Examples of Unlawful Processing by a Controller (Beyond Lack of Consent)
1. Processing Without a Lawful Basis
- GDPR requires one of six lawful bases under Article 6 (e.g., contract, legal obligation, legitimate interest, etc.).
- If none applies, processing is unlawful.
- Example: A company retains employee personal data after termination “just in case†without any lawful basis.
2. Exceeding the Purpose (Purpose Limitation - Art. 5(1)(b))
- Using personal data for a new purpose incompatible with the original purpose without informing the data subject or establishing a new lawful basis.
- Example: Collecting email addresses for billing, then later using them for marketing without proper justification.
3. Excessive Collection (Data Minimisation - Art. 5(1)(c))
- Collecting more data than necessary for the stated purpose.
- Example: An employer asks job applicants for full medical history when only a fitness-for-work certificate is necessary.
4. Failure to Ensure Accuracy (Accuracy - Art. 5(1)(d))
- Continuing to process personal data that is known to be inaccurate or outdated.
- Example: A bank uses an old address to send sensitive financial statements, leading to disclosure to the wrong person.
5. Excessive Retention (Storage Limitation - Art. 5(1)(e))
- Retaining personal data longer than necessary.
- Example: A service provider keeps customer data indefinitely after a contract has ended without a legal or business need.
6. Inadequate Security Measures (Integrity & Confidentiality - Art. 5(1)(f) + Art. 32)
- Failing to implement appropriate technical/organizational measures to secure data.
- Example: Storing unencrypted medical data on a shared drive accessible to unauthorized staff.
7. Non-Transparent Processing (Transparency - Arts. 12-14)
- Not providing sufficient or clear information in privacy notices.
- Example: A mobile app tracks location data in the background without disclosing it to users.
8. Unlawful International Transfers (Chapter V)
- Transferring personal data outside the EU without safeguards (e.g., no adequacy decision, SCCs, or BCRs).
- Example: An EU company sends customer data to a processor in a non-adequate country without using Standard Contractual Clauses.
9. Ignoring Data Subject Rights (Arts. 15-22)
- Failing to honor rights such as access, rectification, erasure, objection, or portability.
- Example: A controller refuses to delete a customer's profile when no lawful basis for retention exists.
✅ Summary
So, unlawful processing extends well beyond consent issues. Examples include:
- No lawful basis,
- Using data for incompatible purposes,
- Collecting/retaining too much,
- Failing security,
- Blocking subject rights,
- Illegal data transfers.
Each of these is a breach of GDPR and can lead to fines under Articles 83-84.