose, necessity and balancing reasoning behind the lawful basis, or cross-refer to an LIA that does.
  • Running them in isolation. Two teams reaching different conclusions on necessity is a red flag for an auditor.
  • Relying on legitimate interests as a public authority for processing that is part of its public tasks.
  • Never revisiting either. Both should be reviewed when the purpose, data or technology changes.

Frequently Asked Questions

Is an LIA a legal requirement?

The GDPR does not name an LIA, but you must be able to show that the legitimate interests test was met. The ICO says you should do one, and a written LIA is the usual way to show it.

Can one document serve as both?

Yes, if it covers everything each requires. The ICO says you can build on or adapt an LIA into a DPIA. The combined document still needs the full Article 35(7) content, the DPO’s advice and a clear outcome.

Which comes first in the DPIA vs LIA sequence?

Usually the LIA, because the lawful basis should be settled early and its balancing test is a useful early warning of high risk. The DPIA screening can run alongside it.

Does consent remove the need for a DPIA?

No. The lawful basis decides whether you need an LIA; it does not affect the high-risk test. Processing based on consent can still need a DPIA.

If your processing needs a DPIA, our free DPIA template screens it, tests necessity, rates the risks to individuals and records the DPO’s advice and sign-off, with the legitimate interest recorded as part of the description. For LIA, DPIA and other GDPR templates in one set, see the GDPR Toolkit.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.