Skip to main content
Compatibility Assessment Template for Data Reuse ProjectsBreach & Risk Assessment
4 min readFor Privacy Officers

Compatibility Assessment Template for Data Reuse Projects

Before you repurpose customer data for a new product or analytics initiative, you must document why it's lawful. This template guides you through the compatibility assessment required under GDPR Article 6(4) and the legitimate interests assessment under Recital 47.

Use this when you're considering reusing data collected for one purpose (like bookings or customer support) for a different purpose (such as profiling or product development). The AEPD's €18 million fine against Amadeus IT Group shows the consequences of skipping this step. They repurposed traveler booking data for a profiling pilot without conducting a proper compatibility assessment or establishing a valid lawful basis.

Prerequisites

Before you start, ensure you have:

Documentation of the original purpose. Review your existing privacy notice or data processing record. What did you tell data subjects when you collected their data? What lawful basis did you cite?

A clear description of the new purpose. Specify exactly what you intend to do with the data. Vague terms like "analytics" won't hold up under scrutiny. The AEPD rejected Amadeus's reliance on broad privacy policy language for this reason.

Access to your retention schedule. Ensure you haven't retained data beyond its allowed period. Amadeus used booking data from 2019 that should have been deleted under sector-specific retention rules.

The Template

Copy this into your documentation system. Complete every section before you begin processing.


PROJECT NAME:
DATE PREPARED:
PREPARED BY:

Part 1: Original Processing

Original purpose(s):
[Describe why you collected this data initially]

Original lawful basis:
Consent
☐ Contract
Legal obligation
☐ Vital interests
☐ Public task
☐ Legitimate interests

Data subjects' reasonable expectations:
[What would a reasonable person expect you to do with their data based on the context in which you collected it?]

Existing privacy notice language:
[Quote the relevant sections]

Part 2: New Processing

New purpose:
[Be specific about what you're building or analyzing]

Why this purpose is different:
[Explain why this isn't covered by your original purpose]

Data categories involved:
[List the specific fields you'll use]

Will you share data with third parties for this purpose?
☐ Yes ☐ No
If yes, list recipients:

Part 3: Compatibility Assessment (Article 6(4))

Answer each question. If you answer "no" to any question, your new purpose may not be compatible.

Is there a link between the original and new purposes?
☐ Yes ☐ No
Explanation:

What is the context in which you collected the data?
[Consider: direct relationship with data subjects? B2B service where you receive data from intermediaries? Sensitive context like health or travel?]

What is the nature of the personal data?
☐ Basic contact details
☐ Transactional data
☐ Behavioral data
☐ Special category data
☐ Data concerning children

What are the possible consequences for data subjects?
[Consider: profiling? Automated decisions? Unexpected marketing? Potential for discrimination?]

What safeguards are in place?
[List: encryption, access controls, pseudonymization, aggregation, time limits]

Compatibility conclusion:
☐ Compatible (proceed to Part 4)
☐ Not compatible (you need consent or another Article 6 basis for the new purpose)

Part 4: Legitimate Interests Assessment

Complete this section only if you're relying on legitimate interests as your lawful basis.

Your legitimate interest:
[Describe the specific Legitimate Interests. "Commercial benefit" isn't enough.]

Is this interest lawful?
☐ Yes ☐ No
[Check it doesn't involve discrimination, manipulation, or breach of other laws]

Is processing necessary to achieve this interest?
☐ Yes ☐ No
Could you achieve the same result through:
☐ Aggregated data
☐ Synthetic data
☐ Data minimization
☐ Other less intrusive means

Balancing test:

Data subjects' interests and rights:
[Consider: vulnerability, power imbalance, reasonable expectations, potential harm]

Your interests:
[Consider: importance to your business, benefits to society, innovation value]

Does your interest outweigh their rights?
☐ Yes ☐ No

If you answered no, legitimate interests is not available. Consider consent instead.

Part 5: Transparency Plan

Will you update your privacy notice?
☐ Yes ☐ No

Draft notice language:
[Write the specific text you'll add about this new purpose]

How will you communicate this to data subjects?
☐ Direct email
☐ Account notification
☐ Website banner
☐ Through our customers/partners (if B2B)
☐ Other:

Timeline:
Notice will be provided by: [DATE]
Processing will begin on: [DATE]

If you have no direct relationship with data subjects:
How will you ensure they receive Article 14 information?
[The Amadeus case shows you can't skip this. If you're a B2B service provider, you need a plan.]


How to Customize It

For high-risk processing, add a section linking to your Data Protection Impact Assessment. If you're doing large-scale profiling, automated decision-making, or processing special category data, you need a DPIA in addition to this assessment.

For cross-border processing, add a section documenting which supervisory authority is your lead authority and whether you've flagged this project with them.

For sector-specific rules, add a retention compliance check. Amadeus violated the Computerised Reservation Systems Regulation by keeping booking data beyond the three-year limit. If you operate in aviation, finance, healthcare, or telecommunications, cite the specific retention rule that applies.

Validation Steps

Before you start processing, verify:

Your legal team has reviewed the completed template. This isn't a checkbox exercise. If your balancing test is weak, you need to strengthen your safeguards or reconsider the project.

Your privacy notice changes are drafted and approved. Don't process first and update the notice later.

Your retention schedule permits this use. Run a query: is any of the data you plan to reuse past its retention deadline?

You've documented this in your Article 30 processing record. Your new purpose needs its own entry.

If you're a processor considering controller activities, review your customer contracts. Do they permit you to act as controller for your own purposes? If not, you need to renegotiate before you proceed.

The AEPD noted that Amadeus had a prior Article 12 violation in 2022. Repeat violations increase fines. If your organization has been sanctioned before, your supervisory authority will scrutinize your compliance program more closely. Document everything.

You Might Also Like