CHAPTER IXPROVISIONS RELATING TO SPECIFIC PROCESSING SITUATIONS

Article 89Safeguards and derogations relating to processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes

Official text

(1)Processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes, shall be subject to appropriate safeguards, in accordance with this Regulation, for the rights and freedoms of the data subject. Those safeguards shall ensure that technical and organisational measures are in place in particular in order to ensure respect for the principle of data minimisation. Those measures may include pseudonymisation provided that those purposes can be fulfilled in that manner. Where those purposes can be fulfilled by further processing which does not permit or no longer permits the identification of data subjects, those purposes shall be fulfilled in that manner.

(2)Where personal data are processed for scientific or historical research purposes or statistical purposes, Union or Member State law may provide for derogations from the rights referred to in Articles 15, 16, 18 and 21 subject to the conditions and safeguards referred to in paragraph 1 of this Article in so far as such rights are likely to render impossible or seriously impair the achievement of the specific purposes, and such derogations are necessary for the fulfilment of those purposes.

(3)Where personal data are processed for archiving purposes in the public interest, Union or Member State law may provide for derogations from the rights referred to in Articles 15, 16, 18, 19, 20 and 21 subject to the conditions and safeguards referred to in paragraph 1 of this Article in so far as such rights are likely to render impossible or seriously impair the achievement of the specific purposes, and such derogations are necessary for the fulfilment of those purposes.

(4)Where processing referred to in paragraphs 2 and 3 serves at the same time another purpose, the derogations shall apply only to processing for the purposes referred to in those paragraphs.

Commentary

Article 89 creates a carefully balanced legal regime for socially valuable uses of personal data. It recognises that archives, scientific and historical research, and statistics may require large datasets, long retention periods and repeated analysis, but it does not give researchers or archivists a general exemption from the GDPR.

The basic bargain is:

Organisations may receive limited flexibility when personal data are genuinely processed for public-interest archiving, scientific or historical research, or statistics. In return, they must build strong safeguards into the processing and use any derogation from individual rights only where exercising the right would make the specific project impossible or seriously impair it.

Article 89 contains four connected rules:

  1. Paragraph 1 imposes mandatory safeguards for all four protected purposes.
  2. Paragraph 2 permits limited legal derogations from four data-subject rights for scientific research, historical research and statistical processing.
  3. Paragraph 3 permits somewhat broader legal derogations for archiving in the public interest.
  4. Paragraph 4 confines those derogations to the protected purpose, preventing them from spreading to commercial, administrative or decision-making uses of the same data.

The Article’s full meaning also depends on Articles 5, 6, 9, 13, 14 and 17, national law, research ethics, professional standards and sector-specific legislation such as clinical-trial law. The official text confirms that pseudonymisation is only one possible safeguard, that genuinely non-identifiable processing must be preferred where it can fulfil the purpose, and that derogations require a Union or Member State law rather than a unilateral decision by the controller.gdpr-info+2

A further contemporary development is the EDPB’s Guidelines 1/2026 on scientific research, adopted for public consultation on 15 April 2026. As of August 2026, the text should still be treated as draft guidance rather than final binding law, but it provides an important indication of developing regulatory interpretation. The consultation closed on 25 June 2026.europa+2


1. Why Article 89 exists

Many socially valuable projects depend on personal data.

A medical study may need to follow patients over twenty years to understand whether an early treatment affects later health. A historical project may need employment, migration or court records to explain past discrimination. A national statistical agency may need household information to calculate unemployment or population trends. A public archive may need to preserve politically sensitive records so that future generations can understand state wrongdoing.

Ordinary GDPR principles still matter in all these settings. However, applying every rule without adjustment could sometimes defeat the purpose.

Illustration: long-term medical research

A university studies whether a childhood environmental exposure contributes to adult cardiovascular disease. The project may need:

  • childhood medical history;
  • residential location;
  • environmental measurements;
  • adult health outcomes;
  • family histories;
  • repeated follow-up information. Deleting every participant’s historical information as soon as it is no longer needed for clinical treatment would make the long-term study impossible. Yet keeping identifiable health data indefinitely without controls would create serious privacy and security risks. Article 89 permits the study to retain and analyse the required information if:
  • a valid lawful basis exists;
  • Article 9 conditions are satisfied;
  • the research is genuine;
  • necessary data are minimised;
  • identities are separated or removed where possible;
  • access is restricted;
  • rights are protected;
  • any derogation is legally authorised and strictly necessary. Article 89 is therefore neither a barrier to research nor a blank cheque. It is an accountability framework.

2. Article 89 does not itself create a lawful basis

One of the most important technical points is that Article 89 is not an independent lawful basis.

A controller cannot say:

“We are conducting research, so Article 89 authorises the processing.”

The controller must separately identify an Article 6 basis. Depending on the circumstances, that may be:

  • consent under Article 6(1)(a);
  • contractual necessity under Article 6(1)(b), although this will be uncommon for research;
  • legal obligation under Article 6(1)(c);
  • vital interests under Article 6(1)(d);
  • public task under Article 6(1)(e);
  • legitimate interests under Article 6(1)(f), where available and properly balanced.

If special-category data are involved, the controller must also satisfy Article 9. A common route may be Article 9(2)(j), which permits processing necessary for archiving in the public interest, scientific or historical research, or statistical purposes where based on Union or Member State law, proportionate to the aim, respectful of the essence of data protection and accompanied by suitable and specific safeguards.

Illustration

A private pharmaceutical company conducts research using genetic and health data. It cannot rely solely on Article 89. It must establish:

  1. an Article 6 lawful basis;
  2. an Article 9 exception;
  3. compliance with the applicable national research law;
  4. Article 89 safeguards;
  5. clinical-trial and ethical requirements where applicable.

The legal analysis therefore has several layers. Article 89 regulates safeguards and possible rights derogations. It does not answer every question of lawfulness.

The EDPS has likewise described the GDPR research regime as a special framework that retains ordinary principles such as lawfulness and rights while allowing carefully defined flexibility for genuine research projects operating in an ethical framework.europa+1


3. Article 89 and compatible further processing

Article 5(1)(b) provides that further processing for:

  • archiving in the public interest;
  • scientific or historical research;
  • statistical purposes

is not considered incompatible with the original purpose, subject to Article 89(1).

This compatibility presumption is valuable, but it is often misunderstood.

It does not mean that every reuse labelled “research” is automatically lawful. The controller still needs:

  • a lawful basis;
  • Article 9 compliance where relevant;
  • genuine protected purpose;
  • safeguards;
  • transparency or a valid exception;
  • purpose-specific governance.

Illustration

A hospital originally collected health data to treat patients. Years later, a university wishes to study treatment outcomes. The new scientific purpose may be presumed compatible with the original treatment purpose if Article 89 safeguards apply. However, the hospital cannot simply transfer complete identifiable records without asking:

  • Can the university use pseudonymised data?
  • Are all fields necessary?
  • Is national law applicable?
  • Who is controller?
  • Is an Article 9 condition available?
  • What notice is required?
  • Is a DPIA necessary?
  • Are transfer safeguards needed?
  • How long will data be retained? The compatibility presumption removes one obstacle. It does not remove the rest of the GDPR. The draft 2026 EDPB guidance confirms that further processing for scientific research is treated as presumptively compatible, but genuine scientific qualification, lawfulness and Article 89 safeguards remain necessary.europa+1

4. The four protected purposes are distinct

Article 89 addresses four purposes:

  1. archiving in the public interest;
  2. scientific research;
  3. historical research;
  4. statistical purposes.

These categories overlap, but they are not interchangeable. A controller should identify the actual purpose instead of using “research” as a general label.

The distinction matters because paragraphs 2 and 3 permit different derogations. Scientific research, historical research and statistics may receive derogations from Articles 15, 16, 18 and 21. Public-interest archiving may additionally receive derogations from Articles 19 and 20.gdpr-info+1


5. Archiving in the public interest

Archiving means much more than keeping old files.

Recital 158 describes relevant archival functions as acquiring, preserving, appraising, arranging, describing, communicating, promoting, disseminating and providing access to records of enduring value in the general public interest.

Qualifying archival bodies may include:

  • national archives;
  • municipal archives;
  • libraries with statutory archival functions;
  • museums;
  • universities;
  • public broadcasters;
  • public or private institutions legally entrusted with preserving records of enduring value.

The phrase“in the public interest” is essential.

Illustration: qualifying archive

A national archive preserves:

  • cabinet documents;
  • historical census information;
  • records of political persecution;
  • documents concerning war crimes;
  • public-health records of historical significance. The objective is to preserve collective memory, support accountability and enable future research.

Illustration: ordinary business storage

A retailer keeps every customer’s transaction history forever because the information may be commercially valuable. That is not public-interest archiving merely because the records are old. Likewise, a company’s backup system is not automatically an archive in the Article 89 sense. Backups typically serve:

  • disaster recovery;
  • continuity;
  • security. Those purposes may justify retention, but they are not necessarily public-interest archiving.

5.1 Private archives

A private institution may perform public-interest archival functions if law entrusts it with the preservation of records of enduring public value.

The relevant question is not simply ownership. It is whether the archival activity has a recognised public-interest purpose and legal framework.

[!example] Illustration A private foundation is legally authorised to preserve and provide controlled access to records concerning a former authoritarian regime. Its private status does not automatically exclude Article 89. By contrast, a private family storing photographs and correspondence for personal reasons is not ordinarily carrying out public-interest archiving, although ordinary GDPR rules may or may not apply depending on the household exemption and broader circumstances.

6. Scientific research

Recital 159 says scientific research should be interpreted broadly and includes:

  • fundamental research;
  • applied research;
  • technological development;
  • demonstration activities;
  • privately funded research;
  • public-health studies.

The concept is not confined to universities or non-profit institutions. Commercial medical, technical or industrial research may qualify.

However, commercial activity does not become scientific merely because an organisation applies data analysis or calls its team “research and development.”

The EDPB’s 2026 draft guidance proposes six indicative factors for genuine scientific research:

  1. a methodical and systematic approach;
  2. adherence to recognised ethical standards;
  3. verifiability and transparency of methods;
  4. autonomy and independence;
  5. a genuine research objective;
  6. potential to contribute to existing knowledge or apply knowledge in a novel way.

