The model for storing biometric data of Police officers and employees requires clarification
The current data retention rules need to be amended. Genetic and biometric data collected from Police officers and employees are currently deleted no later than five years after the termination of their service relationship or employment. According to the President of the Personal Data Protection Office, the adopted model does not ensure full compliance with personal data protection principles and the standards arising from the Constitution of the Republic of Poland and the case law of the Court of Justice of the European Union.
President of the Personal Data Protection Office, Mirosław Wróblewski, has asked the Minister of the Interior and Administration, Marcin Kierwiński, to undertake legislative work on the existing provisions concerning the collection of fingerprints and buccal swabs from Police officers and employees.
The processing of personal data for the purpose of eliminating traces left during activities related to detecting, securing or examining evidence of prohibited acts is, as a rule, subject to the regime of the so‑called Police Directive (2016/680). However, if the data are processed for administrative or HR purposes, the provisions of the GDPR apply.
Although the collection of such personal data from Police officers and employees has a statutory basis, certain issues constituting an interference with the right to privacy and personal data protection have been regulated in a regulation. Such a solution raises significant constitutional concerns – the implementing act modifies the statutory norm, which contradicts, among other things, the constitutional hierarchy of sources of law.
In the opinion of the President of the Personal Data Protection Office, the rules on the retention of this type of personal data should be clarified. Currently, they must be deleted no later than five years after the termination of the service relationship or employment of the person concerned. Such timeframes for storing this category of personal data may be inappropriate, including from the perspective of the principle of data minimisation and the limitation of data processing.
These regulations partially implement the standards arising from the CJEU’s case law, in particular the prohibition of indefinite data storage and the requirement for periodic verification of their continued relevance. Nevertheless, the adopted retention model raises concerns in terms of the principle of data minimisation and the requirement of “strict necessity” for processing biometric and genetic data.
President Wróblewski points out that the GDPR principles protecting citizens’ rights include, among others, the principle of data minimisation (Article 5(1)(c)) and the principle of storage limitation (Article 5(1)(e)). This means that data may be collected only to a limited extent and stored only for as long as is necessary in a given case. This minimises the risk of incidents and exposure to irreversible harm.
Interpretative guidance from the CJEU
In case C‑371/24 Comdribus, the Court of Justice of the European Union recalled that the processing of special categories of personal data (including biometric and genetic data) is permissible only in strictly defined cases provided for by Union or Member State law and subject to additional requirements.
These include ensuring appropriate safeguards for the rights and freedoms of the data subject, as well as demonstrating that the processing is strictly necessary. The condition of “strict necessity” means that the processing must serve specific, explicit and legally justified purposes, and the scope of the data must be adequate, relevant and limited to what is necessary (the principle of minimisation). Moreover, processing is lawful only when it is necessary for the performance of the tasks of competent authorities, and national provisions must precisely define the purposes, scope and legal bases for processing.
The assessment of “strict necessity” should be particularly rigorous and relate to strictly defined, specific processing purposes, distinct from general reasons for carrying it out. It also requires verifying whether the intended purpose could not be achieved equally effectively using less sensitive data.
In case C‑57/23 JH vs Policejní prezidium, the CJEU held that the absence of a maximum retention period for biometric and genetic data is not, in itself, contrary to the Police Directive, provided that national law ensures mechanisms for periodic review of the justification for continued storage and guarantees an assessment of its strict necessity.
Meanwhile, in case C‑118/22, the CJEU stated that Member States should establish appropriate deletion periods for such data or mechanisms for their regular verification in terms of continued necessity, as well as ensure effective procedures guaranteeing compliance with these principles.
Proposals of the President of the Personal Data Protection Office
An analysis of the applicable regulations leads to the conclusion that the current model for processing biometric and genetic data of Police officers and employees does not ensure full compliance with personal data protection principles and the interpretative standards arising from European case law.
The Personal Data Protection Office calls for clarifying the provisions relating to the rules for processing biometric and genetic data of Police officers and employees, including by statutorily defining the grounds for their processing and ensuring that data retention rules comply with the requirements of minimisation and the assessment of the necessity of their processing.