Data Protection HubConcepts and Definitions

Processing (Article 4(2) GDPR)

The GDPR concept of processing: any handling of personal data, automated or manual, from collection through storage and disclosure to erasure.

Article 4(2) GDPR defines processing as any operation or set of operations which is performed on personal data, whether or not by automated means. The concept forms the central point of reference for the entire Regulation: the obligations and limits of the GDPR apply only once an operation qualifies as processing. It is drafted as broadly as conceivable and covers virtually any handling of the data.

Key takeaways

  • The concept of processing is a comprehensive catch-all concept that covers any handling of personal data, from acquisition to destruction.
  • It is purely objective: the intent or knowledge of the processing body is irrelevant.
  • Both automated and manual operations are covered; for manual operations, the GDPR requires that the data are stored, or are intended to be stored, in a filing system.
  • The list of the individual forms of processing (collection, storage, disclosure, etc.) in Article 4(2) GDPR is not exhaustive.
  • Classifying an operation as processing determines the applicability of the entire GDPR, including the requirement of a legal basis under Article 6 GDPR.

1. Overview

The Regulation lists a number of operations that qualify as processing: collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, and erasure or destruction (Article 4(2) GDPR). This list is not exhaustive; it describes typical manifestations without limiting the concept. Any handling of personal data that cannot be assigned to one of the named forms likewise falls under processing by way of the catch-all element of use.

1.2 Purely objective character

The concept of processing is purely objective. It attaches solely to the actual operation and requires no subjective element such as intent or knowledge. It is likewise irrelevant who actually carries out the operation. All that matters is that an operation takes place in relation to personal data.

The GDPR has a single, uniform concept of processing for any handling of personal data. The earlier split under the old version of the German Federal Data Protection Act (BDSG) into "collection, processing, and use," as well as the distinction between "collection and use" under the former German Telecommunications Act (TKG) and German Telemedia Act (TMG), are thus obsolete. Since the German Telecommunications-Telemedia Data Protection Act (TTDSG) (in force since 1 December 2021), this uniform concept also applies in the field of telecommunications and telemedia.

Although the "restriction of processing" is listed in Article 4(2) GDPR as one form of processing, it is at the same time separately defined as a distinct sub-category (Article 4(3) GDPR). What this means in detail is addressed by Restriction of processing.

A conceptual expansion is contained in the amended Convention 108 of the Council of Europe: it expressly also covers the application of logical or arithmetic operations to personal data. This means that the computations typical of artificial intelligence, such as the generation of scoring values, are clearly covered as processing.

2. Automated and non-automated processing

The Regulation distinguishes according to whether processing is carried out with or without the aid of automated means. Both forms are processing within the meaning of the GDPR; the distinction is, however, significant for the scope of application in the case of manual operations.

2.1 Automated means

Automated processing is any handling of personal data using data processing systems, that is, hardware, software, and transmission networks. This covers not only classic computers such as servers, laptops, or PCs, but also smartphones, storage media, and equally devices whose data processing is not the primary function, such as video cameras, copiers, and multifunction devices that store content digitally.

The specific hardware or software is immaterial. Even off-the-shelf standard software such as a word processing program suffices. What is decisive is solely that the data are available in a form that can be evaluated by automated means; this evaluability alone is enough to assume automated processing.

2.2 Non-automated (manual) processing

The manual handling of personal data can also constitute processing. It is, however, covered only if the data are stored, or are intended to be stored, in a filing system (Article 4(6) GDPR). Unstructured files or loose notes that do not belong to a structured set accessible according to specific criteria are therefore not subject to the GDPR when processed purely manually.

3. The individual forms of processing

The following forms give concrete shape to the broad concept of processing. They roughly follow the life cycle of a data record, from acquisition through retention and use to final removal.

The following diagram shows this life cycle as a sequence of states; the subsequent table lists each form with a practical example.

Form of processingBrief descriptionPractical example
CollectionActively obtaining data, typically from the data subjectFilling out an online form with a name and email address
Recording / storageTaking in and retaining data on a data mediumFiling a signed consent declaration in a file
Organization / structuringBuilding a structure within the dataSorting a customer file alphabetically
Adaptation / alterationSubstantive reshaping that changes the informational contentRectifying an incorrect address (Article 16 GDPR)
Retrieval / consultationAccessing one's own or external data holdingsA public authority querying a residents' registration register
UseCatch-all element for any other handlingUsing stored customer data for an internal analysis
Disclosure / transmissionMaking data known to third parties or making them available for retrievalSending application documents to an external recruitment consultancy
Alignment / combinationBringing together data from different sourcesCombining purchase history and location data to create a profile
RestrictionMarking stored data for restricted further processingBlocking a data record following the data subject's objection
Erasure / destructionFinal removal of a data recordPhysical destruction of files after the retention period expires

3.1 Collection

Collection is the obtaining of data, typically from the data subject themselves. It presupposes an active undertaking by the collecting body. The method is immaterial: interviews, observation, image and sound recordings, or measurements are equally possible. The object is always personal data.

Where data are supplied without any request, that is, in effect forced upon the body, there is not yet any collection. The operation becomes relevant under data protection law only once the body further processes the data. Collection must, moreover, be necessary for specified, explicit, and legitimate purposes (Article 5(1)(b) GDPR). Even the video surveillance of publicly accessible spaces constitutes collection, and indeed does so even where no recording takes place.

The information obligations attach to collection: Article 13 GDPR applies to direct collection from the data subject, and Article 14 GDPR applies to collection via third parties; a subsequent notification may become necessary under Article 19 GDPR. Data collected unlawfully may not be stored and must be erased.

3.2 Recording and storage

Recording and storage denote the taking in and retention of data on a data medium. Both terms are to be understood broadly and also encompass optical and acoustic signals as well as copies. Even the mere retention of data in files through storage, and archiving, constitute processing. No subjective component is required; the actual act of retention suffices.

3.3 Organization and structuring

Organization and structuring refer to the building of a structure within the data. Whether the structuring is simple or complex is irrelevant; the quality of the structuring does not matter. Even a plain sorting suffices.

3.4 Adaptation and alteration

Adaptation and alteration cover any substantive reshaping by which the informational content of the data is changed or supplemented. The combination of data from different sources can also constitute an alteration, because it gives rise to a new informational and interpretive context. There is, by contrast, no alteration where the data are only outwardly reshaped, for instance in a mere change of the medium or in the use of abbreviations.

The rectification of inaccurate data (Article 16 GDPR) is a practically significant sub-category of alteration. Anonymization, too, is an alteration; it does not, however, amount to erasure so long as re-identification remains possible with proportionate effort (Recital 26 GDPR).

3.5 Retrieval and consultation

Retrieval and consultation differ according to the location of the data holdings: retrieval accesses an already existing data record of one's own, whereas consultation accesses an external database. Both operations are at the same time a sub-form of collection, because through them the body obtains knowledge of the data.

3.6 Use

Use is an indeterminate catch-all element. It covers any other form of handling personal data that cannot be assigned to one of the other expressly named forms of processing. This ensures that no practically relevant handling falls outside the concept of processing.

3.7 Disclosure and transmission

Disclosure encompasses making data known to others. Making data available for retrieval corresponds to retrieval and consultation on the recipient's side. A transmission is the making known of data to a third party.

To be distinguished from this is the passing on of data within the controller, to a processor, or to the data subject themselves. This is not a transmission in the technical sense, but rather a use in the form of passing on; it is nonetheless subject to purpose limitation and the principle of necessity. The form of the disclosure is immaterial: written form, oral information, fax, email, handing over a data medium, or publication are equally possible.

Even the oral disclosure of data that are stored in a filing system or by automated means is processing. The CJEU clarified this for the case of an oral disclosure of criminal convictions that was to be provided to a company upon request (CJEU, judgment of 7 March 2024, C-740/22, Endemol Shine Finland). The publication of personal data on the internet requires a specific legal basis. There is, by contrast, no retrieval and no disclosure by the controller where a third party gains access without authorization.

