← GDPR · Lawfulness
Art.10 — Criminal convictions and offences data
Requirement
Personal data relating to criminal convictions and offences may be processed only under the control of official authority or where authorised by Union or Member State law providing appropriate safeguards.
UK GDPR: In the UK, processing criminal offence data needs a condition in Schedule 1 of the Data Protection Act 2018 and, for most conditions, an appropriate policy document.
What the engine looks for
Every group below must be satisfied — by an affirmative statement, not a plan, a hedge or a denial — for the control to count as covered. A term ending in … matches any word it begins. Supporting terms do not change the verdict — they raise confidence and distinguish a policy that names a mechanism from one that gestures at a category.
Equivalent controls elsewhere
Matched on shared topics. Satisfying this control usually moves these too.
| Framework | Control | Title | Shared topics |
|---|---|---|---|
| NDPA 2023 | s.30 | Sensitive personal data | data-classification lawful-basis |
| CCPA/CPRA | 1798.121 | Right to limit use of sensitive personal information | data-classification |
| SOC 2 | C1.1 | Identification and protection of confidential information | data-classification |
| SOC 2 | P1.1 | Notice and communication of privacy commitments | lawful-basis |
| ISO 27001 | A.5.12 | Classification of information | data-classification |
| ISO 27001 | A.8.3 | Information access restriction | data-classification |
| PCI DSS 4.0.1 | 3.4 | PAN is masked when displayed and protected from copying | data-classification |
| COPPA | 312.2-312.3 | Determine whether COPPA applies | data-classification |