DPIA vs LIA is one of the most common points of confusion in GDPR compliance, because both documents weigh your organization’s plans against the interests of the people whose data you use. They answer different questions. A legitimate interests assessment (LIA) asks whether you can rely on legitimate interests as your lawful basis at all. A data protection impact assessment (DPIA) asks whether processing that is likely to be high risk can go ahead, and with which measures. This guide sets out the differences, where the two overlap and when you need both.

DPIA vs LIA: The Short Answer
An LIA is about lawfulness: it supports your choice of Article 6(1)(f) as the lawful basis for a processing activity. A DPIA is about risk: Article 35 requires one before any processing that is likely to result in a high risk to people’s rights and freedoms, whatever the lawful basis. An LIA can exist without a DPIA, a DPIA can exist without an LIA, and for some processing you need both.
DPIA vs LIA: Side-by-Side Comparison
| Legitimate interests assessment (LIA) | Data protection impact assessment (DPIA) | |
|---|---|---|
| Legal source | Article 6(1)(f), plus the accountability principle in Article 5(2) | Article 35, with prior consultation under Article 36 |
| Trigger | You choose legitimate interests as your lawful basis | Processing is likely to result in a high risk to individuals |
| Is it mandatory? | Not named in the GDPR, but you need to show the test was met, and regulators expect a record | Yes, where the high-risk test is met, and before the processing starts |
| Scope | One purpose relying on legitimate interests | One processing operation, or a set of similar operations |
| Core test | Purpose, necessity and balancing | Description, necessity and proportionality, risks to individuals, measures |
| Output | A decision that the lawful basis applies, or does not | A decision to proceed, change the design, consult the authority or stop |
| DPO involvement | Good practice | The DPO’s advice must be sought where one is designated (Article 35(2)) |
| Regulator involvement | None required | Prior consultation if high risk remains after measures (Article 36) |
| Typical length | A few pages | Longer, with a risk register |
What an LIA Covers
Article 6(1)(f) allows processing that is necessary for the legitimate interests of the controller or a third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the individual, in particular where the individual is a child. The European Data Protection Board’s Guidelines 1/2024 on legitimate interests, adopted in October 2024, describe three cumulative conditions, and the UK Information Commissioner’s Office uses the same three parts:
- Purpose test. Is there a legitimate interest? It must be lawful, clearly stated and real, not speculative.
- Necessity test. Is the processing necessary for that interest, or could you achieve it in a less intrusive way?
- Balancing test. Do the individual’s interests, rights and freedoms override yours? This is where reasonable expectations, the nature of the data, the relationship and any safeguards come in.
Three limits shape every LIA. Public authorities cannot rely on legitimate interests for processing in the performance of their tasks. Individuals can object under Article 21(1), and you must then stop unless you can show compelling legitimate grounds that override their interests. And for direct marketing the right to object is absolute: once someone objects, the marketing stops. Our legitimate interests assessment guide walks through each part with a template.
What a DPIA Covers
Article 35(7) sets the minimum content of a DPIA: a systematic description of the processing and its purposes, including, where applicable, the legitimate interest pursued; an assessment of necessity and proportionality; an assessment of the risks to individuals; and the measures to address them. Around that core sit the DPO’s advice, the views of the people concerned where appropriate, and prior consultation with the supervisory authority if high risk remains. Our DPIA guide covers the full method, and when is a DPIA required explains the screening.
Note the phrase “including, where applicable, the legitimate interest pursued”. The GDPR itself links the two documents: where legitimate interests is the lawful basis for high-risk processing, the DPIA has to describe that interest.
Where the DPIA vs LIA Question Overlaps
Both documents test necessity, and both weigh the effect on individuals. The difference is depth and purpose. The LIA balancing test asks whether the individual’s interests override yours, which decides the lawful basis. The DPIA risk assessment rates specific harms by likelihood and severity and asks which measures bring them down, which decides whether and how the processing goes ahead.
Free legitimate interests assessment
Can you rely on legitimate interests for this processing?
