Legitimate Interests Assessment — Template

A pre-filled LIA for using LogLens to analyse your server logs, based on the ICO's three-part test. Copy it, replace the italic placeholders, have your DPO/counsel adapt as needed, and keep it on file. It is a starting point, not legal advice.

Part 1 — Purpose test (is there a legitimate interest?)

Controller:

[Your company name, registration number, contact]

Processing under assessment: analysis of web-server/CDN access logs (IP address, user-agent, URL, referrer, timestamp, response metadata) for the websites listed below, using LogLens as a processor under its Data Processing Agreement (incorporated into its Terms of Service).

[List the websites/domains in scope]

Interests pursued: (a) network and information security — detecting attack probes, credential-stuffing, scraping, spoofed crawlers and abusive automation (expressly recognised as a legitimate interest by GDPR Recital 49); (b) fraud prevention (Recital 47); (c) service integrity and performance monitoring; (d) first-party audience/SEO analytics of our own websites without placing cookies or trackers on visitors' devices.

Benefits: earlier detection of attacks and outages; reduced fraud; the ability to measure the website without third-party advertising trackers or consent friction for visitors.

Part 2 — Necessity test (is the processing necessary?)

• The access logs are already generated as an unavoidable by-product of operating the websites; no additional collection from data subjects occurs.
• Security monitoring cannot be performed without request-level data: attack and bot patterns are only visible at the level of individual requests, and IP addresses are required to distinguish legitimate crawlers (verified against publisher IP ranges) from impersonators, and to identify attack sources.
• Less-intrusive alternatives considered: client-side analytics (does not capture bots/attacks at all, and adds trackers to visitors' devices); aggregate-only CDN dashboards (insufficient granularity for security response). Where full IPs are not required, we mitigate further — see Part 3.

Part 3 — Balancing test (do individuals' interests override ours?)

Nature of the data: pseudonymous online identifiers (IP, user-agent) and browsing of our own public websites. No special-category data is processed; a substantial share of records relates to corporate bots rather than natural persons.

Reasonable expectations: it is widely understood that web servers log requests, including IP addresses, for security and operations; Recital 49 reflects this expectation. Visitors are informed via our privacy notice.

[Confirm your privacy notice discloses server-log processing and names LogLens as a processor — add the link]

Impact on individuals: low — the data is not used for advertising, profiling for marketing, or automated decisions with legal effect; it is not sold or shared across customers; no cookies or device access are involved.

Safeguards in place: LogLens Data Processing Agreement (applies automatically under its Terms); UK (London) data residency with encryption in transit and at rest; plan-limited retention of [30 days / 120 days / … per your plan]; per-tenant isolation; optional traffic-class retention filters [state if enabled]; optional upstream PII exclusion (Vercel/Netlify) [state if enabled]; data-subject requests supported via the processor (search/erasure by IP).

Conclusion: the processing pursues recognised legitimate interests, is necessary and proportionate, and — with the safeguards above — does not override the interests, rights or freedoms of data subjects. Lawful basis: Article 6(1)(f) GDPR.

Assessed by:

[Name, role, date — review annually or on material change]