Criminal Data
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing of criminal convictions and offences
Overview
24 sources · Jul 23, 2026Legal Framework
Article 10 GDPR governs the processing of personal data relating to criminal convictions and offences, as well as related security measures. Unlike the general processing regime under Article 6, Article 10 imposes a stricter gatekeeper: such data may only be processed under the control of official authority, or when the processing is specifically authorised by Union or Member State law providing appropriate safeguards for data subjects' rights and freedoms. Comprehensive registers of criminal convictions may be maintained exclusively under official authority control.
This means that private-sector processing of criminal data requires a specific legal basis in national law — the standard Article 6 lawful bases alone are insufficient. Recital 91 reinforces that large-scale processing of sensitive data categories, including criminal data, carries heightened risk and warrants particular attention. The rationale is straightforward: criminal data carries significant stigma and potential for discrimination, meriting elevated protection beyond the standard GDPR regime.
At the constitutional level, Article 10 of the Dutch Constitution (Grondwet) protects the right to private life and delegates to the legislature the task of regulating personal data processing. Where the GDPR's directly effective provisions apply, they supersede national implementation obligations.
Key Developments
Dutch courts have actively shaped the boundaries of lawful criminal data processing. In a 2025 ruling, the Court of Appeal Arnhem-Leeuwarden held that a suspect's palm print should have been destroyed, finding the retention a violation of private life warranting sentence reduction. This signals that even law enforcement processing of biometric criminal data must respect strict necessity and retention limits.
In civil litigation involving ASR, the court examined placement in an incident register and an External Referral Register (EVR). The court applied the Protocol for Incident Warning Systems for Financial Institutions (PIFI) framework, under which financial institutions may exchange criminal data only under an authorisation granted by the Dutch Data Protection Authority. The court found that EVR registration was unlawful while IVR registration was permissible, demonstrating that even within an authorised framework, each processing operation must independently satisfy necessity requirements.
The Romanian DPA fined a natural person €10,000 for publishing identity documents containing criminal data on a website, confirming that Article 10 applies to individuals, not just organisations. The Italian Garante fined the Ordine degli Avvocati di Latina €15,000 for unlawful processing of criminal data by a professional body, underscoring that professional associations cannot process criminal records without a specific legal mandate.
Practical Guidance
Secure a specific national law basis before processing. Verify that your processing of criminal data is grounded in a specific Member State law provision — not merely a GDPR Article 6 lawful basis. In the Netherlands, the UAVG and sector-specific instruments (such as the PIFI protocol under AP authorisation) provide the necessary legal foundation for limited private-sector criminal data exchange.
Obtain DPA authorisation where required. Financial institutions and similar sectors processing criminal data through shared warning systems must hold a valid authorisation from the Autoriteit Persoonsgegevens. Verify that your authorisation covers each distinct register and processing operation.
Apply strict necessity and proportionality to each register. The ASR ruling demonstrates that inclusion in one register (IVR) may be lawful while inclusion in a connected register (EVR) is not. Assess each processing operation independently against necessity criteria.
Implement robust retention and destruction protocols. The Arnhem-Leeuwarden palm print ruling confirms that failure to destroy criminal data when the legal basis lapses constitutes a violation of private life. Establish automated deletion triggers tied to the purpose of processing.
Restrict comprehensive register maintenance. Only official authorities may maintain comprehensive criminal conviction registers. Private entities must limit their records to specific, purpose-bound entries rather than building generalised databases of criminal history.