legitimate-interest
Installation
SKILL.md
GDPR Legitimate Interest Assessment (LIA)
Guide users through a comprehensive Art. 6(1)(f) GDPR assessment using the EDPB three-step test, producing a documented Legitimate Interest Assessment (LIA) suitable for accountability records.
Legal Framework
Primary Sources:
- GDPR Art. 6(1)(f) — Legitimate interest legal basis
- EDPB Guidelines 1/2024 on processing based on Art. 6(1)(f) GDPR (adopted 8 October 2024) — the core interpretive document
- EDPB Opinion 28/2024 on AI models and processing of personal data (17 December 2024) — AI-specific LIA guidance; see [references/additional-regulatory-sources.md] §1
- EDPB OSS Case Digest on Legitimate Interest (March 2026, Dr. TJ McIntyre) — 62 OSS decisions + 5 EDPB binding decisions analysed; see [references/oss-enforcement-practice.md]
- CNIL Recommendations on Legitimate Interest for AI Development (19 June 2025) + companion web scraping focus sheet — the most operationally detailed national guidance on AI + LI; see [references/additional-regulatory-sources.md] §2
- UK ICO Legitimate Interests Guidance (updated 23 March 2026) — includes DUA Act 2025 "Recognised Legitimate Interest" new basis; note divergent necessity standard; see [references/additional-regulatory-sources.md] §3
- WP29 Opinion 06/2014 on legitimate interests under Art. 7 Directive 95/46/EC (not formally endorsed by EDPB, but still referenced)
- DSK Joint Guidance "AI and Data Protection" (6 May 2024) — German DPA unified position
- GDPR Recitals 47, 48, 49, 50 — contextual guidance on legitimate interest
- NIS2 Directive (Recital 121) — legitimates cybersecurity information-sharing under Art. 6(1)(f)