Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: EN

Article 91 Existing data protection rules of churches and religious associations


Summary What does Article 91 of the GDPR regulation say?

This article carves out a specific accommodation for churches and religious associations that already had their own comprehensive data protection rules in place when the GDPR came into force.

Rather than requiring these bodies to discard their existing frameworks, the article permits those rules to continue operating, on the condition that they are brought into alignment with the GDPR.

Crucially, this privilege comes with an oversight requirement: these bodies must be supervised by an independent supervisory authority, which can be one specific to them, but must meet the standards set out in Chapter VI of the Regulation governing supervisory authorities.

Important points:

  • Churches and religious associations with pre-existing comprehensive data protection rules may continue to apply them, provided those rules are brought into line with the GDPR.
  • These bodies must be subject to supervision by an independent supervisory authority — a dedicated one is permitted, but it must meet the conditions of Chapter VI of the Regulation.
  • This article acts as a limited exception within the broader GDPR framework, not an exemption from it.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Where in a Member State, churches and religious associations or communities apply, at the time of entry into force of this Regulation, comprehensive rules relating to the protection of natural persons with regard to processing, such rules may continue to apply, provided that they are brought into line with this Regulation.

    1. Churches and religious associations which apply comprehensive rules in accordance with paragraph 1 of this Article shall be subject to the supervision of an independent supervisory authority, which may be specific, provided that it fulfils the conditions laid down in Chapter VI of this Regulation.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod