CHAPTER IXPROVISIONS RELATING TO SPECIFIC PROCESSING SITUATIONS

Article 90Obligations of secrecy

Official text

(1)Member States may adopt specific rules to set out the powers of the supervisory authorities laid down in points (e) and (f) of Article 58 (1) in relation to controllers or processors that are subject, under Union or Member State law or rules established by national competent bodies, to an obligation of professional secrecy or other equivalent obligations of secrecy where this is necessary and proportionate to reconcile the right of the protection of personal data with the obligation of secrecy. Those rules shall apply only with regard to personal data which the controller or processor has received as a result of or has obtained in an activity covered by that obligation of secrecy.

(2)Each Member State shall notify to the Commission the rules adopted pursuant to paragraph 1, by 25 May 2018 and, without delay, any subsequent amendment affecting them.

Commentary

Article 90 addresses a narrow but important conflict. A supervisory authority must be able to inspect personal-data processing and enforce the GDPR, but some controllers and processors hold information protected by professional secrecy, such as medical confidentiality, legal professional secrecy or another legally recognised duty of confidence.

The core principle is:

Professional secrecy does not place a professional outside the GDPR or beyond regulatory supervision. However, Member States may regulate how a supervisory authority exercises particular access and inspection powers so that an investigation does not unnecessarily expose information entrusted to the professional in confidence.

Article 90 is therefore not a general exemption for doctors, lawyers, accountants or similar professionals. It is a limited opening clause concerning only two supervisory-authority powers:

  1. access to personal data and other necessary information under Article 58(1)(e); and
  2. access to premises, equipment and processing means under Article 58(1)(f).

Any national limitation must be necessary, proportionate and confined to information received or obtained through the secrecy-protected activity. Article 90 does not authorise Member States to eliminate supervisory oversight or to protect an organisation’s ordinary administrative data merely because that organisation also performs confidential professional work.europa+2


1. Why Article 90 is needed

Professional secrecy exists so that people can communicate candidly with trusted professionals.

A patient may need to disclose:

  • symptoms;
  • medical history;
  • substance dependence;
  • mental-health information;
  • family circumstances.

A client may need to tell a lawyer:

  • facts that create legal exposure;
  • possible misconduct;
  • confidential commercial strategies;
  • information relevant to litigation.

A person consulting an accountant or tax adviser may reveal:

  • income;
  • debts;
  • investments;
  • tax disputes;
  • family arrangements.

If people believed that this information could be freely exposed to outsiders, they might withhold essential facts. That could undermine:

  • medical treatment;
  • access to justice;
  • legal advice;
  • tax compliance;
  • financial accuracy;
  • confidence in regulated professions.

Professional secrecy therefore protects more than the private preference of a professional or client. It protects the proper functioning of relationships that depend on trust.

At the same time, professionals process highly sensitive information and may themselves violate the GDPR. A medical practice may disclose patient files unlawfully. A law firm may have weak cybersecurity. An accountant may retain identification documents indefinitely. A professional-secrecy rule cannot become a shield against every regulatory investigation.

Article 90 reconciles these two public interests:

  • effective data protection supervision; and
  • preservation of legally protected professional confidence.

2. Professional secrecy and data protection are different concepts

Professional secrecy and data protection overlap, but they are not identical.

2.1 Data protection

Data protection regulates the processing of personal data. It addresses matters such as:

  • lawful basis;
  • fairness;
  • transparency;
  • purpose limitation;
  • minimisation;
  • accuracy;
  • retention;
  • security;
  • data-subject rights;
  • accountability.

Its focus is the relationship between personal-data processing and the rights of the person concerned.

2.2 Professional secrecy

Professional secrecy governs the confidentiality of information entrusted to or discovered by a person in a protected professional relationship.

Its purposes may include:

  • protecting the client or patient;
  • encouraging full disclosure;
  • preserving trust;
  • protecting access to justice;
  • maintaining professional integrity;
  • protecting the wider public interest.

Illustration

A patient tells a doctor that they have a serious illness. The diagnosis is:

  • personal data;
  • health data under Article 9;
  • information protected by medical secrecy. Different rules therefore apply simultaneously. Data protection asks whether the doctor lawfully collected, stored, used and secured the information. Medical secrecy asks whether the doctor may disclose it to another person. A disclosure may comply with one regime but violate the other.

[!example] Illustration A hospital may have an Article 6 and Article 9 basis to process a patient’s diagnosis for treatment. That does not automatically permit the hospital to tell the patient’s employer. Likewise, a disclosure may be allowed by professional-secrecy law, such as mandatory reporting of a specified contagious disease, but the controller must still comply with applicable GDPR requirements. Article 90 does not merge these legal systems. It controls a particular point at which they conflict, namely regulatory access to secrecy-protected information.

3. Article 90 is an optional opening clause

Paragraph 1 states that Member States“may adopt specific rules.”

This means that the GDPR does not itself establish a single EU-wide solution for inspections involving professional secrecy. Each Member State may enact rules reflecting its legal and professional traditions.

A Member State may regulate matters such as:

  • when a supervisory authority may inspect protected records;
  • whether prior judicial approval is required;
  • whether a professional representative must attend;
  • whether an independent reviewer separates privileged from non-privileged material;
  • whether certain records must be redacted;
  • whether inspection must occur on-site;
  • whether copies may be removed;
  • how the authority must secure the information;
  • which officials may access it.

If a Member State does not adopt special rules, the ordinary GDPR supervisory framework remains applicable, together with any other relevant national procedural or secrecy law.

The word “may” does not allow a Member State to ignore the GDPR. It means only that it may particularise the exercise of the two specified investigative powers.


4. Article 90 regulates supervisory powers, not the underlying GDPR obligations

A crucial distinction is between:

  1. substantive GDPR obligations; and
  2. how those obligations are investigated.

Article 90 concerns the second issue.

It does not exempt a secrecy-bound controller or processor from:

  • Article 5 principles;
  • Article 6 lawful basis requirements;
  • Article 9 special-category rules;
  • transparency obligations;
  • data-subject rights;
  • security;
  • breach notification;
  • processor governance;
  • accountability;
  • administrative fines.

Illustration

A law firm suffers a ransomware attack because:

  • all staff shared one password;
  • systems were unpatched;
  • files were unencrypted;
  • no backups existed. The law firm cannot respond: “Our files are protected by legal professional secrecy, so the supervisory authority cannot investigate our security.” Professional secrecy may affect how access occurs, but it does not erase the firm’s Article 32 obligations. Similarly, a doctor cannot refuse every Article 15 access request from a patient merely because medical records are confidential. The confidentiality duty usually protects the patient and does not ordinarily prevent that same patient from accessing their own personal data, subject to the rights and interests of others.

5. The only Article 58 powers expressly covered

Article 90 refers specifically to Article 58(1)(e) and Article 58(1)(f).

This narrow drafting is significant.

5.1 Article 58(1)(e): Access to personal data and information

The supervisory authority may obtain from a controller or processor access to:

  • personal data;
  • information necessary to perform its tasks.

This may include:

  • case files;
  • databases;
  • policies;
  • correspondence;
  • access logs;
  • audit reports;
  • retention records;
  • processor contracts;
  • evidence concerning rights requests.

Illustration

A patient complains that a clinic disclosed psychiatric information unlawfully. The authority may need to inspect:

  • the patient’s file;
  • disclosure records;
  • staff access logs;
  • recipient information;
  • the clinic’s legal basis;
  • security controls. The information needed to prove the infringement is itself protected by medical confidentiality. Article 90 allows national law to determine how that access should occur without unnecessarily compromising the confidentiality of unrelated patient information.

5.2 Article 58(1)(f): Access to premises and equipment

The supervisory authority may obtain access to:

  • premises;
  • computers;
  • servers;
  • filing rooms;
  • data-processing equipment;
  • processing systems.

Such access remains subject to Union and Member State procedural law.

Illustration

An authority investigates whether a legal practice stores client files in an unsecured room accessible to visitors. Inspectors may need to enter the office and review:

  • access arrangements;
  • storage systems;
  • security controls;
  • server configuration. A search of every legal file in the office would be much more intrusive than inspecting the physical and technical security arrangements. Article 90 enables national law to distinguish between those activities.

6. Article 90 does not expressly restrict other supervisory powers

Article 90 does not refer to all investigative or corrective powers.

It does not expressly modify powers such as:

  • ordering information under Article 58(1)(a);
  • carrying out data-protection audits under Article 58(1)(b);
  • reviewing certifications under Article 58(1)(c);
  • notifying a controller of an alleged infringement;
  • issuing warnings or reprimands;
  • ordering compliance;
  • restricting processing;
  • imposing administrative fines.

This means Article 90 should not be read as a general power to neutralise the supervisory authority.

