Agent skill

Legitimate Interest Lia

by mukul975 in mukul975/Privacy-Data-Protection-Skills

Guides the three-part Legitimate Interest Assessment (LIA) required under GDPR Article 6(1)(f): purpose test, necessity test, and balancing test.

Apache-2.0Auto-check passedLegal & Compliance

Install Legitimate Interest Lia

skills CLI
$ npx skills add mukul975/Privacy-Data-Protection-Skills --skill legitimate-interest-lia -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Privacy-Data-Protection-Skills legitimate-interest-lia --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Privacy-Data-Protection-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/privacy/legitimate-interest-lia .claude/skills/legitimate-interest-lia && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
legitimate-interest-lia
GitHub stars
301
Token cost
~1.9k tokens
SKILL.md length
980 words
Files
5 (incl. scripts, references, assets)
Skills in repo
280
Repo updated
First seen
Licence
Apache-2.0

At a glance

Guides the three-part Legitimate Interest Assessment (LIA) required under GDPR Article 6(1)(f): purpose test, necessity test, and balancing test.

  • Works in 4 steps: Identify the interest: What specific… → Verify legitimacy: The interest must be → Common legitimate interests recognised… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Overview, Part 1: Purpose Test, Part 2: Necessity Test and Part 3: Balancing Test, plus 2 more sections
  • Runs Python scripts from its folder

What it does

Legitimate Interest Lia is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides the three-part Legitimate Interest Assessment (LIA) required under GDPR Article 6(1)(f): purpose test, necessity test, and balancing test. Activate when evaluating legitimate interest as a lawful basis, conducting LIA reviews, or documenting proportionality analysis. Keywords: LIA, legitimate interest, balancing test, necessity test, purpose test, Article 6(1)(f).

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/standards.md` and `references/workflows.md`).

It sits in Legal & Compliance, covering Privacy and GDPR. The repository describes itself as: 282+ structured privacy & data protection skills for AI agents. GDPR, CCPA, EU AI Act, HIPAA, LGPD, PIPL, DPDP Act. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Privacy and GDPR

Example prompts

  • “Use the legitimate-interest-lia skill to guide the three-part Legitimate Interest Assessment (LIA) required under GDPR Article 6(1)(f): purpose…”
  • “/legitimate-interest-lia”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Identify the interest: What specific interest does the controller or third party pursue? The interest must be concrete and articulated…
  2. Verify legitimacy: The interest must be
  3. Common legitimate interests recognised by the GDPR
  4. Document the interest: State the interest in a single clear sentence that could be understood by a non-expert.

What it can do on your machine

Read from SKILL.md and the folder at commit 9b2ef9e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Legitimate Interest Lia loads about 1.9k tokens when it runs, and up to ~5.2k if it reads all its reference files. Until then it costs about 99 tokens; SKILL.md has 980 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~99
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Privacy-Data-Protection-Skills at commit 9b2ef9e, republished under its Apache-2.0 licence (© mukul975). 980 words, ~1,947 tokens.

Download SKILL.mdSave it as .claude/skills/legitimate-interest-lia/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
legitimate-interest-lia
description
Guides the three-part Legitimate Interest Assessment (LIA) required under GDPR Article 6(1)(f): purpose test, necessity test, and balancing test. Activate when evaluating legitimate interest as a lawful basis, conducting LIA reviews, or documenting proportionality analysis. Keywords: LIA, legitimate interest, balancing test, necessity test, purpose test, Article 6(1)(f).
license
Apache-2.0
metadata.author
mukul975
metadata.version
1.0
metadata.domain
privacy
metadata.subdomain
gdpr-compliance
metadata.tags
gdpr, legitimate-interest, lia, balancing-test, article-6, proportionality

Performing Legitimate Interest Assessment

Overview

When a controller relies on Art. 6(1)(f) as the lawful basis for processing, a Legitimate Interest Assessment (LIA) must be conducted and documented before processing begins. The LIA consists of three sequential tests derived from the wording of Art. 6(1)(f) and elaborated in WP29 Opinion 06/2014. If any test fails, legitimate interest cannot be relied upon, and an alternative lawful basis must be found or processing must not proceed.

