What Is — and Is Not — “Data Processing” Under the UK GDPR?
One of the most misunderstood aspects of the UK GDPR is the breadth of “data processing.” Many organisations assume it only refers to complex data analytics or IT-driven activity. In reality, the definition is far wider.
If you handle personal data in almost any way, you are probably processing it.
Understanding what does and does not count as data processing is essential. It determines whether the UK GDPR applies, informs your lawful basis, and whether individuals’ rights are engaged.

The Legal Definition of “Processing”
Under Article 4(2) of the UK GDPR, processing means:
“Any operation or set of operations which is performed on personal data… whether or not by automated means.”
This includes activities such as:
- collection
- recording
- organisation
- structuring
- storage
- adaptation or alteration
- retrieval
- consultation
- use
- disclosure by transmission
- dissemination or otherwise making available
- alignment or combination
- restriction
- erasure
- destruction
That list is intentionally broad. It covers the entire data lifecycle—from the moment you collect information to the moment you delete it.
If personal data is involved, and you are doing something with it, you are almost certainly processing it.
What Counts as Data Processing?
Below are common examples of processing under the UK GDPR.
1. Collecting Personal Data
If you:
- ask someone to complete a form,
- gather CVs during recruitment,
- collect email addresses for marketing,
- record CCTV footage,
- take medical histories,
you are processing personal data.
Collection alone is processing—even if you do nothing further with the data.
2. Storing or Holding Data
Simply keeping personal data is processing.
This includes:
- saving files on a server,
- storing paper personnel files in a cabinet,
- archiving emails,
- keeping backup copies in the cloud.
It does not matter whether you actively use the data. Passive storage still counts.
3. Accessing or Viewing Data
Consulting personal data is processing.
If a manager:
- opens an employee file,
- reviews CCTV footage,
- reads customer emails,
that is processing—even if they do not edit or share the information.
Viewing is enough.
4. Sharing or Disclosing Data
If you:
- send payroll data to a provider,
- provide references,
- respond to a subject access request,
- share patient information with another clinician,
you are processing personal data through disclosure.
Both internal and external sharing count.
5. Editing or Updating Data
Changing information—correcting an address, updating salary details, annotating performance records—is also processing.
So is combining datasets, running analytics, or matching records across systems.
6. Deleting or Destroying Data
It may surprise some people, but deleting data is also processing.
Erasure and destruction fall within the definition because they are operations performed on personal data.
Sign Up Here:
While the definition is broad, there are important boundaries. The UK GDPR only applies to personal data—information relating to an identified or identifiable natural person. If the data: then the UK GDPR does not apply. For example: However, pseudonymised data is still personal data if re-identification is possible. The GDPR does not apply to processing carried out “by a natural person in the course of a purely personal or household activity.” Examples: But this exemption is narrow. Once activity extends beyond personal use—such as running a business or operating a public-facing social media page—the exemption disappears. The UK GDPR applies only to living individuals. Data relating solely to deceased persons falls outside its scope. That said, other laws (such as the common law duty of confidentiality or sector-specific legislation) may still apply. If personal data has been anonymised in such a way that individuals are no longer identifiable—by any reasonably likely means—then it is no longer personal data. However, anonymisation must be robust. If someone could re-identify individuals using additional information reasonably available to them, the data remains personal data. Understanding what counts as processing is not just academic. It affects: Many organisations underestimate how early GDPR obligations begin. The moment you collect or store personal data, the regulation is engaged. Storage is processing. Accessing or holding it is enough. Internal sharing still counts. If re-identification is possible, it is not anonymous. Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course. Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.
The UK GDPR uses an intentionally expansive definition of processing. That breadth reflects the reality of modern organisations: personal data moves constantly, across systems, teams, and suppliers. If you touch personal data in any operational way, you are processing it. The real compliance question is not whether you are processing data—but whether you are doing so lawfully, transparently, and securely.
What Is Not Data Processing Under the UK GDPR?
1. Information That Is Not “Personal Data”
2. Purely Personal or Household Activity
3. Data Processing About Deceased Individuals
4. Information That Has Been Truly Anonymised
Why This Distinction Matters
Common Misconceptions
“We’re not processing it, we’re just storing it.”
“We didn’t use the data.”
“It’s only internal.”
“It’s anonymous.”
Final Thought
- September 2026
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- September 2022
- August 2022
- June 2022
- May 2022
- March 2022
- February 2022
- January 2022
- December 2021
CONTACT US
Switchboard: 0330 221 0547
Training enquiries: 0330 221 0552
Email: hello@wudo.solutions
15 Warland Rd, London, SE18 2EX
Open every day 8am to 8pm except bank holidays.
Get the latest news, resources and special offers direct to your inbox: