Skip to main content
Category: Impact Assessments & Documentation

Assessment of Necessity and Proportionality

Also known as: Necessity and Proportionality Test, Necessity and Proportionality Assessment
Simply put

This is a structured evaluation used to check whether processing personal data (or another measure affecting individuals) is genuinely needed to achieve a legitimate aim and whether the impact on people is justified by the benefit. In practice, it asks whether a less intrusive option could achieve the same goal, and whether the interference with rights is reasonable in the circumstances. It is typically carried out on a case-by-case basis rather than as a one-time, permanent conclusion.

Formal definition

The assessment of necessity and proportionality is an analytical test applied when a measure interferes with rights protected under EU law, including the rights to privacy and to the protection of personal data. Per the EDPS Guidelines (19 December 2019), the test for establishing the necessity and proportionality of a measure is described as comprising three steps: (i) appropriateness (whether the measure is suitable to achieve the stated objective); (ii) necessity (whether the objective could reasonably be achieved by a less intrusive means); and (iii) proportionality in the strict sense (whether the interference is justified relative to the aim). These concepts are generally invoked in the data protection context in relation to assessments such as legitimate interests balancing, restrictions of rights, and impact assessments, and they draw on a broader body of EU fundamental rights jurisprudence rather than being defined by a single self-contained GDPR provision. The precise structure and weighting of the steps remains a subject of scholarly and jurisprudential debate, and the analysis is inherently fact-specific and must be performed on a case-by-case basis. Readers should verify the current EDPS guidance and applicable case law, as this summary reflects the framing in the cited materials and not an exhaustive statement of the law.

Why it matters

The assessment of necessity and proportionality is a structural check against overreach. Many data protection determinations, whether a legitimate interests basis holds, whether a restriction of data subject rights is justified, or how an impact assessment should conclude, turn not merely on whether a legitimate aim exists, but on whether the specific processing is genuinely required to achieve it and whether the intrusion on individuals is warranted. Without this discipline, organisations risk collecting or using more personal data than they can justify, and defending decisions after the fact becomes considerably harder.

The test also draws on a broader body of EU fundamental rights reasoning rather than sitting in a single self-contained GDPR provision, which means it functions as connective tissue across several compliance activities. The EDPS Guidelines (19 December 2019) frame the necessity and proportionality of a measure as a three-step analysis, appropriateness, necessity, and proportionality in the strict sense, giving practitioners a repeatable structure to document their reasoning. This documented reasoning is what typically demonstrates accountability to a regulator or court.

It is worth noting that the precise structure and weighting of these steps remains a subject of scholarly and jurisprudential debate; commentators continue to discuss how the necessity and proportionality elements should be understood and applied. Because the analysis is inherently fact-specific, a conclusion reached for one processing operation cannot simply be transplanted to another, and readers should verify the current EDPS guidance and applicable case law rather than treating any single framing as settled or permanent.

Who it's relevant to

Data Protection Officers and privacy leads
DPOs and privacy teams rely on the necessity and proportionality test when advising on legitimate interests balancing, proposed restrictions of data subject rights, and impact assessments. Structuring the analysis around the appropriateness, necessity, and strict-proportionality steps helps produce defensible, documented reasoning, though the conclusion must be re-examined case by case as facts evolve.
Compliance and legal teams
Lawyers and compliance leads use the test to evaluate whether a processing measure is genuinely required and whether its intrusion on individuals can be justified. Because the concepts draw on a broader body of EU fundamental rights jurisprudence rather than a single GDPR provision, these teams should check the current EDPS guidance and relevant case law rather than treat any one framing as definitive.
Engineers and product teams designing data-driven systems
Teams building features that process personal data can apply the necessity step early by asking whether a less intrusive design, for example collecting less data or achieving the aim by other means, would meet the same objective. This supports privacy-conscious design choices, but the assessment remains fact-specific and should be revisited when a system's purpose or data use changes.
Public authorities and bodies subject to EDPS oversight
The EDPS Guidelines (19 December 2019) that articulate the three-step test are particularly relevant to EU institutions and bodies whose measures may interfere with rights protected under EU law. These organisations should apply the test on a case-by-case basis and verify their approach against the current published guidance.

Inside Assessment of Necessity and Proportionality

Necessity Test
An assessment of whether the processing is genuinely required to achieve the identified purpose, rather than merely useful or convenient. Necessity generally implies that the objective cannot reasonably be achieved by less intrusive means. This concept draws on principles reflected in GDPR (including data minimisation) and on interpretation developed through case law and regulatory guidance, so its precise application is subject to assessment in each context.
Proportionality Test
An evaluation of whether the interference with individuals' rights and freedoms is balanced against the legitimate aim pursued. This typically involves weighing the benefits of the processing against its impact on data subjects, considering the scale, sensitivity, and intrusiveness of the processing. Proportionality is context-dependent and generally requires a documented balancing exercise.
Identification of the Aim
A clear articulation of the specific, legitimate objective the processing seeks to achieve. Without a precisely defined purpose, necessity and proportionality generally cannot be meaningfully assessed, since both tests measure the processing against that stated aim.
Consideration of Less Intrusive Alternatives
An examination of whether alternative approaches, reduced data sets, anonymisation or pseudonymisation, or other safeguards could achieve the same aim with lower impact on data subjects. The availability of a viable less intrusive option typically undermines a claim that the chosen processing is necessary.
Relationship to Broader Compliance Instruments
Necessity and proportionality assessments frequently form components of wider exercises, such as a Data Protection Impact Assessment (Article 35) for high-risk processing or a legitimate interests balancing assessment under Article 6(1)(f). The assessment supports, but does not by itself substitute for, these distinct instruments.
Documentation and Reasoning
A recorded rationale showing how the necessity and proportionality conclusions were reached. This supports the accountability principle and provides evidence that can be reviewed by regulators, though documentation alone does not guarantee that the underlying processing is lawful.

Common questions

Answers to the questions practitioners most commonly ask about Assessment of Necessity and Proportionality.

Does assessing necessity and proportionality simply mean checking whether a lawful basis exists?
No. Identifying a lawful basis under Article 6 (and, where special category data is involved, a condition under Article 9) is a separate step from assessing necessity and proportionality. Necessity asks whether the processing is genuinely required to achieve the specified purpose, or whether a less intrusive means could reasonably achieve the same objective. Proportionality weighs the interference with individuals' rights against the aim pursued. A lawful basis may be present while the specific processing still fails a necessity or proportionality test, so both analyses generally need to be documented.
Is the necessity and proportionality assessment only relevant to public authorities or to processing under the public task and legitimate interests bases?
Not exclusively. Necessity is a recurring requirement across several Article 6 bases and appears in obligations such as data minimisation under Article 5. Proportionality is a general principle drawn from EU law and CJEU case law that informs how many GDPR provisions are interpreted, not only those concerning public authorities. In most cases the assessment is relevant wherever processing interferes with data protection rights, though the emphasis and framing can vary depending on the basis relied upon and the context. Readers should confirm how the principle applies to their specific processing.
How should we document a necessity and proportionality assessment in practice?
Typically the assessment is recorded in a way that shows the reasoning, not just the conclusion. This generally includes the specified purpose, the categories and volume of data involved, why the processing is required to meet that purpose, the less intrusive alternatives considered and why they were rejected, and the balancing of the interference against the aim. Where a Data Protection Impact Assessment is required under Article 35, this reasoning is often captured within it. The level of detail should be proportionate to the risk, and organisations should verify internal templates against current regulatory guidance.
When in a project lifecycle should the assessment be carried out?
In most cases the assessment is best performed at the design stage, before processing begins, consistent with data protection by design and by default under Article 25. Conducting it early allows less intrusive options to genuinely influence system design rather than being reviewed after decisions are fixed. The assessment should also generally be revisited when the purpose, scope, data categories, or technical measures change materially, since a conclusion reached at one point may no longer hold.
What kinds of less intrusive alternatives should we consider to satisfy the necessity element?
Necessity typically requires demonstrating that the same purpose could not reasonably be achieved by a less intrusive route. Alternatives commonly considered include reducing the volume or categories of data collected, using pseudonymisation or aggregation, shortening retention periods, limiting access, or achieving the aim without personal data where feasible. The relevant test is generally whether an alternative would meet the objective effectively, not merely whether one exists in the abstract. What is reasonable is context and risk dependent and subject to assessment.
How does the necessity and proportionality assessment relate to a DPIA and to the record of processing activities?
These are distinct but connected instruments. A Data Protection Impact Assessment under Article 35 is required for processing likely to result in a high risk to individuals, and the necessity and proportionality analysis generally forms a core part of it. The record of processing activities under Article 30 documents processing operations but is not itself the necessity and proportionality assessment. In practice organisations often cross-reference these records, but each serves a different function and the boundaries between them should be maintained. Readers should confirm current thresholds and requirements against the official text and applicable guidance.

Common misconceptions

Necessity means the processing is helpful or beneficial to the organisation.
Necessity generally sets a higher threshold than usefulness. Processing is typically considered necessary only where the aim cannot reasonably be achieved by less intrusive means; a benefit to the organisation does not, on its own, establish necessity.
Passing a necessity and proportionality assessment makes the processing fully compliant.
The assessment is one element within a broader compliance picture. A valid lawful basis under Article 6 (and, for special category data, an additional condition under Article 9), transparency, security, and other obligations must still be satisfied. Compliance is context and risk dependent and cannot be assured by this assessment alone.
The necessity and proportionality assessment is the same as a DPIA.
Necessity and proportionality are typically components considered within a DPIA (Article 35), but the two are distinct. A DPIA is a wider structured process required for certain high-risk processing, whereas a necessity and proportionality assessment can also arise in other contexts, such as a legitimate interests balancing exercise.

Best practices

Define the specific, legitimate aim of the processing before assessing necessity or proportionality, since both tests are measured against that stated purpose.
Actively identify and evaluate less intrusive alternatives, including reduced data sets, pseudonymisation, or anonymisation, and record why any rejected option was not viable.
Document the reasoning and conclusions in a form that can be reviewed later, supporting the accountability principle and enabling regulatory scrutiny.
Situate the assessment within the correct instrument, such as a DPIA under Article 35 for high-risk processing or a legitimate interests balancing assessment under Article 6(1)(f), rather than treating it as a standalone justification.
Use qualified, evidence-based reasoning rather than absolute conclusions, recognising that necessity and proportionality outcomes are context-specific and subject to reassessment if the processing or purpose changes.
Verify the current position against official GDPR text and up-to-date regulatory guidance, noting that interpretation can evolve and may diverge between regulators or under national implementing law.