# The Legitimate Interest Assessment for Cold-Sourced Contacts

*You can complete and file an Article 6(1)(f) LIA - purpose, necessity, and balancing tests plus recorded safeguards - for a sourcing-and-outreach program.*

- Canonical URL: https://www.refolk.ai/guides/lia-cold-sourced-contacts
- Pillar: Process, data, and compliance
- Format: Playbook
- Published: 2026-09-03
- Last reviewed: 2026-09-03
- Reading time: 18 min

This is the document you file before a sourcing-and-outreach program touches a single stranger. It is written for the person who signs off on how the data was gathered - a DPO, RevOps lead, or talent acquisition lead answerable for lawful basis - and it walks the Article 6(1)(f) three-part test through the one activity that generic templates skip: finding a person on a public platform and cold-contacting them. You leave with a filed LIA, not a blank form.

Most LIA guidance is sector-neutral. It explains that legitimate interest has three tests and then hands you a table with empty rows. The hard part of cold-sourcing is not the form. It is that the balancing test almost always turns on one factor - the person has no idea you exist - and every other decision in the program either strengthens or weakens that single point. This playbook builds around it.

## What an LIA is and why cold-sourcing needs its own version

An LIA is the recorded assessment that lets you rely on legitimate interests as your lawful basis under Article 6(1)(f). Both the ICO and the EDPB structure that basis as a cumulative three-part test, and you can only rely on it if the processing passes all three.

The three tests are:

- **Purpose test.** Identify a legitimate interest you are pursuing.
- **Necessity test.** Show the processing is necessary and that no less intrusive route achieves the same result.
- **Balancing test.** Confirm the person's interests, rights, and freedoms do not override yours.

The ICO says the LIA "doesn't have to take any particular form, but you must address each part of the three-part test and record the outcome, including all relevant factors, whether or not they support your conclusion." That last clause matters: an LIA that records only the reasons you win reads as advocacy, and a regulator treats it as such.

The EDPB draft Guidelines 1/2024, published on 8 October 2024 with consultation closed 20 November 2024, tightened how you articulate the interest. The EDPB uses three cumulative criteria to decide whether an interest is "legitimate": it must be lawful, clearly and precisely articulated, and real and present, not speculative. The Guidelines also warn that legitimate interests "cannot be considered a legal basis by default; before relying on it the controller must perform a careful assessment following a specific methodology." These Guidelines supersede the earlier WP29 Opinion 06/2014.

Cold-sourcing needs its own version because the balancing test behaves differently when there is no prior relationship. The person did not give you their data, has not heard of you, and has no reason to expect contact. That single fact loads the scale toward the data subject before you weigh anything else.

**697 - UK-based Data Protection Officer profiles in Refolk's index**

Against 200 in Germany, a 3.49x ratio - the people who review LIAs are far more concentrated in the UK market.

> **Rule:** All three tests must pass
>
> You may rely on legitimate interests only if the processing passes the purpose, necessity, and balancing tests. Passing two is passing none.

## The three tests applied to finding and contacting a stranger

The test does not change for cold-sourcing, but where it bites does. Purpose is usually the easy leg, necessity is the leg people skip, and balancing is where the program lives or dies.

The 2024 CJEU ruling in Case C-621/22, decided 4 October 2024, confirmed that purely commercial interests can qualify as legitimate interests. That makes the purpose test easier: you no longer have to dress up prospecting or recruiting as something loftier. But the ruling is narrow. The three-part test remains non-negotiable, and a commercial justification does not bypass necessity or balancing. The purpose test got easier; the transparency and necessity work did not.

#### Where each test carries the weight for cold-sourcing

1. **Purpose** - State a lawful, clearly articulated, real-and-present interest. Commercial interests now qualify, so this leg is rarely where you fail.
2. **Necessity** - Show sourcing this way is necessary and no less intrusive route works. This is the leg teams skip and regulators probe.
3. **Balancing** - Weigh reasonable expectation against your interest. For strangers this is decided mostly by invisibility, and it is where most programs actually turn.

*Purpose is the thin layer on top; balancing is the load-bearing base.*

### The purpose test

Write the interest so it survives being quoted alone. "Recruiting" is not an articulated interest. "Identifying senior backend engineers with public open-source contributions to fill named open roles, so that qualified candidates hear about relevant opportunities" is. It is lawful, precise, and present rather than speculative. Name who benefits: you, the candidate, and arguably the labour market. If you cannot name a real and present benefit without hedging, the interest is speculative and the whole LIA fails at the top.

### The necessity test

Necessity asks whether you could reasonably achieve the same result in a less intrusive way. If you could, legitimate interests does not apply. This is not a formality. You must record the alternatives you considered and why each fails to deliver the same outcome - inbound applications, job-board postings, referrals - and why targeted sourcing from public profiles is the least intrusive route that actually reaches the specific people you need.

A useful anchor here is volume. LinkedIn tightened enforcement of a roughly 100-connection-request-per-week cap in 2024. That shifted the game from sending to many to sending to the right hundred. A "targeted, not bulk" posture is exactly what the necessity test rewards: it aligns with data minimisation and makes the argument that you are contacting only who you must, not everyone you can.

### The balancing test

Balancing weighs the person's interests, rights, and freedoms against yours. The pivotal ICO factor is reasonable expectation: the person's interests are likely to override yours if they would not reasonably expect you to use the information that way, or if your use would cause unjustified harm. For a stranger, expectation is weak by default. You do not fix that by adding data. You fix it by making the processing visible at the right moment, which is the Article 14 job in the next section.

> For cold-sourcing the balancing test turns on invisibility, not sensitivity - the fix is transparency timing, not more data.

## The balancing factors that pass or fail for cold-sourcing

The balancing test is a weighing, not a checklist, but the factors are known. Two columns decide it: what pushes the scale toward the data subject, and what pulls it back toward you. Record both honestly.

| Factor | Pushes against you | Pulls toward you |
|---|---|---|
| Reasonable expectation | Processing is invisible; no prior relationship | Person could reasonably anticipate the contact |
| Data sensitivity | Special-category or vulnerable-person data | Non-sensitive data already public and known to the person |
| Impact | Distress, reputational harm, or already objected | Minimal, reversible impact |
| Safeguards | None, or bolted on | Meaningful, mapped to specific risks |

The default state of cold-sourcing sits in the left column on the expectation row and the right column on the sensitivity row: invisible, but non-sensitive. That is why sensitivity rarely saves or sinks a sourcing program. Invisibility does. The work is to move the expectation row rightward through transparency, and to keep sensitivity from creeping leftward by refusing to collect special-category signals you do not need.

#### Reading a cold-sourcing balancing call

Horizontal axis runs from Invisible processing to Reasonably expected contact. Vertical axis runs from Minimal reversible impact to Distress or harm.

| Quadrant | What it means |
| --- | --- |
| Invisible but low-impact | Proceed only with a timely Article 14 notice that converts invisibility into expectation |
| Expected and low-impact | Proceed; this is the strongest position for the balance |
| Invisible and harmful | Stop; this is the classic forced-pass trap |
| Expected but harmful | Reconsider purpose and scope; expectation does not cure harm |

*Expectation on one axis, impact on the other, tells you whether to proceed, safeguard, or stop.*

## Filing the LIA start to finish

Here is the procedure end to end, with who owns each stage and how long it takes. Follow it in order. The output at the end is a single filed document.

#### The eight-stage LIA procedure

1. **Scope the processing** - DPO/RevOps or TA lead, 1-2 hours. Write down data categories, sources (public profiles), volumes, retention, recipients, and the outreach action. Done: a one-paragraph processing description covering data flows and categories of data subjects.
2. **Run the purpose test** - Assessor, 1 hour. Articulate the legitimate interest and who benefits, phrased as lawful, clearly and precisely articulated, and real and present. Done: an interest a regulator can read without asking what you actually want.
3. **Run the necessity test** - Assessor, 1-2 hours. Show the processing is necessary and no less intrusive route works. Done: a recorded rejection of the alternatives you considered.
4. **Screen for a DPIA** - Assessor plus DPO, 30-60 min. Run the Article 35(3) triggers and nine EDPB criteria; note the invisible-processing flag applies. Done: a documented screening decision.
5. **Run the balancing test** - Assessor plus DPO, 2-3 hours. Weigh reasonable expectation, sensitivity, impact, and objection likelihood. Done: a reasoned conclusion recording factors on both sides.
6. **Design the safeguards** - Assessor, 1-2 hours. Add unconditional opt-out and suppression, minimisation, and retention limits, mapped to identified risks. Done: safeguards listed and the balance still holds without them.
7. **Draft the Article 14 notice and timing plan** - DPO/Legal, 1-2 hours. Write a notice that fires at or before first contact and within one month of acquisition, disclosing the source. Done: a notice your tooling can enforce.
8. **Record decision, owner, review date** - Accountable manager, 30 min. State a clear decision, name an owner, set a review date. Done: a filed document reading "Proceed under legitimate interests with the safeguards listed."

