Data Processing Purposes
Data processing purposes are the specific reasons an organisation collects and uses someone's personal data, such as measuring website traffic or delivering advertising. Under EU and UK data protection rules, these reasons generally must be identified and clearly explained before the data is collected, and the data should not later be used in ways that conflict with those stated reasons. In a cookie consent context, purposes are typically presented to users so they can make informed choices about which uses they accept.
Under the GDPR and UK GDPR principle of purpose limitation (Article 5(1)(b)), personal data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes. "Processing" is defined broadly to include operations such as collecting, storing, retrieving, using, combining, and erasing personal data, whether automated or manual. Each purpose typically needs an identified lawful basis under Article 6, and in the cookie context the specification of distinct purposes (for example, analytics, advertising, or functionality) supports the "specific" and "informed" requirements of valid consent and enables granular user choices in a consent management platform. Note that the ePrivacy Directive separately governs the placing of and access to information on a user's device, so identifying a GDPR processing purpose does not by itself satisfy any applicable prior-consent requirement for the cookie or similar technology. This definition addresses the general principle; the compatibility of any specific secondary purpose (such as reuse for research, which may be treated with additional safeguards under UK ICO guidance) is fact-specific and outside its scope.
Why it matters
Data processing purposes sit at the heart of how EU and UK data protection law regulates personal data. Under the GDPR and UK GDPR principle of purpose limitation (Article 5(1)(b)), personal data must be collected for specified, explicit, and legitimate purposes and not further processed in a way that is incompatible with those purposes. If an organisation cannot clearly articulate why it is collecting data, it generally cannot demonstrate that its processing is lawful, and it undermines the ability of individuals to understand and control how their information is used.
In the cookie consent context, purposes are what users are actually being asked to accept or reject. Valid consent under the GDPR must be specific and informed, which means the distinct purposes for which cookies and similar technologies are used, for example analytics, advertising, or functionality, typically need to be identified and explained before data is collected. Presenting purposes clearly and granularly is what enables meaningful, purpose-by-purpose choices rather than a single all-or-nothing decision.
It is important not to treat identifying a processing purpose as the end of the compliance analysis. Each purpose generally needs an identified lawful basis under Article 6, and the ePrivacy Directive separately governs the placing of and access to information on a user's device, so specifying a GDPR purpose does not by itself satisfy any applicable prior-consent requirement for the cookie or similar technology. Whether a secondary use is compatible with the original purpose is fact-specific and can turn on regulatory guidance and the safeguards in place.
Who it's relevant to
Inside Data Processing Purposes
Common questions
Answers to the questions practitioners most commonly ask about Data Processing Purposes.