Skip to main content
Category: Special Category Data

Criminal Convictions and Offences

Also known as: Criminal Offence Data, Criminal Records Data, Article 10 Data
Simply put

Criminal convictions and offences data is information about a person's criminal history, such as their arrests, alleged offences, and any convictions handed down by a court. Because this information is especially sensitive and can significantly affect someone, data protection law places extra restrictions on when and how it can be processed. It is treated differently from ordinary personal data, though it is not identical to the 'special category' data covered separately under the GDPR.

Formal definition

Under the GDPR, personal data relating to criminal convictions and offences (and related security measures) is governed by Article 10, which is distinct from the special categories of data addressed in Article 9. Processing of this category is generally permitted only under the control of official authority, or where authorised by Union or Member State law providing appropriate safeguards for the rights and freedoms of data subjects; the availability of a comprehensive register of criminal convictions is likewise typically restricted to official authority control. Article 10 does not itself supply a lawful basis, so a controller must still identify an appropriate Article 6 basis in addition to satisfying the Article 10 conditions. Because member state derogations and national implementing law (for example, differing rules under the UK GDPR and domestic statutes) can materially vary the permitted grounds and required safeguards, practitioners should verify the specific national provisions applicable to a given processing activity. The precise scope of what constitutes 'criminal offence' data, including how allegations, arrests, or 'rap sheet' style summary criminal histories are characterised, may depend on national law and regulatory guidance; controllers should assess this on a case-by-case basis and confirm against the current official text.

Why it matters

Criminal convictions and offences data carries a heightened potential to harm individuals. Information about arrests, alleged offences, or a conviction handed down by a court can affect a person's access to employment, housing, financial services, and other opportunities long after the underlying events. A criminal record, sometimes described as a summary criminal history or 'rap sheet', typically aggregates arrests and convictions into a single picture that can be used to make significant decisions about a person, which is why data protection law subjects this category to additional controls beyond those applying to ordinary personal data.

The legal treatment of this data is a common source of error in compliance programs because it sits in its own regime. Under the GDPR it is governed by Article 10, which is separate from the special categories of data under Article 9. Article 10 does not itself provide a lawful basis, so a controller cannot rely on it alone; an appropriate Article 6 basis is still required in addition to satisfying the Article 10 conditions. Misclassifying criminal offence data as ordinary personal data, or assuming it is simply another special category, can lead an organisation to process it without the official authority control or the specific legal authorisation and appropriate safeguards that generally apply.

The position also varies by jurisdiction. Member state derogations and national implementing law, including differing rules under the UK GDPR and domestic statutes, can materially change the permitted grounds and required safeguards, and the characterisation of allegations, arrests, or summary criminal histories may depend on national law and regulatory guidance. Because of this divergence, and because guidance in this area continues to develop, organisations should verify the specific national provisions applicable to a given processing activity rather than relying on a general EU-level description.

Who it's relevant to

Employers and HR / recruitment teams
Organisations that request or review criminal record information as part of hiring or ongoing employment decisions handle Article 10 data. They should confirm that a specific legal authorisation and appropriate safeguards apply, identify a separate Article 6 basis, and verify how their national implementing law treats arrests and unproven allegations as distinct from convictions.
Data protection officers and compliance leads
DPOs and compliance functions need to ensure criminal offence data is correctly classified under Article 10 rather than conflated with Article 9 special category data or ordinary personal data, and that documentation reflects both the Article 10 conditions and the accompanying Article 6 basis. They should also track divergence between EU, UK, and member state rules relevant to the organisation's operations.
Legal and privacy counsel
Counsel advising on processing of criminal convictions and offences data should assess the availability of official authority control or a qualifying legal authorisation, evaluate the required safeguards, and verify national derogations against the current official text, since permitted grounds and characterisation of this data can vary materially by jurisdiction.
Public authorities and organisations acting under official authority
Bodies that process criminal convictions data under the control of official authority, including those maintaining or accessing comprehensive registers of convictions, operate within the more restricted permissions that generally apply to this category and should ensure their processing remains within the scope of that authority and applicable safeguards.
Engineers and system designers handling records data
Technical teams building systems that store or transmit criminal record information should treat it as a restricted category requiring appropriate safeguards, and should coordinate with legal and compliance colleagues to confirm the applicable lawful basis and national requirements before designing collection, retention, or access controls.

Inside Criminal Convictions and Offences

Article 10 basis
Personal data relating to criminal convictions and offences is addressed under Article 10 GDPR. Such processing may generally be carried out only under the control of official authority, or when authorised by Union or Member State law providing appropriate safeguards for the rights and freedoms of data subjects.
Distinct from special category data
Criminal offence data is not one of the Article 9 special categories, but it is treated as sensitive and subject to its own heightened protection under Article 10. It should not be conflated with health, biometric, or other Article 9 data.
Requirement for an Article 6 lawful basis
Article 10 does not remove the need for a lawful basis under Article 6. A controller must generally identify both an appropriate Article 6 basis and satisfy the Article 10 conditions (official authority or authorising law with safeguards) before processing.
Scope of covered information
The concept can extend to information about criminal convictions, offences, and related security measures. The precise boundaries of what counts as offence-related data (for example, allegations or suspicions) can depend on interpretation and applicable guidance, and readers should verify against the current text and regulator guidance.
Role of national implementing law
Because Article 10 relies on authorisation by Union or Member State law, the availability and conditions for processing vary between jurisdictions. National implementing legislation and, in the UK, the UK GDPR and Data Protection Act framework, set out specific conditions and safeguards.
Register of comprehensive convictions
Article 10 also addresses that any comprehensive register of criminal convictions is to be kept only under the control of official authority.

Common questions

Answers to the questions practitioners most commonly ask about Criminal Convictions and Offences.

Is data about criminal convictions and offences the same as special category data under Article 9?
No. Personal data relating to criminal convictions and offences is addressed separately under Article 10, not Article 9. Although it attracts heightened protection similar in spirit to special category data, it is a distinct category with its own conditions. Processing generally requires a lawful basis under Article 6 and, in addition, must be carried out either under the control of official authority or when authorised by Union or Member State law providing appropriate safeguards. You should verify the specific national provisions that apply, as these vary between Member States and under the UK GDPR.
Does having consent from the individual mean I can process their criminal offence data freely?
Not on its own. Unlike ordinary personal data, an Article 6 lawful basis alone is not sufficient for criminal convictions and offences data. Article 10 additionally requires that the processing be authorised by Union or Member State law providing appropriate safeguards, or be under the control of official authority. In practice this means you typically need a specific legal authorisation in national implementing law, and the availability and conditions of that authorisation should be checked against the applicable domestic legislation.
How do I identify the correct legal authorisation before processing criminal offence data?
Start by identifying which Member State law (or the UK regime) governs the processing, then locate the specific provision that authorises your intended purpose and confirm it provides appropriate safeguards. Because Member State derogations differ, the authorisation available in one jurisdiction may not exist in another. You should generally document the identified authorisation alongside your Article 6 basis, and confirm the position against the current official text of the relevant national law rather than relying on a general summary.
Should processing criminal offence data trigger a Data Protection Impact Assessment?
In many cases, yes. Processing data of this sensitivity, particularly on a large scale or in ways likely to result in a high risk to individuals, will typically warrant a Data Protection Impact Assessment under Article 35. Whether a DPIA is strictly required depends on the nature, scope, context and purposes of the processing and on any lists published by the competent supervisory authority. Where there is doubt, conducting a DPIA is generally advisable as a matter of accountability, and you should consult applicable regulator guidance.
What safeguards should typically accompany processing of criminal convictions and offences data?
Article 10 and the relevant national law generally require appropriate safeguards. In practice these commonly include strict access controls, data minimisation, defined retention limits, purpose limitation, clear internal policies, and documentation of the authorising legal provision. A comprehensive register of criminal convictions may only be kept under the control of official authority. The specific safeguards required depend on the applicable Member State or UK provisions, so you should confirm the mandated measures against that law.
How should I handle criminal offence data received from a third party, such as a background-check provider?
You should confirm that your own processing is authorised under Article 10 and rests on an appropriate Article 6 basis, regardless of the source. Clarify the roles involved: a background-check provider may act as a separate controller or as a processor depending on the arrangement, which affects the contractual instruments needed. Where the provider processes on your behalf, an Article 28 data processing agreement is generally required. You should also verify that any transfer, including cross-border transfers, uses an appropriate mechanism and that retention and access are limited to what the authorising law permits.

Common misconceptions

Criminal offence data is a special category under Article 9.
It is addressed separately under Article 10 rather than being an Article 9 special category. While it receives heightened protection, the applicable conditions and legal framework differ from those for special category data.
Consent alone is sufficient to process criminal conviction data.
Article 10 generally requires that processing occur under the control of official authority or be authorised by Union or Member State law providing appropriate safeguards. A lawful basis under Article 6 is also needed, and consent, even where relied on, does not by itself satisfy the Article 10 conditions.
The rules are uniform across the EU and the UK.
Because Article 10 depends on authorising Union or Member State law, conditions and safeguards vary by jurisdiction. The UK position is governed by the UK GDPR and national implementing law, and member state derogations can produce divergent requirements.

Best practices

Confirm both an Article 6 lawful basis and an Article 10 condition (control of official authority or a specific authorising law with appropriate safeguards) before processing criminal offence data.
Check the applicable national implementing law for the relevant jurisdiction, as conditions and safeguards for Article 10 processing vary between EU member states and the UK.
Document appropriate safeguards and, where required by applicable law, maintain a policy or record demonstrating the basis and protections applied to offence data.
Avoid treating criminal offence data as an Article 9 special category; apply the correct Article 10 analysis while recognising its sensitive nature.
Do not keep a comprehensive register of criminal convictions unless it is under the control of official authority as required by Article 10.
Verify current legislative wording and regulator guidance in the relevant jurisdiction before finalising processing decisions, since scope questions such as allegations or suspicions may turn on interpretation.