Define: Process/Processing
In a contract, Process or Processing refers to any operation performed on personal data, such as collecting, recording, storing, using, disclosing, or destroying it. The term borrows its meaning directly from applicable Data Protection Legislation, giving both parties a shared, legally grounded understanding of what activities are covered when personal data changes hands or is handled under the agreement.
Legal accuracy standard set & glossary spot-checked by Imad Mohammed Nazar , Skadden-trained M&A lawyer, Legal Engineer at GenieAI
What Process/Processing Means in a Contract
When a contract defines Process or Processing by reference to the relevant Data Protection Legislation, it is deliberately borrowing a legal term of art rather than inventing a new one. This ensures that the obligations tied to processing personal data, such as security requirements, notification duties, or restrictions on transfers, are interpreted consistently with the statutory framework that governs data protection in the applicable jurisdiction. It avoids ambiguity that might arise if each contract tried to craft its own bespoke definition.
Practically, this means that almost any interaction with personal data counts as processing. Collecting a customer's email address, storing employee records, analyzing usage data, or even permanently deleting information all fall within the scope of the term. Because the definition is broad by design, contracts rely on it to trigger a wide range of downstream obligations without needing to list every possible activity individually.
This approach also future-proofs the agreement. As data protection law evolves, the contractual definition automatically tracks any statutory amendments or judicial interpretations, so the parties do not need to renegotiate the clause every time the underlying legislation changes.
How Process/Processing Is Defined or Measured
Rather than measuring processing in a quantitative sense, contracts define it by reference to the categories of activity recognized under data protection law. These typically include collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, and destruction of personal data.
- Collection and recording of data from individuals or systems
- Storage, organization, and structuring of data sets
- Use, disclosure, or transmission of data to third parties
- Erasure or destruction at the end of a retention period
Because the list is so extensive, contracts rarely try to enumerate it in full. Instead, they cross-reference the statutory definition, which has the effect of automatically capturing any activity that a court or regulator would recognize as processing, even if it is not explicitly named in the agreement.
Where Process/Processing Appears in Agreements
The term appears most prominently in instruments specifically designed to regulate the handling of personal data, such as a Relevant Circumstances
Relevant Sectors