Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: EN
- General data protection
Basic legislative acts
- GDPR regulation
Article 10 Processing of personal data relating to criminal convictions and offences
Summary What does Article 10 of the GDPR regulation say?
This short but important article addresses a specific and sensitive category of personal data: information relating to criminal convictions, offences, and related security measures.
Building on Article 6(1), which sets out the lawful bases for processing personal data generally, Article 10 imposes stricter conditions on this particular type of data.
Processing is only permitted when carried out under the control of an official authority, or when expressly authorised by Union or Member State law that provides appropriate safeguards.
The article also addresses the keeping of comprehensive criminal conviction registers, restricting these exclusively to official authority control.
Important points:
- Processing of personal data relating to criminal convictions and offences must be carried out under the control of official authority or be authorised by Union or Member State law providing for appropriate safeguards.
- Any comprehensive register of criminal convictions shall be kept only under the control of official authority.
- This article builds directly on Article 6(1), applying heightened restrictions to this sensitive category of data beyond the standard lawful basis requirements.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions shall be kept only under the control of official authority.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
processing
Definition
personal data