4.5.2016
EN
Official Journal of the European Union
L 119/93
execution of criminal penalties, including the safeguarding against and the prevention of threats to public
security, as long as they are laid down by law and constitute a necessary and proportionate measure in a
democratic society with due regard for the legitimate interests of the natural person concerned. The data
protection principle of fair processing is a distinct notion from the right to a fair trial as defined in Article 47 of
the Charter and in Article 6 of the European Convention for the Protection of Human Rights and Fundamental
Freedoms (ECHR). Natural persons should be made aware of risks, rules, safeguards and rights in relation to the
processing of their personal data and how to exercise their rights in relation to the processing. In particular, the
specific purposes for which the personal data are processed should be explicit and legitimate and determined at
the time of the collection of the personal data. The personal data should be adequate and relevant for the
purposes for which they are processed. It should, in particular, be ensured that the personal data collected are not
excessive and not kept longer than is necessary for the purpose for which they are processed. Personal data
should be processed only if the purpose of the processing could not reasonably be fulfilled by other means. In
order to ensure that the data are not kept longer than necessary, time limits should be established by the
controller for erasure or for a periodic review. Member States should lay down appropriate safeguards for
personal data stored for longer periods for archiving in the public interest, scientific, statistical or historical use.
(27)
For the prevention, investigation and prosecution of criminal offences, it is necessary for competent authorities to
process personal data collected in the context of the prevention, investigation, detection or prosecution of
specific criminal offences beyond that context in order to develop an understanding of criminal activities and to
make links between different criminal offences detected.
(28)
In order to maintain security in relation to processing and to prevent processing in infringement of this Directive,
personal data should be processed in a manner that ensures an appropriate level of security and confidentiality,
including by preventing unauthorised access to or use of personal data and the equipment used for the
processing, and that takes into account available state of the art and technology, the costs of implementation in
relation to the risks and the nature of the personal data to be protected.
(29)
Personal data should be collected for specified, explicit and legitimate purposes within the scope of this Directive
and should not be processed for purposes incompatible with the purposes of the prevention, investigation,
detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding
against and the prevention of threats to public security. If personal data are processed by the same or another
controller for a purpose within the scope of this Directive other than that for which it has been collected, such
processing should be permitted under the condition that such processing is authorised in accordance with
applicable legal provisions and is necessary for and proportionate to that other purpose.
(30)
The principle of accuracy of data should be applied while taking account of the nature and purpose of the
processing concerned. In particular in judicial proceedings, statements containing personal data are based on the
subjective perception of natural persons and are not always verifiable. Consequently, the requirement of accuracy
should not appertain to the accuracy of a statement but merely to the fact that a specific statement has been
made.
(31)
It is inherent to the processing of personal data in the areas of judicial cooperation in criminal matters and police
cooperation that personal data relating to different categories of data subjects are processed. Therefore, a clear
distinction should, where applicable and as far as possible, be made between personal data of different categories
of data subjects such as: suspects; persons convicted of a criminal offence; victims and other parties, such as
witnesses; persons possessing relevant information or contacts; and associates of suspects and convicted
criminals. This should not prevent the application of the right of presumption of innocence as guaranteed by the
Charter and by the ECHR, as interpreted in the case-law of the Court of Justice and by the European Court of
Human Rights respectively.
(32)
The competent authorities should ensure that personal data which are inaccurate, incomplete or no longer up to
date are not transmitted or made available. In order to ensure the protection of natural persons, the accuracy,
completeness or the extent to which the personal data are up to date and the reliability of the personal data
transmitted or made available, the competent authorities should, as far as possible, add necessary information in
all transmissions of personal data.
(33)
Where this Directive refers to Member State law, a legal basis or a legislative measure, this does not necessarily
require a legislative act adopted by a parliament, without prejudice to requirements pursuant to the constitutional