Article 10 GDPR
Legal Text
Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions shall be kept only under the control of official authority.
Relevant Recitals
Commentary
Article 10 GDPR is a complementary provision to the Law Enforcement Directive (LED)[1]. It aims to ensure that criminal data processing is still carried out in accordance with the GDPR’s principles and with appropriate safeguards when the LED is not directly applicable. Article 2(2)(d) GDPR excludes any processing that falls under the scope of the LED from the scope of the GDPR. Article 10 GDPR is intended to extend the protection of the GDPR to the processing of certain criminal data that is not included in the scope of the LED. Specifically, this includes data that has the potential to lead to stigmatisation, which may lead to profound effects on different aspects of a data subjects' life due to its sensitive nature. For example, when data is inappropriately processed in the employment context.[2]
This position was affirmed by the Court of Justice in Case C‑439/19, Latvijas Republikas Saeima. In this judgment, the Court noted that data processed under Article 10 GDPR warrants a higher standards of protection for processing and grant of access, as the data which falls under its scope has the potential to expose the data subject to stigmatisation and social disapproval. At paragraphs 74 and 75, the Court observed that the risk of stigmatisation in itself amounts to severe interference in the data subject's private and professional life for the purposes of Articles 7 and 8 of the Charter, consequently justifying stricter thresholds for processing.[3]
"Article 10 of the GDPR is intended to ensure enhanced protection as regards processing which, because of the particular sensitivity of the data at issue, is liable to constitute a particularly serious interference with the fundamental rights to respect for private life and to the protection of personal data, guaranteed by Articles 7 and 8 of the Charter [...].
Since the data to which Article 10 of the GDPR refers relates to behaviour that gives rise to social disapproval, the grant of access to such data is liable to stigmatise the data subject and thereby to constitute a serious interference with his or her private or professional life.
[...]
Under the principle of proportionality, limitations may be made only if they are necessary and genuinely meet objectives of general interest recognised by the European Union or the need to protect the rights and freedoms of others. They must apply only in so far as is strictly necessary and the legislation which entails the interference must lay down clear and precise rules governing the scope and application of the measure in question [...]."
CJEU - C-439/19 - Latvijas Republikas Saeima (Penalty points), margin number 74 et seq, 105.
Criminal “convictions” and “offences”
Article 10 GDPR allows for the processing of data relating to criminal convictions and offences. The term “convictions” makes reference to pronouncements of criminal penalties on perpetrators, instigators or assistants.
[T]he concept of ‘criminal offence’, which is decisive for determining whether Article 10 of the GDPR is applicable to personal data such as those at issue in the main proceedings, requires an autonomous and uniform interpretation throughout the European Union, having regard to the objective pursued by that provision and the context of which it forms part; the classification given by the Member State concerned to the offences in question is not conclusive in that regard as the classification may vary from one Member State to another [...].
CJEU - C‑474/24 - NADA Austria and Others, margin number 114.
Actors such as victims or witnesses are not included. However, there is discussion about whether suspects should be included.[4] The notion of “offence" must be interpreted according to Member State law. In addition, the CJEU has established three criteria that must be examined when determining what constitutes a criminal proceeding: the legal classification of the offence under national law, the nature of the offence and the nature as well as degree of severity of the penalty that the person concerned is liable to incur.[5]
Therefore, the enhanced protection provided for by Article 10 GDPR is generally limited to the criminal field alone and not to mere administrative offences not covered by criminal provisions.[6]
In order to determine whether such access amounts to processing of personal data relating to ‘offences’, within the meaning of Article 10 of the GDPR, it is important to point out, first, that that concept refers exclusively to criminal offences and that the enhanced protection provided for by that article is limited to the criminal field alone, as is apparent inter alia from the history of the GDPR, from which it is clear that the EU legislature deliberately did not include the adjective ‘administrative’ in Article 10 of the GDPR [...].
CJEU - C‑474/24 - NADA Austria and Others, margin number 113.
