Practical Compliance Framework
An organisation processing criminal data should ask a series of questions.
Question 1, What information is being processed?
Is it:
-
a conviction;
-
an allegation;
-
an investigation;
-
a security measure?
Question 2, Why is it being processed?
What is the precise purpose?
Question 3, What is the Article 6 basis?
Is there a valid lawful basis?
Question 4, What permits Article 10 processing?
Is the processing:
Question 5, What safeguards apply?
How are individuals protected?
Question 6, Is the information accurate?
Can the controller distinguish:
-
allegation from conviction;
-
one individual from another;
-
historical information from current information?
Question 7, How long is the information retained?
Is indefinite retention justified?
Question 8, Who receives the information?
Is disclosure limited to persons who genuinely need it?
Question 9, Is automated decision-making involved?
If so, additional GDPR requirements may arise.