The GDPR rule governing personal data about criminal convictions, offences, and related security measures. It generally allows processing only under official authority control or when authorised by EU or member state law with appropriate safeguards, making it a high-protection category for screening decisions.
What Article 10 GDPR Covers
Article 10 is the GDPR provision that treats criminal-conviction and offence data, plus related security measures, as especially sensitive. It narrows when organisations may process it and places the strongest emphasis on legal authority, safeguards, and controlled use.
Why Article 10 Is a High-Control GDPR Rule
Article 10 sits within the GDPR’s broader data-protection structure, but it is narrower than ordinary personal-data processing because the subject matter is inherently trust-sensitive. The rule exists to stop organisations from using criminal-record information casually, especially where screening, eligibility, or access decisions could have lasting consequences.
The practical effect is that organisations need a clear lawful basis under EU or member-state law, or processing under official authority control, before they treat this data as operational input. That makes Article 10 less about convenience and more about constrained decision-making, documented authority, and defensive handling of a high-impact data category.
What Counts as Article 10 Data
Article 10 is triggered by personal data relating to criminal convictions, offences, and related security measures. In practice, that includes information used to decide whether a person may be hired, cleared, admitted, licensed, or monitored, when the record itself carries legal and reputational weight.
It is important not to collapse Article 10 into generic background-check material. The rule is about the legal character of the data, not just the business purpose for collecting it. A screening dataset may include many lawful fields, yet still require separate treatment if it contains conviction or offence information.
- Processing must stay within a narrowly controlled legal basis.
- Access should be limited to the smallest practical set of reviewers.
- Use should remain tied to the specific decision or obligation that justified collection.
- Retention and disclosure should be tightly governed because the data can be highly consequential.
How Article 10 Changes Security and Compliance Practice
Article 10 changes how organisations design screening workflows, recordkeeping, and authorisation around sensitive verdict-like data. It pushes teams to separate eligibility checks, legal review, and operational use so that criminal-history information is not reused beyond its permitted purpose. For privacy interpretation and control mapping, the EU General Data Protection Regulation (GDPR) remains the authoritative reference point, while the NIST Privacy Framework is useful for structuring privacy risk management around sensitive data handling.
Because criminal-conviction data can affect employment, tenancy, licensing, and trust decisions, organisations should treat inaccurate handling as both a compliance issue and an integrity issue. If the data is over-collected, over-shared, or retained too long, the consequence is not just a policy breach, but potentially unfair or unlawful decision-making at scale.
Article 10 also sits close to identity and access governance when screening data is used to approve access, roles, or delegated authority. In that setting, the CIS Controls v8 can help frame account management, logging, and data-protection controls around who may see, use, and review the information.
Risk and Threat Considerations
Article 10 data is high-risk because misuse can expose extremely sensitive personal information, distort eligibility decisions, and create disproportionate harm if leaked or repurposed. The main issue is not only unlawful collection, but also secondary misuse, such as overbroad sharing across HR, compliance, and security teams.
Failure mechanism: Organisations often fail when they treat conviction-related data like ordinary screening metadata, which leads to excessive access, weak purpose limitation, or retention beyond the legal need. Once that happens, the data can be reused in ways the original legal basis does not support.
Impact: The result can include unlawful processing, unfair exclusion, reputational damage, regulatory exposure, and a higher blast radius if the data is disclosed or breached.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Art. 10 — Criminal Convictions and Offences | Directly governs processing of criminal-conviction and offence data. |
| Recommendation — Limit processing to lawful authority and apply strict safeguards, access limits, and purpose restriction. | ||
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Article 10 data handling needs tightly limited access to minimize exposure. |
| AU-2 — Event Logging | Sensitive screening decisions need traceable review and accountability. | |
| Recommendation — Restrict review of conviction-related data to the smallest authorized set of users. Log access and decision actions for conviction-related data handling. | ||
| ISO/IEC 27001:2022 | A.5.34 — Privacy and protection of PII | Article 10 concerns personal data handling under privacy controls. |
| Recommendation — Apply privacy controls and documented handling rules to conviction-related personal data. | ||
| CIS Controls v8 | CIS-3 — Data Protection | Sensitive screening data needs protection from overexposure and misuse. |
| Recommendation — Classify and protect conviction-related data with tighter handling rules and retention limits. | ||
Practitioner Guidance
Why practitioners should care: Article 10 is one of the GDPR’s clearest examples of a rule where legal authority and operational discipline must stay aligned. If you handle screening data, the control question is not just whether the record exists, but whether every use of it is genuinely permitted and traceable.
Common misunderstanding: Teams sometimes assume that a business need for screening automatically justifies broader handling of criminal-history information. In practice, the lawful scope is usually narrower than the business workflow that consumes it.
Practitioner takeaway: Treat Article 10 as a strict-use and strict-access rule, not a general permission to enrich personnel, access, or suitability decisions with sensitive background data.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 30, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org