Skip to content

Data protection in law enforcement

The EU protects individuals' personal data used by law enforcement authorities to prevent, investigate, detect or prosecute criminal offences.

Protecting data in judicial and police cooperation

The specific nature of police and judicial activities in criminal matters means that different rules on the protection of personal data are required in the context of those activities in order to facilitate the free flow of data and promote cooperation between the member states in these areas.

The directive on protecting personal data processed for the purposes of the prevention, investigation, detection or prosecution of criminal offences was adopted in 2016 and entered into application in 2018.

It aims to protect the right of individuals to the protection of their personal data while guaranteeing a high level of public security.

This directive applies to both cross-border and national processing of data by member states' competent authorities for the purposes of:

  • the prevention, investigation, detection and prosecution of criminal offences
  • the safeguarding and prevention of threats to public security

It does not cover activities by EU institutions, bodies, offices and agencies, nor activities falling outside the scope of EU law.

Rights of individuals

The directive sets out a series of principles, including the need to ensure that any personal data collected:

  • is processed lawfully
  • is collected for specific, explicit and legitimate purposes
  • is not excessive in relation to the purpose for which it is processed

The rules include the obligation for member states to provide understandable information and ensure the data subject’s rights of access, rectification, erasure and restriction of processing. However, they also set limitations on these rights, allowing member states to adopt legislative measures restricting them.

Application of data protection rules

The directive on protecting personal data processed for the purpose of criminal law enforcement describes the responsibilities of data controllers (those who are responsible for the processing of data). These include:

the designation of a data protection officer to help the competent authorities ensure compliance with data protection rules

the requirement to carry out an impact assessment where a type of processing is likely to result in a high risk to data subjects’ rights

The supervisory authorities can be the same as those established under the general data protection regulation. The directive defines rules on mandatory mutual assistance and a general obligation to cooperate.

The European Data Protection Advisory Board makes sure that the directive is fully applied. This board consists of representatives of all 27 independent supervisory authorities and also monitors the application of GDPR.

The directive grants individuals the right to receive compensation if they have suffered damage as a consequence of processing that has not respected the rules.

Transfers to non-EU countries

Transfers of personal data to non-EU countries can only take place if required for law enforcement purposes and if the European Commission has adopted an adequacy decision on the level of protection provided by the country in question.

Where no adequacy decision exists, transfers can take place where appropriate safeguards are in place.

A stylised illustration of a digital fingerprint surrounded by EU-style yellow stars, binary digits, and a small padlock icon, representing data protection and privacy in the European Union.
Data protection in the EU

Data protection in the EU

A translucent blue shield with a subtle network pattern stands in front of a circular web of connected yellow dots, symbolising data protection and security.
The general data protection regulation

The general data protection regulation