Back to all lessons
Awareness Lessons
3 months ago

CJEU Rules Retaining Criminal Investigation Data in Police Personnel Files Violates GDPR

A Bulgarian police officer's case before the CJEU highlights that retaining data from a former criminal investigation in an employee's personnel file is unlawful under GDPR Article 6(3), as the data lacks a legitimate purpose tied to the officer's duties. This case underscores the principle of purpose limitation — personal data collected for one purpose (criminal investigation) cannot be repurposed for another (employment records) without a clear legal basis. The failure to remove or segregate this data exposed the organization to legal liability, including compensation claims for non-material damages. It serves as a critical reminder that law enforcement agencies, like all data controllers, must continuously audit retained data to ensure ongoing lawfulness of processing.

Tactical Insight

Immediate actions

  • Audit all personnel files to identify and remove data that lacks a clear, documented legal basis tied to employment purposes.
  • Establish a data erasure process to promptly remove individuals' data from suspect databases once investigations conclude without conviction.

Long-term improvements

  • Implement a data retention schedule aligned with GDPR purpose limitation principles, ensuring each data category has a defined retention period and legal basis.
  • Train HR, legal, and records management staff on GDPR data minimization and purpose limitation requirements specific to law enforcement contexts.
  • Appoint or empower a Data Protection Officer (DPO) to conduct regular reviews of sensitive data holdings in personnel and investigation systems.

Detection & Compliance measures

  • Deploy automated data lifecycle management tools to flag records that have exceeded their defined retention period or legal basis.
  • Conduct periodic Data Protection Impact Assessments (DPIAs) for systems that store sensitive personal data across multiple operational contexts.