DPIA and LIA templates for analytics
Templates for a legitimate interests assessment (LIA) and a data protection impact assessment (DPIA) outline covering Privatus Analytics, ready to fill in.
These templates cover Privatus Analytics only. Fill in the bracketed parts, add your other processing, and have your data protection officer or counsel review them.
Legitimate interests assessment (LIA)#
1. Purpose test#
- Interest: understanding how visitors use [website] to improve its content, performance and conversion, and measuring marketing effectiveness.
- Why it matters: [e.g. prioritizing content, fixing broken pages, deciding campaign budgets].
- Is the interest legitimate? Yes: audience measurement is a normal, expected activity for a website operator.
2. Necessity test#
- Is processing necessary? Counting visits, sources and pages requires processing requests to the website. Privatus Analytics minimizes this: no cookies, no device storage, no persistent identifiers, IP addresses used in memory only and never stored.
- Less intrusive alternatives? [Explain why you need visit and daily visitor counts, e.g. to measure conversion rates and campaign effectiveness, rather than raw pageview totals only.]
3. Balancing test#
| Factor | Assessment |
|---|---|
| Nature of data | Pseudonymous for at most one day, then effectively anonymous aggregates. No special categories. PII scrubber redacts accidental personal data |
| Reasonable expectations | Visitors expect websites to count visits, and the privacy policy explains it |
| Impact on individuals | Minimal: no profiling, no cross-site tracking, no advertising use, no decisions about individuals |
| Safeguards | No cookies, daily salt destroyed, IP and User-Agent processed in memory only and never stored, opt-out, GPC honored, DPA and SCCs with Privatus Analytics |
| Vulnerable groups | [Consider if your site targets children] |
Conclusion: the legitimate interest is not overridden by the interests or rights of visitors. [Date, name, role.]
Data protection impact assessment (DPIA) outline#
A DPIA is usually not required for Privatus Analytics alone, because it isn't large-scale profiling, systematic monitoring of individuals or processing of special categories. If your organization does one anyway (or your regulator's list requires it), cover:
- Description: purposes (audience measurement), data (see the data inventory), recipients (Privatus Analytics as processor and its subprocessors), retention ([your plan's retention]), locations (US processing and storage, IP and User-Agent in memory only).
- Necessity and proportionality: lawful basis (legitimate interests, LIA above), minimization measures, transparency (privacy policy) and data subject rights (opt-out, and no identifiable data is stored, so access requests usually return nothing).
- Risks: re-identification of visitors (mitigated: salt destroyed daily, no IPs stored), accidental collection of personal data in URLs or properties (mitigated: PII scrubber, query stripping, path masks, redaction log), international transfer (mitigated: IP and User-Agent processed in memory only and never stored, SCCs) and unauthorized access to the dashboard (mitigated: roles, 2FA, SSO, audit log).
- Measures and residual risk: [low].
- Sign-off: [DPO opinion, decision, date].
The DPA and the subprocessor list are on our legal pages. The DPA includes our technical and organizational measures.