Criminal convictions or offences
Criminal offence data is governed by GDPR Art. 10 and may only be processed under official authority or specific law.
Keep it how long
The gap we see most
Background-check outcomes copied into a contact record without a legal basis.
What holding it is evidence for
Requirement text and artefacts from a human-verified corpus licensed to Field Register.
Special category data in the CRM GDPR Art.9 · CCPA/CPRA §1798.121 · CCPA/CPRA CCR §7027 · ISO/IEC 27701:2019 7.2.2 · ISO/IEC 27701:2019 7.4.1
GDPR Art.9 Processing of special categories of personal dataDo not process personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs or trade union membership, nor genetic data, biometric data processed to uniquely identify a person, data concerning health, or data concerning a person's sex life or sexual orienta...
CCPA/CPRA §1798.121 Right to Limit Use and Disclosure of Sensitive Personal InformationConsumers have the right to direct a business that collects sensitive PI to limit its use to that necessary to perform services or provide goods reasonably expected by an average consumer, or for specified permitted purposes (security, fraud, short-term transient use, performing services, verifying ...
CCPA/CPRA CCR §7027 Requests to Limit Use of Sensitive PI HandlingOnce a consumer requests to limit, the business shall not use or disclose the sensitive PI for any purpose other than those permitted under §1798.121(a). The business shall comply within 15 business days, notify service providers and contractors, and shall not require account creation. The Limit lin...
ISO/IEC 27701:2019 7.2.2 Identify lawful basisThe organization must determine, document and comply with the lawful basis for each processing activity against its identified purposes, documenting the basis per activity, including any special categories of personal data in its classification scheme with awareness that the classification and its c...
ISO/IEC 27701:2019 7.4.1 Limit collectionThe organization must limit collection of personal data to the minimum that is adequate, relevant, proportional and necessary for the identified purposes, including data collected indirectly through means such as web and system logs, and where any optionality in collection and processing exists each...
Criminal offence data GDPR Art.10 · ISO/IEC 27701:2019 7.2.2
GDPR Art.10 Processing of personal data relating to criminal convictionsProcess personal data relating to criminal convictions and offences, or related security measures, only under the control of official authority or where Union or Member State law authorises the processing and provides appropriate safeguards for the rights and freedoms of data subjects. A comprehensi...
ISO/IEC 27701:2019 7.2.2 Identify lawful basisThe organization must determine, document and comply with the lawful basis for each processing activity against its identified purposes, documenting the basis per activity, including any special categories of personal data in its classification scheme with awareness that the classification and its c...
Do this for your whole CRM
Paste your field list and get this classification for every field at once, with the record of processing per object, the gaps, and the controls the register is evidence for. No account for the first run.
Build my field registerSex life or sexual orientation · Government identifier (passport, national ID, SSN, tax number)