Guide and template

Legitimate interest assessment (LIA) template for universities

Legitimate interests is the most flexible lawful basis in the GDPR, and for universities the most misunderstood. Public authorities cannot use it for the tasks they perform, so the first question is whether your institution can rely on it at all. This guide covers that question, the three-step test as the EDPB describes it, realistic university examples and the mistakes we see most often. A free Word template is included.

Published 7 October 2026 · Sources checked 7 October 2026

The short version

Contents

  1. Can a university use legitimate interests at all?
  2. Why the answer varies by country
  3. The three-step test
  4. Doing the balancing test properly
  5. Where universities typically consider it
  6. Transparency and the right to object
  7. Common mistakes
  8. The template
  9. Sources
  10. About this page

1. Can a university use legitimate interests at all?

Article 6(1)(f) allows processing that is "necessary for the purposes of the legitimate interests pursued by the controller or by a third party", unless those interests are overridden by the data subject's interests or fundamental rights. The next sentence of Article 6(1) adds an important limit: point (f) "shall not apply to processing carried out by public authorities in the performance of their tasks".

Recital 47 gives the reason: it is for the legislator to provide by law the legal basis for public authorities to process personal data. Such processing normally relies on Article 6(1)(e) (task in the public interest or official authority) or 6(1)(c) (legal obligation), and Article 6(3) requires that basis to be laid down in Union or member state law.

The EDPB's Guidelines 1/2024 on legitimate interests, still published as version 1.0 for public consultation when we checked on 7 October 2026, explain the limits in paragraphs 98 and 99:

The UK ICO takes a similar line for the UK GDPR: a public authority cannot rely on legitimate interests for its public tasks, but legitimate interests "may potentially be available" for processing that is not part of performing those tasks.

Validemic's analysis For a university, the first step of any LIA should therefore be a screening question: is this processing part of our tasks under law (teaching, research, student administration, examinations), or a separate activity? If it is part of the tasks and the university is a public authority, stop: the LIA is the wrong tool, and the lawful basis is most likely public task or legal obligation. The template begins with this screening step.

2. Why the answer varies by country

The GDPR does not define "public authority". The answer depends on national law and on the institution's legal form. Three examples show the range:

The UK has also added a separate lawful basis, "recognised legitimate interest", for a set of pre-approved purposes. The ICO presents it as distinct from ordinary legitimate interests; it does not exist in the EU GDPR. This guide and template cover ordinary legitimate interests under Article 6(1)(f).

The examples above describe the sources as read on 7 October 2026. Check your own national law and your institution's legal form with your DPO or legal office before relying on legitimate interests.

3. The three-step test

The EDPB describes three cumulative conditions, each of which must be met. The ICO uses the same structure, calling the steps the purpose, necessity and balancing tests.

Step 1: A legitimate interest

According to the EDPB, an interest can be legitimate if it is lawful, "clearly and precisely articulated", and real and present rather than speculative. "Improving our services" is too vague; "sending event invitations to alumni who have not opted out" is specific. The interest can be the university's own or a third party's. The EDPB mentions historical or other scientific research as a context where third-party interests may be relevant, and recalls that general public interests are mainly a matter for Article 6(1)(e) or (c).

Step 2: Necessity

The processing must be necessary for the interest. The EDPB says to check whether the interest cannot reasonably be achieved "just as effectively" by other means less restrictive of people's rights, taking account of the Article 5(1) principles such as data minimisation. If such means exist, Article 6(1)(f) cannot be used.

Step 3: Balancing

The controller weighs its interest against the interests, fundamental rights and freedoms of the people concerned. Processing may go ahead only if the interest is not overridden. The next section looks at this step in detail.

The EDPB says the assessment should be made at the outset, with the involvement of the DPO where one is designated, and documented in line with the accountability principle in Article 5(2). It also stresses that Article 6(1)(f) is neither a "last resort" nor a preferred option because it seems less constraining, and that each purpose needs its own assessment.

Reviewing a vendor right now? Validemic checks the vendor's documents against GDPR and the EU AI Act and cites every finding. Try the demo workspace

4. Doing the balancing test properly

The EDPB's draft guidelines set out factors to weigh. In summary:

FactorWhat to considerUniversity example (illustrative)
Rights and interests affectedNot only privacy: also freedom of expression, non-discrimination, financial and social interests, and chilling effectsStaff communications monitoring could chill legitimate discussion.
Nature of the dataSpecial category, criminal offence or otherwise sensitive data weighs heavilyHealth data from study adjustments; location data from campus systems.
Context of the processingScale, combination of datasets, vulnerability, power imbalanceStudents and employees are in a dependent relationship with the institution.
Further consequencesPossible decisions, exclusion, reputational or financial effectsWealth screening of alumni could lead to profiling people's finances.
Reasonable expectationsRelationship, place and context of collection, the "average" person's understanding, ageRecent graduates may expect alumni newsletters; applicants who were rejected may not.
Mitigating measuresOnly measures that go beyond what the GDPR already requires countAn unconditional opt-out, shorter retention than legally required, aggregated rather than individual analysis.

Two points from the guidelines are easy to miss. First, reasonable expectations do not follow automatically from having published a privacy notice: the EDPB says that fulfilling the information obligations "is not sufficient in itself". Second, measures that the GDPR already requires, such as security, minimisation or answering rights requests, are not mitigating measures. If you add genuine extra safeguards, the EDPB says you should redo the balancing test with those safeguards in place, and if the balance still tips against the processing, Article 6(1)(f) cannot be used.

