Data Protection Impact Assessment (DPIA) vs. Legitimate Interest Assessment (LIA)
1. Data Protection Impact Assessment (DPIA)
Legal Requirement (GDPR, Article 35)
A DPIA is required where processing is “likely to result in a high risk to the rights and freedoms of natural persons.â€
Triggers include:
- Large-scale processing of sensitive (special category) data (e.g., health, biometric, genetic).
- Systematic monitoring of individuals (e.g., CCTV, profiling, online tracking).
- Large-scale use of innovative technologies (e.g., AI, IoT, facial recognition).
- Combining datasets that could lead to invasive profiling.
DPIA Requirements:
- Describe the nature, scope, context, and purpose of processing.
- Assess necessity and proportionality of the processing.
- Identify risks to data subjects (e.g., confidentiality, integrity, availability, rights).
- Identify measures to mitigate those risks (technical, organizational, legal safeguards).
- Document outcomes and residual risks.
- Involve the Data Protection Officer (DPO) where appointed.
- If high risk remains unmitigated → consult the Supervisory Authority.
2. Legitimate Interest Assessment (LIA)
Legal Requirement (GDPR, Article 6(1)(f))
When relying on legitimate interests as a lawful basis for processing, a controller must balance:
- Purpose test → What is the legitimate interest pursued?
- Necessity test → Is the processing necessary to achieve it, or could a less intrusive means be used?
- Balancing test → Do the interests/rights of the individual override the organization's interest?
LIA Requirements:
- Define the legitimate interest (e.g., fraud prevention, network security).
- Assess necessity and proportionality.
- Assess potential impact on data subjects.
- Identify safeguards (opt-out mechanisms, minimal data collection, transparency).
- Document the reasoning as proof of compliance (accountability principle).
3. Practical Examples
Example A: DPIA
Scenario: A hospital introduces AI-based image recognition to analyse X-rays for diagnosis.
- Description: Large-scale processing of sensitive health data using innovative technology.
- Risks: Misdiagnosis, discrimination, data breaches, unauthorized access.
- Mitigation: Encryption, pseudonymization, strong access controls, regular audits, human oversight in diagnosis.
- Outcome: Risks mitigated to acceptable level. DPIA documented and updated regularly.
Example B: LIA
Scenario: A retail company installs CCTV cameras in its stores for security.
- Purpose Test: Prevent theft and ensure staff/customer safety.
- Necessity Test: CCTV is necessary, as less intrusive methods (e.g., random bag checks) are less effective.
- Balancing Test: Individuals' privacy is impacted, but safeguards (limited access to recordings, signage, retention limits of 30 days) protect their rights.
- Outcome: Legitimate interest is lawful basis. LIA documented.
4. At What Stage Should They Be Conducted?
- DPIA:
- Before starting high-risk processing (privacy by design principle, Art. 25).
- During system/project planning stages (new technology, new process).
- Reviewed periodically, especially if risk environment changes (e.g., new threats, expanded scope).
- LIA:
- Before relying on legitimate interest as a lawful basis (i.e., at the justification stage of processing).
- Should be part of the lawful basis assessment, before processing begins.
- Updated if processing purpose, scope, or risk changes.
✅ Summary
- DPIA → Required where high-risk processing occurs (mandatory, detailed risk-based analysis).
- LIA → Required whenever legitimate interest is claimed as a lawful basis (balancing exercise).
- Stage → Both must be conducted before processing begins and reviewed periodically.