Skip to content
Topic Contested in court

Processing

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Any operation performed on personal data

3,654 linked items 88 Laws323 Case Law409 Guidance2635 Enforcement128 News

Overview

23 sources · Sep 25, 2026

Legal Framework

The concept of "processing" is the foundational regulated activity under the GDPR. Article 2(1) establishes the material scope, applying the Regulation to both automated and non-automated processing of personal data forming part of a filing system. Once processing falls within scope, Article 5 sets the governing principles — lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, and integrity/confidentiality — with an explicit accountability requirement:

"The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1"
— GDPR Art. 5

Article 30 operationalises accountability by requiring both controllers and processors to maintain records of processing activities, documenting purposes, data categories, recipients, transfer arrangements, retention periods, and security measures. Article 10 imposes additional restrictions on processing criminal-conviction data, permitting it only under official authority or authorising Union or Member State law with appropriate safeguards.

Key Developments

The CJEU has reinforced that documentation obligations under Article 30 are procedural duties distinct from the lawful-basis analysis under Article 6(1). In UZ v Bundesrepublik Deutschland, the Court clarified that compliance with Article 26 (joint-controller arrangements) and Article 30 (records) does not itself constitute a ground for lawfulness:

"compliance by the controller with the obligation laid down in Article 26 of the GDPR to conclude an arrangement determining joint responsibility for processing and the obligation to maintain a record of processing activities laid down in Article 30 of that regulation is not among the grounds for lawfulness of processing"
— UZ v Bundesrepublik Deutschland ¶59

Enforcement authorities have applied these requirements rigorously. The Belgian DPA found a legal-information website's privacy notice deficient because it referenced "our services" and "legal obligation" without specifying which services or legislation applied — treating vagueness as non-compliance with the transparency principle. The Irish DPC, in its investigation of the Midlands Regional Hospital Tullamore, scrutinised whether submitted SOPs genuinely satisfied Article 30's record-keeping requirement, noting that documents lacking explicit "Record of Processing Activities" labelling could still qualify if substantively adequate.

The Croatian DPA's action against an IT services company illustrates that processors bear direct security obligations: the failure to implement appropriate technical measures against foreseeable risks constituted a breach independent of the controller's obligations.

Status of the Debate

This topic is contested in court. While the core definition of processing is well-established, its outer boundaries remain actively litigated — particularly regarding the allocation of controller versus processor responsibility, the sufficiency of Article 30 records, and the interplay between documentation obligations and substantive lawfulness requirements. The CJEU's ruling in UZ v Bundesrepublik Deutschland settled the question that Article 30 compliance does not cure a missing lawful basis, but divergent national-level decisions on what constitutes an adequate record of processing activities continue to generate uncertainty. What would resolve the open questions is a definitive CJEU ruling on the minimum substantive content threshold for Article 30 records and on the boundary between processor autonomy and controller instruction under Article 28(3).

Practical Guidance

  • Maintain a structured Article 30 record for every processing activity, documenting all seven elements listed in Article 30(1) — purpose, data categories, recipients, transfers, retention, and security measures. Vague references to "legal obligation" or "applicable administrative obligations" without specificity have been found insufficient by DPAs.
  • Establish a lawful basis under Article 6(1) before relying on documentation: compliance with Article 30 does not substitute for a valid legal ground. Confirm the basis independently.
  • Instruct processors in writing on the boundaries of permissible processing; processors must not exceed the controller's documented instructions, and both parties must maintain separate Article 30 records.
  • Apply Article 5 principles as design constraints: data minimisation, storage limitation, and security should be engineered into each processing operation from inception, not retrofitted.
  • For special-category data such as criminal convictions under Article 10, verify that processing occurs solely under official authority or is authorised by specific Union or Member State law providing appropriate safeguards — generic lawful bases are insufficient.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 5 Principles relating to processing of personal data Laws GDPR Apr 2016 principles for processing
why this is here
The controller shall be responsible for, and be able to demonstrate compliance with, paragraph 1

The provision sets out the principles that govern any processing of personal data, linking directly to the topic of processing.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Personal data processing in vehicles
why this is here
processing of personal data

The document focuses on the processing of personal data in connected vehicles, directly relevant to the concept of processing.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 3/2018 territorial scope of the GDPR (Article 3) Guidelines on the territorial scope of the GDPR Guidelines ·EDPB Guidance EDPB Nov 2019 processing in the context of establishment
why this is here
Article 3(1) confirms that it is not necessary that the processing in question is carried out “ b y ” the relevant EU establishment itself

The document extensively analyses what constitutes 'processing in the context of activities of an establishment' under Article 3(1).

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

art 30 Records of processing activities Laws GDPR Apr 2016 records of processing activities
why this is here
Each controller and, where applicable, the controller's representative, shall maintain a record of processing activities under its responsibility.

The provision requires documenting processing activities, but it is about the record-keeping obligation itself, not the definition or elements of processing operations.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 4/2019 Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidelines on data protection by design and by default Guidelines ·EDPB Guidance EDPB Oct 2020 Processing operations under Article 25
why this is here
processing in question

The document repeatedly refers to 'processing' in the context of Article 25 obligations, making this a primary source.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 1/2018 certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation Guidelines ·EDPB Guidance EDPB Jun 2019 processing operations as certification object
why this is here
the purpose of demonstrating compliance with this Regulation of processing operations by controllers and processors

The document focuses on certification of processing operations, which is a specific aspect of processing, not a general processing topic.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 9/2022 personal data breach notification under GDPR Guidelines ·EDPB Guidance EDPB Apr 2023 processing operations affected by breach
why this is here
personal data transmitted, stored or otherwise processed

The definition of breach refers to processing operations, but the document does not define processing generally.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

art 39 38432 Article 39 Laws EU Oct 2012 rule-making on processing
why this is here
rules relating to the protection of individuals with regard to the processing of personal data

It sets the legal basis for adopting rules on processing personal data, establishing a framework for future detailed processing obligations.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 3/2019 processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Processing definition
why this is here
any disclosure of personal data is a separate kind of processing of personal data for which the controller needs to have a legal basis

Discusses processing operations but does not provide a general definition.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 06/2022 practical implementation of amicable settlements Guidelines on the processing of personal data under Article 6(1)(b) GDPR in the context of the provision of online services to data subjects Guidelines ·EDPB Guidance EDPB May 2022 complaints about processing
why this is here
complaints that are cross-border in nature

The document concerns complaint handling but does not define processing or its elements.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 02/2022 application of Article 60 GDPR Guidelines ·EDPB Guidance EDPB Mar 2022 cross-border processing definition
why this is here
the processing operation has to be cross-border according to Article 4(23)

The processing concept is central to defining the scope of Article 60, but the document is about cooperation among authorities, not the processing itself.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 8/2022 identifying a controller or processor's lead supervisory authority Guidelines for identifying a controller or processor’s lead supervisory authority Guidelines ·EDPB Guidance EDPB Apr 2023 processing in multiple member states
why this is here
processing of personal data which takes place in the context of the activities of establishments in more than one Member State

The document defines cross-border processing, but not the general concept of processing.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Guidelines 8/2020 targeting of social media users Guidelines ·EDPB Guidance EDPB Apr 2021 Processing operations
why this is here
The targeting of social media users involves not just the act of ‘selecting’ the individuals or groups of individuals that are the intended recipients of a particular message

Discusses processing broadly but not a systematic analysis.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

This is the top of each pile — all 88 Laws · all 409 Guidance · all 323 Case Law · all 2635 Enforcement · all 69 Literature · all 128 News