When can personal data be processed?
Your company/organisation can only process personal data in the following circumstances:
- with the consent of the individual concerned;
- where processing is necessary to meet a contractual obligation (a contract between a company/organisation and a client);
- where processing is necessary to meet a legal obligation under EU or national legislation;
- where processing is necessary for the performance of a task carried out in the public interest under EU or national legislation;
- where processing is necessary to protect the vital interests of an individual;
- where processing is necessary for a company/organisation’s legitimate interests, but only after having checked that the fundamental rights and freedoms of the individual whose data is processed are notseriously impacted. If the individual’s rights override a company/organisation’s interests, then processing cannot be carried out based on legitimate interest. This assessment depends on the individual circumstances of the case.
Examples
Consent
A company/organisation offers a music app and asks for individuals’ consent to process their musical preferences in order to suggest tailored songs and possible concerts to them.
Contractual obligation
A company/organisation sells goods online. It can process personal data that is necessary to take steps at the request of the individual prior to entering into the sales contract and for the performance of that contract. Examples of such personal data include the name, delivery address, and the credit card number (if the payment is done by card).
Legal obligation
A company with employees has a legal obligation to carry out social security payments and for that purpose provide its employees’ personal data (for example their name and information on their income) to relevant authorities. It may process its employees’ personal data to comply with that legal obligation.
Task of public interest or official authority
A professional association, such as a bar association or a chamber of medical professionals, is vested with an official authority to carry out disciplinary procedures against its members in case of wrongdoings. It may process personal data of its members when it is necessary to carry out disciplinary procedures.
Vital interests of a person
A hospital is treating an unconscious patient after a serious road accident. Even if the patient is incapable of giving his consent, the hospital may check whether the person has previous medical history in the hospital's database to ensure the safety of the life-saving treatment or to contact his next of kin.
Your organisation’s legitimate interests
A company/organisation ensures its network security by monitoring the use of its employees’ IT devices.
The company/organisation may legitimately process its employees’ personal data for that purpose, but only if the least intrusive method is chosen as regards the privacy and data protection rights of those employees (for example, by limiting the accessibility of certain websites).
However, this cannot be done in EU Member States where national law sets out stricter rules for processing in the employment context.
References
When is consent valid?
When consent is required to process personal data, for that consent to be valid the following conditions must be met:
- it must be freely given;
- it must be informed;
- it must be given for a specific purpose;
- it is clear and given via an affirmative act (for example an electronic tick-box that the individual has to explicitly check online or a signature on a form);
- the request for consent uses clear and plain language and is clearly visible;
- the request for consent states clearly all the reasons for the processing;
- the request for consent states clearly that it is possible to withdraw consent (for example, a visible link to unsubscribe at the end of an electronic newsletter email or another way which must be as easy to use as giving consent).
For consent to be freely given the individual must have a free choice and must be able to refuse or withdraw consent without being at a disadvantage. Consent is not freely given if, for example, there is a clear imbalance between the individual and the company/organisation (for example an employer/employee relationship) or when a company/organisation requires individuals to consent to the processing of unnecessary personal data as a pre-condition to providing a service under a contract.
For consent to be informed, the individual must receive at least the following information in a clear and plain language:
- the identity of the organisation processing the data;
- the specific purposes for which the data is being processed;
- the type of data that will be processed;
- the possibility to withdraw the given consent (for example, an unsubscribe link at the end of an email or another way allowing to withdraw the consent as easily as it was given);
- where applicable the fact that the data will be used for solely automated-based decision-making, including profiling;
- if the consent is related to an international transfer, the possible risks of data transfers to third countries which are not subject of a Commission adequacy decision and where there are no appropriate safeguards.
Where someone consents to the processing of their personal data, the data may be processed only for the purposes for which that consent was given. However, under certain conditions there is some flexibility concerning the specificity of the required consent in case the processing is carried out for scientific research purposes. It is for the company/organisation to demonstrate that the individual has consented to the processing.
Examples
Free consent
An airline company’s privacy notice indicates that the personal data of customers can also be processed for a competition offering a free flight as a prize, if customers agree to this.
The customers who ticked the box in agreeing to participate in the competition have clearly signalled their wish to have their personal data processed for the purpose of the competition. There is consent to process data for the purpose of the competition but not for other purposes.
Consent not free
A company offers online movie services based on a contract. When collecting the personal data needed for the performance of that contract, the company also asks its customers for some additional data, such as the sexual orientation or the ethnic origin of a person.
If the customers believe that they have to consent to the processing of this type of data to access the movies they request, the consent is not free consent, but it is a ‘tied consent’.
References
- Article 4(11) and Article 7 and Recitals 32, 42-43 of the GDPR
- EDPB Guidelines on consent under Regulation 2016/679
How is consent for processing in scientific research obtained?
Some flexibility in relation to the degree of specification and granularity of consent is allowed in the context of scientific research. When collecting personal data, researchers might not be able to fully identify all of the specific purposes for the processing initially envisaged. In those cases, they can ask individuals to give consent for certain areas of scientific research or parts of research projects.
In any case, valid consent must keep its core elements: this means it must be freely given, informed, sought via clear affirmative action and specific to the extent allowed by the scientific research in question. Researchers must make sure they also comply with the ethical and methodological standards required in their field.
Example
A group of researchers wants to process health data to study a specific kind of cancer but are aware of the possible usefulness of that data for other kind of cancer research that they may conduct in the future. In such a case they can ask for a person’s explicit consent to process his or her health data for cancer research in general, without specifying for which kind of cancer.
References
What if somebody withdraws their consent?
It should be as easy to withdraw as to give consent. If consent is withdrawn a company/organisation can no longer process the data. Once consent has been withdrawn, the company/organisation needs to ensure that the data is deleted unless it can be processed on another legal ground (for example, if there is an obligation to keep the data based on law, or as far as it is necessary to fulfil the contract).
If the data was being processed for several purposes, the company/organisation cannotuse the personal data for the part of the processing for which consent has been withdrawn, depending on the nature of the withdrawal of consent.
Example
An individualgives her consent to subscribe to an online newsletter, allowing at the same time the company/organisation providing that newsletter to process any personal data on her interests to build a profile of what articles she consults.
One year later, the client informs the company/organisation that she no longer wishes to receive the online newsletter. The company/organisation must delete from its database all personal data relating to that client collected in the context of the newsletter subscription, including the profile(s) of that client.
References
- Article 7 and Recitals 32-33, 42-43 and 58 of the GDPR
- EDPB Guidelines on consent under Regulation 2016/679
What does a 'legitimate interest’ mean?
A company/organisation often needs to process personal data in order to carry out tasks related to its business activities. The processing of personal data in that context may not always be justified by a legal obligation or the need to execute the terms of a contract with an individual. In such cases, the processing of personal data can sometimes be justified on grounds of legitimate interest.
When collecting personal data directly from individuals, a company/organisation must inform them about the legitimate interests pursued, if they are used as the legal basis for the processing.
A company/organisation must also check that by pursuing its legitimate interests the rights and freedoms of those individuals are not seriously impacted. Otherwise the company/organisation cannot rely on the ground of legitimate interest as a justification for processing the data and another legal ground must be found.
Example
A company/organisation may have a legitimate interest to process its clients’ personal data when the processing takes place within a client relationship and they can reasonably expect that processing to take place, or when the company/organisation processes personal data for direct marketing purposes, to prevent fraud or to ensure the network and information security of its IT systems.
References
Under what conditions can a company/organisation process sensitive data?
A company/organisation can only process special categories of personal data if one of the following conditions is met:
- the explicit consent of the individual was obtained (an EU or national law may rule out this option in certain cases);
- an EU or national law or a collective agreement, requires a company/organisation to process the data to comply with its obligations and rights, and those of the individuals, in the fields of employment, social security and social protection law;
- the vital interests of an individual are at stake and the individual is physically or legally incapable of giving consent;
- the data is processed by a foundation, association or other not-for-profit body with a political, philosophical, religious or trade union aim and it relates only to its members or people in regular contact with the organisation;
- the personal data was manifestly made public by the individual;
- the data is required for the establishment, exercise or defence of legal claims;
- the data is processed for reasons of substantial public interest on the basis of EU or national law;
- the data is processed for the purposes of preventive or occupational medicine, assessment of the working capacity of the employee, medical diagnosis, the provision of health or social care or treatment, or the management of health or social care systems and services on the basis of EU or national law, or on the basis of a contract as a health professional;
- the data is processed for reasons of public interest in the field of public health on the basis of EU or national law;
- the data is processed for archiving in the public interest, scientific or historical research purposes, or statistical purposes on the basis of EU or national law. Further conditions, including limitations, may be imposed by national law on the processing of genetic data, biometric data or data concerning health.
Examples
A company/organisation can process sensitive data
A doctor sees a number of patients at his clinic. He logs the visit in a database that includes fields such as the name/surname of the patient, the description of symptoms and the medication prescribed.
The last two are considered to be health data, which is sensitive personal data. The processing of health data by the clinic is allowed under the data protection law because it is required to treat the person and is carried out under the responsibility of a doctor who is subject to an obligation of professional secrecy.
A company/organisation cannot process sensitive data
Acompany sells dresses online. In addition to the clients’ name, payment method, and the address where the product can be delivered the company asks its clients to provide information about their preferred model, size, colour and material.. The company also asks about its clients’ religious affiliation.
The majority of the information is needed to fulfil the sales contract. However, clients’ religious affiliation is not necessary information to make and deliver their dresses. The company cannot ask for that information under that contract.
References
- Article 9 and Recitals 51-56 of the GDPR
What personal data is considered sensitive?
The following personal data is considered ‘sensitive’ and is subject to specific processing conditions:
- data revealing racial or ethnic origin;
- data revealing political opinions;
- data revealing religious or philosophical beliefs;
- data revealing trade union membership;
- genetic data;
- biometric data for the purpose of uniquely identifying a natural person;
- data concerning health;
- data concerning an individual’s sex life or sexual orientation.
References
- Articles 4(13), 4(14) and 4(15) and 9 and Recitals 51-56 of the GDPR
Can data received from a third party be used for marketing?
Before acquiring a contact list or a database with contact details of individuals from another company/organisation, that company/organisation must be able to demonstrate that the data was obtained in compliance with the GDPR and that it may use it for advertising purposes. For example, if the company/organisation acquired the data based on individuals’ consent, that consent should have covered also the possibility to transmit the data to other recipients for their own direct marketing.
A company/organisation must also ensure that the list or database is up-to-date and that it does not send advertising to individuals who objected to the processing of their personal data for direct marketing purposes.
A company/organisation must also ensure that if it uses communication tools, such as email, for the purposes of direct marketing, it complies with the rules set out in the ePrivacy Directive (Directive 2002/58/EC1).
Such lists with contact details are processed on grounds of legitimate interests A company/organisation must inform individuals, at the latest at the time of the first communication with them, that it is processing their personal data,to send them adverts and that they have the right to object to that processing at any time.
Example
Two friends, Mrs. A and Mr. B, run, respectively, a gym and a book shop. Each collects data from their respective customers.
Mr. B’s book shop is not doing well. His client database has few entries and not many people walk into his shop. He tells Mrs. A that he has a new biography of a famous athlete and asks whether Mrs. A’s clients would be interested in receiving advertising about the book. The terms of Mrs. A’s privacy notice informed her clients that she could share the data with partners offering products in the health and fitness area.
As far as specific consent was given for the purpose of transmitting the data to other recipients for their own direct marketing, Mrs. A can send the client list to Mr. B. However, no data can be sent about an individual who has objected or will object to the processing of their personal data for direct marketing purposes.
References
- Article 4(10) and Articles 5-6, 14 and 21 of the GDPR
- EDPB Guidelines on transparency under Regulation 2016/679
- ePrivacy Directive 2002/58/EC rules on direct marketing, in particular Article 13
1 Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) (OJ L 201, 31.07.2002 p.37).