Processing
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Any operation performed on personal data
Overview
16 sources · Jul 15, 2026Legal Framework
Article 4(2) GDPR defines processing as any operation or set of operations performed on personal data, whether or not by automated means. The definition is deliberately broad, encompassing collection, recording, storage, alteration, retrieval, disclosure, alignment, restriction, erasure, and destruction. Article 2(1) and (2) establishes the material scope: the Regulation applies to processing wholly or partly by automated means, and to non-automated processing of data forming part of a filing system. This expansive formulation ensures that virtually any interaction with personal data falls within the GDPR's reach.
Article 29 GDPR imposes a fundamental constraint on processing operations: processors and any person acting under the authority of the controller or processor may process personal data only on the controller's instructions, unless bound by Union or Member State law. This provision operationalizes the controller's responsibility for determining purposes and means, as defined in Article 4(7). Article 30 requires both controllers and processors to maintain records of processing activities, creating an auditable trail that supervisory authorities can inspect.
The rationale is structural: by defining processing broadly and anchoring accountability to the controller concept, the GDPR ensures that no data manipulation escapes regulatory oversight, regardless of the technical method employed.
Key Developments
In Schrems II (C-311/18), the Court of Justice confirmed that supervisory authorities bear responsibility for monitoring whether processing operations—including transfers to third countries—comply with EU rules, reinforcing that processing accountability cannot be displaced by adequacy decisions alone. The Court's reasoning in paragraphs 8 through 10 underscores that technological scale and globalization have intensified the need for processing oversight.
In Fashion ID (C-210/16), the Court established a critical limitation on information duties tied to processing: operators must provide information to data subjects only regarding the specific operations for which that operator actually determines purposes and means. This narrows the scope of Article 13 obligations for joint controllers and clarifies that processing accountability is operation-specific rather than blanket-based.
Enforcement confirms that deficient processing foundations attract significant penalties. The Norwegian DPA's €1.82 million fine against Elkjøp AS targeted insufficient legal basis for processing, while Romania's ANSPDCP fined Poșta Română €5,000 for inadequate technical safeguards during processing operations. These decisions signal that authorities examine both the legal basis and the technical conditions under which processing occurs.
Practical Guidance
- Map every processing operation against Article 4(2)'s enumerated activities—collection, storage, alteration, disclosure, erasure—and confirm each has a valid legal basis under Article 6 before operations begin.
- Ensure Article 29 compliance by contractually binding all subprocessors and internal personnel to process data solely on documented controller instructions, with no independent purpose determination permitted.
- Maintain Article 30 records that identify each processing operation, its purpose, legal basis, data categories, recipients, retention periods, and technical safeguards—these records are the primary instrument authorities use to assess compliance.
- Apply the Fashion ID principle when multiple parties are involved: delineate precisely which processing operations each party controls, and limit transparency obligations to those specific operations rather than assuming joint responsibility for the entire processing chain.
- Before any international transfer as part of processing operations, conduct a transfer impact assessment consistent with Schrems II requirements, evaluating whether the third country's surveillance framework undermines the adequacy of protection for the processing at issue.