Where the factors are absent, the controller should be able to justify why the activity nevertheless qualifies as scientific research.europa+2

Illustration: genuine commercial research

A pharmaceutical company conducts a controlled study of a new treatment according to:

  • a research protocol;
  • defined hypotheses;
  • recognised scientific methods;
  • ethics oversight;
  • clinical-trial requirements;
  • reproducible analysis;
  • publication or regulatory review. The commercial context does not prevent the activity from being scientific.

Illustration: ordinary product analytics

A retailer analyses customer browsing to increase sales by predicting which advertisement will generate a purchase. The analysis may be complex and use statistical models, but its immediate purpose is individual advertising, not the generation of scientific knowledge. Calling it “consumer science” does not automatically activate Article 89.

6.1 AI development

AI training may or may not be scientific research.

[!example] Illustration A university develops a diagnostic model under a structured research protocol, tests hypotheses, subjects results to peer review and studies generalisable medical questions. The project may qualify. A company trains a recommendation system solely to increase individual engagement and advertising revenue. That is less likely to qualify merely because machine learning is technologically sophisticated. The purpose, methodology, independence, ethics and contribution to knowledge matter more than the technology used.

7. Historical research

Historical research examines past events, institutions, communities, persons and social developments.

It may use:

  • census records;
  • employment records;
  • court files;
  • medical archives;
  • letters;
  • photographs;
  • oral histories;
  • religious records;
  • migration data;
  • military records;
  • government surveillance files.

Recital 160 indicates that historical research includes genealogical research, while reminding controllers that the GDPR does not apply to deceased persons as such.

Illustration

A historian studies how minority communities were treated by public institutions during the twentieth century. The project may require identifiable records to:

  • trace decisions;
  • understand institutional responsibility;
  • connect records across time;
  • correct historical narratives. Removing every name could defeat the research purpose.

7.1 Living persons connected with deceased persons

The GDPR’s non-application to deceased persons does not mean that every record about a deceased person is outside the Regulation.

Illustration

A deceased individual’s genetic information reveals that a living relative has a hereditary condition. The information relates to the living relative and may therefore be their personal, genetic or health data. Similarly, a historical file concerning a deceased political activist may identify living informants, family members or victims. Controllers should analyse every person to whom the information may relate, not only the principal historical subject.

7.2 Historical research versus public curiosity

Research into past events should involve a genuine historical purpose.

A website republishing old private records solely to attract clicks is not necessarily historical research merely because the records are old.

Relevant indicators include:

  • systematic inquiry;
  • contextual analysis;
  • historical methodology;
  • public or scholarly contribution;
  • source criticism;
  • ethical treatment;
  • accountable publication.

8. Statistical purposes

Recital 162 defines statistical purposes as operations needed for statistical surveys or the production of statistical results.

The defining feature is that the result should ordinarily be aggregate information, and neither the result nor the underlying personal data should be used to make measures or decisions concerning a particular natural person.

Illustration: genuine statistical use

A national statistics office uses individual income records to calculate:

  • average household income;
  • regional inequality;
  • unemployment rates. The published results contain aggregated figures and are not used to decide whether a specific individual receives a benefit.

Illustration: individual scoring disguised as statistics

A lender analyses a large dataset and produces a “statistical risk score” for each applicant. It uses each score to approve or reject credit. The use is not purely statistical in the Recital 162 sense because the processing supports a measure or decision about an identifiable individual. The fact that an algorithm uses statistical methods does not make its purpose statistical.

8.1 Aggregated data may still be personal data

Aggregation does not automatically produce anonymity.

9. Article 89(1): Safeguards are mandatory

Paragraph 1 uses the phrase“shall be subject to appropriate safeguards.”

This is not optional.

Every processing operation within Article 89’s protected purposes must have safeguards. The requirement applies even where the controller does not use a derogation under paragraphs 2 or 3.

The safeguards must:

  • protect rights and freedoms;
  • comply with the GDPR;
  • include technical and organisational measures;
  • particularly ensure data minimisation.

Pseudonymisation is one example. Anonymisation or genuinely non-identifiable processing becomes necessary where the purpose can still be fulfilled in that form.gdpr-info+1

A controller should not start with:

“Which rights can we switch off?”

It should start with:

“How can we achieve the purpose using the least identifying and least intrusive data?”


10. Data minimisation

Data minimisation means that personal data must be:

  • adequate;
  • relevant;
  • limited to what is necessary.

In research, “more data may be useful” is not the same as “all available data are necessary.”

Illustration

A study examines whether night-shift work affects cardiovascular health. Potentially relevant data may include:

  • work schedule;
  • age;
  • health outcomes;
  • lifestyle factors. The researchers should justify why they also need:
  • private messages;
  • political opinions;
  • complete browsing history;
  • unrelated disciplinary records. The possibility that a field might produce an interesting correlation does not automatically establish necessity.

10.1 Data minimisation throughout the lifecycle

Minimisation applies to:

  • selection of participants;
  • variables collected;
  • level of detail;
  • identifiers;
  • access;
  • retention;
  • publication.

The project may need detailed data during one phase but not later.

[!example] Illustration A longitudinal study initially needs contact details to arrange follow-up appointments. After follow-up ends, the analysis team may need only coded records. Direct contact details should be separated or deleted if no longer required. Minimisation is dynamic. It should be reviewed as the project evolves.

