The supplied commentary is broadly accurate, but several points require refinement.
First, Article 90 does not generally “limit DPAs’ investigative powers.” It permits national specification of only the powers in Article 58(1)(e) and (f).
Second, the protected obligation must have a recognised legal or regulatory source. An ordinary private NDA is not automatically equivalent to professional secrecy.
Third, the protection is activity-specific. Data held by a secrecy-bound professional for payroll, marketing or procurement do not automatically receive Article 90 protection.
Fourth, professional secrecy does not create immunity from GDPR duties, corrective measures or fines.
Fifth, a professional should not simply “resist handing over” records without examining national procedure, necessity and possible alternatives. A blanket refusal may breach cooperation obligations.
Sixth, secrecy should not make complaint rights ineffective. National law should permit a meaningful investigation through targeted and protected procedures.
Seventh, processors may fall within Article 90, but not merely because they provide services to a confidential profession. The legal extension of secrecy and the protected activity must be demonstrated.
Eighth, supervisory-authority confidentiality under Article 54 is important but may not fully resolve privilege and secrecy concerns.
Finally, notification to the Commission is an oversight mechanism, not approval of the national rule. The Commission’s notification register provides the relevant national instruments, but current domestic law must be checked in each case.europa+1
Conclusion
Article 90 is a narrow procedural reconciliation mechanism.
It begins from two equally important propositions:
- Supervisory authorities need meaningful access to evidence so that GDPR rights can be enforced.
- Certain professional relationships depend on legally protected secrecy that should not be destroyed through unnecessarily broad regulatory access.
Member States may therefore adopt specific rules governing:
- access to personal data and information under Article 58(1)(e); and
- access to premises, equipment and processing means under Article 58(1)(f).
Those rules are valid only where they are:
- necessary;
- proportionate;
- limited to secrecy-protected activities;
- compatible with effective GDPR supervision;
- respectful of data-subject remedies.
The provision does not protect an entire professional organisation indiscriminately. It protects only personal data received or obtained through the secrecy-covered activity.
The correct analysis is therefore:
Who is secrecy-bound? What is the legal source of the obligation? Which activity produced the information? Is the particular information genuinely covered? What evidence does the authority need? Can the investigation proceed through a less intrusive method?
A proportionate system may use:
- redaction;
- targeted access;
- judicial approval;
- independent review;
- on-site inspection;
- restricted evidence rooms;
- technical logs;
- anonymised or aggregated information.
The simplest summary is:
Professional secrecy is a shield for protected relationships, not a shield for GDPR non-compliance. Article 90 allows Member States to control how supervisory authorities inspect confidential information, but not to prevent those authorities from enforcing data protection law altogether.