The President of the Polish Authority Calls for a Review of the Rules on Retention of Police Officers' Biometric and Genetic Data
The Polish data protection authority (UODO) has requested a legislative review of the rules on retention of biometric and genetic data of police officers and employees, considering the current framework non-compliant with data protection principles.
The President of the UODO has addressed the Minister of the Interior and Administration regarding the processing of fingerprints and buccal samples of police personnel. Currently, these data are deleted no later than five years after the end of their service or employment relationship. The authority considers that this fixed period could contravene the principles of data minimisation and storage limitation. Moreover, although the collection is based on a law, essential aspects concerning privacy are governed by an implementing regulation, raising doubts about its compliance with the hierarchy of constitutional norms. The processing of these data falls under Directive (EU) 2016/680 for law enforcement purposes and the GDPR for administrative or human resources purposes.
Relying on the case law of the Court of Justice of the European Union (cases C-371/24, C-57/23 and C-118/22), the UODO recalls that the processing of these sensitive data must be "absolutely necessary" and subject to strict safeguards. The Court requires specific purposes, appropriate deletion periods, or mechanisms for regular review of the necessity of retention. Consequently, the UODO recommends clarifying the legal provisions to define the conditions of processing in a law and ensuring that retention rules comply with the requirements of minimisation (article 5, paragraph 1, point c) and storage limitation (article 5, paragraph 1, point e).
The President of the UODO has addressed the Minister of the Interior and Administration regarding the processing of fingerprints and buccal samples of police personnel. Currently, these data are deleted no later than five years after the end of their service or employment relationship. The authority considers that this fixed period could contravene the principles of data minimisation and storage limitation. Moreover, although the collection is based on a law, essential aspects concerning privacy are governed by an implementing regulation, raising doubts about its compliance with the hierarchy of constitutional norms. The processing of these data falls under Directive (EU) 2016/680 for law enforcement purposes and the GDPR for administrative or human resources purposes.
Relying on the case law of the Court of Justice of the European Union (cases C-371/24, C-57/23 and C-118/22), the UODO recalls that the processing of these sensitive data must be "absolutely necessary" and subject to strict safeguards. The Court requires specific purposes, appropriate deletion periods, or mechanisms for regular review of the necessity of retention. Consequently, the UODO recommends clarifying the legal provisions to define the conditions of processing in a law and ensuring that retention rules comply with the requirements of minimisation (article 5, paragraph 1, point c) and storage limitation (article 5, paragraph 1, point e).
Informations complémentaires
L’analyse complète est réservée aux membres
Montant de la sanction, thèmes, secteurs, entités et données concernées : l’essai gratuit de 14 jours ouvre la fiche entière et la veille personnalisée.
Essayer gratuitement 14 jours · accès complet · sans carte bancaire