Data Protection Impact Assessment (DPIA) vs. Legitimate Interest Assessment (LIA)

1. Data Protection Impact Assessment (DPIA)

Legal Requirement (GDPR, Article 35)

A DPIA is required where processing is “likely to result in a high risk to the rights and freedoms of natural persons.”

Triggers include:

  • Large-scale processing of sensitive (special category) data (e.g., health, biometric, genetic).
  • Systematic monitoring of individuals (e.g., CCTV, profiling, online tracking).
  • Large-scale use of innovative technologies (e.g., AI, IoT, facial recognition).
  • Combining datasets that could lead to invasive profiling.

DPIA Requirements:

  • Describe the nature, scope, context, and purpose of processing.
  • Assess necessity and proportionality of the processing.
  • Identify risks to data subjects (e.g., confidentiality, integrity, availability, rights).
  • Identify measures to mitigate those risks (technical, organizational, legal safeguards).
  • Document outcomes and residual risks.
  • Involve the Data Protection Officer (DPO) where appointed.
  • If high risk remains unmitigated → consult the Supervisory Authority.

2. Legitimate Interest Assessment (LIA)

Legal Requirement (GDPR, Article 6(1)(f))

When relying on legitimate interests as a lawful basis for processing, a controller must balance:

  1. Purpose test → What is the legitimate interest pursued?
  2. Necessity test → Is the processing necessary to achieve it, or could a less intrusive means be used?
  3. Balancing test → Do the interests/rights of the individual override the organization's interest?

LIA Requirements:

  • Define the legitimate interest (e.g., fraud prevention, network security).
  • Assess necessity and proportionality.
  • Assess potential impact on data subjects.
  • Identify safeguards (opt-out mechanisms, minimal data collection, transparency).
  • Document the reasoning as proof of compliance (accountability principle).

3. Practical Examples

Example A: DPIA

Scenario: A hospital introduces AI-based image recognition to analyse X-rays for diagnosis.

  • Description: Large-scale processing of sensitive health data using innovative technology.
  • Risks: Misdiagnosis, discrimination, data breaches, unauthorized access.
  • Mitigation: Encryption, pseudonymization, strong access controls, regular audits, human oversight in diagnosis.
  • Outcome: Risks mitigated to acceptable level. DPIA documented and updated regularly.

Example B: LIA

Scenario: A retail company installs CCTV cameras in its stores for security.

  • Purpose Test: Prevent theft and ensure staff/customer safety.
  • Necessity Test: CCTV is necessary, as less intrusive methods (e.g., random bag checks) are less effective.
  • Balancing Test: Individuals' privacy is impacted, but safeguards (limited access to recordings, signage, retention limits of 30 days) protect their rights.
  • Outcome: Legitimate interest is lawful basis. LIA documented.

4. At What Stage Should They Be Conducted?

  • DPIA:
    • Before starting high-risk processing (privacy by design principle, Art. 25).
    • During system/project planning stages (new technology, new process).
    • Reviewed periodically, especially if risk environment changes (e.g., new threats, expanded scope).
  • LIA:
    • Before relying on legitimate interest as a lawful basis (i.e., at the justification stage of processing).
    • Should be part of the lawful basis assessment, before processing begins.
    • Updated if processing purpose, scope, or risk changes.

✅ Summary

  • DPIA → Required where high-risk processing occurs (mandatory, detailed risk-based analysis).
  • LIA → Required whenever legitimate interest is claimed as a lawful basis (balancing exercise).
  • Stage → Both must be conducted before processing begins and reviewed periodically.