Part 1: Purpose Test

The purpose test establishes whether the controller (or a third party) has a legitimate interest that is real, lawful, and clearly articulated.

Assessment Criteria
  1. Identify the interest: What specific interest does the controller or third party pursue? The interest must be concrete and articulated, not vague or hypothetical.

  2. Verify legitimacy: The interest must be:

    • Lawful (not prohibited by any law)
    • Sufficiently specific to be assessed
    • Real and present (not speculative or future)
    • Consistent with what data subjects would reasonably expect
  3. Common legitimate interests recognised by the GDPR:

    • Fraud prevention (Recital 47)
    • Direct marketing to existing customers (Recital 47)
    • Network and information security (Recital 49)
    • Intra-group transfers for internal administrative purposes (Recital 48)
    • Reporting possible criminal acts or threats to public security (Recital 50)
  4. Document the interest: State the interest in a single clear sentence that could be understood by a non-expert.

Purpose Test Outcome
  • PASS: A legitimate interest has been clearly identified and is lawful.
  • FAIL: No legitimate interest can be articulated, or the interest is prohibited by law. Stop the assessment — Art. 6(1)(f) cannot be relied upon.

Part 2: Necessity Test

The necessity test determines whether the specific processing is necessary to achieve the identified legitimate interest. This is not a test of whether the interest itself is necessary, but whether the processing is necessary for the interest.

Assessment Criteria
  1. Could the interest be achieved without processing personal data? If the same outcome can be reached without personal data, the processing fails the necessity test.

  2. Could the interest be achieved with less personal data? Apply data minimisation — only the minimum data necessary should be processed.

  3. Could the interest be achieved with a less intrusive method? Consider alternatives:

    • Anonymisation or aggregation instead of identifiable data
    • Pseudonymisation to reduce impact
    • Shorter retention periods
    • More limited sharing
    • Technical restrictions on access
  4. Is the processing proportionate to the interest? The scope and intensity of processing should be proportionate to the significance of the interest.

Necessity Test Outcome
  • PASS: The processing is necessary for the legitimate interest, no less intrusive alternative achieves the same result, and the scope is proportionate.
  • FAIL: A less intrusive alternative exists, or the processing scope exceeds what is necessary. Modify the processing to meet the necessity test, or stop — Art. 6(1)(f) cannot be relied upon.

Part 3: Balancing Test

The balancing test weighs the controller's legitimate interest against the interests, fundamental rights, and freedoms of data subjects. This is the most complex and contextual part of the LIA.

Factors Favouring the Controller
  • The interest is strong and compelling (e.g., fraud prevention, security)
  • Processing has minimal impact on data subjects
  • Data subjects would reasonably expect the processing
  • There is an existing relationship between controller and data subject
  • Robust safeguards are in place (pseudonymisation, encryption, access controls)
  • Data subjects have an easy and effective opt-out mechanism
  • Processing uses non-sensitive data
  • Data is not shared with third parties
  • The controller is transparent about the processing
Show full SKILL.md (411 more words)Show less
Factors Favouring the Data Subject
  • Special category or sensitive data is involved (even if not Art. 9 data, sensitivity matters)
  • Data subjects are vulnerable (children, employees, patients, elderly)
  • Processing has significant impact on data subjects (profiling, automated decisions, financial consequences)
  • Data subjects would not reasonably expect the processing
  • There is no direct relationship between controller and data subject
  • Data is shared widely or with third parties
  • Processing involves large-scale monitoring or tracking
  • No opt-out mechanism is provided
  • Data is combined from multiple sources to create profiles
Balancing Methodology
  1. Assess the nature of the interest: How important is the controller's interest? Rate from routine (low) to essential (high).

  2. Assess the impact on data subjects: What is the likely effect? Consider:

    • Physical, material, or financial harm
    • Social disadvantage or discrimination
    • Loss of control over personal data
    • Reputational effects
    • Psychological impact
  3. Consider reasonable expectations: Would data subjects expect their data to be used this way? The closer the processing is to the original context and the existing relationship, the more likely it meets expectations.

  4. Evaluate additional safeguards: Do safeguards sufficiently mitigate the impact? Effective safeguards can tip the balance in the controller's favour.

