4.5.2016
EN
Official Journal of the European Union
L 119/91
necessary to safeguard against and prevent threats to public security and to fundamental interests of the society
protected by law which may lead to a criminal offence. Member States may entrust competent authorities with
other tasks which are not necessarily carried out for the purposes of the prevention, investigation, detection or
prosecution of criminal offences, including the safeguarding against and the prevention of threats to public
security, so that the processing of personal data for those other purposes, in so far as it is within the scope of
Union law, falls within the scope of Regulation (EU) 2016/679.
(13)
A criminal offence within the meaning of this Directive should be an autonomous concept of Union law as
interpreted by the Court of Justice of the European Union (the ‘Court of Justice’).
(14)
Since this Directive should not apply to the processing of personal data in the course of an activity which falls
outside the scope of Union law, activities concerning national security, activities of agencies or units dealing with
national security issues and the processing of personal data by the Member States when carrying out activities
which fall within the scope of Chapter 2 of Title V of the Treaty on European Union (TEU) should not be
considered to be activities falling within the scope of this Directive.
(15)
In order to ensure the same level of protection for natural persons through legally enforceable rights throughout
the Union and to prevent divergences hampering the exchange of personal data between competent authorities,
this Directive should provide for harmonised rules for the protection and the free movement of personal data
processed for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the
execution of criminal penalties, including the safeguarding against and the prevention of threats to public
security. The approximation of Member States' laws should not result in any lessening of the personal data
protection they afford but should, on the contrary, seek to ensure a high level of protection within the Union.
Member States should not be precluded from providing higher safeguards than those established in this Directive
for the protection of the rights and freedoms of the data subject with regard to the processing of personal data
by competent authorities.
(16)
This Directive is without prejudice to the principle of public access to official documents. Under Regulation (EU)
2016/679 personal data in official documents held by a public authority or a public or private body for the
performance of a task carried out in the public interest may be disclosed by that authority or body in accordance
with Union or Member State law to which the public authority or body is subject in order to reconcile public
access to official documents with the right to the protection of personal data.
(17)
The protection afforded by this Directive should apply to natural persons, whatever their nationality or place of
residence, in relation to the processing of their personal data.
(18)
In order to prevent creating a serious risk of circumvention, the protection of natural persons should be technolo
gically neutral and should not depend on the techniques used. The protection of natural persons should apply to
the processing of personal data by automated means, as well as to manual processing, if the personal data are
contained or are intended to be contained in a filing system. Files or sets of files, as well as their cover pages,
which are not structured according to specific criteria should not fall within the scope of this Directive.
(19)
Regulation (EC) No 45/2001 of the European Parliament and of the Council (1) applies to the processing of
personal data by the Union institutions, bodies, offices and agencies. Regulation (EC) No 45/2001 and other
Union legal acts applicable to such processing of personal data should be adapted to the principles and rules
established in Regulation (EU) 2016/679.
(20)
This Directive does not preclude Member States from specifying processing operations and processing procedures
in national rules on criminal procedures in relation to the processing of personal data by courts and other
judicial authorities, in particular as regards personal data contained in a judicial decision or in records in relation
to criminal proceedings.
(1) Regulation (EC) No 45/2001 of the European Parliament and of the Council of 18 December 2000 on the protection of individuals with
regard to the processing of personal data by the Community institutions and bodies and on the free movement of such data (OJ L 8,
12.1.2001, p. 1).