A Scholarly Analysis for Advanced Practitioners
GDPR Article 10 occupies a unique position within the General Data Protection Regulation because it regulates information associated with criminal convictions, criminal offences, alleged offences, investigations, prosecutions, and related security measures.
Unlike Article 9 special category data, criminal offence data constitutes a distinct regulatory category requiring its own legal analysis and governance framework. Article 10 does not create a standalone lawful basis; rather, it imposes an additional layer of restriction on processing that already satisfies Article 6.
The provision reflects a legislative judgment that criminal records possess extraordinary reputational, social, professional, and economic consequences for data subjects. Improper disclosure may result in exclusion from employment, housing, education, financial services, and public participation.
Advanced practitioners should view Article 10 as a "restricted processing regime" — a specialised legal gateway layered on top of the general GDPR framework, not a replacement for it.
Article 10 establishes two fundamental requirements that practitioners must address independently and sequentially.
Must be based upon a valid Article 6 lawful basis, and must occur either:
Any comprehensive register of criminal convictions:
Generally inconsistent with modern European supervisory and judicial approaches.
Criminal convictions and pending criminal proceedings
Criminal charges, arrest records, and police reports
Allegations of criminal conduct and prosecutorial investigations
Sentencing, probation, and bail conditions
Criminal background screening results — including certificates showing no convictions
Acquittal records and security measures associated with criminal proceedings
Important Example
An employer receives a criminal background check indicating "No Criminal Record Found." Many organisations mistakenly conclude no Article 10 processing exists because no conviction is present. Regulatory authorities have consistently treated such information as criminal conviction data because it directly relates to criminal record status.
Satisfying Article 6 alone is insufficient. Controllers must independently satisfy both layers before any processing of criminal offence data may lawfully commence.
Police services and prosecutorial authorities with statutory criminal enforcement functions
Courts and correctional institutions operating under statutory authority
Criminal justice agencies and regulators possessing statutory criminal enforcement functions
Official authority status generally permits broader processing because statutory safeguards already exist. However, it is not an exemption from GDPR. The following principles remain fully applicable:
Data may only be used for the purpose for which it was collected
Only data strictly necessary may be processed
Data must not be kept longer than necessary
Appropriate technical and organisational measures must be maintained
Private organisations face significantly higher compliance burdens than official authorities. The absence of statutory oversight means each processing activity must be independently justified and documented.
Conducting fraud investigations under financial crime legislation
Conducting safeguarding checks for patient-facing roles
Screening staff working with children and vulnerable persons
Performing security vetting under aviation safety regulations
Conducting background checks for sensitive operational roles
A school performs legally mandated criminal background checks for teachers. National law specifically authorises screening. Access is restricted to HR personnel and retention periods are defined.
A bank investigates suspected financial crime. Processing is required under financial crime legislation. Access controls and audit trails exist throughout the investigation lifecycle.
A judicial authority maintains conviction records. Processing occurs under statutory authority with established governance frameworks and defined access controls.
The following scenarios represent common compliance failures identified by supervisory authorities across Member States.
Multiple companies share names of workers suspected of theft. No conviction exists. No statutory authorisation exists.
Likely unlawful.
A multinational creates a database of criminal histories for all employees worldwide. No official authority oversight exists.
Likely violates Article 10's prohibition on comprehensive criminal registers.
A retail employer requests criminal records for every applicant regardless of role. No legal requirement exists for the positions in question.
Likely violates necessity and proportionality principles.
Screening records remain permanently in personnel files with no retention justification or scheduled disposal.
Likely violates Articles 5 and 10 simultaneously.
Advanced practitioners should understand Article 10 as a node within a larger compliance ecosystem. Compliance with Article 10 alone is insufficient — the following provisions interact directly with criminal offence data processing.

Accountability under Article 10 is evidentiary rather than merely procedural. Organisations must be capable of demonstrating — not merely asserting — compliance across every dimension of their criminal data processing activities.
Why criminal data is necessary and why less intrusive alternatives are unavailable
Which national law authorises processing and which safeguards are implemented
How access is restricted to those with a documented operational need
How retention is limited and automated disposal is enforced
How accuracy is maintained and how disclosure to third parties is controlled
"Accountability is therefore evidentiary rather than merely procedural. Organisations that cannot produce documented evidence of each element face significant enforcement exposure."
The following controls represent a comprehensive governance framework for organisations processing criminal offence data. Controls 1–11 are addressed here.
Establish a dedicated classification category for criminal offence data, separate from ordinary personal data and Article 9 data
Maintain documented mappings between processing activities and applicable Union or Member State laws
Require formal legal review before collection begins for any new processing activity
Mandatory DPIA review for criminal data processing activities, assessing stigma, discrimination, and exclusion risks
Technical enforcement preventing secondary uses without explicit authorisation
Restrict access according to operational necessity with documented justification for each role
Introduce contextual restrictions based on purpose, jurisdiction, and risk profile
Store Article 10 data separately from general HR or customer records with logical and physical separation
Encrypt criminal offence data at rest and in transit using current cryptographic standards
Separate encryption key management from operational processing teams to prevent insider access
Record every access, modification, export, and deletion event with tamper-evident logging
Monitor administrators handling criminal offence data with enhanced logging and behavioural analytics
Automatically suppress unnecessary fields at the point of collection and throughout the data lifecycle
Implement automated deletion aligned with legal requirements and documented retention schedules
Assess processors handling criminal offence information before engagement and on a recurring basis
Validate transfer mechanisms before exporting Article 10 data internationally under Articles 44–49
Detect inaccurate, outdated, or expunged conviction information before it influences decisions
Conduct recurring control testing and assurance reviews against documented compliance standards
Define escalation paths specific to criminal data breaches, with accelerated notification timelines
The regulatory landscape surrounding Article 10 continues to evolve rapidly. Advanced practitioners must anticipate enforcement trends in the following areas.
Criminal history data used in employment screening algorithms presents elevated discrimination risk. Profiling decisions based on criminal data may trigger Article 22 considerations regarding automated decision-making, requiring human review and explicit authorisation.
Aggregation of publicly available criminal information can still constitute Article 10 processing. The commercial assembly of criminal data from disparate public sources does not remove the obligation to identify lawful authorisation under Article 10.
Organisations increasingly collect criminal allegations from online sources during due diligence and background screening. Public availability does not remove Article 10 obligations. The source of the data is irrelevant to the classification of the data.
Internal investigations frequently generate criminal offence data as a by-product of monitoring activities. Organisations often fail to recognise Article 10 applicability until enforcement action occurs, at which point remediation is significantly more costly.
Satisfy both Article 6 and Article 10 simultaneously — national law frequently determines permissibility
Criminal offence data extends beyond convictions to include allegations, investigations, acquittals, and background check outcomes
Legal authorisation and accountability documentation must be maintained and producible on demand
Access governance, technical controls, and continuous monitoring must be embedded by design
Article 10 processing demands control rigour comparable to — and often exceeding — Article 9 special category data
From a risk-management perspective, Article 10 processing should be treated with a control rigour comparable to — and in many contexts exceeding — that applied to Article 9 special category data, because of the heightened risk of stigma, exclusion, and irreversible reputational harm to data subjects.
GDPR Article 10: Processing of Personal Data Relating to Criminal Convictions and Offences