Large-Scale Processing
Large-scale processing refers to handling personal data about many individuals, in high volumes, or across wide geographic areas, rather than the limited processing a single professional might carry out. For example, a hospital processing patient records or tracking people across a city's public spaces would generally be considered large-scale, while an individual doctor processing their own patients' data would not. The term is not defined by a fixed number in the applicable law, so whether processing counts as large-scale depends on the specific circumstances.
Under the EU GDPR and UK GDPR, 'large-scale' is a threshold concept that helps trigger certain accountability obligations, notably the requirement to conduct a data protection impact assessment and, in some cases, the requirement to appoint a data protection officer. The legislation does not set a numerical definition; assessment typically considers factors such as the number of data subjects affected (in absolute terms or as a proportion of the relevant population), the volume and range of data processed, the duration or permanence of the processing, and its geographic extent. Regulatory guidance illustrates the concept by example (for instance, a hospital processing patient data versus an individual doctor) rather than by fixed figures, and any specific numeric thresholds cited by commentators are interpretive suggestions rather than statutory tests. This entry does not address the detailed criteria for when a DPIA or DPO is mandatory, cross-border transfer mechanics, retention obligations, or how the concept is treated under non-EU/UK regimes such as the CCPA/CPRA or HIPAA, where it may not appear or may be framed differently. Note that meeting a large-scale threshold triggers assessment and accountability duties but does not by itself determine a lawful basis or guarantee compliance.
Why it matters
Large-scale processing acts as a threshold concept that helps trigger some of the most significant accountability obligations under the EU GDPR and UK GDPR, notably the requirement to carry out a data protection impact assessment (DPIA) and, in certain circumstances, the requirement to appoint a data protection officer. Because these duties can flow from whether processing is deemed large-scale, correctly assessing the concept is a practical gating step in an organisation's governance programme rather than an abstract classification exercise. Misjudging it in either direction carries risk: treating clearly large-scale operations as routine can leave mandatory assessments undone, while over-applying the label can divert compliance resources without cause.
The difficulty for practitioners is that neither the EU GDPR nor the UK GDPR defines large-scale by a fixed number. Regulatory guidance, such as the ICO's, illustrates the concept by example rather than by threshold, a hospital processing patient data is generally considered large-scale, whereas an individual doctor processing their own patients' data generally is not, and tracking individuals across a city's public spaces is offered as a further example. Some commentators have proposed specific figures (for instance, interpretations referencing several million people or a large proportion of a relevant population), but these are interpretive suggestions, not statutory tests, and should be treated as illustrative rather than binding.
Because the assessment is contextual, accountability under the GDPR framework requires organisations to document their reasoning for whether processing is large-scale, not merely to reach a conclusion. Demonstrable evidence of that analysis is part of the accountability principle, and a defensible record of how factors such as data subject numbers, data volume, duration, and geographic extent were weighed is generally more valuable than reliance on any single numeric rule of thumb.
Who it's relevant to
Inside Large-Scale Processing
Common questions
Answers to the questions practitioners most commonly ask about Large-Scale Processing.