Illustration

A bar association member argues that professional secrecy prevents the authority from:

  • issuing a reprimand;
  • ordering implementation of encryption;
  • requiring deletion of unlawfully retained personnel data;
  • imposing a fine. Article 90 does not provide such a blanket defence. Any practical exercise of another power may still need to respect secrecy and proportionality. But a Member State cannot use Article 90 to remove the authority’s entire enforcement competence over a profession.

7. Who may be protected by professional secrecy?

Article 90 does not provide a closed list of professions.

Common examples may include:

  • lawyers;
  • doctors;
  • psychologists;
  • psychotherapists;
  • pharmacists;
  • notaries;
  • auditors;
  • accountants;
  • tax advisers;
  • social workers;
  • clergy;
  • regulated financial professionals.

Actual protection depends on the applicable Union or Member State law or rules established by a competent national body.

The occupation’s title alone is not decisive. The court or authority should ask:

  1. Is there a legally recognised secrecy obligation?
  2. Who is bound by it?
  3. Which activities does it cover?
  4. Which information does it protect?
  5. Are there statutory exceptions?
  6. Does the obligation continue after the relationship ends?

[!example] Illustration A doctor receives medical information while treating a patient. The information is clearly connected with medical secrecy. The same doctor buys office stationery from a supplier and keeps the supplier’s contact information. That information was not obtained through the medical treatment relationship. Article 90 should not automatically protect it merely because a doctor holds it.

8. “Other equivalent obligations of secrecy”

Article 90 is not confined to traditional professional secrecy.

It also covers other equivalent secrecy obligations. The word “equivalent” prevents every ordinary promise of confidentiality from qualifying.

An equivalent obligation should normally have characteristics similar to professional secrecy, such as:

  • recognised legal or regulatory foundation;
  • binding character;
  • connection with a trusted function;
  • protection of significant private or public interests;
  • enforceable sanctions;
  • continuing application beyond a single informal arrangement.

Illustration: likely equivalent obligation

A licensed financial professional is subject to binding confidentiality rules issued by a national financial regulator. Breach may lead to sanctions or loss of authorisation. That obligation may be equivalent to professional secrecy.

Illustration: ordinary commercial confidentiality

A software company signs a nondisclosure agreement concerning a client’s marketing plan. The agreement is legally binding, but it is not automatically equivalent to professional secrecy for Article 90. Otherwise, almost every business could restrict supervisory access simply by signing confidentiality clauses. The relevant distinction is between:

  • ordinary private confidentiality created for commercial convenience; and
  • legally or institutionally recognised secrecy central to a protected professional relationship.

Article 90 recognises three possible sources:

  1. Union law;
  2. Member State law;
  3. rules established by national competent bodies.

9.1 Union law

Certain confidentiality obligations may arise from EU legislation applying to regulated activities.

9.2 Member State law

National statutes may create duties such as:

  • medical confidentiality;
  • legal professional secrecy;
  • tax-adviser secrecy;
  • banking confidentiality;
  • professional secrecy of public officials.

9.3 Rules of competent national bodies

Professional bodies may establish binding rules where national law gives them authority.

Examples

may include:

  • bar councils;
  • medical councils;
  • notarial chambers;
  • audit regulators;
  • financial supervisory bodies. A voluntary association cannot necessarily create an Article 90 limitation merely by declaring that its members’ information is confidential. The body should have recognised competence to issue binding rules.

10. Controllers and processors may both qualify

Article 90 applies to controllers and processors.

This is important because secrecy-protected information is often handled by service providers.

Illustration

A law firm uses:

  • a cloud-storage provider;
  • an e-discovery vendor;
  • a document-scanning company;
  • an external IT-support company. The law firm may be controller. The vendors may be processors. Those processors may obtain access to information covered by legal professional secrecy. National law may extend relevant inspection safeguards to them. However, a processor cannot automatically claim every secrecy right available to the professional controller. The legal analysis should examine:
  • whether the secrecy obligation binds the processor directly;
  • whether it binds the processor contractually;
  • whether national law extends the rule;
  • what information the processor actually holds;
  • whether disclosure to the processor was itself lawful.

[!example] Illustration An ordinary marketing agency also provides an unrelated service to a hospital. It cannot invoke medical secrecy for all its business records simply because one client is a hospital.

11. The activity-specific limitation

The second sentence of Article 90(1) is one of the most important parts of the provision:

The specific rules apply only to personal data received or obtained through an activity covered by the secrecy obligation.

This prevents profession-wide immunity.

