Processing personal data
Also known as: data processing, data use, handling information, process data, processing operation, using personal data
Processing means doing almost anything with personal data, including collecting, recording, organising, viewing, using, sharing, storing, changing, combining, restricting or deleting it. An organisation can therefore process information without analysing or selling it. Even routine storage and access are part of the personal-data lifecycle and should be governed deliberately.
Term explanation
At a glance
“Processing” is the broad umbrella term for operations performed on personal data. It covers the full lifecycle, from the moment information is collected or generated until it is securely deleted or made genuinely anonymous. The concept is deliberately wider than data analysis.
Opening a customer record, backing up a database, sending a staff list to a payroll provider, recording a call and deleting an old account can all be processing operations. An organisation may perform many separate operations within one business activity.
In plain language
Privacy rules are meant to govern what happens to people’s information, not only the most visible or profitable uses. A narrow definition would leave ordinary storage, disclosure or disposal outside the framework even though those activities can create serious harm.
It helps to map processing as verbs: collect, record, organise, retrieve, consult, use, disclose, transmit, combine, restrict, erase and destroy. This makes an abstract system easier to understand and exposes hand-offs that a simple list of databases might miss.
Why it matters
Every processing activity should have a defined purpose. “We might need it later” is not a meaningful purpose. A useful record explains the outcome being pursued, why the information is needed, who is affected, what legal condition supports the activity and when the information will no longer be necessary.
A later use may be compatible with the original purpose, or it may be a genuinely new activity needing its own assessment and communication. This is particularly important when data collected to deliver a service is later considered for advertising, profiling, research or model training.
A practical example
A recruitment team receives an application, stores it in an applicant system, reviews it, shares selected details with an interview panel, records a decision and later deletes or retains the file. Each step is processing. Using unsuccessful applications to build an unrelated commercial dataset would be an additional purpose requiring separate scrutiny.
General principles
Processing is not the same as sharing
Sharing is one kind of processing. Internal access, outsourced hosting and overseas access may also be relevant even if no file is formally “sent”. The roles and safeguards depend on who determines the purpose, who acts under instructions and where the information can be accessed.
Practical next steps
Build a record of processing activities at a useful operational level. For each activity, capture the purpose, controller, people and data involved, sources, systems, recipients, processors, international access, retention, safeguards and legal basis. Review it when the organisation changes a system, supplier, purpose or data flow.
Related terms: personal data; controller; processor; purpose limitation; lawful basis; retention; ROPA
Jurisdiction guidance
Select more lenses from the Hub landing page to compare across jurisdictions.
No jurisdiction-specific guidance is published for this lens yet.
Related terms
- Data controller — controller
- Data processor — processor
- Personal data and personal information — personal data
Sources & citations
Each source below opens the instrument in the Legal Library, where you can read the sanitised text and download the original PDF.
- ACT — Cyber and Data Protection Act (Chapter 12 07) (ACT)
ACT · primary · Read in the Legal Library
- CDPG 3 of 2025 — Conducting a DPIA (CDPG-3-2025)
CDPG-3-2025 · cites · Read in the Legal Library
- CDPG 6 — Processing by Political Parties & Electoral Stakeholders (CDPG-6)
CDPG-6 · cites · Read in the Legal Library
- CDPG 7 of 2025 — Processing by MSMEs (CDPG-7-2025)
CDPG-7-2025 · cites · Read in the Legal Library
Education, not legal advice. Content reflects the published snapshot last reviewed on 31 Jul 2026.