Form
Checklist - Legitimate Interests Assessment (LIA)
In forceView on JOIC's website Source document
Summary
This is a practical checklist published by the Jersey Office of the Information Commissioner (JOIC) to help organisations carry out a Legitimate Interests Assessment (LIA) when relying on 'legitimate interests' as the lawful basis for processing personal data under the Data Protection (Jersey) Law 2018. It is a self-assessment tool rather than a binding rule, guiding users through the standard three-part test (purpose, necessity, balancing) plus documentation steps.
- Before you start: Confirm legitimate interests is available (not for core public authority functions), check no other lawful basis is more appropriate, identify the processing clearly, and check if a DPIA is also needed.
- Purpose test: Describe the purpose, identify whose interests are involved, and confirm it is specific, lawful, ethical and not against public policy.
- Necessity test: Confirm the processing is genuinely necessary, consider less intrusive alternatives or minimisation, and check whether another lawful basis would fit better.
- Balancing test: Weigh organisational interests against individuals' rights, considering vulnerability, special category data, reasonable expectations, transparency, safeguards, and the right to object.
- Documentation and accountability: Record the LIA and its conclusions, note approval details, update Records of Processing Activities and privacy notices, and set review dates.
- When to stop: Reconsider or halt processing if the legitimate interest cannot be clearly explained, high risk data combines with a power imbalance, strong objections are likely, or residual risk remains high despite safeguards.
The checklist does not itself create new statutory deadlines; it operationalises existing accountability and lawful basis requirements under the Data Protection (Jersey) Law 2018 for organisations choosing to rely on legitimate interests.
Key obligations
- Organisations relying on legitimate interests as their lawful basis should complete and document a Legitimate Interests Assessment covering the purpose, necessity and balancing tests before processing.
- Organisations must record the outcome of the LIA, including who approved it and when.
- Organisations should update Records of Processing Activities and privacy notices to reflect the legitimate interests basis and processing details.
- Organisations should set review dates for the LIA based on the level of risk and reassess if circumstances change (e.g. new risks, objections, or power imbalances emerge).
Applies to
Data controllers under the Data Protection (Jersey) Law 2018, Organisations relying on legitimate interests as a lawful basis for processing personal data