Systematic Description of Processing
A systematic description of processing is a structured, comprehensive account of how an organisation intends to handle personal data as part of a Data Protection Impact Assessment. It typically explains what data is involved, how it will be collected, used, stored, shared and deleted, where the data comes from, and why the processing is carried out. It is meant to give a clear, complete picture of the planned activity so that its privacy risks can be assessed.
Under Article 35 GDPR, a Data Protection Impact Assessment must contain, as a minimum, a systematic description of the envisaged processing operations and the purposes of the processing. In practice, and consistent with regulator guidance (for example the ICO), this description generally covers the nature of the processing (how personal data is collected, used, stored and deleted), the sources of the data, any data sharing, and the purposes pursued. The description forms the factual foundation of the DPIA against which necessity, proportionality and risks to individuals are subsequently assessed; it should not be conflated with the necessity/proportionality assessment or the risk-mitigation measures, which are distinct DPIA components. The precise expected content beyond the statutory minimum can vary with regulator guidance and member state practice, so practitioners should verify requirements against the current official text and applicable supervisory authority guidance. Note this term is specific to the DPIA context and is unrelated to 'systematic processing' as used in cognitive psychology.
Why it matters
The systematic description of processing is the factual foundation on which an entire Data Protection Impact Assessment rests. Under Article 35 GDPR, a DPIA must contain, as a minimum, a systematic description of the envisaged processing operations and the purposes of the processing. If this description is incomplete or inaccurate, for example, if it omits data sharing arrangements or fails to identify where data originates, the necessity, proportionality and risk assessments that follow are built on a flawed picture, and any mitigation measures may address the wrong risks. Getting the description right is therefore a precondition for a defensible DPIA.
The description also serves an accountability and evidential function. Regulator guidance, such as that published by the ICO, expects the description to cover the nature of the processing (how personal data is collected, used, stored and deleted), the sources of the data, any data sharing, and the purposes pursued. A clear, complete account allows supervisory authorities, data protection officers and internal reviewers to understand at a glance what is planned and to test whether the processing is justified. It also helps demonstrate that the organisation genuinely engaged with the activity before deploying it, rather than treating the DPIA as a formality.
Because the description is where scope is fixed, it is easy to conflate it with other DPIA components. It should not be treated as the necessity and proportionality analysis, nor as the set of risk-mitigation measures, these are distinct parts of the assessment. Keeping the description separate and comprehensive reduces the chance that a risk is overlooked simply because the underlying processing was never fully mapped. The precise content expected beyond the statutory minimum can vary with regulator guidance and member state practice, so practitioners should verify requirements against the current official text and applicable supervisory authority guidance.
Who it's relevant to
Inside Systematic Description of Processing
Common questions
Answers to the questions practitioners most commonly ask about Systematic Description of Processing.