Art. 11 GDPR – Processing which does not require identification
- If the purposes for which a controller processes personal data do not or do no longer require the identification of a data subject by the controller, the controller shall not be obliged to maintain, acquire or process additional information in order to identify the data subject for the sole purpose of complying with this Regulation.
- 1Where, in cases referred to in paragraph 1 of this Article, the controller is able to demonstrate that it is not in a position to identify the data subject, the controller shall inform the data subject accordingly, if possible. 2In such cases, Articles 15 to 20 shall not apply except where the data subject, for the purpose of exercising his or her rights under those articles, provides additional information enabling his or her identification.
Related Recitals
Frequently Asked Questions about Article 11
+ What does Article 11 GDPR say about identification?
Article 11 states that controllers are not obliged to maintain, acquire, or process additional information just to identify a data subject solely to comply with the GDPR.
+ Do data subject rights apply if a controller cannot identify the person?
If the controller cannot identify the individual, certain rights such as access, rectification, and erasure may not apply, unless the individual provides additional information enabling identification.
+ Does Article 11 encourage data minimisation?
Yes. Article 11 supports minimisation by confirming that organisations should not collect extra identifying data purely to satisfy compliance obligations when processing does not otherwise require identification.