Protecting vital interests is a legal basis for personal data processing
Article 6(1)(d) of the GDPR
Information about Protecting vital interests
Protecting vital interests is a legal basis under the GDPR
Protecting vital interests is a legal basis for personal data processing according to the GDPR. But it is unusual for a company to use this legal basis to process personal data. Article 6(1)(d) of the GDPR states this legal basis. However, it is suitable to use in certain specific cases. In short, this legal basis means that companies have the right to process personal data to save lives. In other words, a company may use this legal basis for processing personal data in an emergency situation. Please note that in some cases it is not possible to support the processing of personal data on this legal basis. For example, if it is possible for the data subject to give their consent.
Protecting vital interests is a legal basis under the GDPR mostly used in emergencies
Below you can read examples of when it may be appropriate to use the protection of vital interests as a legal basis:
● Life-threatening accidents
If a person gets into an accident and is unconscious when the person arrives at the hospital. In such case, the hospital can process the individual’s personal data, such as name and blood type, if necessary.
● Emergencies
In some cases, the processing of personal data may promote a fundamental interest. For example, in emergencies such as natural disasters. A company may process personal data in such cases on the basis of protection of vital interests.
Sensitive personal data according the GDPR
The general rule in Article 9 of the GDPR prohibits the processing of certain special categories of personal data. These types are also known as “sensitive personal data”. However, there are some exceptions from this general rule. Sensitive personal data under the GDPR are, for example, data on health, religious affiliation and political opinions.
If a person arrives at a hospital unconscious and the hospital needs to see what blood type the person has, they process health data, i.e. sensitive personal data. This is permissible on the basis of the protection of vital interests as a legal basis in such cases.
Examples of when it is not possible to use the protection of vital interests as a legal basis
A company is not allowed to use the protection of vital interests as legal basis, for example, if the data subject goes to a medical clinic for an appointment. This is because the person then has the opportunity to give their consent to the processing instead. In addition, the hospital can start the processing on the basis of a task of public interest instead.
More information about the legal and lawful bases of the GDPR
Contract with data subjects is another legal basis
It is important to remember that protecting vital interests is a legal basis under the GDPR and that there are five more legal bases. Companies have the right to process personal data that is necessary for the performance of a contract with the data subject. This is another legal basis of the GDPR. A company that conducts e-commerce may process the customer’s contact information in order to deliver the products to the customer. However, the company does not have the right to process more personal data than is necessary for the performance of the contract.