Skip to main content
Category: Special Category Data

Article 10 Criminal Data

Also known as: Criminal Offence Data, Personal data relating to criminal convictions and offences, Article 10 GDPR data
Simply put

Article 10 criminal data is personal information about a person's criminal convictions, offences, or related security measures, such as records showing that someone has been convicted of or is suspected of a crime. This type of data is treated as particularly sensitive and its processing is subject to extra restrictions under data protection law. It generally covers information about offenders or suspected offenders, rather than information about victims.

Formal definition

Article 10 of the GDPR (and the corresponding Article 10 of the UK GDPR) governs the processing of personal data relating to criminal convictions and offences or related security measures. According to ICO guidance, this category applies to the personal data of offenders or suspected offenders and does not, on that basis, extend to information about victims. Article 10 is distinct from the special category data regime under Article 9, though the two are frequently addressed together in practice; processing criminal offence data requires an Article 6 lawful basis and, in addition, must be carried out either under the control of official authority or when authorised by EU or Member State law providing appropriate safeguards. Under the UK GDPR, the relevant authorising conditions are set out in national implementing law (the Data Protection Act 2018, including provisions such as Section 11(2)). Article 10 also provides that any comprehensive register of criminal convictions may be kept only under the control of official authority. The precise scope, available conditions, and any requirement that certain processing be limited to public authorities can vary by jurisdiction and Member State derogation; some regulators (for example, guidance concerning Sweden) have interpreted Article 10 as restricting certain processing to public authorities, and practitioners should verify the position against the current official text and applicable national law.

Why it matters

Article 10 criminal data sits at the intersection of high sensitivity and high legal risk. Because it concerns information about a person's criminal convictions, offences, or related security measures, its misuse can cause serious and lasting harm to individuals, including stigma, exclusion from employment, and unfair treatment. For this reason, data protection law layers additional restrictions on top of the ordinary rules, and organisations that get this wrong can face significant regulatory and reputational consequences. Correctly identifying when data falls within Article 10 is therefore a threshold compliance question, not an afterthought.

A further reason this matters is scope. According to ICO guidance, Article 10 applies only to the personal data of offenders or suspected offenders and does not, on that basis, cover information about victims. Misclassifying victim data as criminal offence data, or failing to recognise genuine criminal offence data, can lead organisations to apply the wrong safeguards and the wrong lawful basis. This is especially relevant for employers running background checks, financial services firms conducting screening, and any organisation handling incident or investigation records.

The position is also jurisdictionally variable, which raises the stakes for cross-border operations. Under the UK GDPR, the authorising conditions are set out in national implementing law such as the Data Protection Act 2018, while other Member States apply their own derogations. Some regulators have interpreted Article 10 more restrictively; for example, guidance concerning Sweden has been reported as treating certain processing of criminal offence data as permitted only for public authorities. Because these interpretations diverge, organisations should verify the applicable position against the current official text and the relevant national law rather than assume a single EU-wide rule applies.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance teams need to identify when processing falls within Article 10 and ensure both an Article 6 lawful basis and an appropriate authorising condition are in place. They should also confirm whether the applicable jurisdiction imposes additional documentation or restricts certain processing to public authorities, verifying the position against the current national implementing law.
Employers and HR Teams
Organisations conducting background checks or handling records of alleged misconduct may process criminal offence data. They should take care to distinguish data about offenders or suspected offenders, which falls within Article 10, from information about victims, which the ICO indicates is not covered on that basis, and apply the correct safeguards accordingly.
Privacy Counsel Advising Cross-Border Operations
Because Member State derogations and regulator interpretations can vary, lawyers advising multinational clients should not assume a uniform EU-wide rule. Some guidance, such as that reported in relation to Sweden, has been interpreted as restricting certain processing to public authorities, so counsel should verify the specific national position.
Public Authorities and Bodies Maintaining Criminal Records
Article 10 provides that any comprehensive register of criminal convictions may be kept only under the control of official authority. Bodies operating under official authority should confirm the scope of their authorising basis and the safeguards required under applicable law.

Inside Article 10 Criminal Data

Scope of Article 10
Article 10 GDPR governs the processing of personal data relating to criminal convictions and offences, or related security measures. It sits alongside, but is distinct from, the special categories of data under Article 9, and applies specifically to this offence-related category.
Official authority requirement
Processing under Article 10 is generally permitted only under the control of official authority, unless the processing is authorised by Union or Member State law providing appropriate safeguards. This means private organisations cannot rely on Article 10 as freely as they might rely on other bases without such legal authorisation.
Article 6 legal basis still required
Article 10 does not itself supply a lawful basis. A controller must still identify an appropriate Article 6 basis for the processing, and then satisfy the additional conditions in Article 10 relating to official authority or a legal authorisation with safeguards.
Comprehensive registers of convictions
Article 10 provides that any comprehensive register of criminal convictions may be kept only under the control of official authority, reinforcing the restriction on maintaining such consolidated records outside a legally authorised framework.
Interaction with national implementing law
The specific conditions permitting private-sector processing of criminal offence data are largely left to Union or Member State law. As a result, the practical position can vary significantly between jurisdictions, including divergence between the EU GDPR and the UK GDPR as supplemented by national legislation.

Common questions

Answers to the questions practitioners most commonly ask about Article 10 Criminal Data.

Is criminal offence data a type of special category data under Article 9?
No. Data relating to criminal convictions and offences is governed by Article 10, not Article 9, and it forms a distinct category. Although it is often subject to heightened protection similar to special category data, Article 10 has its own conditions: processing generally must be carried out either under the control of official authority or when authorised by EU or member state law providing appropriate safeguards. Treating it simply as Article 9 special category data would apply the wrong legal test.
Does having a valid Article 6 legal basis mean you can process criminal offence data?
Not on its own. As with other higher-risk processing, you generally need both an Article 6 lawful basis and, in addition, to satisfy the specific requirements attaching to Article 10 data. Because Article 10 typically requires that processing be under official authority or authorised by EU or member state law with appropriate safeguards, member state implementing law is often decisive. An Article 6 basis alone is insufficient where that additional authorisation is required.
How do we identify an appropriate authorisation to process criminal offence data?
You typically need to locate a specific authorisation in EU or member state law, or establish that the processing is carried out under the control of official authority. Because national implementing law varies, the relevant provision and any conditions or safeguards it imposes will depend on the member state and the context. Organisations generally should document the specific legal provision relied on and verify it against the current national law, as the position can differ across jurisdictions.
What safeguards should we put in place when processing criminal offence data?
Article 10 contemplates appropriate safeguards for the rights and freedoms of data subjects, and applicable national law may prescribe specific ones. In practice organisations often consider measures such as strict access controls, purpose limitation, retention limits, and enhanced documentation. Where national law requires particular safeguards, those should be followed. The precise required measures depend on the authorising law and the risk assessment, so this should be determined case by case.
Do we need a Data Protection Impact Assessment before processing criminal offence data?
A DPIA under Article 35 is required where processing is likely to result in a high risk to individuals, and processing criminal offence data can fall within that scope depending on the nature, scale, and context. Many organisations treat such processing as a strong indicator that a DPIA should be considered. Whether one is strictly required depends on the specific facts and applicable regulator guidance, so this should be assessed rather than assumed either way.
How should criminal offence data be reflected in a record of processing and internal governance?
Because this data attracts heightened conditions, organisations generally document the specific authorisation relied on, the applicable safeguards, the retention approach, and the purpose. This typically feeds into records of processing activities and internal policies. As the exact obligations can be shaped by national implementing law, the documentation should reference the relevant provisions and be verified against the current official text and guidance.

Common misconceptions

Criminal offence data is simply another special category under Article 9.
Criminal convictions and offences data is treated separately under Article 10, not as an Article 9 special category. While both attract heightened protection, the conditions and the legal architecture differ, and conflating them can lead to reliance on the wrong provision.
Obtaining the individual's consent is sufficient to process criminal offence data.
Consent alone does not generally satisfy Article 10. In addition to an Article 6 basis, processing typically requires either the control of official authority or specific authorisation under Union or Member State law with appropriate safeguards. The precise availability of such authorisation should be verified against the applicable national law.
Any organisation can maintain records of individuals' criminal histories if it has a good reason.
A comprehensive register of criminal convictions may generally be kept only under the control of official authority. Private organisations typically need a specific legal authorisation with safeguards, and cannot rely on a subjective assessment of necessity alone.

Best practices

Confirm both an appropriate Article 6 legal basis and a valid Article 10 condition (official authority control, or a Union/Member State law authorisation with appropriate safeguards) before processing criminal offence data.
Check the specific national implementing law in each relevant jurisdiction, since the conditions for private-sector processing are largely set by Union or Member State law and can diverge, including between the EU GDPR and UK GDPR.
Do not treat consent as a standalone justification; assess whether a legal authorisation with safeguards genuinely covers the intended processing and document that assessment.
Avoid maintaining comprehensive registers of criminal convictions unless you can point to a clear legal authorisation, given the restriction to processing under the control of official authority.
Document the appropriate safeguards being applied and keep the analysis under review, as the interpretation of Article 10 conditions can be shaped by regulator guidance and national law that may evolve.
Verify article references, national provisions, and any authorisations against the current official text and applicable guidance rather than relying on a fixed snapshot.