Skip to content

Privacy Hub · plain-language reference

← Privacy Hub

Processing personal data

Also known as: data processing, data use, handling information, process data, processing operation, using personal data

Processing means doing almost anything with personal data, including collecting, recording, organising, viewing, using, sharing, storing, changing, combining, restricting or deleting it. An organisation can therefore process information without analysing or selling it. Even routine storage and access are part of the personal-data lifecycle and should be governed deliberately.

ZW_CDPA
EU_GDPR
GB_UK_GDPR
v2 · published 31 Jul 2026

Term explanation

At a glance

“Processing” is the broad umbrella term for operations performed on personal data. It covers the full lifecycle, from the moment information is collected or generated until it is securely deleted or made genuinely anonymous. The concept is deliberately wider than data analysis.

Opening a customer record, backing up a database, sending a staff list to a payroll provider, recording a call and deleting an old account can all be processing operations. An organisation may perform many separate operations within one business activity.

In plain language

Privacy rules are meant to govern what happens to people’s information, not only the most visible or profitable uses. A narrow definition would leave ordinary storage, disclosure or disposal outside the framework even though those activities can create serious harm.

It helps to map processing as verbs: collect, record, organise, retrieve, consult, use, disclose, transmit, combine, restrict, erase and destroy. This makes an abstract system easier to understand and exposes hand-offs that a simple list of databases might miss.

Why it matters

Every processing activity should have a defined purpose. “We might need it later” is not a meaningful purpose. A useful record explains the outcome being pursued, why the information is needed, who is affected, what legal condition supports the activity and when the information will no longer be necessary.

A later use may be compatible with the original purpose, or it may be a genuinely new activity needing its own assessment and communication. This is particularly important when data collected to deliver a service is later considered for advertising, profiling, research or model training.

A practical example

A recruitment team receives an application, stores it in an applicant system, reviews it, shares selected details with an interview panel, records a decision and later deletes or retains the file. Each step is processing. Using unsuccessful applications to build an unrelated commercial dataset would be an additional purpose requiring separate scrutiny.

General principles

Processing is not the same as sharing

Sharing is one kind of processing. Internal access, outsourced hosting and overseas access may also be relevant even if no file is formally “sent”. The roles and safeguards depend on who determines the purpose, who acts under instructions and where the information can be accessed.

Practical next steps

Build a record of processing activities at a useful operational level. For each activity, capture the purpose, controller, people and data involved, sources, systems, recipients, processors, international access, retention, safeguards and legal basis. Review it when the organisation changes a system, supplier, purpose or data flow.

Related terms: personal data; controller; processor; purpose limitation; lawful basis; retention; ROPA

Jurisdiction guidance

Select more lenses from the Hub landing page to compare across jurisdictions.

GLOBAL
Global baseline

No jurisdiction-specific guidance is published for this lens yet.

Sources & citations

Each source below opens the instrument in the Legal Library, where you can read the sanitised text and download the original PDF.


Education, not legal advice. Content reflects the published snapshot last reviewed on 31 Jul 2026.