Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: DE

Artikel 11 Verarbeitung, für die eine Identifizierung der betroffenen Person nicht erforderlich ist


Summary What does Article 11 of the GDPR regulation say?

This article addresses a practical limitation on controllers: where the purpose of processing does not require identifying the data subject, the controller is not forced to go out of its way to do so simply to comply with the regulation.

It acts as a relief provision, acknowledging that certain processing activities are designed to operate without identifying individuals, and that imposing identification obligations in such cases would be disproportionate.

The article also sets out what happens to data subject rights in these circumstances, connecting directly to Articles 15 to 20, which cover access, rectification, erasure, and related rights.

Important points:

  • Controllers are not obliged to maintain, acquire, or process additional information solely to identify a data subject when identification is not required for the processing purpose.
  • Where a controller cannot identify the data subject and can demonstrate this, it must inform the data subject of that fact where possible.
  • Data subject rights under Articles 15 to 20 are suspended in these cases, unless the data subject provides additional information that enables their identification.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Ist für die Zwecke, für die ein Verantwortlicher personenbezogene Daten verarbeitet, die Identifizierung der betroffenen Person durch den Verantwortlichen nicht oder nicht mehr erforderlich, so ist dieser nicht verpflichtet, zur bloßen Einhaltung dieser Verordnung zusätzliche Informationen aufzubewahren, einzuholen oder zu verarbeiten, um die betroffene Person zu identifizieren.

    1. Kann der Verantwortliche in Fällen gemäß Absatz 1 des vorliegenden Artikels nachweisen, dass er nicht in der Lage ist, die betroffene Person zu identifizieren, so unterrichtet er die betroffene Person hierüber, sofern möglich. In diesen Fällen finden die Artikel 15 bis 20 keine Anwendung, es sei denn, die betroffene Person stellt zur Ausübung ihrer in diesen Artikeln niedergelegten Rechte zusätzliche Informationen bereit, die ihre Identifizierung ermöglichen.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod