Performing a Legitimate Interests Assessment (LIA)
A Legitimate Interests Assessment (LIA) is a self-conducted evaluation required when a company processes personal data based on legitimate interests rather than legal obligations, contracts, or data subject consent. This process is comparable to a driver's safety check: You must verify your legal right to operate (bring your driver's license) and take protective measures (fasten your seatbelt).
Prerequisites
- In a DI, the legal entity is configured as the Controller.
- In the DI, the Legal Basis for Processing General Personal Data is set to Legitimate Interests.
- In the DI, the data subject is located in the region where the GDPR applies. (This is automatically checked by the system).
Create a LIA
- Log in to the PCMC.
- In the navigation pane, choose .
- Click Create LIA in the upper left corner of the page.
- Enter a name in the LIA Name text box. Select a code from the S Code drop-down list box. In the Data Inventory area, select a DI to be bound. If you open this page by clicking a to-do task, the DI in the task will be bound by default.
- Click Next Step. The Edit LIA page is displayed.
- Configure Has the legitimate interests assessment been completed offline?
- If you have completed the assessment offline, select Yes.
- Click Add File to upload the report attachment for review.
- Click Submit Review.
- If you have not completed the assessment, select No.
- Answer the following questions online:
- Select the data processing activity you are handling: Check whether the DI bound to the LIA is correct.
- Why are you processing this data?: Select the processing purposes and briefly explain them.
- What do you expect to gain from this data processing activity?: Answer it based on actual conditions.
- What impact would there be if you could not proceed with this activity?: Check whether the activity has an impact on services or operations. If it does, briefly describe the impact.
- Do your processing activities comply with relevant data protection regulations, such as the EU GDPR or local personal information protection laws?: Check whether data protection measures are taken in accordance with relevant laws and regulations. If they are, briefly describe the specific laws and regulations, for example, personal information is collected in compliance with the user profile requirements of the GDPR.
- Does this processing process actually help promote the identified purpose?: Check whether the collection of personal information is necessary for achieving the corresponding purposes. If it is, explain the reason.
- Is the current processing activity a reasonable processing method?: Check whether the processing activity is reasonable. If it is not, confirm with the legal affairs personnel about whether to use this method.
- Is there another less intrusive way to achieve the same result?: Check whether the processing activity complies with the data minimization principle. For example, evaluate whether the same objective can be achieved by collecting less personal information.
- What is the nature of your relationship with the data subjects?: Select a business relationship.
- What sensitive or private data did you use?: Check whether the collected personal information fields contain particularly sensitive personal information. The answer must be consistent with that provided in the DI.
- Would people expect you to use their data in the way you plan?: Check whether the data subjects are willing to have their personal data processed in this way.
- Are you willing to explain your use of data to people?: Check whether the processing methods can be legally justified and clearly explained if a data subject exercises their right to information.
- Might some people object or find it intrusive?: Check whether the data subjects are willing to have their personal data processed in this way.
- What might be the impact on individuals?: Select from the provided options.
- What is the impact of the processing purpose on data subjects?: Select from the provided options.
- Are you processing children's data?: Select from the provided options.
- Is this type of data subject particularly vulnerable to loss?: Check whether there is a high risk of infringement on the rights of data subjects.
- Have you taken any protective measures to minimize this impact?: Specify measures based on actual conditions, such as data encryption and local storage.
- Is an opt-out option provided?: Check whether a straightforward mechanism is provided for individuals to object to or terminate processing based on their "legitimate interests" at any time and without cost, for example, unsubscription.
- Have all risks been mitigated?: Check whether protection measures have been taken for each identified risk to reduce the risks to an acceptable level.
- Assessment Conclusion: The assessment consists of a purpose test, a necessity test, and a balance test. Based on these test results, conclude whether the processing activity is supported by legitimate interests.
- Click Next Step. The Generate Report page is displayed. Confirm the content and click Submit Review to submit the application for approval.
- Answer the following questions online:
- If you have completed the assessment offline, select Yes.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot
