Article 10 Criminal Data
Article 10 criminal data is personal information about a person's criminal convictions, offences, or related security measures, such as records showing that someone has been convicted of or is suspected of a crime. This type of data is treated as particularly sensitive and its processing is subject to extra restrictions under data protection law. It generally covers information about offenders or suspected offenders, rather than information about victims.
Article 10 of the GDPR (and the corresponding Article 10 of the UK GDPR) governs the processing of personal data relating to criminal convictions and offences or related security measures. According to ICO guidance, this category applies to the personal data of offenders or suspected offenders and does not, on that basis, extend to information about victims. Article 10 is distinct from the special category data regime under Article 9, though the two are frequently addressed together in practice; processing criminal offence data requires an Article 6 lawful basis and, in addition, must be carried out either under the control of official authority or when authorised by EU or Member State law providing appropriate safeguards. Under the UK GDPR, the relevant authorising conditions are set out in national implementing law (the Data Protection Act 2018, including provisions such as Section 11(2)). Article 10 also provides that any comprehensive register of criminal convictions may be kept only under the control of official authority. The precise scope, available conditions, and any requirement that certain processing be limited to public authorities can vary by jurisdiction and Member State derogation; some regulators (for example, guidance concerning Sweden) have interpreted Article 10 as restricting certain processing to public authorities, and practitioners should verify the position against the current official text and applicable national law.
Why it matters
Article 10 criminal data sits at the intersection of high sensitivity and high legal risk. Because it concerns information about a person's criminal convictions, offences, or related security measures, its misuse can cause serious and lasting harm to individuals, including stigma, exclusion from employment, and unfair treatment. For this reason, data protection law layers additional restrictions on top of the ordinary rules, and organisations that get this wrong can face significant regulatory and reputational consequences. Correctly identifying when data falls within Article 10 is therefore a threshold compliance question, not an afterthought.
A further reason this matters is scope. According to ICO guidance, Article 10 applies only to the personal data of offenders or suspected offenders and does not, on that basis, cover information about victims. Misclassifying victim data as criminal offence data, or failing to recognise genuine criminal offence data, can lead organisations to apply the wrong safeguards and the wrong lawful basis. This is especially relevant for employers running background checks, financial services firms conducting screening, and any organisation handling incident or investigation records.
The position is also jurisdictionally variable, which raises the stakes for cross-border operations. Under the UK GDPR, the authorising conditions are set out in national implementing law such as the Data Protection Act 2018, while other Member States apply their own derogations. Some regulators have interpreted Article 10 more restrictively; for example, guidance concerning Sweden has been reported as treating certain processing of criminal offence data as permitted only for public authorities. Because these interpretations diverge, organisations should verify the applicable position against the current official text and the relevant national law rather than assume a single EU-wide rule applies.
Who it's relevant to
Inside Article 10 Criminal Data
Common questions
Answers to the questions practitioners most commonly ask about Article 10 Criminal Data.