Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: FR

Article 90 Obligations de secret


Summary What does Article 90 of the GDPR regulation say?

This article addresses a specific tension within the regulation: what happens when a controller or processor is bound by professional secrecy obligations under national or Union law?

It gives Member States the flexibility to limit certain investigative powers of supervisory authorities — specifically the powers to access personal data and premises under Article 58(1) — where doing so is necessary and proportionate to reconcile data protection rights with secrecy obligations.

Crucially, any such national rules only apply to personal data obtained through activities that are themselves covered by the secrecy obligation.

Member States must also notify the Commission of any rules they adopt under this article.

Important points:

  • Member States may adopt national rules that limit supervisory authority access powers where controllers or processors are bound by professional secrecy obligations.
  • These limiting rules apply only to personal data received or obtained in the course of activities covered by the secrecy obligation — not to all data held by the controller or processor.
  • Member States are required to notify the Commission of any rules adopted under this article by 25 May 2018, and of any subsequent amendments without delay.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Les États membres peuvent adopter des règles spécifiques afin de définir les pouvoirs des autorités de contrôle visés à l'article 58, paragraphe 1, points e) et f) à l'égard des responsables du traitement ou des sous-traitants qui sont soumis, en vertu du droit de l'Union ou du droit d'un État membre ou de règles arrêtées par les organismes nationaux compétents, à une obligation de secret professionnel ou à d'autres obligations de secret équivalentes, lorsque cela est nécessaire et proportionné pour concilier le droit à la protection des données à caractère personnel et l'obligation de secret. Ces règles ne sont applicables qu'en ce qui concerne les données à caractère personnel que le responsable du traitement ou le sous-traitant a reçues ou a obtenues dans le cadre d'une activité couverte par ladite obligation de secret.

    1. Chaque État membre notifie à la Commission les règles qu'il adopte en vertu du paragraphe 1, au plus tard le 25 mai 2018, et, sans tarder, toute modification ultérieure les concernant.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod