Source: OJ L 119, 4.5.2016, pp. 1–88Consolidated text

Current language: SV

Artikel 91 Befintliga bestämmelser om dataskydd inom kyrkor och religiösa samfund


Summary What does Article 91 of the GDPR regulation say?

This article carves out a specific accommodation for churches and religious associations that already had their own comprehensive data protection rules in place when the GDPR came into force.

Rather than requiring these bodies to discard their existing frameworks, the article permits those rules to continue operating, on the condition that they are brought into alignment with the GDPR.

Crucially, this privilege comes with an oversight requirement: these bodies must be supervised by an independent supervisory authority, which can be one specific to them, but must meet the standards set out in Chapter VI of the Regulation governing supervisory authorities.

Important points:

  • Churches and religious associations with pre-existing comprehensive data protection rules may continue to apply them, provided those rules are brought into line with the GDPR.
  • These bodies must be subject to supervision by an independent supervisory authority — a dedicated one is permitted, but it must meet the conditions of Chapter VI of the Regulation.
  • This article acts as a limited exception within the broader GDPR framework, not an exemption from it.

Springlex's summary of the article is a reading aid, not a substitute for the legal text.

    1. Om kyrkor och religiösa samfund eller gemenskaper i en medlemsstat vid tidpunkten för ikraftträdandet av denna förordning tillämpar övergripande bestämmelser om skyddet av fysiska personer i samband med behandling, får sådana befintliga bestämmelser fortsätta att tillämpas under förutsättning att de görs förenliga med denna förordning.

    1. Kyrkor och religiösa samfund som tillämpar övergripande bestämmelser i enlighet med punkt 1 i denna artikel ska vara föremål för kontroll av en oberoende tillsynsmyndighet som kan vara specifik, förutsatt att den uppfyller de villkor som fastställs i kapitel VI i denna förordning.

We're continuously improving our platform to serve you better.

Your feedback matters! Let us know how we can improve.

Found a bug?

Springflod is a Swedish boutique consultancy firm specialising in cyber security within the financial services sector.

We offer professional services concerning information security governance, risk and compliance.

Crafted with ❤️ by Springflod