Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: FR

Article 91 Règles existantes des églises et associations religieuses en matière de protection des données


Summary What does Article 91 of the GDPR regulation say?

This article carves out a specific accommodation for churches and religious associations that already had their own comprehensive data protection rules in place when the GDPR came into force.

Rather than requiring these bodies to discard their existing frameworks, the article permits those rules to continue operating, on the condition that they are brought into alignment with the GDPR.

Crucially, this privilege comes with an oversight requirement: these bodies must be supervised by an independent supervisory authority, which can be one specific to them, but must meet the standards set out in Chapter VI of the Regulation governing supervisory authorities.

Important points:

  • Churches and religious associations with pre-existing comprehensive data protection rules may continue to apply them, provided those rules are brought into line with the GDPR.
  • These bodies must be subject to supervision by an independent supervisory authority — a dedicated one is permitted, but it must meet the conditions of Chapter VI of the Regulation.
  • This article acts as a limited exception within the broader GDPR framework, not an exemption from it.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Lorsque, dans un État membre, des églises et des associations ou communautés religieuses appliquent, à la date d'entrée en vigueur du présent règlement, un ensemble complet de règles relatives à la protection des personnes physiques à l'égard du traitement, elles peuvent continuer d'appliquer lesdites règles à condition de les mettre en conformité avec le présent règlement.

    1. Les églises et les associations religieuses qui appliquent un ensemble complet de règles conformément au paragraphe 1 du présent article sont soumises au contrôle d'une autorité de contrôle indépendante qui peut être spécifique, pour autant qu'elle remplisse les conditions fixées au chapitre VI du présent règlement.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod