Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: EN
- General data protection
Basic legislative acts
- GDPR regulation
Article 90 Obligations of secrecy
Summary What does Article 90 of the GDPR regulation say?
This article addresses a specific tension within the regulation: what happens when a controller or processor is bound by professional secrecy obligations under national or Union law?
It gives Member States the flexibility to limit certain investigative powers of supervisory authorities — specifically the powers to access personal data and premises under Article 58(1) — where doing so is necessary and proportionate to reconcile data protection rights with secrecy obligations.
Crucially, any such national rules only apply to personal data obtained through activities that are themselves covered by the secrecy obligation.
Member States must also notify the Commission of any rules they adopt under this article.
Important points:
- Member States may adopt national rules that limit supervisory authority access powers where controllers or processors are bound by professional secrecy obligations.
- These limiting rules apply only to personal data received or obtained in the course of activities covered by the secrecy obligation — not to all data held by the controller or processor.
- Member States are required to notify the Commission of any rules adopted under this article by 25 May 2018, and of any subsequent amendments without delay.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Member States may adopt specific rules to set out the powers of the supervisory authorities laid down in points (e) and (f) of Article 58(1) in relation to controllers or processors that are subject, under Union or Member State law or rules established by national competent bodies, to an obligation of professional secrecy or other equivalent obligations of secrecy where this is necessary and proportionate to reconcile the right of the protection of personal data with the obligation of secrecy. Those rules shall apply only with regard to personal data which the controller or processor has received as a result of or has obtained in an activity covered by that obligation of secrecy.
Each Member State shall notify to the Commission the rules adopted pursuant to paragraph 1, by 25 May 2018 and, without delay, any subsequent amendment affecting them.
Relevant recitals
Recital 164 Safeguarding professional secrecy
As regards the powers of the supervisory authorities to obtain from the controller or processor access to personal data and access to their premises, Member States may adopt by law, within the limits of this Regulation, specific rules in order to safeguard the professional or other equivalent secrecy obligations, in so far as necessary to reconcile the right to the protection of personal data with an obligation of professional secrecy. This is without prejudice to existing Member State obligations to adopt rules on professional secrecy where required by Union law.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
processing
Definition
controller
Definition
processor
Definition
supervisory authority
Definition
personal data