Meaning
Subsequent use or analysis of a data set for a purpose that is different from the original objective for which the data was collected. The concept of secondary processing is central to modern analytics and machine learning where existing operational data is repurposed for insight generation. It requires a separate evaluation of lawfulness to ensure the new use does not infringe on individual privacy rights.
Legal Basis
Compatibility tests determine whether the new purpose aligns with the expectations set during the initial data collection. If the secondary processing is not compatible, the entity must find a new justification, such as explicit consent or a statutory obligation. This prevents the exploitation of personal data for uses that the subject never anticipated.
Data Transformation
Anonymisation or aggregation often takes place to reduce the risks associated with the new activity. While the primary use might require individual identifiers for billing, the secondary processing might only need broad demographic trends. These techniques allow for research and development without maintaining a link to the original identities.
Governance Boundary
Policies must clearly distinguish between the data held for operational needs and the data extracted for analytics. Secondary processing should occur in a segregated environment with its own access controls and retention schedules. This separation prevents the mix of administrative and research data within the same database architecture.
Failure to maintain this boundary can lead to purpose creep where data is used for increasingly intrusive activities without oversight.