# DPIA and LIA templates for analytics

> Templates for a legitimate interests assessment (LIA) and a data protection impact assessment (DPIA) outline covering Privatus Analytics, ready to fill in.

These templates cover Privatus Analytics only. Fill in the bracketed parts,
add your other processing, and have your data protection officer or
counsel review them.

## Legitimate interests assessment (LIA)

### 1. Purpose test

- **Interest:** understanding how visitors use [website] to improve its
  content, performance and conversion, and measuring marketing
  effectiveness.
- **Why it matters:** [e.g. prioritizing content, fixing broken pages,
  deciding campaign budgets].
- **Is the interest legitimate?** Yes: audience measurement is a normal,
  expected activity for a website operator.

### 2. Necessity test

- **Is processing necessary?** Counting visits, sources and pages requires
  processing requests to the website. Privatus Analytics minimizes this: no cookies,
  no device storage, no persistent identifiers, IP addresses used in memory
  only and never stored.
- **Less intrusive alternatives?** [Explain why you need visit and daily
  visitor counts, e.g. to measure conversion rates and campaign
  effectiveness, rather than raw pageview totals only.]

### 3. Balancing test

| Factor | Assessment |
|---|---|
| Nature of data | Pseudonymous for at most one day, then effectively anonymous aggregates. No special categories. PII scrubber redacts accidental personal data |
| Reasonable expectations | Visitors expect websites to count visits, and the privacy policy explains it |
| Impact on individuals | Minimal: no profiling, no cross-site tracking, no advertising use, no decisions about individuals |
| Safeguards | No cookies, daily salt destroyed, IP and User-Agent processed in memory only and never stored, opt-out, GPC honored, DPA and SCCs with Privatus Analytics |
| Vulnerable groups | [Consider if your site targets children] |

**Conclusion:** the legitimate interest is not overridden by the
interests or rights of visitors. [Date, name, role.]

## Data protection impact assessment (DPIA) outline

A DPIA is usually **not required** for Privatus Analytics alone, because it isn't
large-scale profiling, systematic monitoring of individuals or processing
of special categories. If your organization does one anyway (or your
regulator's list requires it), cover:

1. **Description:** purposes (audience measurement), data (see the
   [data inventory](/docs/privacy/data-inventory)), recipients (Privatus Analytics as
   processor and its subprocessors), retention ([your plan's retention]),
   locations (US processing and storage, IP and User-Agent in memory only).
2. **Necessity and proportionality:** lawful basis (legitimate
   interests, LIA above), minimization measures, transparency (privacy
   policy) and data subject rights (opt-out, and no identifiable data is stored,
   so access requests usually return nothing).
3. **Risks:** re-identification of visitors (mitigated: salt destroyed
   daily, no IPs stored), accidental collection of personal data in URLs or
   properties (mitigated: PII scrubber, query stripping, path masks,
   redaction log), international transfer (mitigated: IP and User-Agent
   processed in memory only and never stored, SCCs) and unauthorized access to the dashboard (mitigated: roles,
   2FA, SSO, audit log).
4. **Measures and residual risk:** [low].
5. **Sign-off:** [DPO opinion, decision, date].

The [DPA](/legal/dpa) and the [subprocessor list](/legal/subprocessors)
are on our legal pages. The DPA includes our technical and organizational
measures.
