Legitimate Interests as Legal Basis, v1.0

Specifies requirements in accordance with General Data Protection Regulation (GDPR) Art. 6(1)(f).

Assessment Step

1
Legitimate Interests as Legal Basis (LegitimateInterestsasLegalBasis)
Does the entity ensure that personal data is processed lawfully where the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) and supporting notes as appropriate to support the assessor's response to this assessment step.

Conformance Criteria (1)

Legitimate Interests as Legal Basis
The data controller must ensure that personal data is processed lawfully where processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
Citation
GDPR
Art. 6(1)(f), Recital 47–50