Criminal Data
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing of criminal convictions and offences
Overview
27 sources · Sep 25, 2026Legal Framework
Article 10 GDPR governs the processing of personal data relating to criminal convictions and offences. Unlike the special categories under Article 9, criminal data is not absolutely prohibited but is subject to dual conditions: a valid Article 6(1) lawful basis must exist, and processing must additionally satisfy one of two Article 10 pathways.
The provision permits processing only where it occurs under official authority control or is authorised by Union or Member State law with appropriate safeguards:
"shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects"
— GDPR Art. 10
Comprehensive criminal conviction registers are reserved exclusively to official authority control. Additionally, Article 37(1)(c) mandates DPO designation where core activities involve large-scale criminal data processing:
"processing on a large scale of special categories of data pursuant to Article 9 and personal data relating to criminal convictions and offences referred to in Article 10"
— GDPR Art. 37
Key Developments
The CJEU has consistently affirmed that Article 10 imposes restrictions beyond the general Article 6 framework. In Endemol Shine Finland, the Court confirmed that criminal data triggers additional safeguards:
"Article 10 of the GDPR makes their processing subject to additional restrictions"
— Endemol Shine Finland Oy ¶47
This reinforces that a lawful basis under Article 6(1) is necessary but not sufficient — controllers must independently satisfy Article 10's official-authority or national-law conditions.
The Spanish DPA's Mercadona decision illustrates enforcement thresholds. The controller deployed facial recognition in retail stores to track persons with criminal convictions:
"The controller had installed facial recognition systems in Mercadona stores for the purpose of tracking individuals with criminal convictions or restraining orders."
— Mercadona S.A. §1
The €2.52 million fine reflected failures across multiple dimensions: data minimisation, necessity and proportionality, and a deficient DPIA. Processing criminal data through blanket biometric capture of all store visitors — including minors — failed the appropriateness test at every level.
Status of the Debate
This area is actively contested in court. While the CJEU has repeatedly confirmed Article 10's two-pathway structure, Member State implementing laws vary significantly in scope and safeguards, and courts are wrestling with boundary questions — particularly where private entities process criminal data under national law authorisations rather than under direct official authority control. The Latvijas Republikas Saeima and Endemol Shine lines of authority are being distinguished and extended in ongoing litigation. No definitive court split is on record, but the precise threshold for what constitutes "control of official authority" versus mere national-law authorisation, and what safeguards satisfy the "appropriate" standard, remains unresolved. Clarification will likely require a preliminary reference testing private-sector criminal data processing against both pathways simultaneously.
Practical Guidance
Establish dual compliance: Secure an Article 6(1) lawful basis and independently verify Article 10 conditions — either direct official-authority control or specific Union/Member State law authorisation with documented safeguards.
Designate a DPO when threshold is met: If criminal data processing is a core activity conducted on a large scale, Article 37(1)(c) mandates DPO appointment without discretion.
Conduct a DPIA: Criminal data processing inherently carries high risk under Article 35; a deficient or generic DPIA was a standalone violation in Mercadona.
Apply strict minimisation: Blanket collection of criminal data across untargeted populations — as in Mercadona's store-wide facial recognition — fails necessity and proportionality. Limit collection to specific, justified individuals.
Verify national law basis: Where relying on Member State law authorisation, confirm the law specifies appropriate safeguards; a general legal permission without built-in data subject protections will not satisfy Article 10.
why this is here
Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law
This provision is directly about the processing of criminal convictions and offences, establishing the core legal conditions.
assessed by deepseek/deepseek-v4-flash-0731 · 26 Aug 2026
why this is here
More and more law enforcement authorities (LEAs) apply or intend to apply facial recognition technology (FRT).
The context is law enforcement, which involves criminal data, but the document doesn't specifically discuss processing of criminal convictions/offences data.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
data about criminal convictions and health data
The document notes that criminal conviction data was among the breached data, but the core issue is the security measures, not the processing of this category.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
Personal data relating to convictions and criminal (or administrative) offences
The document specifically mentions criminal convictions as a data type contributing to risk.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
in order to combat terrorist offences and serious crime
The document repeatedly references the use of PNR data for combating terrorism and serious crime, connecting to criminal data processing contexts.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
criminal records, in particular terrorism related crimes
The document mentions that countries request criminal records as part of deportation procedures, relevant to processing of criminal data, but it is not the central topic.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
including data of children, criminal data and data related to the private life
The document mentions criminal data as part of the breached personal data, but the legal basis is Article 33, not the specific criminal data provisions.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
why this is here
“Discovering that data has been sent to Europol labelled crime area terrorism is a nightmare.”
The document briefly mentions van der Linde's data being labeled under 'crime area terrorism,' but the core focus is on access rights, not processing of criminal data per se.
assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026
why this is here
Strafrechtelijke gegevens
The table of contents includes a section on strafrechtelijke gegevens (criminal data), indicating the topic is covered but not detailed in the provided text.
assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026
Nothing of this type on this topic.
This is the top of each pile — all 37 Case Law