5. Where universities typically consider it

Validemic's analysis The list below shows activities where universities often ask whether legitimate interests applies. It is not a statement that the basis is available to your institution: run the public authority screening first.

6. Transparency and the right to object

Where processing is based on legitimate interests, the privacy notice must state the legitimate interests pursued (Article 13(1)(d) or Article 14(2)(b)). WP29's transparency guidelines say the specific interest must be identified and, as best practice, information from the balancing test can also be provided, for example in a layered notice. See our privacy notice guide for wording.

People have the right to object under Article 21(1). The controller must then stop unless it demonstrates compelling legitimate grounds that override the person's interests, rights and freedoms, or the processing is needed for legal claims. For direct marketing the right to object is absolute (Article 21(2)). Build the objection route into the process before you start, and record objections in the LIA review log.

7. Common mistakes

  1. Skipping the public authority question. Writing a careful LIA for processing that is part of the university's statutory tasks, where Article 6(1)(f) is excluded.
  2. One LIA for many purposes. The EDPB says processing relying on Article 6(1)(f) should not encompass several purposes without assessing each one.
  3. Vague interests. "Administration" or "service improvement" fails the "clearly and precisely articulated" test.
  4. Necessity on autopilot. Not asking whether aggregated data, a smaller dataset or a shorter retention period would do.
  5. Counting compliance as mitigation. Encryption and access controls are required anyway; they do not tip the balance.
  6. Written after the fact. The EDPB says the assessment should be done before the processing starts.
  7. Forgetting the vendor. The impact on people depends on what the tool provider does with the data. A vendor that reuses data for its own purposes changes the balance. See our vendor assessment guide.
  8. No link to the DPIA. If the processing is likely to be high risk, an Article 35 DPIA is needed as well. Our DPIA screening tool and DPIA template help.

8. The template

The legitimate interest assessment template is a Word document containing:

One filled example (alumni event invitations at a hypothetical institution) shows the expected level of detail. Delete it before use.

The template follows Article 6(1)(f) GDPR and the EDPB's draft Guidelines 1/2024 (version 1.0 for public consultation) as read on 7 October 2026. If the EDPB adopts a final version, check whether the method has changed. It is not legal advice.

Sources

  1. Regulation (EU) 2016/679 (GDPR), Articles 5, 6, 13, 14 and 21 and Recital 47, Official Journal text (retrieved 7 October 2026).
  2. EDPB Guidelines 1/2024 on processing of personal data based on Article 6(1)(f) GDPR, version 1.0 adopted for public consultation on 8 October 2024, in particular paragraphs 6 to 17, 24, 25, 33 to 38, 51 to 60, 98, 99, 106 and 107 (retrieved 7 October 2026).
  3. ICO: How do we apply legitimate interests in practice? (retrieved 7 October 2026).
  4. ICO: When can we rely on legitimate interests? (retrieved 7 October 2026).
  5. Article 29 Working Party, Guidelines on transparency (WP260 rev.01), endorsed by the EDPB, Annex (retrieved 7 October 2026).
  6. Data Protection Act 2018, section 7 and Freedom of Information Act 2000, Schedule 1, Part IV (retrieved 7 October 2026).
  7. University of Glasgow: Development and Alumni Office privacy notice (retrieved 7 October 2026).
  8. Kommittédirektiv Dir. 2026:5, En mer ändamålsenlig organisationsform för statliga universitet och högskolor (retrieved 7 October 2026).
  9. Stockholm University: Personuppgiftsbehandling vid Stockholms universitet (retrieved 7 October 2026).
  10. Health Research Authority: Patient data and research leaflet (retrieved 7 October 2026).

About this page

Sources checked on 7 October 2026. The legal text was read in its Official Journal version; guidance comes from the EDPB, the Article 29 Working Party and the ICO; institutional examples come from the organisations' own pages. Statements labelled as Validemic's analysis are our interpretation, and the template example is hypothetical. This page is not legal advice. If you spot an error, or your institution's position has changed, please contact us and we will correct it.

Frequently asked questions

Can a public university rely on legitimate interests?

Not for processing in the performance of its tasks: the last subparagraph of Article 6(1) GDPR excludes this. The EDPB's draft guidelines say public authorities may rely on it only in exceptional and limited cases where the processing is not linked to their specific tasks and national law permits, and that this should be documented internally. Whether a university counts as a public authority depends on national law.

Is an LIA a legal requirement?

The GDPR does not name a document called an LIA, but the controller must be able to demonstrate compliance (Article 5(2)). The EDPB says the assessment should be done before the processing and documented, and the ICO says you should record your LIA and its outcome.

What are the three steps of a legitimate interest assessment?

First, identify a legitimate interest that is lawful, clearly articulated and real and present. Second, check that the processing is necessary for that interest and that it cannot reasonably be achieved by less intrusive means. Third, balance the interest against the interests, rights and freedoms of the people concerned.

Do we have to tell people we rely on legitimate interests?

Yes. Articles 13(1)(d) and 14(2)(b) require the privacy notice to state the legitimate interests pursued. WP29 recommends, as best practice, also giving people information from the balancing test. People also have a right to object under Article 21(1).

Is an LIA the same as a DPIA?

No. An LIA decides whether Article 6(1)(f) is a valid lawful basis. A DPIA under Article 35 assesses high-risk processing whatever the lawful basis. A high-risk activity relying on legitimate interests may need both.

How often should an LIA be reviewed?

The ICO says to review it regularly and refresh it if anything significant changes. Sensible triggers are a new purpose, new data categories, a new vendor or a complaint or objection.