11. Pseudonymisation

Article 4(5) defines pseudonymisation as processing personal data so that they can no longer be attributed to a specific person without additional information, provided that the additional information is kept separately and protected.

Illustration

A hospital replaces each patient’s name and medical number with a study code. The research dataset contains:

  • study code;
  • diagnosis;
  • treatment;
  • outcome. A separate mapping table connects the study code with the patient’s identity. The analysis team does not receive the mapping table. This reduces risk, but the dataset remains personal data because re-identification remains possible through the additional information.

11.1 Effective pseudonymisation requires more than removing names

Removing direct identifiers may be inadequate where combinations reveal identity.

Illustration

A dataset contains:

  • exact date of birth;
  • rare diagnosis;
  • small village;
  • employer;
  • exact treatment date. Even without a name, the individual may be identifiable. Effective pseudonymisation may require:
  • broader age bands;
  • less precise locations;
  • date shifting;
  • rare-category suppression;
  • separate keys;
  • restricted linkage;
  • contractual prohibitions;
  • audit logging.

11.2 Separation is essential

The mapping information should be kept:

  • separately;
  • under different access rights;
  • under strong encryption;
  • with controlled re-identification procedures.

If every researcher can access both the coded data and the mapping key, pseudonymisation provides little practical protection.


12. Anonymisation and the mandatory preference for non-identifiable processing

Article 89(1) says that where the relevant purposes can be fulfilled through further processing that does not permit, or no longer permits, identification, the purposes shall be fulfilled in that manner.

This creates a hierarchy:

  1. Use anonymous or non-identifiable data where sufficient.
  2. If identification remains necessary, consider pseudonymisation.
  3. Use directly identifiable information only where the purpose genuinely requires it.

Illustration

A city studies average household water consumption by district. It does not need names, addresses or customer account numbers in the final analytical dataset. Properly anonymised district-level data should be used if they can produce reliable results. By contrast, a clinical trial monitoring adverse reactions may need to reconnect findings to individual participants so that clinicians can intervene. Full anonymisation may defeat participant safety.

12.1 Anonymisation is difficult

Data are anonymous only where people are no longer identifiable, taking account of means reasonably likely to be used.

Possible risks include:

  • singling out;
  • linkage;
  • inference;
  • attacks using external datasets;
  • rare-value identification;
  • future technical developments.

Draft EDPB anonymisation guidance adopted in July 2026 remains under consultation and therefore should not yet be treated as final. It continues to emphasise isolation, linkage and inference risks when determining whether data are truly anonymous.europa+2


13. Other technical safeguards

Article 89 does not limit safeguards to pseudonymisation and anonymisation.

Other technical measures may include:

  • encryption;
  • access controls;
  • secure research environments;
  • multi-factor authentication;
  • network segregation;
  • query controls;
  • download restrictions;
  • privacy-preserving record linkage;
  • differential privacy;
  • synthetic datasets;
  • aggregation thresholds;
  • disclosure review;
  • audit logs;
  • deletion controls;
  • secure key management.

Illustration: secure research environment

Researchers do not download raw health records. They access them through a controlled environment where:

  • copying is restricted;
  • queries are logged;
  • outputs are reviewed;
  • identifiers are masked;
  • internet access is limited;
  • data cannot be exported without approval. This reduces the risk of misuse while preserving valuable analysis.

13.1 Synthetic data

Synthetic data can reduce risk where it reproduces statistical patterns without corresponding directly to real individuals.

However, the controller should verify:

  • whether the synthetic data reproduce rare real records;
  • whether the model memorised source data;
  • whether re-identification is possible;
  • whether outputs reveal membership.

“Artificially generated” does not automatically mean anonymous.


14. Organisational safeguards

Technical controls are insufficient without governance.

Suitable organisational measures may include:

  • defined research protocol;
  • ethics review;
  • data management plan;
  • role allocation;
  • confidentiality undertakings;
  • staff training;
  • independent oversight;
  • access approval;
  • incident response;
  • publication review;
  • retention schedule;
  • re-identification rules;
  • participant complaint process;
  • regular audits.

The 2021 study prepared for the EDPB found substantial divergence among national laws and identified safeguards such as DPO involvement, DPIAs, access restrictions, encryption, professional secrecy and documentation. The study itself states that its views are those of its authors and not an official EDPB position, so it is useful comparative material rather than binding guidance.europa

14.1 Ethics approval is important but not sufficient

An ethics committee may assess:

  • participant welfare;
  • research methodology;
  • consent;
  • risk;
  • fairness.

But ethics approval does not itself prove GDPR compliance.

The controller still needs:

  • lawful basis;
  • notices;
  • contracts;
  • security;
  • retention rules;
  • international-transfer compliance;
  • rights procedures.

Similarly, DPO approval cannot substitute for the controller’s legal responsibility.


15. Transparency

Research participants should ordinarily be informed under Articles 13 or 14.

Information may include:

  • research purpose;
  • controller identity;
  • data sources;
  • lawful basis;
  • categories;
  • recipients;
  • retention;
  • rights;
  • international transfers;
  • contact details;
  • complaint rights.

Article 14 contains limited exceptions where personal data were not obtained directly, including situations where providing information proves impossible or would involve disproportionate effort, particularly for archiving, research or statistical processing, subject to Article 89 safeguards. That exception is not automatic.