The whole assessment is roughly a working day of focused effort split across an assessor, a DPO, and an accountable manager. Do not compress the balancing stage to save time; it is the stage that gets read first if anyone challenges you.

Much of the friction in this procedure sits in stage one, scoping, and in the necessity argument, where you have to prove you targeted the right people rather than everyone. If your sourcing is precise and reproducible from public sources, both stages get shorter and more defensible. [Refolk](/) queries public profiles in plain English, which makes "we contacted only the specific people who matched a stated need" a claim you can evidence rather than assert.

I ran this search: `Data Protection Officers at UK software companies who have written about legitimate interests` - [see the full result list](https://www.refolk.ai/s/8xa5vcb94n).

*Returns named DPOs with public writing on the exact basis, useful when you need a reviewer or a second opinion on a borderline LIA.*

## The Article 14 notice: the load-bearing safeguard

Article 14 is the safeguard that converts invisible processing into expected processing, and it is where most B2B prospecting fails. For data not obtained from the individual, you must provide the required information within a reasonable period after obtaining the data, at the latest within one month, and if the data is used to communicate with the person, at the latest at the time of first communication - whichever is earlier.

The clock runs from when you obtained the data, not from when the person converts. A vendor who scraped emails in January and emails them in March is already late. This makes any enrichment-then-wait workflow structurally non-compliant: the delay you built for deliverability or sequencing is the delay that breaks Article 14.

| Event | Article 14 status |
|---|---|
| Data acquired, notice sent same day | Compliant, clock stopped early |
| First contact within one month, notice attached | Compliant, notice at first communication |
| Contact after one month, no earlier notice | Late, breach on acquisition date |
| Acquired then held indefinitely, no contact yet | Notice still due within one month |

The notice is not a formality bolted onto the LIA. It is the mechanism that fixes the weak leg of the balancing test. Because the balance turns on reasonable expectation, and the notice is precisely what makes the person aware, a well-timed Article 14 notice does more to strengthen your position than any amount of extra data enrichment.

> **Watch out:** Enrichment-then-wait is a compliance trap
>
> The one-month clock starts at acquisition. If your pipeline enriches contacts and then waits weeks before outreach, you are late before you send the first message. Send the notice on acquisition or contact fast.

## When cold-sourcing crosses into DPIA territory

A DPIA becomes mandatory the moment your LIA identifies a potential high risk to people's rights and freedoms. This is not a separate judgement call bolted on later; the ICO states that if your LIA flags high risk, you must do a DPIA to assess the risks and safeguards in more detail. Cold-sourcing has a built-in flag: the ICO lists collecting personal data from a source other than the individual without providing a privacy notice - "invisible processing" - as high-risk.

Beyond that specific flag, UK GDPR requires a DPIA for systematic and extensive profiling with significant effects, large-scale processing of special-category or criminal data, or large-scale systematic monitoring of publicly accessible places. The European guidelines add nine criteria, and in most cases any processing involving two or more of them requires a DPIA. The threshold is not fully settled: the ICO says one criterion may suffice. Screen honestly rather than counting to two and stopping.

The consequence of skipping this is real. In 2024 the ICO issued enforcement notices for DPIA failures against the Home Office and Serco Leisure. A missing DPIA is not a paperwork gap; it is an enforceable failure on its own.

> **Note:** The invisible-processing flag usually decides it
>
> If your program collects from public profiles and contacts people who never gave you data, you have at least one high-risk indicator. Treat a DPIA as the default, and record your reasoning if you conclude one is not needed.

## Safeguards that actually strengthen the balance

Safeguards can change the outcome of the balancing test so that the person's interests no longer override yours. The ICO confirms this mechanism directly. But there is a hard limit: safeguards can flip a balance that is genuinely close, and they cannot manufacture one that is not there.

