Article 10 GDPR: Difference between revisions
Line 195: | Line 195: | ||
Article 10 GDPR is a complementary provision to the Law Enforcement Directive (LED),<ref>[https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016L0680 Directive (EU) 2016/680] of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and the free movement of such data and repealing Council Framework Decision 2008/977/JHA.</ref> that aims at ensuring that criminal data processing is still carried out in accordance with the GDPR principles and with appropriate safeguards when the LED is not directly applicable. | Article 10 GDPR is a complementary provision to the Law Enforcement Directive (LED),<ref>[https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016L0680 Directive (EU) 2016/680] of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and the free movement of such data and repealing Council Framework Decision 2008/977/JHA.</ref> that aims at ensuring that criminal data processing is still carried out in accordance with the GDPR principles and with appropriate safeguards when the LED is not directly applicable. | ||
=== General Aspects === | |||
[[Article 2 GDPR|Article 2(2)(d) GDPR]] excludes from the scope of the GDPR any processing that falls under the scope of the LED. Article 10 GDPR is intended to extend the protection of the GDPR to the processing of certain criminal data that is not included in the scope of the LED. Specifically, data that due to its sensitive nature, can lead to stigmatisation and profound effects on different aspects of a data subjects' life (when it is inappropriately processed in the employment context, for example).<ref>''Georgieva'', in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 10 GDPR, p. 388 (Oxford University Press, Oxford, 2020).</ref> | [[Article 2 GDPR|Article 2(2)(d) GDPR]] excludes from the scope of the GDPR any processing that falls under the scope of the LED. Article 10 GDPR is intended to extend the protection of the GDPR to the processing of certain criminal data that is not included in the scope of the LED. Specifically, data that due to its sensitive nature, can lead to stigmatisation and profound effects on different aspects of a data subjects' life (when it is inappropriately processed in the employment context, for example).<ref>''Georgieva'', in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 10 GDPR, p. 388 (Oxford University Press, Oxford, 2020).</ref> | ||
=== Criminal “Convictions” and “Offences” === | |||
Article 10 GDPR allows for the processing of data relating to criminal convictions and offences. | Article 10 GDPR allows for the processing of data relating to criminal convictions and offences. | ||
Line 206: | Line 206: | ||
Regarding the meaning of “offence", the term may be subject to interpretation by Member State law. In addition, the CJEU has established three criteria that must be examined when determining what constitutes a criminal proceeding: the legal classification of the offence under national law, the nature of the offence and the nature and degree of severity of the penalty that the person concerned is liable to incur.<ref>CJEU, 5 June 2012, Bonda, C‑489/10, margin number 37 (available here https://curia.europa.eu/juris/document/document.jsf?text=&docid=123501&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=2694396). </ref> | Regarding the meaning of “offence", the term may be subject to interpretation by Member State law. In addition, the CJEU has established three criteria that must be examined when determining what constitutes a criminal proceeding: the legal classification of the offence under national law, the nature of the offence and the nature and degree of severity of the penalty that the person concerned is liable to incur.<ref>CJEU, 5 June 2012, Bonda, C‑489/10, margin number 37 (available here https://curia.europa.eu/juris/document/document.jsf?text=&docid=123501&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=2694396). </ref> | ||
=== Conditions for the Processing === | |||
Any processing still needs to rely on a legal basis from [[Article 6 GDPR|Article 6(1) GDPR]] and comply with the principles enshrined in [[Article 5 GDPR]]. Additionally, the processing will still be subject to other GDPR provisions that may be applicable, such as the obligation to carry out a data protection impact assessment from [[Article 35 GDPR]] or the obligation to designate a data protection officer from [[Article 37 GDPR]].<ref>''Georgieva'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR), Article 10 GDPR, p. 388 (Oxford University Press, Oxford, 2020).</ref> | Any processing still needs to rely on a legal basis from [[Article 6 GDPR|Article 6(1) GDPR]] and comply with the principles enshrined in [[Article 5 GDPR]]. Additionally, the processing will still be subject to other GDPR provisions that may be applicable, such as the obligation to carry out a data protection impact assessment from [[Article 35 GDPR]] or the obligation to designate a data protection officer from [[Article 37 GDPR]].<ref>''Georgieva'', in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR), Article 10 GDPR, p. 388 (Oxford University Press, Oxford, 2020).</ref> | ||
=== Authorised Entities === | |||
The processing shall only be carried out by public authorities and private entities that are entitled to do so by Member State law. In this regard, interpreting the norm ''sensu contrario,'' the public authorities are those excluded by the scope of [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016L0680 Article 3(7) LED]. In addition, the national law allowing private entities to process such data shall provide for appropriate safeguards for the rights and freedoms of data subjects. Processing by private entities shall happen under direct control of authorized entities; the authorized entity shall be fully or largely responsible for the processing. Mere supervision that does not, in practice, allow for the reliable control of the conditions of individual processing is not enough.<ref>''Schiff'', in Ehmann/Selmayr, Datenschutz-Grundverordnung, Article 10 GDPR, margin number 7-8 (Beck, 2nd edition 2018) (accessed 13 May 2021).</ref> | The processing shall only be carried out by public authorities and private entities that are entitled to do so by Member State law. In this regard, interpreting the norm ''sensu contrario,'' the public authorities are those excluded by the scope of [https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32016L0680 Article 3(7) LED]. In addition, the national law allowing private entities to process such data shall provide for appropriate safeguards for the rights and freedoms of data subjects. Processing by private entities shall happen under direct control of authorized entities; the authorized entity shall be fully or largely responsible for the processing. Mere supervision that does not, in practice, allow for the reliable control of the conditions of individual processing is not enough.<ref>''Schiff'', in Ehmann/Selmayr, Datenschutz-Grundverordnung, Article 10 GDPR, margin number 7-8 (Beck, 2nd edition 2018) (accessed 13 May 2021).</ref> | ||
---- | ---- |
Revision as of 17:45, 16 August 2021
Legal Text
Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions shall be kept only under the control of official authority.