The CJEU pointed out that the fact that a rule penalising a specific offence is directed towards all citizens indicates a criminal nature of the sanction while rules applying to a specific group of persons covered by a body of specific rules (e.g. disciplinary rules for a certain profession) indicates a mere civil nature of the rules (e.g. in case of a disciplinary procedure).[7]
Conditions for the processing
The processing of data relating to criminal convictions and offences must be carried out either under the control of official authority or when the processing is authorised by Union or Member State law.
However, any processing still needs to rely on a legal basis under Article 6(1) GDPR and comply with the principles enshrined in Article 5 GDPR. Additionally, the processing will still be subject to other GDPR provisions that may be applicable, such as the obligation to carry out a data protection impact assessment from Article 35 GDPR or the obligation to designate a data protection officer from Article 37 GDPR.[8]
Authorised entities
The processing shall only be carried out by public authorities and private entities that are entitled to do so under Member State law. In this regard, interpreting the norm sensu contrario, the public authorities are those not in the scope of Article 3(7) LED.
Processing by private entities shall happen under direct control of authorised entities; the authorised entity shall be fully or largely responsible for the processing. Mere supervision that does not, in practice, allow for the reliable control of the conditions of individual processing is not enough.[9]
Alternatively, the processing can be authorised by Union or Member state law. Such law allowing private entities to process data relating to criminal convictions and offences must provide for appropriate safeguards for the rights and freedoms of data subjects. Specifically, the legitimate purpose(s) and and necessary requirements should be stipulated together with the applicable safeguards in such a provision.[10]
Comprehensive registers
The last sentence of Article 10 GDPR states that any comprehensive register of criminal convictions must be kept only under the control of official authority. This provision further narrows the possibilities to process information about criminal convictions. A register can be considered comprehensive if it contains information concerning numerous data subjects. It is not necessary that such a register contains the information about all criminal convictions in the respective Member State.[11] This provision excludes the possibility of private criminal databases.[12]
Decisions
→ You can find all related decisions in Category:Article 10 GDPR
References
- ↑ Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and the free movement of such data and repealing Council Framework Decision 2008/977/JHA.
- ↑ Georgieva, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 10 GDPR, p. 388 (Oxford University Press, Oxford, 2020).
- ↑ CJEU Case C‑439/19, Latvijas Republikas Saeima, 22 June 2021, margin number 74-75 (available here); see also CJEU, Case C-474/24. NADA Austria, 14 July 2026, margin number 112 (available here).
- ↑ Weichert, in Kühling, Buchner, DS-GVO BDSG, Article 10 GDPR, margin number 6 (C.H. Beck 2020, 3rd Edition).
- ↑ CJEU, C‑489/10, 5 June 2012, Bonda, margin number 37 (available here).
- ↑ CJEU Case C‑439/19, Latvijas Republikas Saeima, 22 June 2021, margin number 78 (available here).
- ↑ CJEU, Case C-474/24. NADA Austria, 14 July 2026, margin number 114 et seq. (available here).
- ↑ Georgieva, in Kuner, Bygrave, Docksey, The EU General Data Protection Regulation (GDPR): A Commentary, Article 10 GDPR, p. 388 (Oxford University Press, Oxford, 2020).
- ↑ Schiff, in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 10 GDPR, margin number 7 (C.H. Beck, 3rd Edition 2024).
- ↑ Schiff, in Ehmann, Selmayr, Datenschutz-Grundverordnung, Article 10 GDPR, margin number 8 (C.H. Beck, 3rd Edition 2024).
- ↑ Kastelitz, Hötzendorfer, Tschohl, in Knyrim, DatKomm, Article 10 GDPR, margin numbers 21 et seqq (Manz 2020).
- ↑ Weichert, in Kühling, Buchner, DS-GVO BDSG, Article 10 GDPR, margin number 16 (C.H. Beck 2024, 4th Edition).




