Skip to main content
Category: Impact Assessments & Documentation

Data Processed on a Large Scale

Also known as: Large-Scale Processing, Large-Scale Data Processing
Simply put

"Data processed on a large scale" is a GDPR concept used to describe processing that involves personal data about a substantial number of people, large volumes of data, or activities spread across wide geographic areas. The GDPR does not fix a single numeric threshold, so whether processing counts as large scale generally depends on an assessment of factors such as how many individuals are affected and the extent of the data involved. This concept matters because certain obligations may be triggered when processing reaches a large scale.

Formal definition

"Large scale" is a qualitative GDPR notion rather than a term with a fixed statutory definition in the Regulation text, and no single numeric threshold is set by the GDPR itself. Assessment typically considers factors including the number of data subjects affected (whether an absolute figure or a proportion of a relevant population), the volume and range of personal data being processed, and the geographical extent of the processing activity. Regulatory guidance and commentary have suggested indicative reference points (for example, some sources describe operations covering several million people as large scale), but such figures should be treated as illustrative rather than definitive and verified against current official guidance. Practitioners should note that the classification is context-dependent and can influence whether particular obligations arise; the boundary of the term is not settled by a bright-line rule, and regulator interpretations may vary.

Why it matters

The classification of processing as "large scale" is significant because it can act as a trigger for specific GDPR obligations. In particular, the concept is relevant to when a Data Protection Impact Assessment may be required and to when an organisation may be obliged to designate a Data Protection Officer. Because the GDPR does not set a single numeric threshold, the determination generally rests on a case-by-case assessment rather than a bright-line count, which means organisations must document their reasoning about why a given operation does or does not reach a large scale.

The absence of a fixed threshold creates practical uncertainty. Regulatory guidance and commentary have offered indicative reference points, some sources describe operations covering several million people as large scale, but these figures should be treated as illustrative rather than definitive and verified against current official guidance. Regulator interpretations may vary, and the boundary of the term is not settled by a formal statutory rule, so relying on a specific headcount alone can be misleading.

For compliance programs, the consequence of getting the assessment wrong can be an omitted DPIA or an ungoverned high-risk activity. Because the concept is context-dependent, organisations should assess the number of individuals affected, the volume and range of data, and the geographic extent together rather than in isolation, and should revisit that assessment as processing activities change over time.

Who it's relevant to

Data Protection Officers
DPOs typically need to evaluate whether an organisation's processing activities reach a large scale, since this can bear on obligations such as when a DPIA is warranted and when a DPO must be designated. They generally document the assessment of factors, number of individuals, data volume and range, and geographic extent, rather than relying on a single number.
Compliance and Privacy Leads
Those responsible for compliance programs generally use the large-scale concept to help prioritise risk assessments and record-keeping. Because no bright-line threshold applies, they benefit from a defensible, documented methodology that can withstand scrutiny where regulator interpretations may vary.
Legal and Advisory Practitioners
Lawyers advising on GDPR matters generally need to frame large scale as a qualitative, context-dependent notion rather than a fixed statutory figure. They should flag that any indicative reference points drawn from guidance or commentary are illustrative and should be verified against current official sources.
Engineers and Data Teams
Engineers designing systems that handle personal data in high volumes, across many individuals, or spanning wide geographic areas may find their work implicated by large-scale processing considerations. Early involvement can help ensure that relevant assessments are informed by accurate information about data volume and reach.

Inside Data Processed on a Large Scale

Concept origin
The phrase 'large scale' is not defined numerically in the GDPR text. It appears in provisions such as those addressing the mandatory designation of a Data Protection Officer and the circumstances triggering a Data Protection Impact Assessment. Its interpretation draws heavily on regulatory guidance rather than a fixed statutory threshold, so the reader should verify current guidance and any relevant recitals against the official text.
Number of data subjects
One typically considered factor is the number of individuals affected, either as a specific figure or as a proportion of a relevant population. Guidance generally treats this qualitatively rather than setting a definitive cut-off.
Volume and range of data
The quantity of personal data and the variety of different data items being processed are generally relevant. Processing a broad range of attributes about individuals can weigh toward a large-scale characterisation, subject to assessment.
Duration and permanence
The length of time processing continues, or its ongoing or permanent nature, is generally a factor. Sustained or indefinite processing tends to support a large-scale finding more than a brief, one-off activity.
Geographical extent
The territorial reach of the processing activity is generally considered. Processing spanning wide geographic areas may point toward large scale, though this must be weighed alongside the other factors rather than in isolation.
Relationship to accountability obligations
Whether processing is 'large scale' can be one input into determining obligations such as DPO designation (subject to the applicable Article conditions) and whether a DPIA is required (subject to Article 35 criteria). These are distinct assessments and should not be collapsed into a single test.
Scope boundary
The concept concerns personal data of individuals under the GDPR. It does not extend to genuinely anonymous data, and its application to matters such as deceased persons or legal entities is generally outside the Regulation's scope, subject to member state derogations that may vary the position.