Relevant Recitals
Commentary on Article 10
Article 10 GDPR is a complementary provision to the Law Enforcement Directive (LED),[1] that aims at ensuring that criminal data processing is still carried out in accordance with the GDPR principles and with appropriate safeguards when the LED is not directly applicable.
General Aspects
Article 2(2)(d) GDPR excludes from the scope of the GDPR any processing that falls under the scope of the LED. Article 10 GDPR is intended to extend the protection of the GDPR to the processing of certain criminal data that is not included in the scope of the LED. Specifically, data that due to its sensitive nature, can lead to stigmatisation and profound effects on different aspects of a data subjects' life (when it is inappropriately processed in the employment context, for example).[2]
Criminal “Convictions” and “Offences”
Article 10 GDPR allows for the processing of data relating to criminal convictions and offences.
The term “convictions” makes reference to pronouncements of criminal penalties on perpetrators, instigators or assistants. Actors such as victims or witnesses are not included. However, there is discussion about whether suspects should be included.[3]
Regarding the meaning of “offence", the term may be subject to interpretation by Member State law. In addition, the CJEU has established three criteria that must be examined when determining what constitutes a criminal proceeding: the legal classification of the offence under national law, the nature of the offence and the nature and degree of severity of the penalty that the person concerned is liable to incur.[4]
Conditions for the Processing
Any processing still needs to rely on a legal basis from Article 6(1) GDPR and comply with the principles enshrined in Article 5 GDPR. Additionally, the processing will still be subject to other GDPR provisions that may be applicable, such as the obligation to carry out a data protection impact assessment from Article 35 GDPR or the obligation to designate a data protection officer from Article 37 GDPR.[5]
Authorised Entities
The processing shall only be carried out by public authorities and private entities that are entitled to do so by Member State law. In this regard, interpreting the norm sensu contrario, the public authorities are those excluded by the scope of Article 3(7) LED. In addition, the national law allowing private entities to process such data shall provide for appropriate safeguards for the rights and freedoms of data subjects. Processing by private entities shall happen under direct control of authorized entities; the authorized entity shall be fully or largely responsible for the processing. Mere supervision that does not, in practice, allow for the reliable control of the conditions of individual processing is not enough.[6]
Decisions
→ You can find all related decisions in Category:Article 10 GDPR
References
- ↑ Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and the free movement of such data and repealing Council Framework Decision 2008/977/JHA.
- ↑ Georgieva, in Kuner et al., The EU General Data Protection Regulation (GDPR), Article 10 GDPR, p. 388 (Oxford University Press, Oxford, 2020).
- ↑ Weichert, in Kühling/Buchner, DS-GVO BDSG, Article 10 GDPR, margin numbers 6-8a (Beck 2020, 3rd ed.) (accessed 13 May 2021).
- ↑ CJEU, 5 June 2012, Bonda, C‑489/10, margin number 37 (available here https://curia.europa.eu/juris/document/document.jsf?text=&docid=123501&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=2694396).
- ↑ Georgieva, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR), Article 10 GDPR, p. 388 (Oxford University Press, Oxford, 2020).
- ↑ Schiff, in Ehmann/Selmayr, Datenschutz-Grundverordnung, Article 10 GDPR, margin number 7-8 (Beck, 2nd edition 2018) (accessed 13 May 2021).