Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: DE

Artikel 90 Geheimhaltungspflichten


Summary What does Article 90 of the GDPR regulation say?

This article addresses a specific tension within the regulation: what happens when a controller or processor is bound by professional secrecy obligations under national or Union law?

It gives Member States the flexibility to limit certain investigative powers of supervisory authorities — specifically the powers to access personal data and premises under Article 58(1) — where doing so is necessary and proportionate to reconcile data protection rights with secrecy obligations.

Crucially, any such national rules only apply to personal data obtained through activities that are themselves covered by the secrecy obligation.

Member States must also notify the Commission of any rules they adopt under this article.

Important points:

  • Member States may adopt national rules that limit supervisory authority access powers where controllers or processors are bound by professional secrecy obligations.
  • These limiting rules apply only to personal data received or obtained in the course of activities covered by the secrecy obligation — not to all data held by the controller or processor.
  • Member States are required to notify the Commission of any rules adopted under this article by 25 May 2018, and of any subsequent amendments without delay.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Die Mitgliedstaaten können die Befugnisse der Aufsichtsbehörden im Sinne des Artikels 58 Absatz 1 Buchstaben e und f gegenüber den Verantwortlichen oder den Auftragsverarbeitern, die nach Unionsrecht oder dem Recht der Mitgliedstaaten oder nach einer von den zuständigen nationalen Stellen erlassenen Verpflichtung dem Berufsgeheimnis oder einer gleichwertigen Geheimhaltungspflicht unterliegen, regeln, soweit dies notwendig und verhältnismäßig ist, um das Recht auf Schutz der personenbezogenen Daten mit der Pflicht zur Geheimhaltung in Einklang zu bringen. Diese Vorschriften gelten nur in Bezug auf personenbezogene Daten, die der Verantwortliche oder der Auftragsverarbeiter bei einer Tätigkeit erlangt oder erhoben hat, die einer solchen Geheimhaltungspflicht unterliegt.

    1. Jeder Mitgliedstaat teilt der Kommission bis zum 25. Mai 2018 die Vorschriften mit, die er aufgrund von Absatz 1 erlässt, und setzt sie unverzüglich von allen weiteren Änderungen dieser Vorschriften in Kenntnis.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod