Skip to main content
Category: Impact Assessments & Documentation

Purposes of the Processing

Also known as: Processing Purpose, Purpose of Data Processing, Processing Purposes
Simply put

The purposes of the processing are the specific reasons an organisation collects and uses personal data, such as fulfilling an order or carrying out research. Under data protection law, personal data can generally only be used for a specified purpose rather than for any purpose the organisation might later choose. The organisation responsible for deciding these purposes is known as the controller.

Formal definition

The purposes of the processing refer to the specified aims for which a controller processes personal data. A controller is the party that determines the purposes and means of processing, as distinguished from a processor, which processes personal data on the controller's behalf under contract. Identifying the purpose is foundational: it informs the applicable lawful basis under Article 6 of the (UK) GDPR (for example, public task or legitimate interests may be relevant for research purposes), and it engages the purpose limitation principle, under which personal data collected for specified purposes should generally not be further processed in an incompatible manner. Guidance indicates that reuse for research-related purposes may be permitted where appropriate safeguards are in place; practitioners should assess compatibility and safeguards case by case and note that member state and national implementing provisions can affect the position. Special category data under Article 9 requires an additional condition beyond an Article 6 basis. This entry addresses the concept of purpose specification and does not itself establish the full purpose limitation test; readers should verify article references and applicable derogations against the current official text.

Why it matters

Identifying the purposes of the processing is foundational to nearly every other data protection obligation. Because personal data can generally only be processed for a specified purpose rather than for any purpose an organisation might later choose, the purpose an organisation sets at the point of collection shapes what it can lawfully do with that data afterwards. It informs the choice of lawful basis under Article 6 of the (UK) GDPR, engages the purpose limitation principle, and underpins the transparency information provided to individuals. An unclear or overly broad purpose statement can undermine the lawfulness of the entire processing activity.

The purpose also determines who is accountable. The controller is the party that decides the purposes and means of processing, and it is this decision-making role, rather than mere technical handling of data, that distinguishes a controller from a processor acting on its behalf under contract. Correctly attributing purpose is therefore essential to allocating responsibility and identifying who must be able to demonstrate compliance.

Purpose specification is particularly significant where organisations wish to reuse data. Guidance indicates that existing personal data may in some circumstances be reused for research-related purposes where appropriate safeguards are in place, but this compatibility should be assessed case by case. Because member state and national implementing provisions can affect the position, and because special category data under Article 9 requires an additional condition beyond an Article 6 basis, organisations should not assume that reuse is permitted without a documented assessment.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads rely on clearly articulated purposes to map processing activities, select and document lawful bases, and demonstrate accountability. A well-specified purpose supports transparency obligations and helps determine whether a proposed new use is compatible with the original purpose or requires further assessment.
Controllers (and Those Assessing Controller Status)
Because the controller is the party that determines the purposes and means of processing, organisations must identify who is making these decisions to correctly allocate responsibility. This is central to distinguishing controllers from processors, who act on a controller's behalf under contract, and to understanding where compliance obligations sit.
Researchers and Teams Reusing Personal Data
Teams undertaking research or seeking to reuse existing personal data should pay close attention to purpose specification. Guidance indicates reuse for research-related purposes may be permitted where appropriate safeguards are in place, and for research the lawful basis is in most circumstances likely to be public task or legitimate interests. Compatibility and safeguards should be assessed case by case, with attention to any additional Article 9 condition for special category data and to relevant national provisions.
Privacy Engineers and System Designers
Engineers building systems that collect and use personal data need to understand the specified purpose so that data flows, retention, and access controls align with what the data was collected for. Purpose specification supports the purpose limitation principle by helping ensure data is not repurposed in an incompatible manner without assessment.

Inside Purposes of the Processing

Specified purpose
A clearly identified reason for which personal data is collected and processed. Under the purpose limitation principle (Article 5(1)(b) GDPR), purposes must be specified at the point of collection rather than left open-ended, so that data subjects and regulators can assess what the processing entails.
Explicit and legitimate character
The purpose must be expressed clearly enough to be understood (explicit) and must be lawful and consistent with the applicable legal basis (legitimate). A purpose that is vague, such as 'business purposes', is generally insufficient to satisfy the requirement.
Link to a legal basis
Each purpose should be tied to an Article 6 legal basis (for example consent, contract, legal obligation, vital interests, public task, or legitimate interests), and, where special category data under Article 9 is involved, to an additional Article 9 condition. The purpose and the basis are distinct: the purpose is the 'why', while the basis is the 'lawful ground'.
Compatibility of further processing
Where personal data is later used for a new purpose, GDPR generally requires an assessment of whether that new purpose is compatible with the original one, taking into account factors such as the relationship between the purposes, the context of collection, the nature of the data, and possible consequences for data subjects.
Transparency to data subjects
The purposes typically must be communicated to individuals, for example through information provided at collection, so that processing is not carried out for reasons the data subject would not reasonably expect.

Common questions

Answers to the questions practitioners most commonly ask about Purposes of the Processing.

Does specifying the purpose of processing mean I have automatically established a lawful basis under Article 6?
No. Specifying the purpose and identifying a lawful basis are distinct requirements that must both be satisfied. The purpose describes why the data is being processed and relates to the purpose limitation principle, while the lawful basis is one of the Article 6 conditions (consent, contract, legal obligation, vital interests, public task, or legitimate interests) that makes the processing lawful. A clearly stated purpose does not by itself make processing lawful; you must separately assess and document which lawful basis applies, and for special category data under Article 9 an additional condition is generally required.
Can I define purposes broadly so that I have flexibility to use the data in different ways later?
Generally, no. Purposes are expected to be specified, explicit, and legitimate, which typically means they should be sufficiently precise rather than vague or open-ended. Overly broad purposes may undermine transparency and make it difficult to assess compatibility if the data is later used for something new. In most cases, using data for a purpose that is incompatible with the originally specified purpose requires a separate assessment, and depending on the circumstances a new lawful basis or additional transparency steps may be needed. Practices and regulatory guidance can vary, so the boundary should be assessed case by case.
How specific does a stated purpose need to be in practice?
In most cases, a purpose should be granular enough that a data subject can understand what is being done with their data and why, and precise enough that you can map each purpose to a lawful basis and to the categories of data actually used. Very general labels typically provide insufficient specificity. The appropriate level of detail depends on the context and the risk involved, and it is advisable to check current regulatory guidance, which can differ between authorities.
Where should purposes of the processing be documented?
Purposes are typically recorded in several places, including transparency information provided to data subjects and internal records of processing activities. Documenting each purpose alongside its associated lawful basis, the categories of data, and retention approach generally supports accountability. The exact documentation expectations can depend on your role and on applicable national implementing law, so verify against the current official text and any relevant guidance.
What should I do if I want to use personal data for a new purpose not originally specified?
Generally, you should assess whether the new purpose is compatible with the original purpose for which the data was collected. Where the new purpose is not based on consent or a legal provision, a compatibility assessment considering factors such as the link between purposes, the context of collection, the nature of the data, possible consequences, and the presence of safeguards is typically expected. Depending on the outcome, you may need to identify an appropriate lawful basis, provide further information to data subjects, or, in some cases, obtain fresh consent. This is context and risk dependent and should be assessed on the specific facts.
How do purposes relate to data minimisation and retention decisions?
The specified purpose generally acts as the reference point for deciding what data is adequate, relevant, and limited to what is necessary, and for how long the data should be kept. In practice, you should typically map each category of data and each retention period back to a defined purpose, and review whether data is still needed once the purpose is fulfilled. The appropriate approach depends on the circumstances, and specific retention requirements may be affected by other legal obligations.

Common misconceptions

Stating a broad purpose such as 'to improve our services' is enough to meet the specificity requirement.
Purposes generally need to be specific and explicit enough for a data subject to understand what will happen to their data. Overly broad or generic wording is typically regarded as insufficient, though the precise threshold can be a matter of assessment and regulator interpretation.
Defining a purpose means consent is required for the processing.
Specifying a purpose is separate from choosing a legal basis. Consent is only one of several Article 6 bases, and in many cases a different basis (such as contract or legitimate interests) applies. Special category data additionally requires an Article 9 condition.
Once data is collected, it can be reused for any new purpose.
Using data for a new purpose generally requires assessing compatibility with the original purpose, and in some cases a fresh legal basis or additional information to data subjects. Whether a new use is permitted is context and risk dependent rather than automatic.

Best practices

Document each processing purpose specifically and explicitly at the point of collection, avoiding generic catch-all descriptions.
Map every stated purpose to a distinct Article 6 legal basis, and identify an additional Article 9 condition where special category data is involved.
Communicate purposes clearly to data subjects through transparency information so that processing aligns with reasonable expectations.
Before reusing data for a new purpose, carry out and record a compatibility assessment, and consider whether a fresh basis or notice is needed.
Review purposes periodically to confirm they remain accurate, current, and consistent with actual processing activities.
Verify wording and any applicable article references against the current official GDPR text and relevant regulator guidance, noting that interpretations can diverge between authorities.