The analysis must be conducted:

  • dataset by dataset;
  • document by document;
  • processing operation by processing operation;
  • purpose by purpose.

Illustration: law firm

The law firm holds:

  1. client legal advice files;
  2. employee payroll records;
  3. CCTV footage;
  4. supplier invoices;
  5. marketing contact lists.

Client legal files may be protected by professional secrecy.

Payroll, CCTV and supplier information are not automatically protected merely because the law firm holds them.

Illustration: hospital

The hospital holds:

  1. patient treatment records;
  2. medical consultation notes;
  3. employee attendance data;
  4. procurement records;
  5. cafeteria customer data.

Patient information may be covered by medical secrecy. Procurement and cafeteria data ordinarily are not.

This limitation is essential for effective supervision. Without it, any organisation employing one secrecy-bound professional might claim immunity for its whole information environment.


12. “Received as a result of” or “obtained in” the protected activity

The formulation is broad enough to cover information that the professional:

  • receives from the client or patient;
  • observes directly;
  • infers professionally;
  • creates as part of the professional activity;
  • obtains from third parties for the protected service.

Illustration

A patient personally tells a doctor about symptoms. That is received through the protected activity. The doctor conducts tests and reaches a diagnosis. That diagnosis is obtained or created through the protected activity. A laboratory sends results to the doctor. Those results also form part of the protected professional relationship. Similarly, legal professional secrecy may cover:

  • the client’s statements;
  • legal advice;
  • litigation strategy;
  • lawyer work product;
  • correspondence;
  • evidence gathered for advice. The exact scope still depends on national law. Article 90 does not create or define the underlying secrecy privilege.

13. Professional secrecy belongs to the protected relationship, not merely the professional

The protected interest often belongs substantially to the client or patient, even though the legal duty is imposed on the professional.

Illustration

A lawyer cannot waive the client’s confidentiality merely because disclosure would be convenient for the firm. Similarly, a physician cannot disclose a patient’s condition because the physician personally sees no harm. This matters when a supervisory authority investigates a complaint.

Illustration

A patient complains about an unlawful disclosure and voluntarily provides the authority with medical records. That may reduce the secrecy conflict concerning those particular records because the patient has chosen to disclose them for the complaint. However, the clinic’s files may also contain personal data about:

  • relatives;
  • other patients;
  • professionals;
  • confidential third-party sources. The authority should limit inspection accordingly.

14. The conflict is not solved simply by saying that supervisory officials are confidential

Members and staff of supervisory authorities are bound by professional secrecy under Article 54(2) regarding confidential information learned in their duties.

That safeguard is important. It reduces the risk that confidential material obtained during an investigation will be disclosed publicly.

But it does not automatically resolve every Article 90 concern.

Illustration

A law firm’s client files contain privileged litigation strategy. Even if the supervisory authority promises confidentiality, compulsory access may still interfere with:

  • the lawyer-client relationship;
  • privilege;
  • fair-trial rights;
  • source confidentiality;
  • protection against self-incrimination. Therefore, national law may require additional safeguards such as:
  • judicial authorisation;
  • independent privilege review;
  • sealed handling;
  • narrow search terms;
  • restricted investigator access;
  • destruction of irrelevant copies. Confidentiality within the authority is necessary, but it may not always be sufficient.

15. Necessity and proportionality

A Member State may adopt Article 90 rules only where necessary and proportionate to reconcile data protection with secrecy.

Both requirements are binding.

15.1 Necessity

A rule is necessary where the secrecy interest cannot be protected adequately through a less restrictive approach.

Illustration

A law completely prohibits the supervisory authority from ever inspecting any law-firm system. That is likely broader than necessary. Less restrictive alternatives may include:

  • inspection of security configurations without opening client files;
  • independent screening of privileged material;
  • redaction;
  • on-site review;
  • anonymised samples;
  • judicial approval.

15.2 Proportionality

The restriction must maintain a fair balance between:

  • the seriousness of the data-protection allegation;
  • the importance of the secrecy interest;
  • the information sought;
  • availability of alternatives;
  • protection against onward disclosure;
  • rights of complainants;
  • regulatory effectiveness.

Illustration

A supervisory authority investigates whether a clinic’s patient portal uses adequate encryption. It may be able to inspect:

  • technical architecture;
  • security policies;
  • access logs;
  • test accounts without reading complete treatment notes. Demanding all patient files would be disproportionate if technical evidence is sufficient. By contrast, if the allegation is that staff unlawfully altered or disclosed one patient’s record, limited access to the relevant record may be necessary.

16. Blanket restrictions are difficult to justify

A national law should not simply state:

“The supervisory authority has no access to data held by lawyers or doctors.”

Such a rule could make GDPR enforcement ineffective.

Suppose a law firm:

  • secretly sells client information;
  • ignores access rights;
  • has no cybersecurity;
  • discloses files to advertisers.

If the authority cannot inspect anything, professional secrecy would become protection for unlawful processing rather than protection for clients.

A better rule should differentiate according to:

  • type of information;
  • protected person;
  • investigation purpose;
  • risk;
  • less intrusive evidence;
  • applicable privilege.

17. Possible models for national rules

Article 90 does not prescribe one model. Member States may use different mechanisms.

17.1 Prior judicial authorisation

The authority may need a court order before inspecting secrecy-protected records.

This adds independent review but may slow urgent investigations.

17.2 Independent reviewer

A judge, professional representative or independent specialist may separate:

  • privileged material;
  • relevant non-privileged material;
  • unrelated information.

17.3 On-site inspection

The authority may inspect records at the professional’s premises without taking unrestricted copies.

17.4 Redaction

Names, confidential advice or unrelated records may be masked.

17.5 Targeted search terms

Electronic searches may be confined to:

  • specific dates;
  • users;
  • file types;
  • incidents.

17.6 Secure evidence room

Highly confidential information may be reviewed in a restricted environment.

17.7 Aggregated or anonymised evidence

Where individual information is unnecessary, the controller may provide:

  • statistics;
  • control reports;
  • anonymised samples;
  • system logs.

No single safeguard is sufficient in every case. The mechanism should be tailored to the particular secrecy interest and enforcement need.


Legal professional secrecy deserves especially careful treatment because it may protect:

  • access to legal advice;
  • defence rights;
  • fair-trial interests;
  • confidential communications;
  • litigation strategy.

Not every document held by a lawyer is automatically privileged.

Relevant distinctions may include:

  • legal advice versus business advice;
  • independent lawyer versus in-house counsel;
  • existing documents versus communications created for legal advice;
  • client identity and billing information;
  • communications intended to further a crime or fraud;
  • national definitions of privilege.

19. Medical secrecy

Medical secrecy protects information learned through healthcare relationships.

It can cover:

  • diagnoses;
  • symptoms;
  • medication;
  • test results;
  • mental health;
  • reproductive health;
  • genetic findings;
  • consultation history;
  • treatment decisions.

Recital 53 recognises that health data require heightened protection and highlights processing by persons subject to professional secrecy. It also acknowledges legitimate health-system purposes such as continuity of care, quality control, public health, research and supervision, provided appropriate legal safeguards exist.

Illustration

A hospital’s internal quality-control team reviews treatment outcomes. This may be lawful health-system processing. But access should be limited to what the quality-control function requires. If the supervisory authority later investigates a data breach, it may need to inspect security and access records. It does not necessarily need every clinical detail.

19.1 Professional secrecy and patient access

Medical secrecy generally protects information against disclosure to outsiders. It does not normally prevent the patient from accessing their own data.

However, a medical record may contain information about:

  • relatives;
  • another patient;
  • confidential third-party statements;
  • professional notes whose disclosure is subject to national rules.

The controller must balance Article 15 with the rights and freedoms of others.

Article 90 is not itself the legal basis for denying patient access because it concerns supervisory-authority powers, not data-subject access rights.


20. Accountants, auditors and tax advisers

Financial professionals may hold:

  • tax details;
  • ownership structures;
  • suspicious-transaction information;
  • family wealth;
  • business strategy;
  • evidence of possible misconduct.

Their secrecy duties may coexist with:

  • audit obligations;
  • anti-money-laundering reporting;
  • tax disclosure duties;
  • court orders;
  • regulatory supervision.

[!example] Illustration An accountant is legally required to report a suspicious transaction. Professional secrecy does not automatically override that reporting law. Similarly, Article 90 does not create a new substantive right to refuse every governmental disclosure. It concerns only how the data protection supervisory authority exercises Article 58(1)(e) and (f). This distinction prevents Article 90 from being misread as a general secrecy provision applicable against all public authorities.

21. Clergy and counselling relationships

Some national laws recognise secrecy concerning:

  • religious confession;
  • pastoral counselling;
  • therapeutic counselling;
  • social-work communications.

Whether these qualify depends on:

  • legal recognition;
  • competence of the rule-making body;
  • binding nature;
  • scope of the activity;
  • national constitutional law.

Illustration

A church operates both:

  1. a confidential pastoral-counselling service; and
  2. a commercial event venue.

Article 90 protections may apply to counselling records if national law recognises an equivalent secrecy obligation.

They should not automatically apply to:

  • venue customer lists;
  • catering invoices;
  • marketing information.

Again, the protection follows the activity and the information, not the institution’s identity.


22. Internal investigations and mixed files

Professional organisations often maintain files containing both secrecy-protected and ordinary information.

Illustration

A hospital investigation file includes:

  • patient treatment notes;
  • staff schedules;
  • CCTV;
  • security logs;
  • procurement records;
  • internal emails. Medical secrecy may protect the treatment material. It does not necessarily protect all schedules, CCTV and procurement records to the same extent. The controller should classify records before refusing access. A useful disclosure process may involve:
  1. identifying the requested evidence;
  2. determining which parts are secrecy-protected;
  3. separating unrelated data;
  4. considering redaction;
  5. documenting the legal basis;
  6. proposing less intrusive alternatives;
  7. preserving evidence pending resolution.

A blanket refusal may itself violate the duty to cooperate under Article 31 or an Article 58 requirement.


23. A processor should not exploit secrecy to hide its own misconduct

Suppose a cloud provider hosts medical records for several hospitals. It suffers a breach because of poor access control.

The provider may argue that the records are medically confidential. That confidentiality is real, but it should not prevent the authority from investigating the provider’s own security failure.

The authority may not need to read every medical record. It may require:

  • configuration documents;
  • authentication logs;
  • breach timeline;
  • access-control policies;
  • encryption details;
  • affected-record counts;
  • processor contracts.

Article 90 should guide the manner of investigation, not extinguish processor accountability.


24. Professional secrecy does not belong to the organisation’s convenience

An organisation may be tempted to invoke secrecy because disclosure would be:

  • embarrassing;
  • commercially damaging;
  • inconvenient;
  • likely to reveal non-compliance.

Those are not professional-secrecy interests.

Illustration

A law firm refuses to disclose its retention policy because the policy reveals that client data are kept indefinitely. The retention policy itself is an organisational document. It is not necessarily protected merely because it concerns client files. The authority may be able to assess compliance without accessing confidential client communications. Controllers should distinguish:

  • the existence and structure of compliance systems;
  • the confidential content stored within those systems.

25. Article 90 and data breaches

A professional-secrecy obligation does not eliminate Articles 33 and 34.

If a breach occurs, the controller may need to notify:

  • the supervisory authority;
  • affected data subjects.

The notification can be designed to minimise unnecessary disclosure.

Illustration

A psychotherapist’s laptop containing patient notes is stolen. The breach notification to the supervisory authority may describe:

  • number of records;
  • categories of data;
  • encryption status;
  • risk;
  • mitigation. It may not always need to include complete therapy notes or every patient’s identity at the first stage. The controller should provide enough information for effective supervision while respecting confidentiality. If identities later become necessary, Article 90 national safeguards may regulate access.

26. Recital 75 and loss of confidentiality

Recital 75 identifies the loss of confidentiality of personal data protected by professional secrecy as a serious risk to rights and freedoms.

This means professional secrecy is not only a reason to limit regulatory access. Its breach may itself increase the seriousness of a GDPR infringement.

Illustration

A database leak exposes:

  • ordinary professional contact details; and
  • confidential psychotherapy records. The second category presents much greater risks of:
  • stigma;
  • discrimination;
  • distress;
  • relationship harm;
  • professional consequences. A controller cannot invoke professional secrecy defensively while failing to apply strong security to the same information. Secrecy creates both:
  • a basis for careful regulatory procedure; and
  • a reason for heightened controller responsibility.

27. Relationship with Article 9

Professional secrecy appears in several Article 9 contexts.

For example, Article 9(3) permits certain health-data processing under Article 9(2)(h) where the data are processed:

  • by or under the responsibility of a professional subject to professional secrecy; or
  • by another person subject to an equivalent obligation.

This is different from Article 90.

Article 9(3) helps determine whether health-data processing is substantively lawful.

Article 90 concerns supervisory access during enforcement.

[!example] Illustration A hospital lawfully processes health data for treatment under Article 9(2)(h) and Article 9(3). If the supervisory authority investigates the hospital’s security, Article 90 may govern how the authority accesses confidentiality-protected records. The hospital must satisfy both provisions for different reasons.

