Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: SV

Artikel 11 Behandling som inte kräver identifiering


Summary What does Article 11 of the GDPR regulation say?

This article addresses a practical limitation on controllers: where the purpose of processing does not require identifying the data subject, the controller is not forced to go out of its way to do so simply to comply with the regulation.

It acts as a relief provision, acknowledging that certain processing activities are designed to operate without identifying individuals, and that imposing identification obligations in such cases would be disproportionate.

The article also sets out what happens to data subject rights in these circumstances, connecting directly to Articles 15 to 20, which cover access, rectification, erasure, and related rights.

Important points:

  • Controllers are not obliged to maintain, acquire, or process additional information solely to identify a data subject when identification is not required for the processing purpose.
  • Where a controller cannot identify the data subject and can demonstrate this, it must inform the data subject of that fact where possible.
  • Data subject rights under Articles 15 to 20 are suspended in these cases, unless the data subject provides additional information that enables their identification.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Om de ändamål för vilka den personuppgiftsansvarige behandlar personuppgifter inte kräver eller inte längre kräver att den registrerade identifieras av den personuppgiftsansvarige, ska den personuppgiftsansvarige inte vara tvungen att bevara, förvärva eller behandla ytterligare information för att identifiera den registrerade endast i syfte att följa denna förordning.

    1. Om den personuppgiftsansvarige, i de fall som avses i punkt 1 i denna artikel, kan visa att denne inte är i stånd att identifiera den registrerade, ska den personuppgiftsansvarige om möjligt informera den registrerade om detta. I sådana fall ska artiklarna 15–20 inte gälla, förutom när den registrerade för utövande av sina rättigheter i enlighet med dessa artiklar tillhandahåller ytterligare information som gör identifieringen möjlig.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod