GDPR: Understanding Everything About Purpose Limitation
The response to the survey "Is it possible to reuse data for another processing purpose that is incompatible with the first one?"
To introduce the subject, we offered you a survey on February 15th on our LinkedIn page, asking you if it was possible to reuse data for another processing whose purpose is incompatible with the first one.
Well done! Out of 209 voters, 93% of you answered "No, it is prohibited". Indeed, you cannot reuse data for another processing whose purpose is incompatible.
The 6 principles set out in Article 5 of the GDPR
Article 5.1 of the GDPR lists five principles to which the processing of personal data must comply:
- Lawfulness, fairness and transparency
- Purpose limitation
- Data minimisation
- Accuracy
- Storage limitation
- Integrity and confidentiality
Our previous articles present and explain some of these concepts. Follow us so you don't miss the upcoming ones! ?
# A Principle to Be Qualified
At the same time, the GDPR qualifies the principle of purpose limitation with the notion of "compatible purpose". It allows, under certain conditions, the reuse of collected data for another purpose.
Everything depends in particular on the initial legal basis on which your initial processing is founded.
If it is a legitimate interest, a contract or vital interests, the data can be used for another purpose provided that the following points have been verified to ensure compatibility.
The following points deserve particular attention (conditions established by the EDPB):
- "the link between the initial purpose and the new or future purpose;
- the context in which the data was collected (What is the relationship between your company/organisation and the data subject?);
- the type and nature of the data (Is it sensitive?);
- the possible consequences of the envisaged further processing (What impact will it have on the data subject?);
- the existence of appropriate safeguards (such as encryption or pseudonymisation)".
If you use the data for statistical purposes or scientific research, it is not necessary to carry out a compatibility test.
If the initial processing is based on consent or on a legal obligation, no further processing that goes beyond the scope of the areas covered by the initial basis is possible. Further processing would require obtaining new consent or a new legal basis.
An example of a sanction for non-compliance with the purpose limitation principle ??
The Spanish supervisory authority, the AEPD, sanctioned Bankia bank for violation of Article 5.1 on purpose limitation. In this case, the applicant closes their bank account, 16 years later contacts the banking institution to obtain information relating to an inheritance issue.
It turns out that, in accordance with its internal procedures, the bank retains the data of its former customers in intermediate archiving for the period of legal limitation (in case of litigation).
This is a subsequent purpose compatible with the initial purpose (managing the customer account).
Nevertheless, as the supervisory authority points out, using this archived data to respond to a new request, unrelated to the initial intended purposes is contrary to the principle of purpose limitation of processing. This is, in fact, a new processing operation that was not initially envisaged by the controller and which proves to be incompatible with the existing one.
Consequently, the AEPD decided to impose a fine of €50,000 on 28 August 2020 for violation of the principle of purpose limitation of personal data processing.
Data Comply One (formerly Mission RGPD) in the Face of the Purpose Limitation Principle
Are you struggling to identify your processing purposes? Don't you have time to think about and concretely implement your processing register? Or do you lack the resources to be compliant?
✅ With Data Comply One (formerly Mission RGPD), you can easily identify the purposes and sub-purposes of your processing activities.
Thanks to our pre-filled templates, you will find ready-to-use proposals for drafting purposes and sub-purposes. You can obviously modify them if necessary and even create your own templates.
Don't waste any more time, it's so simple!
How do you limit purposes?
To begin with, it is necessary to identify the purpose of the processing beforehand. To do this, the processing must meet a specific, determined, explicit, legitimate and well-defined objective. Similarly, the purpose must be clear to the data subject and be justified by the data controller.
This allows, on the one hand, to comply with the principle of minimisation (which we will discuss next week).
On the other hand, you assure data subjects that their data will not be used or reused outside of this intended purpose.
Indeed, the data controller cannot reuse the data for another processing whose purpose is incompatible with the first one. ?
This principle is paramount and immutable. In case of misappropriation of purpose, the company concerned is liable to a fine and its representative to a prison sentence.