Public Authority
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Government bodies and their data processing activities
Overview
21 sources · Jul 15, 2026Legal Framework
Under Article 4(7) GDPR, a public authority, agency, or other body qualifies as a controller when it determines the purposes and means of processing personal data. Public authorities must identify a valid legal basis under Article 6(1). Unlike private entities, public bodies typically rely on Article 6(1)(c) (compliance with a legal obligation) or Article 6(1)(e) (performance of a task carried out in the public interest or in the exercise of official authority). Recital 154 permits public authorities to reconcile public access to official documents with data protection rights, provided disclosure is mandated by Union or Member State law. Furthermore, Article 10 restricts the processing of criminal conviction data, permitting it only under official government supervision or where authorized by national law with appropriate safeguards.
Key Developments
The Court of Justice of the European Union has established critical boundaries for public authority data processing. In Valsts policijas Rīgas reģiona pārvaldes Kārtības policijas pārvalde v. Rīgas pašvaldības SIA ‘Rīgas satiksme’, the Court ruled that while a public authority might have a legitimate interest in processing data, it must also have a specific legal obligation or statutory basis to do so lawfully. This significantly narrows the ability of public bodies to rely on Article 6(1)(f). Regarding data subject access rights, the X decision established that when a public authority levies a fee for providing access to personal data, that fee cannot exceed the actual cost of communicating the data. Transparency obligations also feature prominently: Client Earth v. EFSA underscored that transparency in administrative processes enhances the legitimacy and democratic accountability of public authorities. Enforcement actions reflect these strict standards. The Polish Data Protection Authority fined the Minister of Justice €23,540 for insufficient technical and organizational measures, while the Belgian DPA fined the public water utility Société Wallonne des Eaux €86,000 for lacking a valid legal basis for its processing activities.
Practical Guidance
- Ground all processing activities in explicit national legislation authorizing the public task or legal obligation, avoiding reliance on the legitimate interest basis under Article 6(1)(f) as established by the Valsts policijas ruling.
- Ensure that any fees charged to data subjects exercising their right of access are strictly limited to the administrative cost of communication, as mandated by the X decision.
- Implement specific safeguards and ensure official oversight when processing criminal conviction data, as required by Article 10 GDPR.
- Establish internal protocols to balance the public's right to access official documents (per Recital 154) with the data protection rights of individuals, ensuring any disclosure is backed by specific national access laws.
- Conduct regular reviews of technical and organizational security measures to prevent enforcement actions, as demonstrated by the €23,540 fine levied against the Polish Minister of Justice.