  5. Consider the possibility of objection: Is there a mechanism for data subjects to object under Art. 21? The right to object is a mandatory counterbalance when relying on Art. 6(1)(f).

Balancing Test Outcome
  • PASS: The controller's legitimate interest is not overridden by the data subject's interests, rights, and freedoms, taking into account all relevant factors and safeguards.
  • FAIL: The data subject's rights outweigh the controller's interest. Consider additional safeguards that could tip the balance, or use a different lawful basis (typically consent), or do not process.

Documentation Requirements

The completed LIA must document:

  1. Assessment metadata: Date, assessor, processing activity, RoPA reference.
  2. Purpose test: The identified interest, evidence of legitimacy, outcome.
  3. Necessity test: Analysis of alternatives, proportionality, outcome.
  4. Balancing test: Factors considered, weighting rationale, safeguards, outcome.
  5. Overall conclusion: Whether Art. 6(1)(f) can be relied upon.
  6. Safeguards committed: Specific measures to mitigate data subject impact.
  7. Right to object: How the Art. 21 right to object is facilitated.
  8. Review schedule: When the LIA will be reassessed.

Reassessment Triggers

  • Material change in processing scope, purpose, or data categories
  • Change in the relationship with data subjects
  • New technology or methodology introduced
  • Supervisory authority guidance or enforcement action relevant to the processing
  • Data subject complaints challenging the legitimate interest basis
  • Periodic review (minimum annual)

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (scripts, references, assets) in skills/privacy/legitimate-interest-lia of mukul975/Privacy-Data-Protection-Skills.

  • SKILL.md
  • assets/template.md
  • references/standards.md
  • references/workflows.md
  • scripts/process.py

Open the folder on GitHubat commit 9b2ef9e

Compare with similar skills

Legitimate Interest Lia next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Legitimate Interest Lia compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Legitimate Interest Lia this skillmukul975/Privacy-Data-Protection-Skills301—~1.9kAutomated safety check: PassApache-2.0
C15tc15t/c15t1.9k1 repos~1.6kAutomated safety check: PassApache-2.0
HIPAA Safe Harbor Coverage Auditmaziyarpanahi/openmed5.5k—~1.7kAutomated safety check: PassApache-2.0
Korean Privacy Termskimlawtech/korean-privacy-terms587—~2.9kAutomated safety check: PassApache-2.0
Gdpr ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~3.9kAutomated safety check: PassMIT
Hipaa ComplianceSushegaad/Claude-Skills-Governance-Risk-and-Compliance9461 repos~2.3kAutomated safety check: PassMIT

Similar skills

  • C15t

    c15t/c15t

    Work with c15t consent management docs, APIs, and integrations for Next.js, React, and JavaScript.

    1.9k GitHub starsUsed in 1 repo~1.6k tokens
    Legal & ComplianceAuto-check passed
  • Checks OpenMed de-identified clinical text against the 18 HIPAA Safe Harbor identifier categories and reports gaps and residual re-identification risk.

    5.5k GitHub stars~1.7k tokensUpdated today
    Legal & ComplianceAuto-check passed
  • Korean Privacy Terms

    kimlawtech/korean-privacy-terms

    처리방침·이용약관 자동 생성 스킬 패키지 (v4.0). An agent skill from kimlawtech/korean-privacy-terms.

    587 GitHub stars~2.9k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Gdpr Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert GDPR compliance assistant covering all four core workflows: (1) auditing code and systems for GDPR violations, (2) drafting GDPR-compliant documents such as privacy policies, Data Processing…

    946 GitHub starsUsed in 1 repo~3.9k tokens
    Legal & ComplianceAuto-check passed
  • Hipaa Compliance

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert HIPAA compliance assistant for healthcare and software contexts.

    946 GitHub starsUsed in 1 repo~2.3k tokens
    Legal & ComplianceAuto-check passed
  • Pii Contract Analyze

    gregmos/PII-Shield

    Universal legal document processor with PII anonymization. An agent skill from gregmos/PII-Shield.

