The purpose is fixed at collection, which means the interesting question is always what was written down at the start.
Why it matters when the plan changes
Data gathered for one question tends to attract others. A dataset assembled to inform one decision is useful for a second, and the second is usually proposed by someone with no knowledge of what was agreed at collection. Article 5 of the General Data Protection Regulation makes incompatible further processing the test, which is what forces that conversation to happen before the processing rather than after a complaint. Article 28 extends the same limit down a supply chain, since a processor cannot bring in another processor without the controller's written authorisation.
The tension is between value and trust. Reusing evidence is where much of the value of any data asset sits, and the reuse is exactly what employees and their representatives are concerned about. A narrow, written purpose costs some of that value and is the only thing that makes the original collection defensible, whether the reuse crosses one customer's data or moves down a chain of processors bound by their own written authorisation.
In practice
Behavioural evidence is gathered to inform one decision about a reorganisation, with that purpose stated. A year later someone proposes using the same dataset to inform promotion decisions. It is the same data and a different purpose, so it needs its own basis, its own assessment and its own conversation rather than a technical export.
Evidence
Personal data must be collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with them.
Article 5, General Data Protection Regulation (2016)A processor may not bring in another processor without the controller's written authorisation, which is how the limitation is carried down a supply chain.
Article 28, General Data Protection Regulation (2016)
What it cannot tell you
Purpose limitation fixes what data can be used for, but it does not tell you whether the original purpose was legitimate, proportionate or necessary in the first place. It is silent on data quality, on whether the stated purpose was broad enough to be meaningless, and on what happens once the purpose genuinely lapses.
Questions
One that a reasonable person would have expected given what was originally stated, judged on the relationship between the purposes, the context of collection, the nature of the data and the consequences for the individual. Convenience for the organisation is not among the criteria.
It has to be specific and explicit, which is the opposite of broad. A purpose written widely enough to cover everything fails the requirement, and a purpose that employees could not have understood from the wording is unlikely to support the processing it was meant to authorise.
The controller, which in an employment context is the employer rather than the vendor. That is why the purpose belongs in the agreement between them, and why a supplier proposing a new use of existing data is asking the client to make a decision rather than making one.
Retention is tied to the purpose, so data kept beyond it needs a basis of its own, the same test Article 5 of the General Data Protection Regulation (2016) sets for collection itself. In practice this is the requirement most often missed, since deleting requires action and keeping does not.
Cross-customer use is a different purpose from the one data was collected for, so it needs its own rights assessment, in the same way Article 28 of the General Data Protection Regulation (2016) requires a processor to get written authorisation before adding another processor. Aggregation is part of the answer, not the whole of it.