CHAPTER IIPRINCIPLES

Article 10Processing of personal data relating to criminal convictions and offences

Official text

Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6 (1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects. Any comprehensive register of criminal convictions shall be kept only under the control of official authority.

Commentary

At a glance

ScopePersonal data on criminal convictions, offences and related security measures
Core ruleProcessing only under control of official authority, or authorised by Union / Member State law with appropriate safeguards
Relation to Art. 9Not a special category under Art. 9, but subject to an extra layer above Art. 6
Key pointA lawful basis under Art. 6 alone is never sufficient

A Detailed Legal Commentary

Legislative Philosophy and Objective

Introduction

Article 10 GDPR establishes a special regime for the processing of personal data relating to criminal convictions and offences and related security measures.

At first sight, Article 10 may appear narrower than Article 9. Article 9 addresses particularly sensitive categories such as health data, genetic data, biometric data, religious beliefs and political opinions. Criminal-conviction data does not form part of Article 9's list of special categories.

Nevertheless, the GDPR recognises that information concerning criminal conduct requires a heightened level of protection.

The reason is straightforward: criminal information can have consequences extending far beyond ordinary privacy interests.

The disclosure or misuse of criminal data may affect:

  • employment opportunities;

  • professional licensing;

  • reputation;

  • access to housing;

  • access to financial services;

  • social relationships;

  • insurance or commercial opportunities;

  • personal dignity;

  • rehabilitation.

A criminal record may therefore become a persistent digital label attached to an individual long after the underlying criminal proceedings have ended.

Article 10 seeks to prevent this information from becoming freely available for unrestricted commercial or administrative use.

Its philosophy is consequently protective but not absolute. Criminal information can legitimately be processed where society has a sufficiently strong reason to do so. Law-enforcement authorities need criminal records. Courts require them. Certain regulated professions may legitimately require background checks.

The GDPR therefore does not say:

Criminal data can never be processed.

Instead, it establishes a principle of controlled processing.

The Textual Framework of Article 10

Article 10 provides:

“Processing of personal data relating to criminal convictions and offences or related security measures based on Article 6(1) shall be carried out only under the control of official authority or when the processing is authorised by Union or Member State law providing for appropriate safeguards for the rights and freedoms of data subjects.”

The provision contains several distinct legal elements.

It concerns:

  1. personal data;

  2. relating to criminal convictions and offences;

  3. or related security measures;

  4. processed on a basis referred to in Article 6(1);

  5. under the control of official authority; or

  6. where authorised by Union or Member State law;

  7. with appropriate safeguards for the rights and freedoms of data subjects.

Every element matters.

Article 10 therefore should not be reduced to the proposition that “criminal records require consent.” Consent by itself does not resolve the Article 10 requirement.

The provision creates an additional layer of protection beyond the ordinary Article 6 lawful bases.

Historical Development

Article 10 developed from the approach contained in Article 8(5) of Directive 95/46/EC. The earlier Directive already recognised that information concerning criminal offences and convictions deserved heightened protection.

The GDPR retains that protective philosophy while placing it within a broader accountability framework.

The underlying policy concern is that criminal information traditionally belongs within a controlled legal environment rather than an unrestricted commercial information market.

For example, there is an obvious difference between:

  • a court maintaining a criminal record for judicial purposes; and

  • a private company compiling a permanent database of individuals' criminal histories for commercial profiling.

Both involve personal data, but the risks and legitimacy of the processing are fundamentally different.

Article 10 reflects this distinction.

Why Criminal Data Requires Special Protection

Criminal information has a unique capacity to affect how other people perceive an individual.

Consider two pieces of information:

“The individual changed their telephone number.”

and:

“The individual was convicted of fraud ten years ago.”

Both are personal data.

But the second can profoundly influence:

  • whether an employer hires the person;

  • whether a bank trusts them;

  • whether a professional regulator licenses them;

  • whether a landlord accepts them;

  • whether the public associates them with criminality.

The second piece of information can therefore create social and economic consequences disproportionate to the underlying data itself.