The safeguards with EDPB and WP29 lineage are:

- **Data minimisation.** Strict limits on what you collect, or immediate deletion after use.
- **Functional separation.** Keep sourced data walled off from unrelated processing.
- **Anonymisation.** Where the outcome does not need identity, remove it.
- **Increased transparency.** The Article 14 notice, delivered on time.
- **An unconditional right to object.** A general opt-out that works without conditions.

Note the caveat on opt-out. Providing an opt-out does not turn the basis into consent, and a person's failure to opt out does not demonstrate consent. The opt-out is a mitigation on the legitimate-interest scale, not a lawful basis in its own right. Keep the two ideas separate in the document.

The stress test is simple: strip the safeguards out and see whether the balance still holds. WP29 lineage warns that mitigations should be considered but should not play a significant role in determining which way the scale leans. If the balance only passes because of a bolted-on opt-out, the LIA is fragile, and a data-subject objection will expose it.

**1.05 - Sourcers per DPO in the UK (Refolk's index, derived)**

Germany runs 0.85, so a German program faces more DPO scrutiny per outreach seat - and a higher documentation bar.

That oversight-density gap is worth planning around. In Refolk's index there are 731 Technical Recruiter or Sourcer profiles in the UK against 169 in Germany, and 697 DPOs in the UK against 200 in Germany. Divide them and Germany shows more DPO oversight per sourcer than the UK. A German program is more likely to face internal review per seat, which raises the bar on how well your LIA and safeguards are documented.

| Country | Sourcers | DPOs | Sourcers per DPO |
|---|---|---|---|
| United Kingdom | 731 | 697 | 1.05 |
| Germany | 169 | 200 | 0.85 |

## How the LIA goes wrong: failure modes and false positives

Most failed LIAs fail the same handful of ways. Each has a false positive - a reason the team believes they are fine - and a check that catches it.

- **Skipping the Article 14 notice.** False positive: the team believes the LIA alone makes outreach lawful. Check: is a notice delivered at or before first contact and within one month of acquisition? This is where most B2B prospecting tools fail.
- **Forcing the balance to pass.** False positive: the assessor writes only the points in their favour. If you are forcing the assessment to pass, that is often a sign the processing is too intrusive, too unexpected, or insufficiently safeguarded. Check: would a typical person be surprised to hear from you?
- **Treating opt-out as consent.** False positive: logging non-responses as agreement. Check: failure to opt out does not demonstrate consent, so your records should never imply it does.
- **Over-weighting safeguards.** False positive: the balance passes only because of mitigations. Check: does the balance still hold if you strip the safeguards out?
- **"Public profile therefore fair game."** False positive: assuming public data removes obligations. Check: source disclosure and the Article 14 notice are still required regardless of public availability.
- **Set-and-forget LIA.** False positive: filed once, never revisited. Check: is there a named owner and a review date? The LIA must be regularly reviewed.
- **Missing DPIA when the LIA flags risk.** False positive: assuming the LIA covers everything. Check: if the LIA identifies a potential high risk, a DPIA is mandatory.

#### Where cold-sourcing programs leak compliance

| Stage | Figure | Note |
| --- | --- | --- |
| Programs relying on legitimate interests | 100% | Starting point |
| Have a filed three-part LIA | fewer | Skipping the LIA drops you here |
| Send Article 14 notice on time | fewer still | Enrichment-then-wait leaks out here |
| Balance holds without safeguards | narrowest | Forced passes fail this test |

*Each stage sheds programs that treated an obligation as optional.*

The most common single failure is the first one. Teams do the LIA, feel covered, and never wire the Article 14 notice into the outreach itself. The LIA and the notice are two halves of one obligation. One without the other is not defensible.

## Verifying before you file, and keeping the LIA current

Before you call the job done, verify the document against a fixed checklist. An LIA that passes this list is one you can hand to a data subject or a regulator without editing.

#### Before you file the LIA

- [ ] The purpose is stated as lawful, clearly articulated, and real and present, not speculative.
- [ ] The necessity test records the less-intrusive alternatives considered and why each fails.
- [ ] A DPIA screening decision is documented, and a DPIA is run if the LIA flags high risk.
- [ ] The balancing test records factors on both sides, whether or not they support the conclusion.
- [ ] The balance still holds when safeguards are stripped out.
- [ ] An Article 14 notice fires at or before first contact and within one month of acquisition, and discloses the source.
- [ ] The opt-out is described as a safeguard, never as consent.
- [ ] The document names an accountable owner and a review date.

