Skip to main content
Category: Breach and Risk Assessment

Large-Scale Processing

Also known as: large scale processing, processing on a large scale
Simply put

Large-scale processing refers to handling personal data about many individuals, in high volumes, or across wide geographic areas, rather than the limited processing a single professional might carry out. For example, a hospital processing patient records or tracking people across a city's public spaces would generally be considered large-scale, while an individual doctor processing their own patients' data would not. The term is not defined by a fixed number in the applicable law, so whether processing counts as large-scale depends on the specific circumstances.

Formal definition

Under the EU GDPR and UK GDPR, 'large-scale' is a threshold concept that helps trigger certain accountability obligations, notably the requirement to conduct a data protection impact assessment and, in some cases, the requirement to appoint a data protection officer. The legislation does not set a numerical definition; assessment typically considers factors such as the number of data subjects affected (in absolute terms or as a proportion of the relevant population), the volume and range of data processed, the duration or permanence of the processing, and its geographic extent. Regulatory guidance illustrates the concept by example (for instance, a hospital processing patient data versus an individual doctor) rather than by fixed figures, and any specific numeric thresholds cited by commentators are interpretive suggestions rather than statutory tests. This entry does not address the detailed criteria for when a DPIA or DPO is mandatory, cross-border transfer mechanics, retention obligations, or how the concept is treated under non-EU/UK regimes such as the CCPA/CPRA or HIPAA, where it may not appear or may be framed differently. Note that meeting a large-scale threshold triggers assessment and accountability duties but does not by itself determine a lawful basis or guarantee compliance.

Why it matters

Large-scale processing acts as a threshold concept that helps trigger some of the most significant accountability obligations under the EU GDPR and UK GDPR, notably the requirement to carry out a data protection impact assessment (DPIA) and, in certain circumstances, the requirement to appoint a data protection officer. Because these duties can flow from whether processing is deemed large-scale, correctly assessing the concept is a practical gating step in an organisation's governance programme rather than an abstract classification exercise. Misjudging it in either direction carries risk: treating clearly large-scale operations as routine can leave mandatory assessments undone, while over-applying the label can divert compliance resources without cause.

The difficulty for practitioners is that neither the EU GDPR nor the UK GDPR defines large-scale by a fixed number. Regulatory guidance, such as the ICO's, illustrates the concept by example rather than by threshold, a hospital processing patient data is generally considered large-scale, whereas an individual doctor processing their own patients' data generally is not, and tracking individuals across a city's public spaces is offered as a further example. Some commentators have proposed specific figures (for instance, interpretations referencing several million people or a large proportion of a relevant population), but these are interpretive suggestions, not statutory tests, and should be treated as illustrative rather than binding.

Because the assessment is contextual, accountability under the GDPR framework requires organisations to document their reasoning for whether processing is large-scale, not merely to reach a conclusion. Demonstrable evidence of that analysis is part of the accountability principle, and a defensible record of how factors such as data subject numbers, data volume, duration, and geographic extent were weighed is generally more valuable than reliance on any single numeric rule of thumb.

Who it's relevant to

Data Protection Officers and Privacy Leads
DPOs and privacy leads use the large-scale assessment as a practical trigger point for deciding whether a DPIA is warranted and for informing whether a DPO appointment obligation may arise. They are typically responsible for documenting the factors considered and the reasoning reached, since accountability requires demonstrable evidence of the analysis rather than a stated conclusion alone.
Compliance and Information Governance Teams
These teams need to embed the large-scale question into governance workflows so that processing activities are assessed consistently, weighing data subject numbers, data volume, duration, and geographic extent against organisational context. This is a governance and policy responsibility that complements, but does not replace, separate determinations of lawful basis and security controls.
Legal and Regulatory Advisors
Advisors interpreting the EU GDPR or UK GDPR should treat large-scale as a contextual threshold illustrated by regulatory examples rather than by fixed figures, and should caution clients that numeric thresholds cited in commentary are interpretive suggestions, not statutory tests. They should also flag that treatment may differ or be absent under non-EU/UK regimes such as the CCPA/CPRA or HIPAA.
Organisations in Health, Public Sector, and Monitoring Contexts
Bodies such as hospitals processing patient records or entities tracking individuals across public spaces are the kinds of operations regulatory guidance offers as illustrative of large-scale processing. For these organisations, recognising that their activities may meet the threshold is a starting point for assessment obligations, though it does not by itself resolve questions of lawful basis, retention, or cross-border transfers, which fall outside the scope of this concept.

Inside Large-Scale Processing

Concept origin and scope
Large-scale processing is a qualifying concept used within the EU GDPR (and mirrored in the UK GDPR) to help determine when certain heightened obligations apply, such as the potential need to designate a data protection officer or to conduct a data protection impact assessment. It is not a standalone legal category, and its treatment differs under other regimes such as the CCPA and CPRA, HIPAA, ISO/IEC 27701, or the NIST Privacy Framework, which do not use this term in the same way.
Undefined numeric threshold
The GDPR does not fix a precise numeric threshold for what counts as large-scale. Assessment is contextual rather than tied to a specific count of data subjects or records, so practitioners generally weigh several factors together rather than applying a single figure.
Assessment factors
Whether processing is large-scale is typically evaluated by considering factors such as the number of data subjects affected (in absolute terms or as a proportion of a population), the volume and range of data involved, the duration or permanence of the processing, and its geographical extent. These factors are weighed together and no single factor is generally decisive.
Relationship to heightened obligations
Large-scale processing is one trigger that can raise the likelihood of obligations under the GDPR, but it operates alongside other criteria. For example, a data protection impact assessment may be indicated where large-scale processing coincides with special category data or systematic monitoring, but large-scale processing on its own does not automatically make a DPIA mandatory.
Interaction with special category data
Large-scale processing of special category (sensitive) data is treated as a particularly relevant trigger for heightened scrutiny. This is distinct from large-scale processing of ordinary personal data, and the two should not be conflated when assessing obligations.
Accountability dimension
Under the GDPR accountability principle, a controller or processor that concludes its processing is or is not large-scale should be able to demonstrate the reasoning behind that determination with documented evidence, rather than relying on stated intent alone.

Common questions

Answers to the questions practitioners most commonly ask about Large-Scale Processing.

Is there a fixed number of data subjects or records that qualifies processing as 'large-scale'?
No. The EU GDPR and UK GDPR do not set a specific numeric threshold for what counts as large-scale processing, and you should be cautious of any source that asserts one. The assessment is generally qualitative and contextual, weighing factors such as the number of data subjects (either as an absolute figure or as a proportion of a relevant population), the volume and range of data processed, the duration or permanence of the processing, and its geographical extent. Because there is no bright-line figure in the instrument, treating a single record count as determinative is a common mistake. This answer does not address how other regimes, such as the CCPA and CPRA or HIPAA, frame comparable concepts, where the treatment differs.
Does large-scale processing automatically trigger a mandatory Data Protection Impact Assessment or the appointment of a Data Protection Officer?
Not automatically, and the two obligations should not be conflated. Under the EU GDPR and UK GDPR, large-scale processing is one factor that feeds into these obligations rather than an automatic trigger on its own. A DPIA is generally required where processing is likely to result in a high risk to individuals, and large scale is typically one criterion considered alongside others; it is not the case that every DPIA is mandatory or that scale alone always makes one so. Similarly, the obligation to designate a DPO generally arises where core activities involve large-scale processing of certain categories of data or large-scale regular and systematic monitoring, but this is a scoped condition, not a blanket rule. This entry does not cover the full criteria for either obligation, which should be assessed against the applicable text and guidance.
How should an organisation practically assess whether its processing meets the large-scale threshold?
In most cases the assessment is documented rather than calculated. Organisations generally consider the qualitative factors together, number and proportion of data subjects affected, volume and variety of personal data, duration and permanence of the activity, and geographical reach, and record the reasoning behind their conclusion. Because accountability under the EU GDPR and UK GDPR requires demonstrable evidence rather than stated intent, the value lies in retaining a defensible written rationale that a reviewer or supervisory authority could examine. This answer does not prescribe a scoring method or template, as none is fixed in the instrument.
Where does the large-scale assessment fit within existing governance documentation?
The determination typically informs, and is informed by, records that a controller or processor already maintains, such as records of processing activities and any risk or impact assessments. It is worth noting that a records of processing obligation is a documentation duty and is not the same as a data inventory tool; the tool may support the record but does not discharge the obligation. The large-scale conclusion should be traceable through this documentation so that the basis for downstream decisions, such as whether a DPIA or DPO is warranted, is evident. This entry does not detail the full content requirements of those records.
Does pseudonymising or encrypting the data change whether processing is large-scale?
Generally no. Pseudonymisation is reversible and the data typically remains personal data, and encryption or tokenisation likewise does not make data non-personal for the purposes of this assessment. Because the large-scale evaluation concerns the scope and nature of processing of personal data, applying these techniques does not by itself remove the processing from consideration. They may be relevant as risk-mitigating measures elsewhere in your analysis, but they should not be treated as taking the activity out of scope. This answer does not address anonymisation, which is a distinct, irreversible outcome assessed on its own terms.
Which party is responsible for making the large-scale determination and acting on it?
Accountability generally rests with the controller, who determines the purposes and means of processing, while a processor acts on the controller's instructions and carries its own more limited obligations. In practice the controller is typically responsible for reaching and documenting the large-scale conclusion and for the obligations that may follow from it, though a processor may need to make its own assessment for duties that apply to it directly. Both should be able to evidence their reasoning. This entry does not set out the full allocation of responsibilities between controllers and processors.

Common misconceptions

Large-scale processing is defined by a fixed number of individuals or records.
The GDPR does not set a definitive numeric threshold. The determination is contextual and generally weighs multiple factors, including the number of data subjects, the volume and variety of data, the duration, and the geographical scope, together.
Large-scale processing automatically makes a data protection impact assessment mandatory.
Large-scale processing is one factor that can indicate the need for a DPIA, but it is not by itself an automatic trigger in all cases. A DPIA is typically indicated when large-scale processing combines with other risk factors, such as special category data or systematic monitoring, and the assessment remains context-dependent.
The large-scale processing concept applies uniformly across all privacy regimes.
The term originates in the EU GDPR and is reflected in the UK GDPR. Other frameworks such as the CCPA and CPRA, HIPAA, ISO/IEC 27701, or the NIST Privacy Framework do not use this concept in the same manner, so its treatment cannot be assumed to be universal.

Best practices

Assess large-scale status against multiple factors together, including the number of data subjects, the volume and range of data, the duration or permanence, and the geographical extent, rather than relying on any single count.
Document the reasoning behind your large-scale determination so the conclusion can be demonstrated as evidence under the accountability principle, not merely asserted.
Treat large-scale processing as one input among several when evaluating whether a DPIA or DPO designation is required, and consider it alongside factors such as special category data and systematic monitoring.
Give particular attention to processing that combines large scale with special category data, and keep this distinct from large-scale processing of ordinary personal data in your risk analysis.
Do not assume the concept transfers to non-GDPR regimes; where you operate under frameworks such as the CCPA and CPRA, HIPAA, ISO/IEC 27701, or the NIST Privacy Framework, apply their own criteria instead.
Revisit large-scale determinations periodically, since changes in data subject numbers, data volume, duration, or geographical reach can alter the assessment over time.