CJEU Ruling Stresses Need for Proportional Data Retention in Biometric and DNA Records

Home / Publications / CJEU Ruling Stresses Need for Proportional Data Retention in Biometric and DNA Records

The Court of Justice of the European Union (CJEU) recently emphasized the importance of compliance with GDPR principles, particularly around the sensitive issue of biometric and DNA data. This decision speaks to the ongoing challenges data controllers face in balancing lawful retention practices with individual privacy rights, calling for a personalized approach to storage duration based on relevant factors.

The CJEU’s guidance discourages blanket retention periods for all individuals, advocating instead for case-by-case assessment. A one-size-fits-all retention strategy, the court maintains, does not align with European law, which prioritizes proportionality and careful minimization of data storage duration.

Prompted by various national discussions—including a recent debate on Bulgarian police policies on retaining biometric and DNA data—this ruling calls for EU member states to enact periodic reviews of data retention practices. Additionally, individuals should have the right to request deletion of their personal data if its retention is no longer necessary.

To help organizations navigate these requirements, here are three actionable guidelines for GDPR-compliant data management of biometric and DNA records:

Set Tailored Retention Policies

Create retention policies tailored to individual cases rather than applying uniform rules. Retention periods should account for the purpose for processing the data. This approach ensures that data storage remains relevant and justified.

Establish Regular Review Processes

Set up a structured system for periodic assessments of stored data to determine whether ongoing retention is necessary. These reviews should be documented with reasons for retaining or deleting data, maintaining compliance with GDPR principles on data minimization and proportionality.

Enable Requests for Data Deletion

Make it easy for individuals to request data deletion when continued storage isn’t justified. Ensure that this option is clearly communicated and that responses are prompt, with clear instructions on how requests are processed.

By following these practices, data controllers can align with the CJEU ruling, supporting GDPR compliance while respecting individual privacy rights. This ruling also serves as a timely reminder for organizations to evaluate their data management strategies, balancing business needs with responsible data protection practices.

The article above is for information purposes only. It is not a (binding) legal advice. For a thorough understanding of the subjects covered and prior acting on any issue discussed we kindly recommend Readers consult Ilieva, Voutcheva & Co. Law Firm attorneys at law.