Illustration

A historical study uses millions of records collected a century ago. Contacting every living person reflected in or affected by the records may be impossible. The controller should still consider alternative transparency measures, such as:

  • public project notice;
  • website explanation;
  • archive catalogue statement;
  • notices through relevant communities;
  • accessible rights procedure. “Disproportionate effort” does not mean “sending notices would cost money.” It requires a reasoned assessment of burden, feasibility, risk and available alternatives.

Recital 33 recognises that scientific purposes may not always be fully identifiable when data are collected. It permits consent to certain areas of scientific research where consistent with recognised ethical standards. Participants should be able to consent only to particular areas or project parts to the extent allowed by the intended purpose.

Broad consent is not consent to:

“Any research, by anyone, forever, for every purpose.”

A valid broad-consent model should identify a meaningful research area.

Better example

“Research concerning causes, diagnosis and treatment of neurodegenerative disease.”

Poor example

“Any present or future research that we or our partners consider useful.”

Safeguards may include:

  • ethics oversight;
  • staged information;
  • participant portal;
  • withdrawal mechanisms;
  • project updates;
  • limits on recipients;
  • governance review;
  • pseudonymisation.

The draft 2026 EDPB guidance addresses broad and dynamic consent but remains non-final as of August 2026. It treats broad consent as requiring a defined research area and additional safeguards rather than unrestricted permission.igdpr+2

Consent to undergo a medical intervention or join a clinical trial is ethically and legally distinct from consent as the GDPR lawful basis for processing.

A clinical trial may involve:

  • informed consent to participate;
  • a different GDPR lawful basis;
  • Article 9 conditions;
  • clinical-trial legislation;
  • safety reporting obligations.

Recital 161 specifically points to Regulation 536/2014 for consent to clinical-trial participation.

Withdrawal from a trial and withdrawal of GDPR consent may therefore have different effects. Some data may need to remain for:

  • safety;
  • scientific integrity;
  • legal obligations;
  • regulatory records.

These consequences should be explained clearly.


17. Special-category data

Research frequently uses:

  • genetic data;
  • biometric data;
  • health data;
  • racial or ethnic origin;
  • political opinions;
  • religious beliefs;
  • trade-union status;
  • sexual orientation.

Article 9 prohibits such processing unless an exception applies.

Article 9(2)(j) may permit necessary research, statistical or archival processing where:

  • based on Union or Member State law;
  • proportionate;
  • respectful of the essence of data protection;
  • accompanied by suitable and specific measures.

Illustration

A university researches discrimination using ethnicity and employment outcomes. The study’s importance does not eliminate Article 9. The university needs a valid Article 9 route and should implement safeguards such as:

  • pseudonymisation;
  • aggregation;
  • access restrictions;
  • disclosure control;
  • ethics review;
  • minimised publication. Consent may be one route, but it is not universally required or always appropriate.

18. Data Protection Impact Assessments

A DPIA is required under Article 35 where processing is likely to create high risk.

Research projects are particularly likely to require a DPIA where they involve:

  • large-scale health or genetic data;
  • vulnerable participants;
  • systematic monitoring;
  • AI inference;
  • linkage of multiple databases;
  • criminal records;
  • novel technologies;
  • long-term tracking;
  • international data sharing.

A DPIA should examine:

  • purpose;
  • necessity;
  • proportionality;
  • risks;
  • security;
  • rights;
  • re-identification;
  • publication;
  • participant vulnerability;
  • mitigation.

Illustration

A project links national health, education and tax records to study intergenerational disadvantage. Even if each linkage serves a genuine scientific purpose, the combined dataset may reveal an exceptionally detailed life profile. The DPIA should ask whether:

  • linkage needs direct identifiers;
  • a trusted intermediary can link records;
  • analysts need row-level access;
  • outputs could stigmatise small communities;
  • retention is justified;
  • participants can exercise rights.

19. Publication and disclosure of research results

Article 89 protects the research process, but publication can create new risks.

Researchers should ensure that outputs do not reveal individuals through:

  • direct identifiers;
  • rare combinations;
  • detailed quotations;
  • photographs;
  • small sample sizes;
  • genetic findings;
  • precise locations;
  • unique timelines.

Illustration

A paper describes: “The only female neurosurgeon aged 43 in a named hospital who received treatment for addiction.” The combination may identify the person even without a name. Safeguards may include:

  • broader categories;
  • removal of location;
  • suppression of rare cells;
  • paraphrased quotations;
  • participant review in qualitative research;
  • controlled-access publication;
  • delayed release. Research transparency and reproducibility do not always require public release of raw identifiable data. Verification may occur through:
  • secure access;
  • approved researchers;
  • audited environments;
  • reproducible code;
  • synthetic datasets;
  • restricted repositories.

20. Article 89(2): Derogations for scientific research, historical research and statistics

Paragraph 2 allows Union or Member State law to create derogations from:

  • Article 15, access;
  • Article 16, rectification;
  • Article 18, restriction;
  • Article 21, objection.

The derogations are not created automatically by Article 89 itself.

A controller cannot simply decide:

“Answering this access request is inconvenient, so Article 89 lets us refuse.”

