L 119/92
EN
Official Journal of the European Union
4.5.2016
(21)
The principles of data protection should apply to any information concerning an identified or identifiable natural
person. To determine whether a natural person is identifiable, account should be taken of all the means
reasonably likely to be used, such as singling out, either by the controller or by another person to identify the
natural person directly or indirectly. To ascertain whether means are reasonably likely to be used to identify the
natural person, account should be taken of all objective factors, such as the costs of and the amount of time
required for identification, taking into consideration the available technology at the time of the processing and
technological developments. The principles of data protection should therefore not apply to anonymous
information, namely information which does not relate to an identified or identifiable natural person or to
personal data rendered anonymous in such a manner that the data subject is no longer identifiable.
(22)
Public authorities to which personal data are disclosed in accordance with a legal obligation for the exercise of
their official mission, such as tax and customs authorities, financial investigation units, independent adminis
trative authorities, or financial market authorities responsible for the regulation and supervision of securities
markets should not be regarded as recipients if they receive personal data which are necessary to carry out a
particular inquiry in the general interest, in accordance with Union or Member State law. The requests for
disclosure sent by the public authorities should always be in writing, reasoned and occasional and should not
concern the entirety of a filing system or lead to the interconnection of filing systems. The processing of personal
data by those public authorities should comply with the applicable data protection rules according to the
purposes of the processing.
(23)
Genetic data should be defined as personal data relating to the inherited or acquired genetic characteristics of a
natural person which give unique information about the physiology or health of that natural person and which
result from the analysis of a biological sample from the natural person in question, in particular chromosomal,
deoxyribonucleic acid (DNA) or ribonucleic acid (RNA) analysis, or from the analysis of another element enabling
equivalent information to be obtained. Considering the complexity and sensitivity of genetic information, there is
a great risk of misuse and re-use for various purposes by the controller. Any discrimination based on genetic
features should in principle be prohibited.
(24)
Personal data concerning health should include all data pertaining to the health status of a data subject which
reveal information relating to the past, current or future physical or mental health status of the data subject. This
includes information about the natural person collected in the course of the registration for, or the provision of,
health care services as referred to in Directive 2011/24/EU of the European Parliament and of the Council (1) to
that natural person; a number, symbol or particular assigned to a natural person to uniquely identify the natural
person for health purposes; information derived from the testing or examination of a body part or bodily
substance, including from genetic data and biological samples; and any information on, for example, a disease,
disability, disease risk, medical history, clinical treatment or the physiological or biomedical state of the data
subject independent of its source, for example from a physician or other health professional, a hospital, a medical
device or an in vitro diagnostic test.
(25)
All Member States are affiliated to the International Criminal Police Organisation (Interpol). To fulfil its mission,
Interpol receives, stores and circulates personal data to assist competent authorities in preventing and combating
international crime. It is therefore appropriate to strengthen cooperation between the Union and Interpol by
promoting an efficient exchange of personal data whilst ensuring respect for fundamental rights and freedoms
regarding the automatic processing of personal data. Where personal data are transferred from the Union to
Interpol, and to countries which have delegated members to Interpol, this Directive, in particular the provisions
on international transfers, should apply. This Directive should be without prejudice to the specific rules laid down
in Council Common Position 2005/69/JHA (2) and Council Decision 2007/533/JHA (3).
(26)
Any processing of personal data must be lawful, fair and transparent in relation to the natural persons concerned,
and only processed for specific purposes laid down by law. This does not in itself prevent the law-enforcement
authorities from carrying out activities such as covert investigations or video surveillance. Such activities can be
done for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the
(1) Directive 2011/24/EU of the European Parliament and of the Council of 9 March 2011 on the application of patients' rights in crossborder healthcare (OJ L 88, 4.4.2011, p. 45).
(2) Council Common Position 2005/69/JHA of 24 January 2005 on exchanging certain data with Interpol (OJ L 27, 29.1.2005, p. 61).
(3) Council Decision 2007/533/JHA of 12 June 2007 on the establishment, operation and use of the second generation Schengen
Information System (SIS II) (OJ L 205, 7.8.2007, p. 63).