Skip to main content
Category: Breach and Risk Assessment

Necessity and Proportionality Assessment

Also known as: Necessity and Proportionality Test
Simply put

A necessity and proportionality assessment is an evaluation that checks whether a proposed use of personal data is genuinely needed to achieve a stated purpose and whether the impact on people is justified relative to that purpose. It asks whether the same goal could be reached in a less intrusive way, and whether the processing actually delivers the intended outcome. It is commonly carried out as part of a data protection impact assessment.

Formal definition

A structured analysis, typically forming a component of a Data Protection Impact Assessment (DPIA) under the UK GDPR and EU GDPR, that tests whether a processing operation is necessary and proportionate to its identified purpose. Necessity generally examines whether the processing genuinely achieves the stated purpose and whether a less intrusive means is available; proportionality weighs the interference with individuals' rights against the objective pursued. EDPS guidance frames the assessment for measures affecting fundamental rights as a multi-step test addressing appropriateness, necessity, and proportionality. In DPIA practice, ICO guidance situates this step alongside identifying the lawful basis for processing and documenting compliance and proportionality measures. This entry covers the assessment concept and its role within a DPIA; it does not address DPIA triggering criteria, cross-border transfer mechanics, retention rules, or enforcement outcomes, and identifying a lawful basis alone does not by itself establish that processing is necessary or proportionate. Treatment differs across jurisdictions and instruments.

Why it matters

A necessity and proportionality assessment is often the analytical heart of a Data Protection Impact Assessment. It moves an organisation beyond the threshold question of whether it has a lawful basis and forces a harder inquiry: whether the processing genuinely achieves the stated purpose and whether the intrusion on individuals is justified by that objective. Identifying a lawful basis alone does not establish that processing is necessary or proportionate; these remain distinct tests, and treating one as a proxy for the other is a common expert-level error.

The stakes are practical as well as legal. ICO DPIA guidance situates the assessment of necessity and proportionality alongside documenting the lawful basis and asking whether the processing actually achieves its purpose. Where a less intrusive means could reach the same goal, a well-conducted assessment surfaces that alternative before deployment rather than after harm has occurred. Privacy International frames this in the context of data analytics and surveillance technologies, where a necessity assessment is expected to demonstrate clearly that recourse to a particular system is necessary to achieve the objective, rather than merely convenient or available.

Under governance and accountability principles, the value of the assessment lies in demonstrable evidence, not stated intent. A documented, reasoned assessment that weighs interference against objective can support an organisation's accountability posture, while an unrecorded or conclusory judgement generally cannot. This entry does not address DPIA triggering criteria, retention rules, cross-border transfer mechanics, or enforcement outcomes, and treatment differs across jurisdictions and instruments.

Who it's relevant to

Data protection officers and privacy engineers
DPOs and privacy engineers commonly conduct or advise on this assessment as part of a DPIA. They are responsible for testing whether a less intrusive means could achieve the same purpose and for documenting the reasoning so that necessity and proportionality can be demonstrated, not merely asserted. Identifying a lawful basis does not discharge this obligation.
Compliance and information governance leads
Those accountable for governance rely on the assessment to produce demonstrable evidence supporting an organisation's accountability posture. They should ensure the assessment is recorded alongside the lawful basis and proportionality measures rather than treated as a formality, and should recognise that its scope does not extend to retention, transfer mechanics, or enforcement questions.
Teams deploying data analytics or surveillance technologies
Where processing involves analytics systems or technologies that affect individuals' rights, a necessity assessment is expected to demonstrate clearly that recourse to the particular system is necessary to achieve the objective. For such measures affecting fundamental rights, EDPS guidance frames a multi-step test addressing appropriateness, necessity, and proportionality that these teams should work through before deployment.
Legal advisers reviewing processing proposals
Legal professionals assessing proposed processing use this analysis to scrutinise whether the interference with rights is justified relative to the purpose. They should keep the necessity and proportionality tests distinct from the lawful basis question and should note that treatment differs across the UK GDPR, EU GDPR, and other regimes.

Inside Necessity and Proportionality Assessment

Necessity Test
An assessment of whether a given processing activity is actually required to achieve a specified, legitimate purpose, and whether the same purpose could reasonably be achieved by less intrusive means. Generally, if a less privacy-invasive alternative would work, the processing is not considered necessary.
Proportionality Test
An evaluation of whether the interference with individuals' rights and freedoms is balanced against the benefit or objective pursued. This weighs the intrusiveness and volume of data against the value of the aim, and typically considers whether the impact on data subjects is excessive relative to the purpose.
Specified Purpose
A clearly articulated processing objective against which necessity and proportionality are measured. Without a defined and legitimate purpose, neither test can be meaningfully applied.
Less Intrusive Alternatives
Consideration of options such as reducing the data collected, using pseudonymized rather than directly identifying data, shortening retention, or aggregating data, to determine whether the same purpose can be met with reduced impact on individuals.
Relationship to Broader Assessments
Necessity and proportionality analysis commonly forms a component of wider exercises such as a data protection impact assessment or a legitimate interests balancing exercise, rather than standing alone. Its treatment can vary by jurisdiction and legal instrument.

Common questions

Answers to the questions practitioners most commonly ask about Necessity and Proportionality Assessment.

Does documenting a lawful basis mean the necessity and proportionality test is satisfied?
No. Identifying a lawful basis and completing a necessity and proportionality assessment are distinct steps. Necessity asks whether the processing is genuinely required to achieve the stated purpose and whether a less intrusive means could achieve the same outcome; proportionality asks whether the interference with individuals' rights is justified relative to the objective. A lawful basis may be validly identified while the specific volume, scope, or duration of processing still fails a proportionality analysis. The two assessments should be conducted and evidenced separately.
Is a necessity and proportionality assessment only relevant when relying on legitimate interests?
No. While necessity and proportionality feature prominently in a legitimate interests analysis in regimes such as the EU GDPR and UK GDPR, the necessity element applies across most lawful bases, since generally only processing that is necessary for the stated purpose is permitted. Even where consent is the basis, minimisation and necessity considerations remain relevant. Treating the assessment as exclusive to legitimate interests risks overlooking necessity obligations that attach to other bases and to processing generally.
How does a necessity and proportionality assessment relate to a data protection impact assessment?
Necessity and proportionality analysis is typically a component within a broader data protection impact assessment where one is conducted, rather than a wholly separate exercise. However, a DPIA is not always mandatory, and necessity and proportionality reasoning may need to be documented outside of a formal DPIA, for example within a legitimate interests assessment or general processing records. Practitioners should confirm which vehicle is appropriate for the specific processing rather than assuming the two are interchangeable.
What evidence should be retained to demonstrate a necessity and proportionality assessment was performed?
Accountability under governance frameworks generally requires demonstrable evidence rather than stated intent, so retain a dated record of the assessment showing the purpose, the data categories and volumes involved, the alternatives considered and why they were rejected as less effective, the balancing reasoning, and any safeguards or mitigations applied. This entry does not prescribe a specific retention period or template, which will depend on your jurisdiction, internal policy, and the nature of the processing.
Who should be responsible for conducting the assessment?
Responsibility typically sits with the party determining the purposes and means of the processing, which in controller-processor arrangements is generally the controller. A data protection officer, where one is designated, may advise on and review the assessment but does not usually own the underlying processing decision. Input from business owners, legal, and security functions is commonly needed. This entry does not address how obligations are allocated in joint controller or complex cross-border arrangements.
When should a necessity and proportionality assessment be revisited?
An assessment reflects the processing as understood at a point in time, so it should generally be reviewed when the purpose changes, when the data categories or volumes expand, when new recipients or transfers are introduced, or when the safeguards relied upon change materially. Periodic review is also common practice. This entry does not specify review intervals or cross-border transfer mechanics, which depend on your regime, risk profile, and internal governance requirements.

Common misconceptions

A necessity and proportionality assessment guarantees that processing is lawful and compliant.
It is one analytical component that supports a defensible position, but compliance depends on context, jurisdiction, the applicable lawful basis, and implementation. No single assessment guarantees compliance across regimes such as the EU GDPR, the UK GDPR, or other frameworks.
If a purpose is legitimate, any processing that helps achieve it is automatically necessary.
Necessity generally requires that no reasonably available less intrusive means could achieve the same purpose. A legitimate aim does not justify collecting or processing more data than is required for that aim.
A necessity and proportionality assessment is the same thing as a data protection impact assessment.
Necessity and proportionality analysis is typically a component within a data protection impact assessment or a legitimate interests balancing exercise, not a substitute for it. A DPIA is not always mandatory, and its triggers and scope differ by jurisdiction and instrument.

Best practices

Define and document the specific, legitimate purpose before assessing necessity, since both tests are measured against that stated purpose.
Actively identify and evaluate less intrusive alternatives, such as reduced data collection, pseudonymization, aggregation, or shorter retention, and record why they were or were not adopted.
Retain demonstrable evidence of the reasoning and outcome, as accountability under governance frameworks requires documented justification rather than stated intent alone.
Scope the assessment to the applicable legal instrument and note where treatment may differ across jurisdictions, rather than assuming a single universal standard.
Integrate the analysis into broader exercises such as a data protection impact assessment or legitimate interests balancing where relevant, rather than treating it as a standalone conclusion.
Use qualified, context-aware conclusions and revisit the assessment when the purpose, data, or processing means change materially.