This explains why Article 10 imposes additional safeguards.

Article 10 and Fundamental Rights

Article 10 should be interpreted consistently with the fundamental rights protected by EU law.

Article 7 of the EU Charter, Respect for Private Life

Criminal history may form part of an individual's private life.

Unrestricted disclosure can expose a person to continuing public scrutiny.

This is particularly significant after:

  • completion of a sentence;

  • acquittal;

  • dismissal of proceedings;

  • expiration of a legal restriction;

  • rehabilitation.

The privacy concern is therefore not limited to the moment of criminal proceedings.

Article 8 of the EU Charter, Protection of Personal Data

Article 8 of the Charter establishes the right to protection of personal data.

It emphasises principles including:

  • fair processing;

  • specified purposes;

  • legal control;

  • independent supervision.

Article 10 reinforces these principles by requiring criminal-data processing to operate under official authority or an appropriate legal framework.

The Principle of Rehabilitation

One of the most important policy considerations underlying Article 10 is rehabilitation.

Criminal justice systems generally recognise that individuals should, subject to applicable law, have the possibility of reintegrating into society.

Unlimited circulation of criminal records can undermine this objective.

For example:

A person commits an offence at age 20, serves the applicable sentence and subsequently lives without further offending.

If an online database permanently displays the conviction, the individual may continue to experience consequences decades later.

The data may therefore become a form of permanent punishment outside the criminal justice system.

Article 10 helps prevent uncontrolled processing from producing this effect.

Understanding the Scope of Article 10

Article 10 refers to:

  1. criminal convictions;

  2. criminal offences;

  3. related security measures.

These concepts should be distinguished.

Criminal Convictions

A criminal conviction generally concerns a judicial determination establishing criminal responsibility.

Examples include convictions for

  • fraud;
  • theft;
  • assault;
  • corruption;
  • cybercrime.

The important point is that the information concerns the individual's relationship with criminal justice.

A database recording:

“Person X was convicted of fraud in 2021”

therefore plainly involves Article 10 information.

Criminal Offences

Article 10 is not limited to final convictions.

This is important.

Information concerning criminal offences may exist before a conviction.

Examples include

  • criminal allegations;
  • investigations;
  • prosecutions;
  • suspected offences.

The distinction is critical because treating Article 10 as applying only after conviction would leave a significant protection gap.

An allegation of criminal conduct can be extremely damaging even when the individual is eventually acquitted.

Presumption of Innocence and Accuracy

The treatment of allegations creates an important interaction with principles of fairness and accuracy.

A database that states:

“Person X committed fraud”

when the actual position is:

“Person X was investigated for suspected fraud but was never convicted”

could create a serious distortion.

Controllers therefore need to distinguish carefully between:

  • allegation;

  • investigation;

  • charge;

  • prosecution;

  • conviction;

  • acquittal.

This is not merely a factual distinction.

It can fundamentally change the meaning and consequences of the information.

Article 10 also covers related security measures.

The concept captures measures connected with criminal proceedings and criminal responsibility.

Examples in the uploaded material include

  • probation;
  • restrictions imposed following conviction;
  • rehabilitation-related measures. The inclusion of security measures demonstrates that Article 10 is concerned not merely with the historical fact of conviction but with the broader legal consequences associated with criminal conduct.

Article 10 Is About Processing, Not Merely Collection

The word “processing” is crucial.

Article 10 does not merely regulate the initial collection of criminal data.

Processing under the GDPR is extremely broad.

It may include:

  • collection;

  • recording;

  • organisation;

  • storage;

  • consultation;

  • use;

  • disclosure;

  • transmission;

  • publication;

  • combination with other datasets;

  • profiling.

Consequently, even if criminal information was lawfully obtained initially, subsequent uses must still be examined.

Publicly Available Criminal Information

A common misconception is:

“If criminal information is publicly available, Article 10 no longer applies.”

That is incorrect.

Public availability does not automatically remove personal-data protection.

For example, suppose a court publishes a judgment.

A private company subsequently:

  1. extracts names from the judgment;

  2. creates a searchable criminal database;

  3. ranks individuals by criminal history;

  4. sells access to employers.

The company's activity remains processing of personal data.

The fact that the original source was public does not automatically make unrestricted secondary processing lawful.

The uploaded material similarly recognises that publication of criminal information by a website constitutes processing even where the information originated from public records.

Article 10 and Article 6

Article 10 expressly refers to processing “based on Article 6(1).”

This is important because Article 10 does not replace Article 6.

The controller must generally satisfy the ordinary requirements of Article 6 and the additional requirements imposed by Article 10.

Therefore, a controller cannot simply say:

“We have legitimate interests under Article 6(1)(f), therefore we can process criminal records.”

The Article 10 requirements must additionally be satisfied.

This creates a two-layer analysis:

Layer 1, Article 6

Is there a lawful basis?

Layer 2, Article 10

Is the processing permissible under the special regime governing criminal data?

Both questions must be answered.

The First Route: Processing Under the Control of Official Authority

Article 10 permits processing under the control of an official authority.

This recognises the legitimate role of the State in managing criminal information.

Examples include

  • courts;
  • police authorities;
  • prosecution authorities;
  • correctional institutions;
  • other competent public authorities performing criminal justice functions.

The reason for this special route is institutional.

Criminal records are part of the criminal justice system, and public authorities require access to such information to perform legally assigned functions.

What “Control of Official Authority” Means

The requirement of official control is significant.

Article 10 is not merely saying that a public authority may possess criminal data.

It establishes a relationship between the processing and official authority.

This helps ensure:

  • legal accountability;

  • institutional supervision;

  • controlled access;

  • defined purposes;

  • procedural safeguards.

A private company cannot necessarily obtain the same freedom merely because it performs a function that is vaguely connected to public interests.

The legal framework must be examined carefully.

The Second Route: Authorisation by Union or Member State Law

The second route applies where processing is authorised by:

  • Union law; or

  • Member State law.

This is particularly important for private-sector processing.

For example, legislation may require background checks for particular occupations.

The uploaded material identifies regulated professions such as:

  • teaching;

  • healthcare;

  • financial-sector employment.

In such circumstances, criminal-data processing may be justified because the legislature has determined that criminal-history information is relevant to the particular regulatory objective.

The requirement of legal authorisation prevents organisations from independently deciding that criminal information would simply be “useful.”

There is an important difference between:

“This information would help us make better hiring decisions.”

and:

“The law requires this category of employer to conduct this particular criminal-record check.”

Article 10 gives considerably greater legitimacy to the second situation because the processing has been placed within a legal framework.

Appropriate Safeguards

Legal authorisation alone is insufficient.

Article 10 expressly requires the relevant law to provide:

“appropriate safeguards for the rights and freedoms of data subjects.”

This is a critical qualification.

The law should therefore not simply say:

“Employers may collect criminal records.”

It should establish appropriate limits and protections.

Depending on context, safeguards may concern:

  • who may access information;

  • which offences may be considered;

  • how long information may be retained;

  • when checks may be conducted;

  • who may receive results;

  • how inaccuracies are corrected;

  • how individuals may challenge decisions.

The precise safeguards will depend upon the applicable Union or Member State law.

Employment Background Checks

Employment screening is one of the most practical Article 10 scenarios.

An employer may want to know whether an applicant has a criminal record because it believes the information is relevant to:

  • integrity;

  • security;

  • trust;

  • safeguarding;

  • financial risk.

But the employer cannot automatically assume that every criminal conviction is relevant.

Necessity and Relevance

Consider two positions:

Position A

A person is applying to work with vulnerable children.

A criminal-history check may have a clear connection to safeguarding obligations.

Position B

A person is applying for a purely administrative software-development role.

A demand for unrestricted disclosure of every historical offence may require substantially greater justification.

The key question is therefore:

What legitimate objective does the criminal-data processing serve, and is the particular information genuinely necessary for that objective?