There must be an applicable Union or Member State law providing the derogation. The law must be read strictly and applied only where:

  1. Article 89(1) safeguards are present;
  2. exercising the right is likely to make the specific purpose impossible or seriously impair it;
  3. the derogation is necessary to fulfil that purpose.gdpr-info+2

This is a demanding cumulative test.


21. Derogation from Article 15 access

Access ordinarily allows the person to obtain:

  • confirmation of processing;
  • a copy of personal data;
  • processing information.

In some research projects, unrestricted access could compromise:

  • blinded trials;
  • confidentiality of others;
  • test validity;
  • research methodology;
  • source protection;
  • massive archival systems not indexed by person.

Illustration: blinded clinical trial

A participant requests information revealing whether they received the drug or placebo while the trial remains blinded. Immediate disclosure could:

  • influence behaviour;
  • invalidate results;
  • compromise safety analysis. A carefully limited and time-bound derogation may be necessary if authorised by law. The controller should consider whether delayed access after unblinding would protect both interests.

Illustration: large historical dataset

A researcher holds millions of unindexed scanned records. Locating every reference to one individual might require years of manual review. The controller should not assume impossibility merely because retrieval is expensive. It should assess:

  • indexing capability;
  • risk;
  • scope of request;
  • whether partial access is possible;
  • whether identification would require new processing not otherwise needed;
  • national-law conditions.

22. Derogation from Article 16 rectification

Rectification is complicated in research and archives because historical records may accurately show what was recorded at the time, even if the recorded information was false.

Illustration

A historical police file falsely described a person as politically dangerous. Changing the original document would destroy evidence of past state misconduct. A better safeguard may be:

  • preserve the original;
  • attach a correction;
  • record the dispute;
  • explain that the allegation was false;
  • ensure future researchers see both. In scientific datasets, rectification may be necessary where an input value is simply wrong.

[!example] Illustration A participant’s blood pressure was entered as 820 instead of 120. Correcting the value supports both the person’s rights and research accuracy. A blanket rectification derogation would be difficult to justify. The controller must distinguish preserving historical authenticity from retaining avoidable factual errors in an analytical dataset.

23. Derogation from Article 18 restriction

Restriction ordinarily permits personal data to be stored but temporarily prevents other processing in specified circumstances.

A restriction request may seriously impair a project if removing one person’s data from active analysis would invalidate a longitudinal dataset or trial.

However, the controller should examine whether the data can be:

  • temporarily excluded;
  • flagged;
  • analysed separately;
  • included only in locked results;
  • retained without new use.

[!example] Illustration A participant disputes whether a laboratory result belongs to them. Continuing to analyse the disputed value may corrupt the research. Restriction may actually improve research integrity until identity is resolved. The existence of a research purpose does not automatically make restriction harmful.

24. Derogation from Article 21 objection

Where processing relies on public task or legitimate interests, a person may ordinarily object based on their particular situation.

Article 21(6) already contains a research-specific rule: where processing is necessary for scientific, historical or statistical purposes under Article 89(1), the person has the right to object unless processing is necessary for a task carried out for reasons of public interest.

Article 89(2) may permit further legal derogation where objections would make the specific purpose impossible or seriously impair it and the derogation is necessary.

Illustration

A national epidemiological study requires near-complete population data to detect a rare fatal condition. Allowing large-scale opt-out may create severe selection bias and undermine the study’s reliability. A national law may restrict objection if:

  • the study serves public interest;
  • safeguards are strong;
  • individual risk is minimised;
  • data are pseudonymised;
  • no decisions are made about participants. By contrast, a commercial research project studying consumer preferences may have a weaker basis for removing objection rights completely.

25. Rights not listed in paragraph 2 remain applicable

Paragraph 2 does not authorise derogation from every data-subject right.

It does not list:

  • Articles 13 and 14 transparency;
  • Article 17 erasure;
  • Article 19 notification;
  • Article 20 portability;
  • Article 22 automated decisions.

Other GDPR provisions may contain their own qualifications.

For example, Article 17(3)(d) limits erasure where processing is necessary for Article 89 purposes and erasure is likely to make the objectives impossible or seriously impair them.

This is not the same as a national derogation under paragraph 2.

[!example] Illustration A researcher cannot state: “Article 89 means no one has a right to erasure.” The researcher must examine Article 17 itself, the specific purpose, necessity, impairment and safeguards.

26. Article 89(3): Derogations for public-interest archiving

Paragraph 3 allows Union or Member State law to provide derogations from:

  • Article 15, access;
  • Article 16, rectification;
  • Article 18, restriction;
  • Article 19, notification to recipients;
  • Article 20, portability;
  • Article 21, objection.

The same strict conditions apply:

  • paragraph 1 safeguards;
  • likely impossibility or serious impairment;
  • necessity;
  • valid Union or Member State law.

The broader list reflects the distinctive nature of archives. Archives preserve authentic records and may hold materials over very long periods in formats not designed for individual data-service requests.


27. Article 19 recipient notification

Article 19 generally requires a controller to communicate rectification, erasure or restriction to recipients, unless impossible or disproportionate.

In an archive, a document may have been consulted by:

  • thousands of researchers;
  • libraries;
  • museums;
  • public bodies;
  • publishers.

