Processing
Any operation performed on personal data, including collection, storage, use, disclosure, restriction, erasure or destruction.
Under Article 4(2) GDPR, processing means any operation or set of operations performed on personal data, whether or not by automated means. The definition includes collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, making data available, restriction, erasure and destruction. A single access to personal data can therefore amount to processing.
For businesses, processing covers much more than permanent storage. A company processes personal data when it enters customer details into a CRM, manages employee records, operates a website with cookies, retrieves a request or sends data to a service provider. The definition does not itself make a processing activity lawful. Each activity needs an appropriate legal basis, and special categories of personal data also require the additional conditions in Article 9 GDPR.
A business should record each processing activity by its purpose, data categories, data subjects, recipients, storage locations and deletion approach. It should also clarify the roles involved. An organisation that decides the purposes and essential means will generally be the controller. A service provider processing data on the organisation’s behalf may be a processor. The privacy compliance and governance section and the processors and service providers section place this assessment in context.
For initial orientation, describe the actual process: which data are collected for which purpose, who can access them, to whom are they disclosed and when does the processing end? The role check supports the distinction between the organisations involved. For cookies and tracking, see the marketing, cookies and tracking section; for employee records, see employee data protection. The processor assessment checklist provides a practical structure when an external provider is involved.
Learn more
General orientation, not individual advice.
Discuss your data protection matter
Tell us briefly what is happening. We will help classify the situation and discuss which documents and next step are useful for your business.
Clarify a data protection question
Address
BRANDAUER Rechtsanwälte GmbH Giselakai 51 5020 Salzburg Österreich
Phone
+43 662 6280000