Check whether legitimate interests is available, set out the purpose, test necessity, weigh the impact on people from 25 scenarios and choose the safeguards that tip the balance. Built to GDPR Article 6(1)(f), free.
Regulators draw the connection explicitly. The EDPB guidelines say that where high risks come to light in the balancing test, the controller should consider a DPIA under Article 35. The ICO’s guidance on applying legitimate interests in practice says an LIA that shows potential for high risk is likely to mean you need a DPIA, and that you can build on or adapt the LIA into the DPIA rather than duplicating the work.
When You Need Both
This is where DPIA vs LIA stops being a choice. You need both when the lawful basis is legitimate interests and the processing is likely to be high risk. Common examples:
- Employee monitoring. Telematics, email monitoring or productivity tracking justified by security or safety. Employees are treated as vulnerable in the relationship, and monitoring is systematic. Our DPIA example works through a telematics case built on legitimate interests.
- Fraud prevention and profiling. Scoring customers or transactions using data from several sources.
- Large-scale tracking or analytics. Location data, device tracking or combining datasets beyond what customers would expect.
- CCTV and access control. Especially where it covers publicly accessible areas or uses biometrics.
In these cases, do the LIA first, or at least the purpose and necessity parts. If the balancing test turns up high risk, carry it into the DPIA screening and let the DPIA hold the detailed risk rating and measures. Cross-reference the two so a reader can follow the reasoning from one to the other.
When You Need Only One
| Processing | Lawful basis | LIA? | DPIA? |
|---|---|---|---|
| Postal marketing to existing customers | Legitimate interests | Yes | Usually not |
| Network security logging | Legitimate interests | Yes | Usually not, unless it becomes monitoring of staff |
| New patient records system in a hospital | Public task and health care conditions | No | Yes |
| AI shortlisting of job applicants | Often legitimate interests | Yes | Yes |
| Payroll processing | Contract and legal obligation | No | Usually not |
The DPIA vs LIA decision is therefore two separate questions: which lawful basis applies (an LIA only if it is legitimate interests), and whether the processing is likely to be high risk (a DPIA if it is).
A Note on the UK: Recognised Legitimate Interests
UK GDPR now includes a list of recognised legitimate interests, such as certain safeguarding, crime prevention and emergency purposes, where the balancing test is not needed. That changes the LIA side of the comparison for those purposes, but not the DPIA side: if the processing is likely to be high risk, Article 35 still applies. Our guide to recognised legitimate interests covers the list and its conditions.
Common Mistakes
Most DPIA vs LIA mistakes come from treating the two as interchangeable:
- Treating an LIA as a DPIA. A balancing test that says “our interests win” does not rate the risks or set measures, and will not satisfy Article 35.
- Skipping the LIA because a DPIA exists. The DPIA should still show the purpose, necessity and balancing reasoning behind the lawful basis, or cross-refer to an LIA that does.
- Running them in isolation. Two teams reaching different conclusions on necessity is a red flag for an auditor.
- Relying on legitimate interests as a public authority for processing that is part of its public tasks.
- Never revisiting either. Both should be reviewed when the purpose, data or technology changes.
Frequently Asked Questions
Is an LIA a legal requirement?
The GDPR does not name an LIA, but you must be able to show that the legitimate interests test was met. The ICO says you should do one, and a written LIA is the usual way to show it.
Can one document serve as both?
Yes, if it covers everything each requires. The ICO says you can build on or adapt an LIA into a DPIA. The combined document still needs the full Article 35(7) content, the DPO’s advice and a clear outcome.
Which comes first in the DPIA vs LIA sequence?
Usually the LIA, because the lawful basis should be settled early and its balancing test is a useful early warning of high risk. The DPIA screening can run alongside it.
Does consent remove the need for a DPIA?
No. The lawful basis decides whether you need an LIA; it does not affect the high-risk test. Processing based on consent can still need a DPIA.
If your processing needs a DPIA, our free DPIA template screens it, tests necessity, rates the risks to individuals and records the DPO’s advice and sign-off, with the legitimate interest recorded as part of the description. For LIA, DPIA and other GDPR templates in one set, see the GDPR Toolkit.