Examples of Unlawful Processing by a Controller (Beyond Lack of Consent)

1. Processing Without a Lawful Basis

  • GDPR requires one of six lawful bases under Article 6 (e.g., contract, legal obligation, legitimate interest, etc.).
  • If none applies, processing is unlawful.
  • Example: A company retains employee personal data after termination “just in case” without any lawful basis.

2. Exceeding the Purpose (Purpose Limitation - Art. 5(1)(b))

  • Using personal data for a new purpose incompatible with the original purpose without informing the data subject or establishing a new lawful basis.
  • Example: Collecting email addresses for billing, then later using them for marketing without proper justification.

3. Excessive Collection (Data Minimisation - Art. 5(1)(c))

  • Collecting more data than necessary for the stated purpose.
  • Example: An employer asks job applicants for full medical history when only a fitness-for-work certificate is necessary.

4. Failure to Ensure Accuracy (Accuracy - Art. 5(1)(d))

  • Continuing to process personal data that is known to be inaccurate or outdated.
  • Example: A bank uses an old address to send sensitive financial statements, leading to disclosure to the wrong person.

5. Excessive Retention (Storage Limitation - Art. 5(1)(e))

  • Retaining personal data longer than necessary.
  • Example: A service provider keeps customer data indefinitely after a contract has ended without a legal or business need.

6. Inadequate Security Measures (Integrity & Confidentiality - Art. 5(1)(f) + Art. 32)

  • Failing to implement appropriate technical/organizational measures to secure data.
  • Example: Storing unencrypted medical data on a shared drive accessible to unauthorized staff.

7. Non-Transparent Processing (Transparency - Arts. 12-14)

  • Not providing sufficient or clear information in privacy notices.
  • Example: A mobile app tracks location data in the background without disclosing it to users.

8. Unlawful International Transfers (Chapter V)

  • Transferring personal data outside the EU without safeguards (e.g., no adequacy decision, SCCs, or BCRs).
  • Example: An EU company sends customer data to a processor in a non-adequate country without using Standard Contractual Clauses.

9. Ignoring Data Subject Rights (Arts. 15-22)

  • Failing to honor rights such as access, rectification, erasure, objection, or portability.
  • Example: A controller refuses to delete a customer's profile when no lawful basis for retention exists.

✅ Summary

So, unlawful processing extends well beyond consent issues. Examples include:

  • No lawful basis,
  • Using data for incompatible purposes,
  • Collecting/retaining too much,
  • Failing security,
  • Blocking subject rights,
  • Illegal data transfers.

Each of these is a breach of GDPR and can lead to fines under Articles 83-84.