What is Data Processing?

What Is — and Is Not — “Data Processing” Under the UK GDPR?

One of the most misunderstood aspects of the UK GDPR is the breadth of “data processing.” Many organisations assume it only refers to complex data analytics or IT-driven activity. In reality, the definition is far wider.

If you handle personal data in almost any way, you are probably processing it.

Understanding what does and does not count as data processing is essential. It determines whether the UK GDPR applies, informs your lawful basis, and whether individuals’ rights are engaged.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

 

Periodic Table of the GDPR

 


The Legal Definition of “Processing”

Under Article 4(2) of the UK GDPR, processing means:

“Any operation or set of operations which is performed on personal data… whether or not by automated means.”

This includes activities such as:

  • collection
  • recording
  • organisation
  • structuring
  • storage
  • adaptation or alteration
  • retrieval
  • consultation
  • use
  • disclosure by transmission
  • dissemination or otherwise making available
  • alignment or combination
  • restriction
  • erasure
  • destruction

That list is intentionally broad. It covers the entire data lifecycle—from the moment you collect information to the moment you delete it.

If personal data is involved, and you are doing something with it, you are almost certainly processing it.


What Counts as Data Processing?

Below are common examples of processing under the UK GDPR.

1. Collecting Personal Data

If you:

  • ask someone to complete a form,
  • gather CVs during recruitment,
  • collect email addresses for marketing,
  • record CCTV footage,
  • take medical histories,

you are processing personal data.

Collection alone is processing—even if you do nothing further with the data.


2. Storing or Holding Data

Simply keeping personal data is processing.

This includes:

  • saving files on a server,
  • storing paper personnel files in a cabinet,
  • archiving emails,
  • keeping backup copies in the cloud.

It does not matter whether you actively use the data. Passive storage still counts.


3. Accessing or Viewing Data

Consulting personal data is processing.

If a manager:

  • opens an employee file,
  • reviews CCTV footage,
  • reads customer emails,

that is processing—even if they do not edit or share the information.

Viewing is enough.


4. Sharing or Disclosing Data

If you:

  • send payroll data to a provider,
  • provide references,
  • respond to a subject access request,
  • share patient information with another clinician,

you are processing personal data through disclosure.

Both internal and external sharing count.


5. Editing or Updating Data

Changing information—correcting an address, updating salary details, annotating performance records—is also processing.

So is combining datasets, running analytics, or matching records across systems.


6. Deleting or Destroying Data

It may surprise some people, but deleting data is also processing.

Erasure and destruction fall within the definition because they are operations performed on personal data.

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 


What Is Not Data Processing Under the UK GDPR?

While the definition is broad, there are important boundaries.


1. Information That Is Not “Personal Data”

The UK GDPR only applies to personal data—information relating to an identified or identifiable natural person.

If the data:

  • cannot identify anyone,
  • has been properly anonymised,
  • relates solely to companies (not individuals),

then the UK GDPR does not apply.

For example:

  • Fully anonymised statistical reports
  • General company performance metrics without identifiable individuals
  • Information about a limited company (as opposed to a sole trader)

However, pseudonymised data is still personal data if re-identification is possible.


2. Purely Personal or Household Activity

The GDPR does not apply to processing carried out “by a natural person in the course of a purely personal or household activity.”

Examples:

  • Keeping personal address books
  • Sending private emails to friends
  • Taking photos at a family event for private use

But this exemption is narrow. Once activity extends beyond personal use—such as running a business or operating a public-facing social media page—the exemption disappears.


3. Data Processing About Deceased Individuals

The UK GDPR applies only to living individuals. Data relating solely to deceased persons falls outside its scope.

That said, other laws (such as the common law duty of confidentiality or sector-specific legislation) may still apply.


4. Information That Has Been Truly Anonymised

If personal data has been anonymised in such a way that individuals are no longer identifiable—by any reasonably likely means—then it is no longer personal data.

However, anonymisation must be robust. If someone could re-identify individuals using additional information reasonably available to them, the data remains personal data.


Why This Distinction Matters

Understanding what counts as processing is not just academic. It affects:

  • whether you need a lawful basis,
  • what you must include in your privacy information,
  • if a DPIA is required,
  • whether individuals can exercise rights such as access or erasure,
  • whether breach notification rules apply.

Many organisations underestimate how early GDPR obligations begin. The moment you collect or store personal data, the regulation is engaged.


Common Misconceptions

“We’re not processing it, we’re just storing it.”

Storage is processing.

“We didn’t use the data.”

Accessing or holding it is enough.

“It’s only internal.”

Internal sharing still counts.

“It’s anonymous.”

If re-identification is possible, it is not anonymous.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial


Final Thought

The UK GDPR uses an intentionally expansive definition of processing. That breadth reflects the reality of modern organisations: personal data moves constantly, across systems, teams, and suppliers.

If you touch personal data in any operational way, you are processing it.

The real compliance question is not whether you are processing data—but whether you are doing so lawfully, transparently, and securely.