Keeping it current is a discrete task, not an afterthought. Set both a cadence and trigger points. A common cadence is 12 months; the trigger points are a new audience, new data types, or increased frequency. The ICO says to refresh the LIA when there is a significant change in the purpose, nature, or context of your use of the data, and to revisit the balancing test if a new and unforeseen impact arises.

Two moving pieces are worth watching by mechanism rather than date. The regulatory ground shifts: the Data (Use and Access) Act came into law on 19 June 2025, with some ICO privacy-notice guidance under review, so re-check the ICO's live LIA and Article 14 pages at each review rather than trusting a saved copy. And your own program shifts: every time volume, audience, or data type changes, the necessity and balancing arguments you filed may no longer describe what you do.

**LIA decision block**

```
Decision: Proceed under legitimate interests with the safeguards listed below.
Legitimate interest: [one lawful, precise, present interest and who benefits]
Necessity: Less intrusive alternatives considered and rejected: [list]
Balancing conclusion: [reasoned outcome, factors on both sides]
Safeguards mapped to risks: opt-out/suppression; minimisation; retention limit; Article 14 notice timing
DPIA: [required / not required] because [reason]
Article 14 notice fires: at or before first contact and within one month of acquisition
Accountable owner: [name and role]
Review date: [date] or on trigger: new audience / new data types / increased frequency
```

*Paste at the top of your filed LIA. Fill each field; leave none blank.*

File the decision block, attach the three tests, wire the notice into your outreach, and set the review reminder. That is a defensible LIA for cold-sourced contacts - one that survives an objection because it was built to be read by the person objecting.

## Frequently asked questions

### Is a legitimate interest assessment legally required or just good practice?

You cannot rely on Article 6(1)(f) without it. The ICO is explicit that legitimate interests cannot be used by default; before relying on it you must perform a careful assessment following a specific methodology. The LIA is the record that shows you did. It need not take a particular form, but you must address each part of the three-part test and record the outcome, including factors that do not support your conclusion. Without that record you have no documented lawful basis to point to under a data-subject objection.

### Can I use legitimate interests if the profiles are already public?

Public availability lets you argue the data is non-sensitive and already known to the person, but it does not remove your Article 14 obligations or win the balancing test on its own. Because the person has no relationship with you, the reasonable-expectation prong is weak by default, and 'public profile therefore fair game' is a common failure mode. You still owe a source disclosure and a privacy notice at or before first contact.

### When does the Article 14 privacy notice have to be sent for cold outreach?

At the earlier of one month after you obtained the data or the time of first communication. The clock runs from data acquisition, not from when the person becomes a customer. A workflow that enriches contacts in January and emails them in March is already late. This is why enrichment-then-wait pipelines are structurally non-compliant and why most B2B prospecting tools fail this exact test.

### Does offering an opt-out turn my basis into consent?

No. An unconditional right to object is a strong safeguard that helps the balancing test, but the ICO is clear that providing an opt-out does not turn the basis into consent, and failure to opt out does not demonstrate consent. Logging non-responses as agreement is a documented failure mode. Keep the two bases separate: you are relying on legitimate interests, and the opt-out is a mitigation, not a substitute for it.

### When does cold-sourcing require a DPIA on top of the LIA?

Whenever the LIA itself identifies a potential high risk to people's rights and freedoms, a DPIA becomes mandatory. Cold-sourcing triggers the ICO's 'invisible processing' flag - collecting data from a source other than the individual without a privacy notice - which is listed as high-risk. The EDPB nine-criteria rule says two or more criteria usually require a DPIA, though the ICO notes one may suffice. Screen honestly rather than assuming the LIA covers you.

### How often should I review a filed LIA?

Set both a cadence and trigger points. A common cadence is 12 months, with triggers for a new audience, new data types, or increased frequency. The ICO says to refresh the LIA when there is a significant change in the purpose, nature or context of your use of the data, and to revisit the balancing test if a new and unforeseen impact arises. A set-and-forget LIA with no named owner or review date is a failure mode in itself.

---

*From the Refolk guide library. I revise these guides rather than replacing them, so the current version is always at https://www.refolk.ai/guides/lia-cold-sourced-contacts*