Common questions

Answers to the questions practitioners most commonly ask about Data Processed on a Large Scale.

Is there a fixed numerical threshold that defines when processing is 'large scale'?
No. The GDPR does not set a specific number of data subjects, volume of records, or percentage of a population that automatically makes processing large scale. Recital 91 gives context and regulatory guidance (notably from the former Article 29 Working Party, endorsed by the European Data Protection Board) has suggested factors to weigh rather than a bright-line figure. Whether processing qualifies is assessed case by case, and regulators may differ in how they apply the factors, so you should treat any threshold as a matter of judgment rather than a fixed rule.
Does 'large scale' refer only to the raw number of individuals whose data is processed?
Not solely. Guidance typically points to several factors considered together, which generally include the number of data subjects (either as a specific figure or as a proportion of a relevant population), the volume and range of data items processed, the duration or permanence of the processing, and its geographical extent. A relatively modest number of individuals could still weigh toward large scale where, for example, the data is extensive or the processing is prolonged. Because the assessment is multi-factor and context dependent, no single element is determinative.
How does a determination that processing is large scale affect our obligation to appoint a Data Protection Officer?
Large-scale processing is one of the triggers relevant to the mandatory DPO appointment criteria under Article 37, specifically where core activities consist of large-scale regular and systematic monitoring, or large-scale processing of special category data under Article 9 or data relating to criminal convictions and offences. If you assess your processing as large scale in these contexts, appointment may be required. However, the DPO obligation depends on the full wording of Article 37 and can also be affected by member state law, which may impose additional appointment requirements, so verify against the current text and any national implementing rules.
Should a large-scale assessment feed into whether we need a Data Protection Impact Assessment?
Yes, it is a relevant input. Large-scale processing features in the DPIA framework under Article 35, for example in connection with large-scale systematic monitoring of a publicly accessible area or large-scale processing of special category data. A conclusion that processing is large scale should be documented and used as one factor in your DPIA screening, alongside the criteria in Article 35 and any list of processing operations that your supervisory authority has published as requiring or not requiring a DPIA. Because those lists vary between member states, check the position for each relevant jurisdiction.
How should we document our reasoning when concluding that processing is or is not large scale?
Because the determination is a matter of judgment applied to multiple factors, it is generally advisable to record the analysis rather than the conclusion alone. Documentation might set out the factors you considered, such as the number or proportion of data subjects, the volume and range of data, the duration, and the geographical scope, together with the reasoning that led to your view. Retaining this reasoning supports your accountability obligations and helps you revisit the assessment if the processing changes. This is a matter of good practice; the specific form of documentation is not prescribed.
When should we revisit a large-scale determination once it has been made?
A large-scale assessment reflects the circumstances at the time it was carried out, and those circumstances can change. It is generally sensible to reassess when the number or proportion of data subjects grows, when the range or volume of data items expands, when the processing becomes more prolonged or permanent, or when its geographical reach increases. Changes in regulatory guidance or in a supervisory authority's published lists may also warrant review. Treating the determination as a point-in-time judgment that can shift, rather than a permanent classification, aligns with the context-dependent nature of the concept.

Common misconceptions

There is a fixed number of records or data subjects above which processing is automatically 'large scale'.
The GDPR does not set a numerical threshold. Assessment is generally qualitative and multi-factorial, weighing considerations such as the number of individuals, volume and range of data, duration, and geographical extent. A single figure should not be treated as decisive, and the reader should verify against current guidance.
Large-scale processing automatically means consent is required and a DPIA and DPO are always mandatory.
Scale is only one input. The applicable legal basis is determined separately under Article 6 (consent being just one of several bases), with an additional condition under Article 9 for special category data. DPIA obligations turn on the Article 35 criteria, and DPO designation turns on its own conditions; large scale may contribute to these assessments but does not, on its own, resolve them.
The interpretation of 'large scale' is settled and identical across all jurisdictions.
The term is interpreted largely through regulatory guidance rather than a precise statutory definition, and positions can differ between the EU GDPR context and the UK GDPR or national implementing law. Member state derogations and evolving guidance mean the boundary is not fixed, so the current official text and relevant regulator guidance should be checked.

Best practices

Assess scale using the recognised qualitative factors together, number of data subjects, volume and range of data, duration or permanence, and geographical extent, rather than relying on any single number.
Document the reasoning behind any large-scale determination so it can be evidenced as part of your accountability record and revisited if the processing changes.
Treat the scale assessment as an input to, not a substitute for, separate analyses of the Article 6 legal basis, any Article 9 condition for special category data, DPIA requirements under Article 35, and DPO designation conditions.
Check the relevant regulator guidance and the current official Regulation text before finalising a determination, and note where interpretation may diverge between EU GDPR, UK GDPR, and national implementing law.
Re-evaluate the characterisation periodically, since increases in data subjects, data volume, duration, or geographic reach can move an activity into large-scale territory over time.
Use qualified, defensible language in internal assessments, acknowledging that the classification is context-dependent and subject to evolving guidance rather than a permanent conclusion.