    150 GitHub stars~8.9k tokensUpdated 3 mo ago
    Legal & ComplianceAuto-check: notes

More from mukul975/Privacy-Data-Protection-Skills

All 280 skills in this repo
  • Age Gating Services

    mukul975/Privacy-Data-Protection-Skills

    Implements age-gating mechanisms for online services to restrict access based on user age.

    301 GitHub stars~3.7k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Data Retention

    mukul975/Privacy-Data-Protection-Skills

    Manages AI model retention and machine unlearning requirements.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • AI Dpia

    mukul975/Privacy-Data-Protection-Skills

    Conducts Data Protection Impact Assessments for AI and ML systems per EDPB Guidelines 04/2025 on AI processing.

    301 GitHub stars~3.4k tokensUpdated 6 mo ago
    Auto-check passed
  • Dpia Mitigation Plan

    mukul975/Privacy-Data-Protection-Skills

    Structures risk mitigation planning and residual risk tracking for Data Protection Impact Assessments under GDPR Article 35(7)(d).

    301 GitHub stars~846 tokensUpdated 6 mo ago
    Auto-check passed
  • Gdpr Accountability

    mukul975/Privacy-Data-Protection-Skills

    Guides implementation of the GDPR accountability principle under Articles 5(2) and 24, including documentation requirements for policies, DPIAs, RoPA, training records, and breach logs.

    301 GitHub stars~1.9k tokensUpdated 6 mo ago
    Auto-check passed
  • Pia Threshold Screening

    mukul975/Privacy-Data-Protection-Skills

    Conducts pre-DPIA threshold screening to determine whether a full Data Protection Impact Assessment is required under GDPR Article 35.

    301 GitHub stars~880 tokensUpdated 6 mo ago
    Auto-check passed

Questions about Legitimate Interest Lia

What does Legitimate Interest Lia do?

Guides the three-part Legitimate Interest Assessment (LIA) required under GDPR Article 6(1)(f): purpose test, necessity test, and balancing test. Legitimate Interest Lia is an agent skill from mukul975/Privacy-Data-Protection-Skills. Guides the three-part Legitimate Interest Assessment (LIA) required under GDPR Article 6(1)(f): purpose test, necessity test, and balancing test.

When should I use Legitimate Interest Lia?

Legitimate Interest Lia fits situations like: tasks that involve Privacy and GDPR.

How do I install Legitimate Interest Lia in Claude Code?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill legitimate-interest-lia -a claude-code`. Or copy the skill folder (skills/privacy/legitimate-interest-lia in mukul975/Privacy-Data-Protection-Skills) into .claude/skills/legitimate-interest-lia in your project. Claude Code loads it when a task matches its description.

How do I install Legitimate Interest Lia in Codex?

Run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill legitimate-interest-lia -a codex`. Or copy the skill folder (skills/privacy/legitimate-interest-lia in mukul975/Privacy-Data-Protection-Skills) into .agents/skills/legitimate-interest-lia in your project. Codex loads it when a task matches its description.

Can I use Legitimate Interest Lia in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Privacy-Data-Protection-Skills --skill legitimate-interest-lia -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/legitimate-interest-lia, .gemini/skills/legitimate-interest-lia, .github/skills/legitimate-interest-lia and .opencode/skills/legitimate-interest-lia in your project.

What does Legitimate Interest Lia need to run?

Going by SKILL.md and its folder, Legitimate Interest Lia needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Legitimate Interest Lia access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Legitimate Interest Lia safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Legitimate Interest Lia use?

Legitimate Interest Lia is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Legitimate Interest Lia use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.2k tokens, read only when the agent opens those files.

What are the alternatives to Legitimate Interest Lia?

Skills that share tags, products or a category with Legitimate Interest Lia: C15t (c15t/c15t, 1.9k stars), HIPAA Safe Harbor Coverage Audit (maziyarpanahi/openmed, 5.5k stars), Korean Privacy Terms (kimlawtech/korean-privacy-terms, 587 stars) and Gdpr Compliance (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 946 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Legitimate Interest Lia?

mukul975 (a GitHub user) maintains it in mukul975/Privacy-Data-Protection-Skills, which has 301 GitHub stars. The repository holds 280 skills in this directory. The repository was last updated on March 16, 2026.

Source: mukul975/Privacy-Data-Protection-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.