Case Assessment
learn

What are INTERPOL's Rules on the Processing of Data (RPD)?

What are INTERPOL's Rules on the Processing of Data (RPD)?. What the measure is, the grounds that work, and the realistic prospects. Confidential and independent, lawful mandates only.

By Nadia Cheref6 min read

INTERPOL's rules are not a single document most people know by name. Yet those rules determine whether a Red Notice stands or falls, whether data about you is accurate, and whether the Commission for the Control of INTERPOL's Files (CCF) has grounds to act. As of mid-2025, understanding the RPD is the starting point for any serious challenge.

INTERPOL's Rules on the Processing of Data – known as the RPD – are the binding internal rules that govern how INTERPOL collects, stores, uses and deletes personal data, including Red Notices and diffusions. The RPD is the primary legal instrument the CCF applies when it reviews a request for deletion or correction. It is distinct from INTERPOL's Constitution, though both instruments work together.

This page explains what the RPD is, how it connects to the CCF process, and why it matters if your data appears in INTERPOL's systems.

What exactly is the RPD, and why does it matter?

The RPD is the rulebook INTERPOL's General Secretariat and national bureaux must follow whenever they process personal data. It covers data accuracy, data quality, processing conditions and retention – the same branches the CCF examines when it reviews whether a Red Notice or diffusion should remain in INTERPOL's files.

The rules exist because INTERPOL processes data about individuals across more than 190 member countries. Without binding internal standards, there would be no mechanism to correct a notice that is inaccurate, politically motivated or retained beyond its legitimate purpose. The RPD provides that mechanism.

In our practice, the RPD's data-accuracy and data-quality requirements are among the most frequently argued branches. A notice that relies on outdated charges, a closed case, or a conviction that has been quashed may fail the RPD's conditions for continued processing. That failure is the legal basis for a deletion request – not a general complaint about unfairness, but a specific argument rooted in INTERPOL's own rules.

The RPD does not stand alone. Article 2 of INTERPOL's Constitution requires the organisation's activities to respect human rights, in the spirit of the Universal Declaration of Human Rights. Article 3 bars processing linked to offences of a political, military, religious or racial character. Together, the Constitution and the RPD form the complete legal basis the CCF applies.

How does the RPD connect to Red Notices and diffusions?

A Red Notice is a request to locate and provisionally detain a person with a view to extradition. It is not an arrest warrant, and it is not a judicial decision. A diffusion is an alert circulated directly by a national bureau, outside the formal notice system. Both are forms of data processing, and both fall within the RPD's scope.

That categorisation matters. Because a Red Notice is data – not a court order – it can be challenged on data-law grounds. The RPD's processing conditions require, among other things, that the underlying information is accurate, that it serves a legitimate purpose, and that it is not retained once that purpose no longer exists. A notice based on charges that have since been withdrawn, or issued primarily to pursue a political opponent through INTERPOL's channels, may breach one or more of those conditions.

A single border check can turn into a provisional arrest. That is not a theoretical risk. It is the practical consequence of a Red Notice circulating in INTERPOL's databases unchallenged. The RPD is the tool that allows a properly constructed CCF file to remove that risk at source.

In a recent matter (a MENA-origin notice, winter 2024), the data-accuracy branch of the RPD was the decisive argument: the underlying prosecution had been terminated, yet the notice remained active. The CCF's review led to deletion once the procedural record was placed before the Commission.

What does the CCF actually examine under the RPD?

The CCF reviews whether INTERPOL's processing of your data complies with the RPD and with the Constitution. It does not retry the underlying criminal case. It asks a narrower question: is this data lawful for INTERPOL to hold and circulate?

The CCF's Requests Chamber handles both access requests and deletion requests. An access request – to learn whether data is held – is to be answered within four months. A deletion request, once found admissible, is to be decided within nine months. There is no appeal against a CCF decision; a fresh request requires new elements. That last point is the honest limitation every client needs to understand before filing.

The branches of the RPD the CCF most commonly applies are:

  • Data accuracy: is the underlying information factually correct and up to date?
  • Data quality: does the file meet the standards required for inclusion in INTERPOL's systems?
  • Processing conditions: was the data published in accordance with the rules governing Red Notices and diffusions?
  • Retention: does a legitimate purpose still exist for keeping the data active?

A weak first file – one that asserts a violation without evidencing it against these specific branches – lowers the odds on any later review. Because there is no appeal, the quality of the initial submission is not a procedural nicety. It is the single most important variable in the outcome.

In another matter (a CIS-origin diffusion, summer 2025), the retention branch of the RPD provided the clearest argument: the requesting bureau had failed to demonstrate a continuing purpose. Once that gap was evidenced to the CCF, the diffusion was withdrawn.

The steps above describe the general picture. Whether the RPD provides grounds in your specific situation depends on the file, the requesting state and the current state of the underlying proceedings.

For an honest view of whether the RPD creates grounds to challenge data held about you, reach us through our secure channel or write to info@northlarkfirm.com.

Related

Frequently asked questions

What is the short answer?

The RPD – INTERPOL's Rules on the Processing of Data – is the binding internal rulebook governing how INTERPOL collects, stores and circulates personal data, including Red Notices and diffusions. It is the primary instrument the CCF applies when reviewing deletion and correction requests. It works alongside INTERPOL's Constitution, particularly Article 2 (human rights) and Article 3 (political character bar).

Does this create any obligation to arrest me?

No. A Red Notice is a request to locate and provisionally detain with a view to extradition. It is not an arrest warrant and not a judicial decision. No country is obliged to arrest you; each state decides under its own national law. The RPD's importance is that it gives the CCF grounds to order deletion of the data before that question ever arises at a border.

Where does this sit in the CCF process?

The CCF is the independent body that reviews INTERPOL's processing of personal data. It applies the RPD and the Constitution when assessing deletion requests. An access request is answered within four months; a deletion request decided within nine months of admissibility. There is no appeal against a CCF decision, which is why the quality and specificity of the first submission – argued against the RPD's own branches – is critical.

NORTHLARK is an independent international boutique focused on INTERPOL Red Notices, diffusions and CCF proceedings. We act only on lawful mandates. We do not help anyone evade legitimate justice, and we take on a matter only where we see genuine grounds. The first assessment is confidential. Our enquiry form does not require your real name, and you can reach us through a secure channel – Signal, Telegram or WhatsApp – or directly at info@northlarkfirm.com.

Facing an unjustified Red Notice?

Free initial assessment. Challenging Interpol Red Notices and extradition defence.

Request an assessment