Article 10 GDPR: Difference between revisions
No edit summary |
No edit summary |
||
Line 210: | Line 210: | ||
== Commentary == | == Commentary == | ||
'''General aspects''' | '''General aspects''' | ||
Line 235: | Line 236: | ||
<references /> | <references /> | ||
<span id="r1"><span id="r1"> | <span id="r1"><span id="r1"> |
Revision as of 10:43, 14 May 2021
← Article 10: Processing of personal data relating to criminal convictions and offences → |
---|
Expand
Chapter 1: General provisions
Collapse
Chapter 2: Principles
Article 5: Principles relating to processing of personal data Expand
Chapter 3: Rights of the data subject
Expand
Chapter 4: Controller and processor
Expand
Chapter 5: Transfers of personal data
Expand
Chapter 6: Supervisory authorities
Expand
Chapter 7: Cooperation and consistency
Expand
Chapter 8: Remedies, liability and penalties
Expand
Chapter 9: Specific processing situations
Expand
Chapter 10: Delegated and implementing acts
Expand
Chapter 11: Final provisions
|
Legal Text
Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions shall be kept only under the control of official authority.
Relevant Recitals
Overview
Article 10 is a complementary provision to the Law Enforcement Directive (LED)[1] that aims at ensuring that criminal data processing is still carried out in accordance with the GDPR principles and with appropriate safeguards when the LED is not directly applicable.
Commentary
General aspects
The LED extends its scope to the processing of data for the purpose of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security carried out by public authorities that are competent for such activities, or by other bodies or entities that are entrusted those activities by a national law.
Consequently, Article 2(2)(d) GDPR excludes of the scope of the Regulation any processing that falls under the scope of the LED. However, Article 10 GDPR is intended to extend the protection of the GDPR to the processing of certain criminal data that is not included in the scope of the Directive, given the sensitive nature of such data, that can lead to a stigmatization that may profoundly affect the data subject in different aspects of life.[2]Some examples of such processing activities may be, according to Recital 19, anti-money laundering activities or the activities of forensic laboratories.
Criminal “convictions” and “offences”
Hence, Article 10 allows for the processing of data relating to criminal convictions and offences. The term “convictions” makes reference to pronouncements of criminal penalties on perpetrators, instigators or assistants. Actors such as victims or witnesses are not included. However, there is discussion about whether suspects should be included.[3]
Regarding the meaning of “offence”, the term may be subject to interpretation by Member States law. In addition, in the same sense, the CJEU has established three criteria must be examined when determining what constitutes a criminal proceeding: the legal classification of the offence under national law, the nature of the offence and the nature and degree of severity of the penalty that the person concerned is liable to incur.[4]
Conditions for the processing
Any processing still needs to rely in a legal basis from Article 6(1) GDPR and comply with the principles enshrined in Article 5. Additionally, the processing will still be subject to other GDPR provisions that may be applicable, such as the obligation to carry out a data protection impact assessment from Article 35 or the obligation to designate a data protection officer from Article 37.[5]
Authorized entities
The processing shall only be carried out by public authorities and private entities that are entitled to do it by Member States law. In this regard, interpreting the norm sensu contrario, the public authorities mentioned in Article 10 would be the ones that are not included in Article 3(7) LED. In addition to this, the national law allowing private entities to process such data shall provide for appropriate safeguards for the rights and freedoms of data subjects. It is also important to note that such processing shall happen under direct control of the mentioned entities; the entity shall be fully or largely responsible for the processing. Mere supervision or control that does not allow in practice to determine the conditions of individual processing is not enough.[6]
Decisions
→ You can find all related decisions in Category:Article 10 GDPR
References
- ↑ Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and the free movement of such data and repealing Council Framework Decision 2008/977/JHA, accessible at: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016L0680
- ↑ Georgieva, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 10 GDPR, p. 388 (Oxford University Press, Oxford, 2020)
- ↑ Weichert, in Kühling, Buchner, DS-GVO, Article 10 GDPR, margin numbers 6-8a (Beck 2020, 3nd ed.) (accessed 13.05.2021)
- ↑ CJEU, 05.06.2012, Bonda, C‑489/10, § 37 (available here https://curia.europa.eu/juris/document/document.jsf?text=&docid=123501&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=2694396)
- ↑ Georgieva, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 10 GDPR, p. 388 (Oxford University Press, Oxford, 2020)
- ↑ Schiff, in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 10 GDPR, margin numbers 7-8 (Beck 2018, 2nd ed.) (accessed 13.05.2021)