Legitimate Interests Assessment
This Legitimate Interests Assessment (LIA) documents how Klokk Nettablering evaluates the use of "legitimate interest" (Article 6(1)(f) GDPR) as a legal basis for processing personal data in connection with Tenderax, in particular for business-development outreach. It is published for transparency and is reviewed whenever our outreach practices change.
Current status
Cold B2B outreach is not currently active in production. Any outreach functionality that relies on legitimate interest as its legal basis is presently running in test mode only, limited to a small internal cohort in the United States, and has not been enabled for prospects in any other jurisdiction. This page documents the assessment that would govern such outreach if and when it is switched on more broadly, and the jurisdiction rules that gate that rollout.
1. Purpose test
The purpose of using legitimate interest as a legal basis is to allow Klokk Nettablering to identify and contact procurement-relevant businesses that have not yet interacted with Tenderax, in order to inform them of a service directly relevant to their commercial activity (competing for public tenders). This is a genuine, clearly articulated business interest: reasonable, targeted B2B business development is a recognised legitimate interest under GDPR Recital 47, which explicitly names direct marketing as a potential legitimate interest.
This purpose does not apply to inbound users — anyone who signs up, starts a trial, or otherwise contacts us first is processed under contract (Article 6(1)(b)), not legitimate interest. This LIA concerns first-party outreach to parties who have not yet engaged with Tenderax.
2. Necessity test
Is legitimate interest necessary, or could the purpose be achieved with a less intrusive method or a different legal basis?
- Obtaining prior consent from every prospect before any first contact is not practicable for outbound business development — it would defeat the purpose of introducing the service to businesses who do not yet know it exists.
- Processing is limited to business contact data (company name, work email, role) — not private individuals in a personal capacity.
- The processing is proportionate: a small number of relevant, well-targeted messages, not bulk or repeated contact, with a functioning opt-out on first contact.
- No special category data, no profiling beyond company-level relevance, and no automated decision-making with legal effect is involved.
Conclusion: legitimate interest is necessary and proportionate for this narrowly defined purpose, subject to the jurisdictional restrictions below.
3. Balancing test
We weigh our interest in business development against the rights and freedoms of the data subject, jurisdiction by jurisdiction, because GDPR enforcement posture and local ePrivacy/marketing rules differ significantly:
| Jurisdiction category | Outcome | Rationale |
|---|---|---|
| United States | Legitimate interest permitted (test mode) | Not subject to GDPR; CAN-SPAM allows opt-out-based B2B email contact. Lower regulatory risk supports a controlled test rollout. |
| Inbound / first-party (any jurisdiction) | Always permitted | User-initiated contact (trial sign-up, contact form, demo request) is processed under contract, not legitimate interest — this LIA does not restrict it. |
| Germany, Italy | Excluded from cold outreach | Both jurisdictions apply notably strict interpretations of unsolicited B2B electronic communication (e.g. UWG in Germany, Garante enforcement in Italy) that in practice require prior consent even for B2B email marketing. The balance tips against legitimate interest. |
| Norway | Excluded from cold outreach | As the jurisdiction of the controller, we hold ourselves to the stricter Norwegian Marketing Control Act (markedsføringsloven) standard on unsolicited electronic marketing, which functions as a de facto consent requirement for cold B2B email. |
| Other GDPR-strict jurisdictions (assessed case by case) | Excluded pending individual review | Any jurisdiction with a national ePrivacy implementation or enforcement history that raises the practical bar above "opt-out" is excluded from cold outreach until a jurisdiction-specific balancing test is completed and documented here. |
| Rest of EU/EEA not separately listed | Excluded from cold outreach until individually assessed | Default posture is exclusion; inclusion requires a documented, jurisdiction-specific LIA addendum before activation. |
Safeguards applied wherever legitimate interest is used
- Every outreach message includes a clear, working opt-out;
- Opt-out requests are honoured immediately and are not contacted again;
- No special category data is used to select or target recipients;
- Contact data used for outreach is limited to business contact details reasonably obtained from public professional sources;
- Volume and frequency are capped to avoid nuisance contact;
- This assessment is reviewed before any expansion beyond the current US test cohort, and updated here.
Conclusion
Legitimate interest is a defensible legal basis for narrowly scoped, opt-out-enabled B2B outreach in the United States test cohort. It is not currently used, and will not be used, for cold outreach into Norway, Germany, Italy, or any other jurisdiction until a jurisdiction-specific balancing test has been completed and published. Inbound, user-initiated interactions with Tenderax are unaffected by this assessment and are always processed under contract.
Questions about this assessment can be sent to [email protected].
← Back to Tenderax