Skip to content
Topic Contested in court

Criminal Data

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Processing of criminal convictions and offences

83 linked items 4 Laws37 Case Law18 Guidance15 Enforcement7 News

Overview

27 sources · Sep 25, 2026

Legal Framework

Article 10 GDPR governs the processing of personal data relating to criminal convictions and offences. Unlike the special categories under Article 9, criminal data is not absolutely prohibited but is subject to dual conditions: a valid Article 6(1) lawful basis must exist, and processing must additionally satisfy one of two Article 10 pathways.

The provision permits processing only where it occurs under official authority control or is authorised by Union or Member State law with appropriate safeguards:

"shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects"
— GDPR Art. 10

Comprehensive criminal conviction registers are reserved exclusively to official authority control. Additionally, Article 37(1)(c) mandates DPO designation where core activities involve large-scale criminal data processing:

"processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10"
— GDPR Art. 37

Key Developments

The CJEU has consistently affirmed that Article 10 imposes restrictions beyond the general Article 6 framework. In Endemol Shine Finland, the Court confirmed that criminal data triggers additional safeguards:

"Article 10 of the GDPR makes their processing subject to additional restrictions"
— Endemol Shine Finland Oy ¶47

This reinforces that a lawful basis under Article 6(1) is necessary but not sufficient — controllers must independently satisfy Article 10's official-authority or national-law conditions.

The Spanish DPA's Mercadona decision illustrates enforcement thresholds. The controller deployed facial recognition in retail stores to track persons with criminal convictions:

"The controller had installed facial recognition systems in Mercadona stores for the purpose of tracking individuals with criminal convictions or restraining orders."
— Mercadona S.A. §1

The €2.52 million fine reflected failures across multiple dimensions: data minimisation, necessity and proportionality, and a deficient DPIA. Processing criminal data through blanket biometric capture of all store visitors — including minors — failed the appropriateness test at every level.

Status of the Debate

This area is actively contested in court. While the CJEU has repeatedly confirmed Article 10's two-pathway structure, Member State implementing laws vary significantly in scope and safeguards, and courts are wrestling with boundary questions — particularly where private entities process criminal data under national law authorisations rather than under direct official authority control. The Latvijas Republikas Saeima and Endemol Shine lines of authority are being distinguished and extended in ongoing litigation. No definitive court split is on record, but the precise threshold for what constitutes "control of official authority" versus mere national-law authorisation, and what safeguards satisfy the "appropriate" standard, remains unresolved. Clarification will likely require a preliminary reference testing private-sector criminal data processing against both pathways simultaneously.

Practical Guidance

  • Establish dual compliance: Secure an Article 6(1) lawful basis and independently verify Article 10 conditions — either direct official-authority control or specific Union/Member State law authorisation with documented safeguards.

  • Designate a DPO when threshold is met: If criminal data processing is a core activity conducted on a large scale, Article 37(1)(c) mandates DPO appointment without discretion.

  • Conduct a DPIA: Criminal data processing inherently carries high risk under Article 35; a deficient or generic DPIA was a standalone violation in Mercadona.

  • Apply strict minimisation: Blanket collection of criminal data across untargeted populations — as in Mercadona's store-wide facial recognition — fails necessity and proportionality. Limit collection to specific, justified individuals.

  • Verify national law basis: Where relying on Member State law authorisation, confirm the law specifies appropriate safeguards; a general legal permission without built-in data subject protections will not satisfy Article 10.

Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
art 10 Processing of personal data relating to criminal convictions and offences Laws GDPR Apr 2016 Conditions for processing criminal data
why this is here
Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law

This provision is directly about the processing of criminal convictions and offences, establishing the core legal conditions.

assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026

Guidelines 05/2022 use of facial recognition technology in the area of law enforcement Guidelines ·EDPB Guidance EDPB May 2023 law enforcement processing of criminal matters
why this is here
More and more law enforcement authorities (LEAs) apply or intend to apply facial recognition technology (FRT).

The context is law enforcement, which involves criminal data, but the document doesn't specifically discuss processing of criminal convictions/offences data.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

AEPD publishes GDPR Risk Assessment > GDPR RISK ASSESSMENT is intended to assist controllers and processors to identify the risk factors for the rights and freedoms of data subjects whose data are present in the… News AEPD Oct 2022 Criminal convictions and offences as risk factor
why this is here
Personal data relating to convictions and criminal (or administrative) offences

The document specifically mentions criminal convictions as a data type contributing to risk.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

CJEU: PNR Directive Valid if Limited to the “Strictly Necessary” > In a landmark ruling of 21 June 2022, the CJEU (Grand Chamber), upheld the EU’s regime to collect and use records of travellers, provided that it is strictly interpreted in line… News eucrim Aug 2022 Use for serious crime and terrorism
why this is here
in order to combat terrorist offences and serious crime

The document repeatedly references the use of PNR data for combating terrorism and serious crime, connecting to criminal data processing contexts.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

“Social media profiles and phone contacts” used as proof of identity for deportations > Thirteen non-EU countries sometimes accept “social media profiles and phone contacts” as evidence of identity for the purpose of deportations, according to an internal European… News European Digital Rights Mar 2023 criminal records requested in readmission
why this is here
criminal records, in particular terrorism related crimes

The document mentions that countries request criminal records as part of deportation procedures, relevant to processing of criminal data, but it is not the central topic.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

Europol told to hand over personal data to Dutch activist The European Data Protection Supervisor ordered Europol to hand over personal data to Dutch activist Frank van der Linde. The decision is the result of a two-year investigation… News Fair Trials Sep 2022 Data labeled as terrorism-related
why this is here
“Discovering that data has been sent to Europol labelled crime area terrorism is a nightmare.”

The document briefly mentions van der Linde's data being labeled under 'crime area terrorism,' but the core focus is on access rights, not processing of criminal data per se.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

This is the top of each pile — all 37 Case Law