Notifying every past recipient may be impossible or may threaten the integrity of archival dissemination.

A national derogation may therefore be justified.

However, the archive should consider proportionate alternatives, such as:

  • updating the catalogue;
  • adding correction notices;
  • informing current licensed users;
  • correcting future copies;
  • publishing an erratum.

28. Article 20 portability

Portability concerns personal data provided by the individual where processing is automated and based on consent or contract.

It may rarely fit archival processing, but paragraph 3 allows legal derogation where necessary.

Illustration

A person asks a national archive to provide all historical records concerning them in a structured machine-readable format. The archive may hold:

  • handwritten letters;
  • scanned documents;
  • analogue recordings;
  • third-party records. Creating a new machine-readable dataset could be practically burdensome and may disclose other people’s data. The archive must still assess whether Article 20 applies at all before invoking a derogation. If processing is not based on consent or contract, or the data were not “provided by” the individual in the relevant sense, portability may already be unavailable.

29. The “impossible or seriously impair” threshold

This threshold is deliberately high.

Minor inconvenience is insufficient.

The controller should demonstrate concrete effects, such as:

  • invalidation of the study;
  • destruction of archival integrity;
  • severe statistical bias;
  • compromise of blinding;
  • loss of essential longitudinal continuity;
  • disproportionate diversion of resources that would terminate the project;
  • disclosure of protected research methods or confidential third-party data.

Weak justification

“Responding would take staff time.”

Stronger justification

“Removing participants after outcome events have been incorporated into a small controlled trial would invalidate the pre-specified statistical model, make reproducibility impossible and require destruction of regulatory evidence, while pseudonymised data are already locked and no new individual use occurs.”

Even then, the controller must consider narrower alternatives.

The test is project-specific. An organisation cannot rely on a generic policy that all rights always impair research.


30. Necessity of the derogation

Even where a right creates serious impairment, the derogation must be necessary.

The controller should consider:

  • delay rather than refusal;
  • partial access;
  • redaction;
  • correction by annotation;
  • temporary restriction;
  • aggregation;
  • pseudonymisation;
  • independent intermediary;
  • staged disclosure;
  • secure access;
  • project-specific exceptions.

[!example] Illustration A participant’s access request would reveal treatment allocation during a blinded trial. A temporary delay until unblinding may be sufficient. A permanent refusal after trial completion would be harder to justify. Necessity requires the least rights-restrictive effective option.

31. Article 89(4): Mixed-purpose processing

Paragraph 4 prevents research or archival derogations from leaking into unrelated processing.

Where the same data serve both:

  • a protected Article 89 purpose; and
  • another purpose.

the derogation applies only to the protected purpose.

Illustration

A pharmaceutical company holds patient data for:

  1. scientific safety research;
  2. targeted product marketing.

A lawful research derogation from access or objection cannot be used to refuse rights concerning marketing.

Illustration

A university stores student records for:

  1. historical research;
  2. current disciplinary decision-making.

The university cannot apply the historical-research derogation to the current disciplinary use.

31.1 Practical separation

Mixed purposes should be separated through:

  • different systems;
  • separate access roles;
  • distinct notices;
  • purpose tags;
  • different retention rules;
  • different lawful bases;
  • independent decision pathways.

If the data remain in one database, governance must still distinguish the operations.

A research label cannot immunise the whole database.


32. Research results used for individual decisions

Recital 162 says statistical results and underlying data should not be used to support measures or decisions concerning a particular person.

Recital 159 similarly indicates that if scientific research results justify further measures in the individual’s interest, the ordinary GDPR rules apply to those measures.

Illustration

A research project discovers that a participant may have a life-threatening condition. The project may have a protocol for returning clinically significant findings. Once the hospital uses the finding to:

  • contact the patient;
  • diagnose;
  • alter treatment. that operation is individual healthcare processing. Ordinary GDPR and medical-law rules apply. Similarly, a research model may later be deployed in employment or credit decisions. Operational deployment is a new purpose and does not automatically inherit Article 89 privileges.

33. International transfers

Article 89 does not exempt research transfers from Chapter V.

A research consortium transferring personal data outside the EEA may need:

  • adequacy decision;
  • standard contractual clauses;
  • binding corporate rules;
  • another Article 46 safeguard;
  • a narrowly interpreted Article 49 derogation.

Illustration

A European hospital transfers pseudonymised genetic data to a non-EEA university. Pseudonymisation reduces risk but does not automatically remove the transfer from the GDPR. The parties should assess:

  • whether the recipient can identify participants;
  • access to the key;
  • legal environment;
  • supplementary measures;
  • onward transfers;
  • security;
  • contractual prohibitions;
  • return or deletion. Genuine international scientific collaboration is valuable, but Article 89 is not a substitute for Chapter V.

34. Controllers, processors and research collaborations

Research projects often involve:

  • sponsor;
  • university;
  • hospital;
  • laboratory;
  • cloud provider;
  • statistical centre;
  • registry;
  • biobank;
  • contract research organisation.

Roles must be determined factually.

Illustration

A pharmaceutical sponsor designs the trial, selects outcomes and determines essential methods. Hospitals recruit participants and contribute to protocol decisions. A cloud provider stores data on instructions. Possible roles include:

  • sponsor and hospitals as controllers or joint controllers;
  • cloud provider as processor;
  • independent laboratory as controller for legally required quality functions. A contract label is not decisive. Joint controllers should clearly allocate:
  • transparency;
  • rights handling;
  • security;
  • breach response;
  • lawful basis;
  • publication;
  • retention;
  • Article 89 safeguards.

35. Recital 27 and deceased persons

The GDPR does not apply to deceased persons as such, but Member States may adopt national rules for deceased persons.

Historical and genealogical projects must still consider living people.

Illustration

An archive publishes letters written by a deceased person. The letters contain:

  • allegations against a living colleague;
  • information about a living child’s parentage;
  • genetic information relevant to living relatives;
  • addresses of living witnesses. Those elements may be personal data of living persons. The archive should not classify the entire collection as outside the GDPR merely because the author is deceased.

36. Common misconceptions

“Research is automatically in the public interest”

Incorrect. Scientific research can be privately funded and commercially motivated. Public interest may strengthen some legal bases, but genuine scientific character and lawful processing must still be established.

“Article 89 is a lawful basis”

Incorrect. Article 6 and, where necessary, Article 9 remain essential.

“Pseudonymised data are anonymous”

Incorrect. Pseudonymised data remain personal data where re-identification is possible.

“All aggregate data are anonymous”

Incorrect. Small groups, rare traits and external datasets may permit identification.

“Researchers can refuse every access request”

Incorrect. Paragraphs 2 and 3 require an applicable law, serious impairment, necessity and safeguards.

“Consent is always required for research”

Incorrect. Other lawful bases may apply. But where consent is relied upon, it must meet GDPR requirements.

“Ethics approval proves GDPR compliance”

Incorrect. Ethics review and data-protection compliance overlap but are not identical.

“The right to erasure never applies to research”

Incorrect. Article 17(3)(d) provides a qualified exception, not blanket immunity.

“Commercial research cannot qualify”

Incorrect. Privately funded research can qualify if it is genuinely scientific.

“Any AI development is research”

Incorrect. Technological sophistication does not prove scientific purpose.


37. A practical Article 89 compliance model

A responsible controller should document the following sequence.

First, define the purpose

Identify whether the project is:

  • public-interest archiving;
  • scientific research;
  • historical research;
  • statistical processing.

Avoid vague labels.

Second, establish genuine qualification

Document:

  • methodology;
  • protocol;
  • knowledge objective;
  • ethical standards;
  • independence;
  • expected outputs;
  • scientific or public value.

Third, identify lawful bases

Specify:

  • Article 6 basis;
  • Article 9 condition;
  • Article 10 condition where needed;
  • national law;
  • sector-specific law.

Fourth, minimise data

List every variable and justify why it is needed.

Fifth, use the least identifiable form

Determine whether the purpose can be fulfilled through:

  • anonymised data;
  • aggregate data;
  • synthetic data;
  • pseudonymised data;
  • directly identifiable data.

Sixth, implement governance and security

Use:

  • access controls;
  • encryption;
  • separation of keys;
  • secure environments;
  • ethics review;
  • DPO involvement;
  • contractual rules;
  • logging;
  • publication review.

Seventh, address transparency and rights

Create:

  • participant notices;
  • public notices where appropriate;
  • rights procedures;
  • documented derogation tests;
  • escalation routes.

Eighth, assess high risk

Complete a DPIA where Article 35 requires it.

Ninth, control sharing and transfers

Document:

  • recipients;
  • roles;
  • contracts;
  • international transfers;
  • onward disclosure;
  • publication.

Tenth, review throughout the project

Reassess:

  • necessity;
  • identifiability;
  • retention;
  • risks;
  • rights restrictions;
  • purpose changes;
  • possibility of anonymisation.

Conclusion

Article 89 creates a special but disciplined GDPR regime for activities that preserve collective memory, generate scientific and historical knowledge, and produce reliable statistics. The flexibility is real:

  • scientific purposes are interpreted broadly;
  • further processing may benefit from compatibility;
  • research objectives may sometimes be defined by area rather than exact future project;
  • certain rights may be restricted by law;
  • long-term retention may be justified;
  • identifiable data may be used where necessary. But each flexibility has limits. Article 89 requires:
  • an independent lawful basis;
  • Article 9 compliance for special-category information;
  • genuine archival, scientific, historical or statistical purpose;
  • technical and organisational safeguards;
  • data minimisation;
  • pseudonymisation where possible;
  • anonymisation or non-identifiable processing where sufficient;
  • strict necessity before limiting rights;
  • legal authority for derogations;
  • separation of research from other purposes. Paragraphs 2 and 3 do not themselves switch off data-subject rights. They allow Union or Member State law to create carefully limited derogations. The controller must demonstrate that exercising the particular right is likely to make the specific project impossible or seriously impair it and that no less restrictive solution will suffice. Paragraph 4 prevents misuse of the regime. A company cannot collect data for research and then carry the research exemption into advertising, employment, insurance, credit or other individual decision-making.

The essential principle is:

Society may preserve records and produce knowledge using personal data, but the social value of the purpose does not make the people behind the data disappear. Article 89 requires researchers, archivists and statisticians to achieve their objectives with the least identifying data, the strongest proportionate safeguards and the smallest necessary interference with individual rights.