For the complete documentation index, see llms.txt. This page is also available as Markdown.

Large Scale Data Collection

Contents

1. What is large-scale data collection?

Certain data protection requirements only apply if your business collects data on a ‘large scale’.

Unlike the numerical thresholds set in some US data regulations, the GDPR does not set out a particular threshold for when processing becomes ‘large scale’. Rather, it is assessed based on several factors. These include:

  • the number of data subjects concerned (although no number is given);

  • the variety of data;

  • the duration of the processing; and

  • the geographical spread of the processing.

Based on suggestions from regulators (such as the ICO) and what we see in practice, the following categories are common examples of large scale processing:

  • hospitals;

  • insurance companies;

  • banks;

  • AI infrastructure companies; and

  • businesses tracking individuals’ real-time locations.

2. Requirements for large-scale data collection

  1. DPO: If your business conducts ‘large scale’ sensitive data collection or ‘large scale’ regular and systematic monitoring of customers, it is required (under the GDPR) to engage a DPO.

  2. DPIA: Separately, where your business is deemed to be engaging in high-risk data processing, it must complete a data protection impact assessment (DPIA) before that processing begins. A DPO will help your business determine if a DPIA is necessary in your individual case.

Last updated