Example

Excessive Background Screening Suppose a company hiring a software engineer asks applicants to provide:

  • complete criminal history;
  • juvenile records;
  • spent convictions;
  • allegations that never resulted in prosecution. If no applicable legal framework authorises such collection, the employer may face serious Article 10 concerns. The fact that the employer considers “trustworthiness” important is not enough by itself. The uploaded material similarly emphasises that criminal-data processing should be supported by legal authority, necessity and safeguards.

Article 10 and Private Criminal Databases

One of the risks Article 10 seeks to control is the creation of private criminal databases.

Imagine a company compiling information from:

  • court judgments;

  • news reports;

  • police publications;

  • social media.

It then creates individual “criminal risk profiles” and sells them to:

  • employers;

  • landlords;

  • financial institutions.

Such processing could produce enormous consequences for individuals.

The organisation would need to establish the necessary Article 6 basis and satisfy Article 10's specific requirements.

The fact that the data was gathered from multiple public sources does not eliminate these obligations.

Article 10 and Accuracy

Accuracy becomes particularly important for criminal information.

An incorrect address may cause inconvenience.

An incorrect criminal record can destroy an individual's reputation or employment prospects.

Therefore, controllers processing criminal data should pay particular attention to:

  • identity matching;

  • accuracy;

  • updates;

  • correction;

  • distinction between allegations and convictions;

  • removal of outdated information where required.

Criminal Data and Artificial Intelligence

AI creates a new layer of Article 10 risk.

The uploaded material identifies several applications of AI involving criminal information, including:

  • risk assessment;

  • fraud detection;

  • predictive policing;

  • recruitment screening.

These systems may process criminal records not simply as historical facts but as inputs into predictions about future behaviour.

That distinction is extremely important.

From Historical Fact to Predictive Risk

Consider:

“Person X was convicted of an offence in 2019.”

This is historical information.

An AI system may transform it into:

“Person X has a high probability of future misconduct.”

The second statement is an inference.

It can be substantially more consequential than the underlying historical fact.

The system therefore risks turning criminal history into a predictive label.

Algorithmic Discrimination

AI systems can reproduce patterns contained in historical data.

Suppose an AI recruitment system learns that applicants with certain criminal histories were less frequently hired in the past.

It may learn to associate criminal records with poor employment outcomes.

The result could be systematic exclusion.

The uploaded material identifies this concern, noting that AI trained on historical criminal information may reproduce existing biases.

Article 10 therefore needs to be considered alongside the GDPR's broader principles of:

  • fairness;

  • accuracy;

  • transparency;

  • accountability;

  • purpose limitation.

Predictive Policing

Predictive policing illustrates the problem even more clearly.

An AI system might analyse:

  • historical crime records;

  • geographical information;

  • social connections;

  • behavioural patterns.

It then predicts where crime may occur or which individuals may represent a future risk.

The legal and ethical concern is that the system may move from:

“What has this person done?”

to:

“What might this person do?”

That shift can fundamentally alter the relationship between criminal data and individual rights.

A person may effectively be treated as a potential offender because of statistical associations rather than actual conduct.

The uploaded material identifies precisely this concern.

Article 10 and Profiling

Article 10 should therefore be read alongside the GDPR provisions dealing with profiling and automated decision-making.

The risk becomes particularly serious where criminal information is used to:

  • rank individuals;

  • assign risk scores;

  • determine eligibility;

  • deny employment;

  • determine access to services.

Criminal information should not automatically become a proxy for:

  • trustworthiness;

  • financial reliability;

  • future criminality;

  • professional competence.

The controller must examine the purpose and consequences of the processing.

Article 10 and the Right to Rehabilitation

The increasing availability of criminal information online makes rehabilitation particularly difficult.

Historically, a criminal record might have been accessible only through:

  • official records;

  • physical archives;

  • authorised institutions.

Digitalisation can make the same information:

  • searchable;

  • duplicable;

  • downloadable;

  • permanently available;

  • algorithmically searchable.

The result is that an event from decades ago can remain computationally relevant indefinitely.

