The Danish authority authorizes the transfer of former employees' data for research purposes despite delayed deletion
In an opinion, the Danish Data Protection Authority considered that a controller, having failed to fulfill its data deletion obligation, could nevertheless retain and disclose the data to a third party, provided that a new legitimate purpose, namely scientific research, had emerged.
Facts and context
The Danish Data Protection Authority (Datatilsynet) issued an opinion regarding the possibility for the University of Copenhagen to disclose personal data about former employees to Bispebjerg Hospital for scientific research purposes, even though these data should have been deleted.
The case originated from a request by the University of Copenhagen, which questioned the legality of transferring personnel files whose retention period, set at 10 years by its internal rules, had been exceeded.
Reasons for the decision
The authority analyzed the situation in light of several GDPR principles and obligations:
- Storage limitation obligation (Article 5(1)(e) of the GDPR): The authority first criticized the university for not respecting its own internal deletion rules, thus breaching the storage limitation principle. However, it considered that the emergence of a new purpose – the transfer of data to a hospital for occupational health research – exceptionally justified the extended retention of the data, but only until their effective communication, after which they must be deleted.
- Purpose limitation obligation (Article 5(1)(b) of the GDPR): The authority recalled that while data cannot be further processed in a manner incompatible with the initial purposes, further processing for scientific research purposes is, in principle, considered compatible. The transfer envisaged by the university was therefore compatible with the initial personnel management purpose.
- Lawfulness of processing obligation (Article 6 and 9 of the GDPR): For the data transfer to be lawful, the university must identify a legal basis. The authority suggested the performance of a task carried out in the public interest (Article 6(1)(e)). If sensitive data are involved, a derogation condition is necessary, such as scientific research (Article 9(2)(j)), which must be provided for by national law, as is the case in Denmark with Article 10 of the Data Protection Act.
- Data minimization obligation (Article 5(1)(c) of the GDPR): The authority emphasized that the university must assess whether the transfer of all data is necessary, or if only certain information relevant to the research should be disclosed, to comply with the minimization principle.
- Information obligation (Articles 13 and 14 of the GDPR): Finally, the authority reminded the university of its duty to inform the data subjects of this new processing, in accordance with transparency rules.
Authority's decision
Consequently, the authority concluded that the University of Copenhagen could lawfully retain and disclose the data to Bispebjerg Hospital, subject to compliance with the aforementioned conditions.
Lessons learned
This decision clarifies that:
- The emergence of a new legitimate purpose, such as scientific research of public interest, can exceptionally justify the temporary retention of data that should have been deleted under the storage limitation principle.
- The justification for extended retention for a new purpose is strictly temporary and ends as soon as this purpose is achieved; the data must then be immediately deleted by the original controller.
- The disclosure of data to a third party constitutes a separate processing operation requiring its own legal basis, even if the extended retention of the data was justified by this disclosure purpose.
- Further processing of data for scientific research purposes is presumed compatible with the initial purpose of their collection, pursuant to Article 5(1)(b) of the GDPR.
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire