Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: FR

Article 10 Traitement des données à caractère personnel relatives aux condamnations pénales et aux infractions


Summary What does Article 10 of the GDPR regulation say?

This short but important article addresses a specific and sensitive category of personal data: information relating to criminal convictions, offences, and related security measures.

Building on Article 6(1), which sets out the lawful bases for processing personal data generally, Article 10 imposes stricter conditions on this particular type of data.

Processing is only permitted when carried out under the control of an official authority, or when expressly authorised by Union or Member State law that provides appropriate safeguards.

The article also addresses the keeping of comprehensive criminal conviction registers, restricting these exclusively to official authority control.

Important points:

  • Processing of personal data relating to criminal convictions and offences must be carried out under the control of official authority or be authorised by Union or Member State law providing for appropriate safeguards.
  • Any comprehensive register of criminal convictions shall be kept only under the control of official authority.
  • This article builds directly on Article 6(1), applying heightened restrictions to this sensitive category of data beyond the standard lawful basis requirements.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

▼C1

Le traitement des données à caractère personnel relatives aux condamnations pénales et aux infractions ou aux mesures de sûreté connexes fondé sur l’article 6, paragraphe 1, ne peut être effectué que sous le contrôle de l’autorité publique, ou si le traitement est autorisé par le droit de l’Union ou par le droit d’un État membre qui prévoit des garanties appropriées pour les droits et libertés des personnes concernées. Tout registre complet des condamnations pénales ne peut être tenu que sous le contrôle de l’autorité publique.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod