[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3At3YqfT0c9szkr9qOm8ZTqbL42boEJzDxLwsiF9D_U":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":42},"34c82bdc-b082-4c37-9b4d-469f5305dfc2","cjeu-rules-member-states-must-clarify-legal-basis-for-law-enforcement-biometric-data-processing","ddb811db-1977-41e2-9b33-6c2a4581cf4c","CJEU Rules Member States Must Clarify Legal Basis for Law Enforcement Biometric Data Processing","The CJEU ruling in C-205\u002F21 highlights a critical compliance gap: organizations and member states must clearly identify which legal framework — GDPR or Directive 2016\u002F680 — governs the processing of sensitive biometric and genetic data in law enforcement contexts. The ambiguity between overlapping legal instruments creates risk of unlawful data processing and violations of individuals' fundamental rights. This matters because failing to establish a clear legal basis for processing special category data (DNA, fingerprints, photographs) can render entire investigative processes legally invalid and expose authorities to liability. Organizations handling dual-purpose data — where both civil and law enforcement uses are possible — must proactively map their data flows against applicable legal instruments before processing begins.","**Immediate actions:**\n- Conduct a legal basis audit for all existing biometric and genetic data processing activities to determine whether GDPR, Directive 2016\u002F680, or both apply.\n- Establish a documented data classification policy that explicitly distinguishes between law enforcement data processing and general public-sector data processing.\n\n**Long-term improvements:**\n- Develop and maintain a Data Processing Register (Article 30 GDPR) that records the applicable legal instrument for each processing activity involving special category data.\n- Engage legal counsel and Data Protection Officers to create clear decision frameworks for scenarios where GDPR and Directive 2016\u002F680 overlap.\n- Implement regular staff training on the distinctions between GDPR and EU Directive 2016\u002F680 obligations for personnel handling biometric data.\n\n**Governance & Oversight measures:**\n- Establish a cross-functional review board to assess new biometric data collection initiatives against both regulatory frameworks before deployment.\n- Require mandatory Data Protection Impact Assessments (DPIAs) for any processing of genetic, biometric, or facial recognition data in law enforcement contexts.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 9 — Processing of special categories of personal data","GDPR Article 10 — Processing of criminal conviction data","GDPR Article 30 — Records of processing activities","GDPR Article 35 — Data Protection Impact Assessment (DPIA)","EU Directive 2016\u002F680 — Law Enforcement Directive (LED)","EU Directive 2016\u002F680 Article 10 — Processing of special categories of data","NIST SP 800-188 — De-Identification of Government Datasets","NIST Privacy Framework PR.PO-P1 — Policies and procedures for data processing","CIS Control 3 — Data Protection","ISO\u002FIEC 27701 — Privacy Information Management System (PIMS)","published","2026-07-24T14:21:27.98699+00:00","2026-07-24T14:21:27.876+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CJEU_-_C-205\u002F21_-_Ministerstvo_na_vatreshnite_raboti&diff=52482&oldid=33165","cjeu-c-205-21-ministerstvo-na-vatreshnite-raboti-e4addf","CJEU - C-205\u002F21 - Ministerstvo na vatreshnite raboti",[30,36],{"id":31,"name":32,"slug":33,"description":34,"color":35},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]