3.8 Alignment and combination

Alignment checks whether data are identical across several filing systems or whether the same person is involved in several sets of circumstances. Combination goes beyond this: it links or completes existing data records and thereby creates new interpretive connections.

3.9 Erasure and destruction

Erasure and destruction end the life cycle of a data record. The right to the removal of data that are no longer necessary has a constitutional root in the general right of personality (Article 2(1) in conjunction with Article 1(1) of the German Basic Law (GG)).

3.9.1 Technical requirements for erasure

Effective erasure requires more than the removal of a logical link. In automated systems, merely cancelling the reference to the data record is not sufficient; simple formatting is also regularly inadequate. What is required is an actual removal, for instance by overwriting multiple times. In non-automated files, removal is effected by redaction or by physical destruction of the medium in accordance with the relevant technical standards (today DIN 66399, formerly DIN 32757-1 and DIN 33858).

Backups must be included in the erasure. A temporal delay is to be accepted within the bounds of proportionality, but as a rule not beyond a period of about two months.

3.9.2 Timing of erasure, retention periods, and routines

The controller should establish standard periods and set up erasure routines in order to implement removal reliably. The timing of erasure is determined by necessity. Statutory retention periods must be observed as a priority, for instance under §§ 146 et seq. of the German Fiscal Code (AO) and § 257 of the German Commercial Code (HGB). Where no specific period exists, retention may be guided by limitation, warranty, or professional-code periods.

3.9.3 Privileged treatment of archiving purposes

Despite an existing obligation to erase, further processing for archiving purposes remains permissible (Article 17(3)(d) GDPR), provided that the safeguards of Article 89 GDPR are observed. In addition, there are special archive-law provisions of the federal government and the Länder (the German Federal Archives Act (Bundesarchivgesetz) and the archive acts of the Länder (Landesarchivgesetze)) as well as § 28 BDSG.

3.9.4 Right to be forgotten

The right to erasure includes the right to be forgotten (Article 17 GDPR). A search engine operator may be obliged to de-list references from its list of results (CJEU C-131/12, Google Spain). The obligation to de-list is, however, confined to the territorial scope of the GDPR and thus to the Member States; the operator is in principle not required to carry out a worldwide de-listing (CJEU, judgment of 24 September 2019, C-507/17, Google/CNIL). For especially sensitive data and for data concerning criminal convictions, heightened requirements apply here (CJEU C-136/17, GC and Others/CNIL).

4. Relationship to the principles relating to processing

Every processing operation must be measured against the principles of Article 5 GDPR. Of particular practical significance are, above all, purpose limitation, which establishes the point of reference for every processing operation, and storage limitation, which governs the timing of erasure.

About the author

About the author

This article was written by Dr. Thomas Helbing, specialist lawyer for IT law in Munich.

Since 2020 and continuously through today (2026), Handelsblatt has recognized Dr. Helbing as one of "Germany's Best Lawyers" in IT law and data protection law.

According to Kanzleimonitor.de (2024 to 2026 editions), he ranks among the leading lawyers for data protection and IT law and is listed among the top 100 lawyers in Germany (2024/25). Kanzleimonitor is considered a particularly meaningful market study because it is based exclusively on personal recommendations from in-house counsel.

Dr. Helbing has many years of advisory experience in data protection and IT law and advises clients of all sizes, from startups through fast-growing SaaS companies and unicorns to international corporate groups.

His professional background covers the full spectrum of IT and technology law practice. He began his career at a major international law firm, then gained in-house experience at a DAX-listed company, and is himself an entrepreneur and founder of several digital ventures. He also has hands-on programming experience, which allows him to understand technical systems, software architectures and digital business models not only from a legal perspective but also from a technical one.

For many years, his clients have included technology companies and SaaS providers, leading German research institutions and a systemically important German bank. His advisory focus lies in particular on GDPR compliance, the data economy, SaaS, AI regulation and IT contract law.

Follow me on LinkedIn