Skip to content

Processing

What is Processing?

Any operation or set of operations performed on personal data, whether or not by automated means. Under GDPR, processing includes collection, recording, storage, retrieval, consultation, use, disclosure, erasure, and destruction.

Privacy

What the standards actually require on processing

Requirements naming processing across 6 standards, quoted from the control text.

ISO 27701:201939 controls

The organization must provide a mechanism for individuals to object to the processing of their data, documenting the legal and regulatory requirements relating to objection such as objection to direct marketing, informing individuals of their ability to object...

iso-27701-2019::7.3.5 · Providing mechanism to object to PII processing
GDPR30 controls

The processor, and any person acting under the authority of the controller or of the processor who has access to personal data, must not process that data except on instructions from the controller, unless required to do so by Union or Member State law.

GDPR-Art.29 · Processing under the authority of the controller or processor

Principles of lawfulness, good faith, proportionality, purpose limitation, and accuracy

FADP-6 · Processing Principles (Articles 6-8)

Definitions for law enforcement processing. Article 26 sets the definitions applicable to Title 2 (law-enforcement processing), including personal data, processing, competent authority and related terms.

BE-DPA-16 · Definitions for law enforcement processing

Personal data may be processed for archiving in the public interest, including in the National Archives system, subject to safeguards under the Archives Act and appropriate technical and organisational measures.

EST-IKS-§7 · Processing for archiving in the public interest

Where the operator entrusts personal data processing to another person, this must be done on the basis of an agreement that contains the list of operations, processing purposes, confidentiality and protection obligations, and the requirement to act on the oper...

RU-152FZ-011 · Processing on Behalf of Another Operator

Questions people ask about processing

What is Processing?
Any operation or set of operations performed on personal data, whether or not by automated means. Under GDPR, processing includes collection, recording, storage, retrieval, consultation, use, disclosure, erasure, and destruction.
Why is Processing important for compliance?
Processing is a key concept in Privacy. Understanding processing helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Processing?
Processing appears in the requirement text of ISO 27701:2019, GDPR, Switzerland New Federal Act on Data Protection (nFADP/nDSG, 2023), Belgium Data Protection Act (Wet van 30 juli 2018, Loi du 30 juillet 2018), Estonia Personal Data Protection Act (Isikuandmete kaitse seadus, 2019). Across these standards we have identified 136 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Processing?
Explore our compliance framework pages to see how processing applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Processing applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.