A legitimate interests assessment example shows what the finished record should say, which the GDPR itself never spells out: Article 6(1)(f) sets the test, not the form. This guide walks through a complete legitimate interests assessment example for a fictional retailer that wants to send personalised offers to its loyalty card customers, from the screening to the conclusion, with the safeguards that tipped the balance.
It follows the three-part test the regulators use: the purpose test, the necessity test and the balancing test, as set out in the EDPB Guidelines 1/2024 on legitimate interest and the UK ICO’s guidance. Our guide to the legitimate interests assessment explains the test itself; this is the worked version.

What a Legitimate Interests Assessment Must Show
Article 6(1)(f) allows processing that is necessary for the legitimate interests of the controller or a third party, except where those interests are overridden by the interests or fundamental rights and freedoms of the people concerned, in particular where they are children. An LIA records three things:
- Purpose: there is a legitimate interest, which is lawful, clearly set out and real.
- Necessity: the processing is needed for that interest, and a less intrusive way would not do.
- Balance: the people’s interests, rights and freedoms do not override it, taking account of their reasonable expectations and the safeguards in place.
The accountability principle in Article 5(2) means you must be able to show all three, which is why a written assessment is expected even though the GDPR does not name one.
The Organization in This Legitimate Interests Assessment Example
Northfield Home Supplies (a fictional company) runs 60 home and garden stores and an online shop in the UK and Ireland. About 410,000 adults hold its loyalty card. Northfield wants to send each member up to two postal and four email offers a month, chosen from the product ranges they have bought from before, using five years of purchase history.
Step 1: Screening
Every legitimate interests assessment example should start by checking that legitimate interests is available at all, before the three-part test. Northfield’s screening:
| Question | Answer | Why |
|---|---|---|
| Public authority performing its tasks? | No | A private company |
| Do other rules require consent? | No | Emails go only to customers covered by the soft opt-in; postal offers need no consent |
| Does another basis fit better? | No | Offers are not necessary for the loyalty contract, and no law requires them |
| UK recognised legitimate interest? | No | Marketing is not one of the Annex 1 conditions |
| Factors calling for extra care | 2 of 7 | Profiling and direct marketing |
The second question matters most for marketing. Where the ePrivacy rules (PECR in the UK) require consent for emails or texts, legitimate interests cannot make them lawful; the ICO says plainly that you must not use it in that case. Northfield’s emails qualify for the soft opt-in because they go to its own customers, about similar products, and every customer was offered a way to refuse when they signed up and is offered one in every message.
Step 2: The Purpose Test
| Element | What Northfield recorded |
|---|---|
| Purpose | Offers chosen from the ranges each member has bought from before |
| Interest, and whose | Northfield’s commercial interest in marketing to its own customers; members benefit from relevant offers |
| Benefit | Targeted offers redeemed at about three times the rate of the full catalogue, with half the paper |
| Why it is legitimate | Lawful when the ePrivacy rules are met and people can object; specific and present, not speculative |
| Data and source | Name, address, email, card number and five years of purchases, all collected from members directly |
| People and relationship | Adult loyalty members who joined a scheme that promises member offers |
A commercial interest can be legitimate. Recital 47 of the GDPR says direct marketing may be regarded as a legitimate interest, and in October 2024 the Court of Justice confirmed, in the Royal Dutch Lawn Tennis Association case (C-621/22), that a purely commercial interest can qualify, provided it is lawful.
Step 3: The Necessity Test
| Question | Answer | Note |
|---|---|---|
| Does the processing help achieve the purpose? | Yes | A 2025 test showed the difference in redemption |
| Is it reasonable and proportionate? | Yes | A monthly cap on offers |
| Is there no less intrusive way? | Partly | Category-level segments work almost as well with less detail |
| Is only the data needed used? | Partly | Five years of history is more than offers need |
Two “partly” answers became safeguards. Necessity does not mean the processing is indispensable, but the EDPB expects it to be targeted: if a less intrusive way achieves the same result, legitimate interests does not cover the extra processing.
Step 4: The Balancing Test in This Legitimate Interests Assessment Example
| Question | Answer | Note |
|---|---|---|
| Would people reasonably expect it? | Yes | The sign-up page says offers are based on purchases |
| Are they told, with the interest named? | Partly | The notice covers marketing, not the profiling |
| Can they object easily, and does marketing stop when they do? | Yes | Unsubscribe in every email; one suppression list for post and email |
| Are children protected, or not involved? | Yes | The scheme is for adults only |
| Do safeguards limit the impact? | Partly | Sensitive ranges still feed the segments |
| Is any imbalance of power considered? | Yes | Customers can shop without the card |
Northfield then rated the ways the processing could affect its customers, for the customers and not for the business, on 1 to 5 scales:
| Impact on customers | Level before | Safeguard (GDPR) | Level after |
|---|---|---|---|
| Offers based on mobility, continence or first aid purchases suggest a health condition | 12 High | Exclude sensitive ranges from segments (Art 9, 25) | 4 Low |
| Five years of item-level history builds a detailed household profile | 12 High | Two years only; category-level segments (Art 5(1)(c)) | 6 Medium |
| The privacy notice does not explain the profiling | 12 High | Update the notice and sign-up page (Art 13, 21(4)) | 6 Medium |
| A postal offer arrives after an objection | 8 Medium | Daily suppression file to the printing house (Art 21(3), 28) | 4 Low |
Rating the impact on people, not the business, is what makes this a balancing test rather than a marketing risk log. The health-related offers were the decisive item: a customer who bought a walking aid for a parent does not expect to be sent mobility offers, and several members of a customer panel said so.
Step 5: Conclusion
The DPO advised that legitimate interests can apply if the sensitive ranges are excluded, history is cut to two years and the privacy notice explains the profiling and the right to object before the next campaign. Northfield followed the advice in full. The conclusion of this legitimate interests assessment example, approved by the Chief Customer Officer: legitimate interests applies once the planned safeguards are in place, with a review in a year or earlier if the offers change.
Two things carry through from the LIA. The privacy notice must name the legitimate interest (Article 13(1)(d)), and the right to object to direct marketing must be brought to people’s attention clearly and separately, at the latest in the first communication (Article 21(4)). Once someone objects to direct marketing, it stops, with no balancing at all.
Common Mistakes This Legitimate Interests Assessment Example Avoids
- Skipping the screening. An LIA written for email marketing that needs consent under PECR is wasted work.
- A purpose too vague to test. “Improving customer experience” cannot be balanced; “offers from ranges a member has bought from” can.
- Balancing without safeguards. The safeguards are what tip the balance; list them and make them happen.
- Ignoring what the data reveals. Ordinary purchase data can suggest health, religion or family circumstances.
- Writing it once. New data, new channels or new segments call for a review.
Frequently Asked Questions
Can I reuse this legitimate interests assessment example as a template?
Reuse the structure, not the answers. The balance depends on your purpose, your data and your relationship with the people concerned.
How long should an LIA be?
As long as the risk needs. This legitimate interests assessment example runs to a few pages because profiling and marketing call for care; a low-risk purpose, such as internal administration, can be recorded in a page.
Does every use of legitimate interests need its own LIA?
One assessment per purpose. Related processing for the same purpose can share one; a different purpose needs its own test.
Do I also need a DPIA?
Only if the processing is likely to be high risk. Large-scale profiling can be, so screen for it. Our comparison of DPIA vs LIA explains how the two fit together.
Is it different in the UK?
The test is the same, but since 5 February 2026 the UK GDPR also has recognised legitimate interests, which need no balancing test. Marketing is not one of them.
To build your own in the same order, use our free legitimate interests assessment template, which screens the basis, runs the three tests, rates the impact on people and records the conclusion. For the privacy notice, records of processing and policies around it, see the GDPR Toolkit.