Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: FR
- General data protection
Basic legislative acts
- GDPR regulation
Article 90 Obligations de secret
Summary What does Article 90 of the GDPR regulation say?
This article addresses a specific tension within the regulation: what happens when a controller or processor is bound by professional secrecy obligations under national or Union law?
It gives Member States the flexibility to limit certain investigative powers of supervisory authorities — specifically the powers to access personal data and premises under Article 58(1) — where doing so is necessary and proportionate to reconcile data protection rights with secrecy obligations.
Crucially, any such national rules only apply to personal data obtained through activities that are themselves covered by the secrecy obligation.
Member States must also notify the Commission of any rules they adopt under this article.
Important points:
- Member States may adopt national rules that limit supervisory authority access powers where controllers or processors are bound by professional secrecy obligations.
- These limiting rules apply only to personal data received or obtained in the course of activities covered by the secrecy obligation — not to all data held by the controller or processor.
- Member States are required to notify the Commission of any rules adopted under this article by 25 May 2018, and of any subsequent amendments without delay.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
Les États membres peuvent adopter des règles spécifiques afin de définir les pouvoirs des autorités de contrôle visés à l'article 58, paragraphe 1, points e) et f) à l'égard des responsables du traitement ou des sous-traitants qui sont soumis, en vertu du droit de l'Union ou du droit d'un État membre ou de règles arrêtées par les organismes nationaux compétents, à une obligation de secret professionnel ou à d'autres obligations de secret équivalentes, lorsque cela est nécessaire et proportionné pour concilier le droit à la protection des données à caractère personnel et l'obligation de secret. Ces règles ne sont applicables qu'en ce qui concerne les données à caractère personnel que le responsable du traitement ou le sous-traitant a reçues ou a obtenues dans le cadre d'une activité couverte par ladite obligation de secret.
Chaque État membre notifie à la Commission les règles qu'il adopte en vertu du paragraphe 1, au plus tard le 25 mai 2018, et, sans tarder, toute modification ultérieure les concernant.
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
données à caractère personnel
(En. personal data)
Definition
traitement
(En. processing)
Definition
responsable du traitement
(En. controller)
Definition
sous-traitant
(En. processor)