figma guide
Designing legitimate interest assessment (LIA) workflow UI in Figma: balancing tests, records, and objections
Design legitimate interest assessment workflow UI in Figma with three-part balancing tests, purpose linkage, objection handling, review cadence, and ROPA integration for Privacy teams.
- Published
- Updated
- Aug 04, 2026
- Read time
- 8 min
- Level
- Intermediate
Quick answer
A legitimate interest assessment (LIA) documents the GDPR three-part test: purpose, necessity, and balancing—before you rely on Article 6(1)(f) instead of consent. Design an LIA registry with draft → review → approved states; a balancing worksheet capturing impacts, safeguards, and opt-out paths; and objection queues tied to ROPA activities and privacy settings. Start from the Figma guides hub and pair with consent records admin, PIA/DPIA workflow, DSAR portal, data retention policies, and Dev Mode handoff.
Who this is for
- Product designers building privacy ops tools where Marketing and Product default to “we have legitimate interest.”
- Design system teams standardizing LIA status badges, balancing scorecards, and objection SLA chips.
- DPOs and Privacy counsel who need structured records—not Word docs named
LIA_final_v7_really_final.docx.
LIA hub (internal overview)
LIAHub — Acme Privacy · 34 assessments · 6 draft · 2 balancing failed · 1 objection overdue
├── Header: Approved 28 · Under review 4 · Superseded 2 · Linked ROPA rows 34
├── Actions: [ New LIA ] [ Clone template ] [ Export register ] [ Schedule re-review ]
├── Tabs: Assessment register · Objections · Templates · ROPA sync · Audit trail · Reports
├── Alert: LIA-2026-09 · Product analytics · Balancing failed · Blocks new data category
├── Filters: Business unit · Status · ROPA activity · Contains marketing · Re-review due
└── Link: [ROPA hub](/designing-records-of-processing-activities-and-data-mapping-ui-in-figma/) · PIA registry · Consent admin · Trust center
| Section | Purpose |
|---|---|
| Assessment register | All LIAs with status, owner, and linked purposes |
| Objections | Article 21 requests with SLA and outcome |
| Templates | Reusable worksheets by use case (analytics, fraud, B2B prospecting) |
| ROPA sync | Lawful basis Art. 6(1)(f) requires approved LIA |
| Audit trail | Version history when product scope changes |
| Reports | ICO-style summary export for regulator questions |
Verdict: LIA UI prevents “legitimate interest” as a checkbox—without an approved balancing record, ROPA rows should not publish as Active.
LIA detail workspace (three-part test)
LIADetail — LIA-2026-09 · Product usage analytics · Status: Balancing failed
├── Linked: ROPA PA-331 · Purpose: Improve product features · Owner: @product-privacy
├── Part 1 — Purpose identification:
│ ├── Controller interest: Understand feature adoption to prioritize roadmap
│ ├── Data subjects: Authenticated SaaS customers · Not prospects
│ └── Plain language summary: "We analyze how teams use dashboards to improve UX"
├── Part 2 — Necessity test:
│ ├── Is processing necessary for the stated purpose? Partial — aggregate would suffice
│ ├── Less intrusive alternatives: Aggregated metrics · Sampled sessions · User surveys
│ └── Decision: User-level events NOT necessary for stated purpose · Gap flagged
├── Part 3 — Balancing test:
│ ├── Subject expectations: Medium — B2B admin users expect product improvement
│ ├── Impact: Identifiable usage trails · Sensitive: No special category
│ ├── Safeguards: Pseudonymization option · 90-day retention · Admin-only access
│ ├── Opt-out: Link [privacy settings](/designing-privacy-settings-and-data-management-ui-in-figma/) · "Analytics off" toggle
│ └── Outcome: FAIL — necessity gap; recommend aggregate-only or consent path
├── Approvals: DPO review pending · Legal comment Aug 2 · Product ack required
└── [ Save draft ] [ Submit for DPO ] [ Convert to consent purpose ] [ Deprecate processing ]
| Test section | UI pattern |
|---|---|
| Purpose | Free text + structured “controller interest” field |
| Necessity | Required alternatives list—cannot skip with empty state |
| Balancing | Impact slider + safeguards checklist + opt-out link field |
| Outcome | Pass · Fail · Conditional (with remediation tasks) |
| ROPA gate | Cannot set lawful basis LI until Outcome = Pass or Conditional cleared |
Failed balancing should offer guided remediation: switch to consent (consent admin), reduce granularity, or deprecate processing.
Template library by use case
LIATemplates — 8 approved templates · 2 org-specific
├── T-01 B2B product analytics · Last used 12x · Default retention 90d · Opt-out required
├── T-02 Fraud prevention · Necessity strong · Minimal opt-out · Re-review annual
├── T-03 Customer success health scores · Balancing medium · Admin-visible only
├── T-04 Marketing lookalike modeling · Usually FAIL → redirect to consent purpose
├── T-05 Security logging · Necessity strong · Link [audit log UI](/designing-audit-log-and-security-activity-ui-in-figma/)
├── Clone: Start from T-01 · Pre-fill safeguards · Edit necessity alternatives
└── [ Create template ] [ Deprecate template ] [ Preview worksheet PDF ]
| Template type | Design guardrail |
|---|---|
| Marketing prospecting | Default banner: “Consider consent instead” |
| Employee monitoring | High impact preset; mandatory Legal review |
| Analytics | Force “aggregate alternative” field |
| Security | Cross-link retention policy; shorter re-review |
| AI training | Auto-suggest PIA/DPIA if personal data |
Templates accelerate intake but never auto-approve—each instance needs DPO sign-off.
Objection handling queue (Article 21)
ObjectionQueue — 23 open · 2 overdue SLA · Avg close 4.2 days
├── OBJ-881 · user_442 · PA-331 analytics · Received Aug 1 · SLA Aug 8
│ ├── Request: "Stop analyzing my team's usage"
│ ├── LIA link: LIA-2024-04 · Approved · Opt-out path documented
│ ├── Action: Verify toggle off · Purge 90d rolling events · Confirm email
│ └── Status: In progress · Engineering ticket ENG-991
├── OBJ-902 · user_118 · B2B prospecting · Received Aug 3 · Competing rights review
│ ├── LIA link: LIA-2025-11 · Conditional · Legal reviewing override
│ └── Status: Legal hold · Cannot auto-close
└── [ Bulk export ] [ SLA dashboard ] [ Link DSAR ]
| Objection state | SLA note |
|---|---|
| Received | Acknowledge within 72h—template email |
| Verified | Confirm identity via account dashboard |
| Remediated | Processing stopped + deletion jobs tracked |
| Denied (rare) | Compelling grounds documented; Legal-only action |
| Closed | User notification + ledger entry |
Objections differ from DSAR erasure—design separate queues with cross-link when requests combine both.
ROPA integration and lawful basis gate
ROPASync — Lawful basis Legitimate interest · 34 activities · 2 missing approved LIA
├── PA-331 · Analytics · LIA-2026-09 · Status Balancing failed · ROPA blocked
├── PA-118 · Account management · Contract · No LIA required
├── PA-204 · Marketing email · Consent · Link [consent admin](/designing-consent-records-and-preference-management-admin-ui-in-figma/)
├── Gate rule: Art. 6(1)(f) → requires LIA status Approved or Conditional-cleared
└── [ Run gap scan ] [ Notify activity owners ]
Changing a ROPA activity’s scope (new data category, new recipient) should auto-open LIA addendum—mirror TIA addendum flows for transfers.
When LIA fails, guide owners to either narrow processing or migrate lawful basis with explicit Legal approval—not silent checkbox edits.
Re-review cadence and change triggers
ReReviewCalendar — 5 due this quarter · Trigger rules active
├── LIA-2023-08 · Fraud scoring · Due Sep 2026 · Owner @risk-team
├── Trigger fired: LIA-2024-02 · New subprocessor · Auto-opened addendum Jul 28
├── Trigger fired: LIA-2025-11 · Marketing expanded to US · DPO task created
├── Rules: Subprocessor change · New region · Retention extension · Purpose text change
└── [ Complete re-review ] [ Snooze with justification ]
| Trigger | UI behavior |
|---|---|
| Subprocessor add | Compare data categories; open addendum |
| Retention extension | Re-run balancing impact section |
| New region | Check local law overrides (e.g., marketing rules) |
| Product launch | Block feature flag until LIA Pass or consent path |
| Annual calendar | Task assigned 30 days before due |
Stale LIAs are a common audit finding—show days overdue on ROPA rows and security posture dashboard privacy widgets.
Handoff checklist (Dev Mode)
- LIA — id, ropa_activity_id, status, outcome, owner_id, approved_at, re_review_date.
- Purpose section — controller_interest, data_subjects[], plain_summary.
- Necessity — is_necessary, alternatives[], necessity_decision, notes.
- Balancing — impact_level, safeguards[], opt_out_url, opt_out_mechanism_id, outcome.
- Objection — id, user_id, lia_id, status, sla_due, remediation_job_ids[].
- Template — template_id, use_case, default_safeguards[], recommended_retention_days.
- Accessibility — worksheet sections as expandable panels; outcomes announced to screen readers.
Common mistakes
| Mistake | Why it hurts | Fix |
|---|---|---|
| LIA as one checkbox on ROPA | No balancing proof | Separate worksheet with three parts |
| Marketing uses LI for email | Unlawful in most EU contexts | Template redirects to consent |
| No opt-out documented | Balancing fails | Required opt-out link field |
| Necessity section skipped | ICO scrutiny | Block submit until alternatives listed |
| Objections in generic support queue | SLA misses | Dedicated objection tab with timers |
| Approved LIA never re-reviewed | Scope creep invalidates | Triggers + calendar |
| LI and consent on same purpose | Conflicting lawful basis | Mutual exclusion in purpose registry |
| PDF export only | Not queryable for audits | Structured fields + PDF |
| Product launches before DPO sign-off | Compliance debt | ROPA gate on feature flags |
| Copy-paste balancing text | Identical assessments | Require per-activity impact notes |
Recommended workflow
- Create LIA templates for common use cases with guardrail banners.
- Build three-part worksheet with necessity alternatives and balancing outcome.
- Wire ROPA gate so Art. 6(1)(f) requires Approved LIA.
- Add objection queue with SLA, remediation jobs, and DSAR cross-link.
- Configure change triggers for subprocessors, regions, and retention.
- Connect privacy settings opt-out toggles to objection remediation checks.
- Export LIA register for compliance audit evidence packs.
FAQ
LIA vs PIA/DPIA?
LIA decides if legitimate interest is an appropriate lawful basis. DPIA assesses high-risk processing regardless of basis—run DPIA when triggers apply even if LIA passes.
When is legitimate interest inappropriate?
Direct marketing to individuals often needs consent (or soft opt-in where allowed)—template T-04 should default to Fail with consent redirect.
Link to consent records?
Mutually exclusive per purpose—migrating LI → consent requires new capture events and LIA deprecation workflow.
Objection vs withdrawal?
Withdrawal applies to consent-based processing. Objection applies to LI—different queues, same user lookup.
Public trust center?
Summarize LI categories in plain language (“product improvement analytics”) with opt-out instructions—do not publish internal balancing scores.
Next steps
- Design records of processing activities and data mapping UI in Figma — lawful basis and activity linkage
- Design consent records and preference management admin UI in Figma — when LI is not appropriate
- Design privacy impact assessment and DPIA workflow UI in Figma — high-risk processing assessments
- Design privacy settings and data management UI in Figma — opt-out and objection controls
- Design data subject access request and GDPR portal UI in Figma — combined access and objection requests
§ Keep reading