28. Relationship with Article 14 and secrecy

Article 14(5)(d) contains a separate rule concerning information obtained under professional secrecy. The Article 14 notice requirement may not apply where the personal data must remain confidential under an obligation of professional secrecy regulated by Union or Member State law.

That is another distinct function.

[!example] Illustration A lawyer receives information about an opposing party during confidential legal representation. Article 14(5)(d) may affect whether the lawyer must provide a notice to that party, depending on applicable law. Article 90 concerns whether a supervisory authority can inspect that information. The existence of several secrecy-related GDPR provisions shows that the analysis must be provision-specific. Article 90 is not a universal secrecy exemption.

29. Rights and remedies of complainants

Professional secrecy should not leave data subjects without an effective remedy.

Suppose a patient alleges that a clinic unlawfully disclosed their file.

If national law prevents the authority from seeing any relevant evidence, the complaint may become impossible to investigate. Such a blanket restriction could undermine:

  • Article 77 complaint rights;
  • Article 78 judicial review;
  • Article 47 of the Charter;
  • effectiveness of the GDPR.

National law should therefore seek a procedure that permits meaningful investigation while protecting unrelated secrecy interests.

Illustration

Possible procedure:

  1. the patient identifies the relevant consultation;
  2. the clinic provides access logs and disclosure metadata;
  3. the confidential clinical content remains sealed;
  4. an independent reviewer checks whether content access is necessary;
  5. only relevant extracts are disclosed under restricted conditions.

This protects both enforcement and medical confidentiality.


30. Judicial review of secrecy claims

Disputes may arise over whether:

  • a person is secrecy-bound;
  • a document is protected;
  • the authority’s request is necessary;
  • redaction is sufficient;
  • the national restriction is proportionate.

An independent court should be able to resolve these issues.

Illustration

A law firm claims that every server and database is covered by privilege. The supervisory authority argues that it needs only:

  • security logs;
  • access permissions;
  • retention settings. A court may distinguish protected client content from non-privileged system information and permit a targeted inspection. Effective judicial review also protects the authority against abusive secrecy claims and the professional against overbroad demands.

31. Cross-border processing

Professional-secrecy rules vary substantially among Member States.

A cross-border professional organisation may face different rules concerning:

  • scope of legal privilege;
  • medical confidentiality;
  • in-house counsel;
  • inspection powers;
  • judicial authorisation;
  • disclosure procedures.

Illustration

A multinational law firm stores European client files in a central cloud environment. A supervisory authority in one Member State investigates a breach affecting several offices. The firm must analyse:

  • which authority is competent;
  • which national Article 90 rules apply;
  • where the confidential activity occurred;
  • where the controller or processor is established;
  • whether several privilege regimes apply;
  • how evidence can be exchanged between authorities. Article 90 does not harmonise these rules completely. Cross-border investigations therefore require careful procedural planning.

32. Notification to the European Commission under paragraph 2

Member States had to notify the Commission of Article 90 rules by 25 May 2018 and must notify subsequent amendments without delay.

The Commission maintains a collection of Member State GDPR notifications, including provisions concerning Article 90 obligations of secrecy.europa+1

The notification obligation supports:

  • transparency;
  • comparison of national rules;
  • Commission oversight;
  • detection of excessive restrictions;
  • legal certainty in cross-border cases.

32.1 Notification is not approval

A national law does not become automatically valid merely because it was notified.

The Commission, national courts or the CJEU may still find that the rule:

  • goes beyond Article 90;
  • is unnecessary;
  • is disproportionate;
  • removes effective supervision;
  • violates the Charter.

32.2 Amendments

A Member State should notify changes affecting:

  • protected professions;
  • categories of secrecy;
  • inspection procedures;
  • judicial-authorisation requirements;
  • supervisory access;
  • handling of protected evidence.

The obligation concerns legal rules, not each individual professional-secrecy dispute.


33. Practical framework for a secrecy-bound controller

When receiving an Article 58 request, a controller or processor should not respond with either automatic disclosure or automatic refusal.

A structured process is preferable.

Step 1: Identify the exact supervisory request

Determine whether the authority seeks:

  • personal-data content;
  • system information;
  • policies;
  • logs;
  • premises access;
  • equipment access.

Step 2: Classify the information

Separate:

  • secrecy-protected professional information;
  • ordinary organisational information;
  • third-party data;
  • privileged legal material;
  • technical evidence.

Document:

  • statute;
  • EU rule;
  • professional regulation;
  • competent body;
  • protected persons;
  • exceptions.

