Art. 90 GDPR – Obligations of secrecy

  1. 1Member States may adopt specific rules to set out the powers of the supervisory authorities laid down in points (e) and (f) of Article 58(1) in relation to controllers or processors that are subject, under Union or Member State law or rules established by national competent bodies, to an obligation of professional secrecy or other equivalent obligations of secrecy where this is necessary and proportionate to reconcile the right of the protection of personal data with the obligation of secrecy. 2Those rules shall apply only with regard to personal data which the controller or processor has received as a result of or has obtained in an activity covered by that obligation of secrecy.
  2. Each Member State shall notify to the Commission the rules adopted pursuant to paragraph 1, by 25 May 2018 and, without delay, any subsequent amendment affecting them.

Frequently Asked Questions about Article 90

+What does Article 90 GDPR say about professional secrecy?
Article 90 lets member states set rules governing the powers of supervisory authorities over controllers and processors who are subject to professional secrecy obligations.
+How does the GDPR treat confidential professions?
It allows specific national rules to reconcile data protection supervision with duties of secrecy in professions such as law, medicine, or other regulated fields.
+ Can authorities access data held under professional secrecy?
Access may be limited by national rules that protect professional secrecy, balancing supervision with confidentiality obligations.

Related Key Issues

Scroll to Top