CJEU Rules Retaining Criminal Investigation Data in Police Personnel Files Violates GDPR
A Bulgarian police officer's case before the CJEU highlights that retaining data from a former criminal investigation in an employee's personnel file is unlawful under GDPR Article 6(3), as the data lacks a legitimate purpose tied to the officer's duties. This case underscores the principle of purpose limitation — personal data collected for one purpose (criminal investigation) cannot be repurposed for another (employment records) without a clear legal basis. The failure to remove or segregate this data exposed the organization to legal liability, including compensation claims for non-material damages. It serves as a critical reminder that law enforcement agencies, like all data controllers, must continuously audit retained data to ensure ongoing lawfulness of processing.
Tactical Insight
Immediate actions
- Audit all personnel files to identify and remove data that lacks a clear, documented legal basis tied to employment purposes.
- Establish a data erasure process to promptly remove individuals' data from suspect databases once investigations conclude without conviction.
Long-term improvements
- Implement a data retention schedule aligned with GDPR purpose limitation principles, ensuring each data category has a defined retention period and legal basis.
- Train HR, legal, and records management staff on GDPR data minimization and purpose limitation requirements specific to law enforcement contexts.
- Appoint or empower a Data Protection Officer (DPO) to conduct regular reviews of sensitive data holdings in personnel and investigation systems.
Detection & Compliance measures
- Deploy automated data lifecycle management tools to flag records that have exceeded their defined retention period or legal basis.
- Conduct periodic Data Protection Impact Assessments (DPIAs) for systems that store sensitive personal data across multiple operational contexts.