Article 10 therefore has an important role in preventing criminal data from becoming a permanent identity marker.

Relationship Between Article 9 and Article 10

Article 9 and Article 10 are sometimes mistakenly treated as interchangeable.

They are not.

Article 9

Protects specified special categories such as:

  • health;

  • genetic information;

  • biometric information used for identification;

  • religious beliefs;

  • political opinions;

  • sexual orientation.

Article 10

Specifically regulates:

  • criminal convictions;

  • criminal offences;

  • related security measures.

The legal structures are also different.

Article 9 begins with a general prohibition, followed by enumerated exceptions.

Article 10 instead establishes a specific controlled-processing regime based upon:

  • official authority; or

  • Union/Member State law containing appropriate safeguards.

The distinction is important when determining the legal basis for processing.

Article 10 Does Not Mean Every Criminal-Related Fact Is Automatically Forbidden

The provision should not be interpreted as creating an absolute prohibition.

Criminal data can legitimately be processed where the legal requirements are satisfied.

Examples include legitimate functions of

  • courts;
  • police;
  • prosecutors;
  • correctional authorities;
  • regulated organisations subject to legally mandated checks.

The objective is therefore controlled access and processing, not absolute secrecy.

Practical Compliance Framework

An organisation processing criminal data should ask a series of questions.

Question 1, What information is being processed?

Is it:

  • a conviction;

  • an allegation;

  • an investigation;

  • a security measure?

Question 2, Why is it being processed?

What is the precise purpose?

Question 3, What is the Article 6 basis?

Is there a valid lawful basis?

Question 4, What permits Article 10 processing?

Is the processing:

  • under official authority; or

  • authorised by Union or Member State law?

Question 5, What safeguards apply?

How are individuals protected?

Question 6, Is the information accurate?

Can the controller distinguish:

  • allegation from conviction;

  • one individual from another;

  • historical information from current information?

Question 7, How long is the information retained?

Is indefinite retention justified?

Question 8, Who receives the information?

Is disclosure limited to persons who genuinely need it?

Question 9, Is automated decision-making involved?

If so, additional GDPR requirements may arise.

Common Misconceptions

Misconception 1: “Criminal data is Article 9 special-category data.”

Not technically. Article 10 creates a separate protection regime.

Misconception 2: “If the information is public, GDPR does not apply.”

Incorrect. Public availability does not automatically remove personal-data protection.

Misconception 3: “Consent automatically solves Article 10.”

Incorrect. Article 10 imposes additional requirements.

Misconception 4: “Employers can always ask about criminal records.”

Not automatically. The legal framework and safeguards must be examined.

Misconception 5: “A conviction is simply historical information.”

Not necessarily. It may continue to affect employment, reputation, profiling and access to services.

Misconception 6: “AI can use criminal records if the prediction is statistically accurate.”

Accuracy does not by itself establish lawful processing.

CJEU and Regulatory Interpretation

The uploaded material notes that relatively fewer CJEU decisions directly address Article 10 itself, but identifies the broader principles of:

  • necessity;

  • proportionality;

  • legal certainty;

  • safeguards.

These principles are particularly important because Article 10 operates at the intersection of:

  • privacy;

  • criminal justice;

  • public safety;

  • employment;

  • rehabilitation;

  • data protection.

A restrictive interpretation is therefore appropriate where criminal data is used for purposes capable of producing serious consequences for individuals.

Critical Analysis

Article 10 represents a careful compromise.

Society has legitimate reasons to process criminal information.

A police authority cannot perform its function without criminal records.

A court cannot adjudicate criminal proceedings without relevant information.

Certain regulated professions may legitimately require criminal background checks.

But the existence of legitimate public interests does not mean that criminal information should circulate without restriction.

The central danger is function creep.

Information originally collected for criminal justice purposes may gradually be repurposed for:

  • employment;

  • commercial profiling;

  • insurance;

  • advertising;

  • automated risk scoring.

Each additional use increases the possibility that a person's criminal history will become a permanent component of their digital identity.