Step 4: Check national Article 90 rules

Determine:

  • inspection procedure;
  • required authorisation;
  • redaction rights;
  • review mechanism;
  • confidentiality controls.

Step 5: Assess necessity

Ask whether the authority can fulfil its task using:

  • metadata;
  • logs;
  • redacted information;
  • samples;
  • pseudonymised records;
  • on-site inspection;
  • independent review.

Step 6: Cooperate constructively

Offer a lawful alternative rather than issuing a blanket refusal.

Step 7: Preserve evidence

Do not delete or alter disputed material while the secrecy issue is being resolved.

Step 8: Seek judicial resolution where necessary

If no agreement is possible, use the available legal procedure rather than obstructing the investigation.


34. Common misunderstandings

“Professional secrecy means the GDPR does not apply”

Incorrect. The GDPR applies to secrecy-protected personal data.

“The supervisory authority can always read everything”

Incorrect. National Article 90 rules may limit or structure access where necessary and proportionate.

“Every confidentiality agreement qualifies”

Incorrect. Ordinary contractual confidentiality is not automatically equivalent to legally recognised professional secrecy.

“Everything held by a lawyer or doctor is protected”

Incorrect. Protection follows the secrecy-covered activity and data, not merely professional status.

“Article 90 limits data-subject access rights”

Not directly. It concerns specified supervisory-authority powers.

“A processor can never invoke professional secrecy”

Incorrect. Article 90 expressly refers to processors, but the secrecy obligation and activity-specific scope must be established.

“Professional secrecy prevents breach notification”

Incorrect. Notifications may still be required, though disclosure should be minimised.

“A national law can prohibit all DPA inspections of a profession”

Such a blanket rule would raise serious necessity, proportionality and effectiveness concerns.


35. Corrections and qualifications to the supplied commentary

The supplied commentary is broadly accurate, but several points require refinement.

First, Article 90 does not generally “limit DPAs’ investigative powers.” It permits national specification of only the powers in Article 58(1)(e) and (f).

Second, the protected obligation must have a recognised legal or regulatory source. An ordinary private NDA is not automatically equivalent to professional secrecy.

Third, the protection is activity-specific. Data held by a secrecy-bound professional for payroll, marketing or procurement do not automatically receive Article 90 protection.

Fourth, professional secrecy does not create immunity from GDPR duties, corrective measures or fines.

Fifth, a professional should not simply “resist handing over” records without examining national procedure, necessity and possible alternatives. A blanket refusal may breach cooperation obligations.

Sixth, secrecy should not make complaint rights ineffective. National law should permit a meaningful investigation through targeted and protected procedures.

Seventh, processors may fall within Article 90, but not merely because they provide services to a confidential profession. The legal extension of secrecy and the protected activity must be demonstrated.

Eighth, supervisory-authority confidentiality under Article 54 is important but may not fully resolve privilege and secrecy concerns.

Finally, notification to the Commission is an oversight mechanism, not approval of the national rule. The Commission’s notification register provides the relevant national instruments, but current domestic law must be checked in each case.europa+1


Conclusion

Article 90 is a narrow procedural reconciliation mechanism. It begins from two equally important propositions:

  1. Supervisory authorities need meaningful access to evidence so that GDPR rights can be enforced.
  2. Certain professional relationships depend on legally protected secrecy that should not be destroyed through unnecessarily broad regulatory access.

Member States may therefore adopt specific rules governing:

  • access to personal data and information under Article 58(1)(e); and
  • access to premises, equipment and processing means under Article 58(1)(f).

Those rules are valid only where they are:

  • necessary;
  • proportionate;
  • limited to secrecy-protected activities;
  • compatible with effective GDPR supervision;
  • respectful of data-subject remedies.

The provision does not protect an entire professional organisation indiscriminately. It protects only personal data received or obtained through the secrecy-covered activity.

The correct analysis is therefore:

Who is secrecy-bound? What is the legal source of the obligation? Which activity produced the information? Is the particular information genuinely covered? What evidence does the authority need? Can the investigation proceed through a less intrusive method?

A proportionate system may use:

  • redaction;
  • targeted access;
  • judicial approval;
  • independent review;
  • on-site inspection;
  • restricted evidence rooms;
  • technical logs;
  • anonymised or aggregated information.

The simplest summary is:

Professional secrecy is a shield for protected relationships, not a shield for GDPR non-compliance. Article 90 allows Member States to control how supervisory authorities inspect confidential information, but not to prevent those authorities from enforcing data protection law altogether.