figma guide

Designing legitimate interest assessment (LIA) workflow UI in Figma: balancing tests, records, and objections

Design legitimate interest assessment workflow UI in Figma with three-part balancing tests, purpose linkage, objection handling, review cadence, and ROPA integration for Privacy teams.

Published
Updated
Aug 04, 2026
Read time
8 min
Level
Intermediate

Quick answer

A legitimate interest assessment (LIA) documents the GDPR three-part test: purpose, necessity, and balancing—before you rely on Article 6(1)(f) instead of consent. Design an LIA registry with draft → review → approved states; a balancing worksheet capturing impacts, safeguards, and opt-out paths; and objection queues tied to ROPA activities and privacy settings. Start from the Figma guides hub and pair with consent records admin, PIA/DPIA workflow, DSAR portal, data retention policies, and Dev Mode handoff.


Who this is for

  • Product designers building privacy ops tools where Marketing and Product default to “we have legitimate interest.”
  • Design system teams standardizing LIA status badges, balancing scorecards, and objection SLA chips.
  • DPOs and Privacy counsel who need structured records—not Word docs named LIA_final_v7_really_final.docx.

LIA hub (internal overview)

LIAHub — Acme Privacy · 34 assessments · 6 draft · 2 balancing failed · 1 objection overdue
├── Header: Approved 28 · Under review 4 · Superseded 2 · Linked ROPA rows 34
├── Actions: [ New LIA ] [ Clone template ] [ Export register ] [ Schedule re-review ]
├── Tabs: Assessment register · Objections · Templates · ROPA sync · Audit trail · Reports
├── Alert: LIA-2026-09 · Product analytics · Balancing failed · Blocks new data category
├── Filters: Business unit · Status · ROPA activity · Contains marketing · Re-review due
└── Link: [ROPA hub](/designing-records-of-processing-activities-and-data-mapping-ui-in-figma/) · PIA registry · Consent admin · Trust center
SectionPurpose
Assessment registerAll LIAs with status, owner, and linked purposes
ObjectionsArticle 21 requests with SLA and outcome
TemplatesReusable worksheets by use case (analytics, fraud, B2B prospecting)
ROPA syncLawful basis Art. 6(1)(f) requires approved LIA
Audit trailVersion history when product scope changes
ReportsICO-style summary export for regulator questions

Verdict: LIA UI prevents “legitimate interest” as a checkbox—without an approved balancing record, ROPA rows should not publish as Active.


LIA detail workspace (three-part test)

LIADetail — LIA-2026-09 · Product usage analytics · Status: Balancing failed
├── Linked: ROPA PA-331 · Purpose: Improve product features · Owner: @product-privacy
├── Part 1 — Purpose identification:
│   ├── Controller interest: Understand feature adoption to prioritize roadmap
│   ├── Data subjects: Authenticated SaaS customers · Not prospects
│   └── Plain language summary: "We analyze how teams use dashboards to improve UX"
├── Part 2 — Necessity test:
│   ├── Is processing necessary for the stated purpose? Partial — aggregate would suffice
│   ├── Less intrusive alternatives: Aggregated metrics · Sampled sessions · User surveys
│   └── Decision: User-level events NOT necessary for stated purpose · Gap flagged
├── Part 3 — Balancing test:
│   ├── Subject expectations: Medium — B2B admin users expect product improvement
│   ├── Impact: Identifiable usage trails · Sensitive: No special category
│   ├── Safeguards: Pseudonymization option · 90-day retention · Admin-only access
│   ├── Opt-out: Link [privacy settings](/designing-privacy-settings-and-data-management-ui-in-figma/) · "Analytics off" toggle
│   └── Outcome: FAIL — necessity gap; recommend aggregate-only or consent path
├── Approvals: DPO review pending · Legal comment Aug 2 · Product ack required
└── [ Save draft ] [ Submit for DPO ] [ Convert to consent purpose ] [ Deprecate processing ]
Test sectionUI pattern
PurposeFree text + structured “controller interest” field
NecessityRequired alternatives list—cannot skip with empty state
BalancingImpact slider + safeguards checklist + opt-out link field
OutcomePass · Fail · Conditional (with remediation tasks)
ROPA gateCannot set lawful basis LI until Outcome = Pass or Conditional cleared

Failed balancing should offer guided remediation: switch to consent (consent admin), reduce granularity, or deprecate processing.


Template library by use case

LIATemplates — 8 approved templates · 2 org-specific
├── T-01 B2B product analytics · Last used 12x · Default retention 90d · Opt-out required
├── T-02 Fraud prevention · Necessity strong · Minimal opt-out · Re-review annual
├── T-03 Customer success health scores · Balancing medium · Admin-visible only
├── T-04 Marketing lookalike modeling · Usually FAIL → redirect to consent purpose
├── T-05 Security logging · Necessity strong · Link [audit log UI](/designing-audit-log-and-security-activity-ui-in-figma/)
├── Clone: Start from T-01 · Pre-fill safeguards · Edit necessity alternatives
└── [ Create template ] [ Deprecate template ] [ Preview worksheet PDF ]
Template typeDesign guardrail
Marketing prospectingDefault banner: “Consider consent instead”
Employee monitoringHigh impact preset; mandatory Legal review
AnalyticsForce “aggregate alternative” field
SecurityCross-link retention policy; shorter re-review
AI trainingAuto-suggest PIA/DPIA if personal data

Templates accelerate intake but never auto-approve—each instance needs DPO sign-off.


Objection handling queue (Article 21)

ObjectionQueue — 23 open · 2 overdue SLA · Avg close 4.2 days
├── OBJ-881 · user_442 · PA-331 analytics · Received Aug 1 · SLA Aug 8
│   ├── Request: "Stop analyzing my team's usage"
│   ├── LIA link: LIA-2024-04 · Approved · Opt-out path documented
│   ├── Action: Verify toggle off · Purge 90d rolling events · Confirm email
│   └── Status: In progress · Engineering ticket ENG-991
├── OBJ-902 · user_118 · B2B prospecting · Received Aug 3 · Competing rights review
│   ├── LIA link: LIA-2025-11 · Conditional · Legal reviewing override
│   └── Status: Legal hold · Cannot auto-close
└── [ Bulk export ] [ SLA dashboard ] [ Link DSAR ]
Objection stateSLA note
ReceivedAcknowledge within 72h—template email
VerifiedConfirm identity via account dashboard
RemediatedProcessing stopped + deletion jobs tracked
Denied (rare)Compelling grounds documented; Legal-only action
ClosedUser notification + ledger entry

Objections differ from DSAR erasure—design separate queues with cross-link when requests combine both.


ROPA integration and lawful basis gate

ROPASync — Lawful basis Legitimate interest · 34 activities · 2 missing approved LIA
├── PA-331 · Analytics · LIA-2026-09 · Status Balancing failed · ROPA blocked
├── PA-118 · Account management · Contract · No LIA required
├── PA-204 · Marketing email · Consent · Link [consent admin](/designing-consent-records-and-preference-management-admin-ui-in-figma/)
├── Gate rule: Art. 6(1)(f) → requires LIA status Approved or Conditional-cleared
└── [ Run gap scan ] [ Notify activity owners ]

Changing a ROPA activity’s scope (new data category, new recipient) should auto-open LIA addendum—mirror TIA addendum flows for transfers.

When LIA fails, guide owners to either narrow processing or migrate lawful basis with explicit Legal approval—not silent checkbox edits.


Re-review cadence and change triggers

ReReviewCalendar — 5 due this quarter · Trigger rules active
├── LIA-2023-08 · Fraud scoring · Due Sep 2026 · Owner @risk-team
├── Trigger fired: LIA-2024-02 · New subprocessor · Auto-opened addendum Jul 28
├── Trigger fired: LIA-2025-11 · Marketing expanded to US · DPO task created
├── Rules: Subprocessor change · New region · Retention extension · Purpose text change
└── [ Complete re-review ] [ Snooze with justification ]
TriggerUI behavior
Subprocessor addCompare data categories; open addendum
Retention extensionRe-run balancing impact section
New regionCheck local law overrides (e.g., marketing rules)
Product launchBlock feature flag until LIA Pass or consent path
Annual calendarTask assigned 30 days before due

Stale LIAs are a common audit finding—show days overdue on ROPA rows and security posture dashboard privacy widgets.


Handoff checklist (Dev Mode)

  • LIA — id, ropa_activity_id, status, outcome, owner_id, approved_at, re_review_date.
  • Purpose section — controller_interest, data_subjects[], plain_summary.
  • Necessity — is_necessary, alternatives[], necessity_decision, notes.
  • Balancing — impact_level, safeguards[], opt_out_url, opt_out_mechanism_id, outcome.
  • Objection — id, user_id, lia_id, status, sla_due, remediation_job_ids[].
  • Template — template_id, use_case, default_safeguards[], recommended_retention_days.
  • Accessibility — worksheet sections as expandable panels; outcomes announced to screen readers.

Common mistakes

MistakeWhy it hurtsFix
LIA as one checkbox on ROPANo balancing proofSeparate worksheet with three parts
Marketing uses LI for emailUnlawful in most EU contextsTemplate redirects to consent
No opt-out documentedBalancing failsRequired opt-out link field
Necessity section skippedICO scrutinyBlock submit until alternatives listed
Objections in generic support queueSLA missesDedicated objection tab with timers
Approved LIA never re-reviewedScope creep invalidatesTriggers + calendar
LI and consent on same purposeConflicting lawful basisMutual exclusion in purpose registry
PDF export onlyNot queryable for auditsStructured fields + PDF
Product launches before DPO sign-offCompliance debtROPA gate on feature flags
Copy-paste balancing textIdentical assessmentsRequire per-activity impact notes

  1. Create LIA templates for common use cases with guardrail banners.
  2. Build three-part worksheet with necessity alternatives and balancing outcome.
  3. Wire ROPA gate so Art. 6(1)(f) requires Approved LIA.
  4. Add objection queue with SLA, remediation jobs, and DSAR cross-link.
  5. Configure change triggers for subprocessors, regions, and retention.
  6. Connect privacy settings opt-out toggles to objection remediation checks.
  7. Export LIA register for compliance audit evidence packs.

FAQ

LIA vs PIA/DPIA?

LIA decides if legitimate interest is an appropriate lawful basis. DPIA assesses high-risk processing regardless of basis—run DPIA when triggers apply even if LIA passes.

When is legitimate interest inappropriate?

Direct marketing to individuals often needs consent (or soft opt-in where allowed)—template T-04 should default to Fail with consent redirect.

Mutually exclusive per purpose—migrating LI → consent requires new capture events and LIA deprecation workflow.

Objection vs withdrawal?

Withdrawal applies to consent-based processing. Objection applies to LI—different queues, same user lookup.

Public trust center?

Summarize LI categories in plain language (“product improvement analytics”) with opt-out instructions—do not publish internal balancing scores.


Next steps

Share on X

§ Keep reading

Related guides.