Data Processed on a Large Scale
"Data processed on a large scale" is a GDPR concept used to describe processing that involves personal data about a substantial number of people, large volumes of data, or activities spread across wide geographic areas. The GDPR does not fix a single numeric threshold, so whether processing counts as large scale generally depends on an assessment of factors such as how many individuals are affected and the extent of the data involved. This concept matters because certain obligations may be triggered when processing reaches a large scale.
"Large scale" is a qualitative GDPR notion rather than a term with a fixed statutory definition in the Regulation text, and no single numeric threshold is set by the GDPR itself. Assessment typically considers factors including the number of data subjects affected (whether an absolute figure or a proportion of a relevant population), the volume and range of personal data being processed, and the geographical extent of the processing activity. Regulatory guidance and commentary have suggested indicative reference points (for example, some sources describe operations covering several million people as large scale), but such figures should be treated as illustrative rather than definitive and verified against current official guidance. Practitioners should note that the classification is context-dependent and can influence whether particular obligations arise; the boundary of the term is not settled by a bright-line rule, and regulator interpretations may vary.
Why it matters
The classification of processing as "large scale" is significant because it can act as a trigger for specific GDPR obligations. In particular, the concept is relevant to when a Data Protection Impact Assessment may be required and to when an organisation may be obliged to designate a Data Protection Officer. Because the GDPR does not set a single numeric threshold, the determination generally rests on a case-by-case assessment rather than a bright-line count, which means organisations must document their reasoning about why a given operation does or does not reach a large scale.
The absence of a fixed threshold creates practical uncertainty. Regulatory guidance and commentary have offered indicative reference points, some sources describe operations covering several million people as large scale, but these figures should be treated as illustrative rather than definitive and verified against current official guidance. Regulator interpretations may vary, and the boundary of the term is not settled by a formal statutory rule, so relying on a specific headcount alone can be misleading.
For compliance programs, the consequence of getting the assessment wrong can be an omitted DPIA or an ungoverned high-risk activity. Because the concept is context-dependent, organisations should assess the number of individuals affected, the volume and range of data, and the geographic extent together rather than in isolation, and should revisit that assessment as processing activities change over time.
Who it's relevant to
Inside Data Processed on a Large Scale
Common questions
Answers to the questions practitioners most commonly ask about Data Processed on a Large Scale.