CHAPTER IXPROVISIONS RELATING TO SPECIFIC PROCESSING SITUATIONS

Article 91Existing data protection rules of churches and religious associations

Official text

(1)Where in a Member State, churches and religious associations or communities apply, at the time of entry into force of this Regulation, comprehensive rules relating to the protection of natural persons with regard to processing, such rules may continue to apply, provided that they are brought into line with this Regulation.

(2)Churches and religious associations which apply comprehensive rules in accordance with paragraph 1 of this Article shall be subject to the supervision of an independent supervisory authority, which may be specific, provided that it fulfils the conditions laid down in Chapter VI of this Regulation.

Commentary

Article 91 GDPR recognises a specific institutional situation concerning churches and religious associations or communities that already operated under comprehensive data protection rules when the GDPR entered into force.

The provision allows such rules to continue, provided that they are brought into line with the GDPR. It therefore creates a limited form of continuity for pre-existing religious data protection regimes rather than a general exemption from the GDPR.

This provision must also be understood against the broader constitutional protection afforded to religious freedom and institutional autonomy. Recital 165 expressly states that the GDPR does not prejudice the status of churches and religious associations or communities under the constitutional law of Member States, as recognised by Article 17 TFEU.

1. Conditions for the special regime

The possibility of continuing a religious organisation's own data protection rules is subject to several cumulative conditions.

First, the organisation must qualify as a church, religious association or religious community.

Second, it must have applied comprehensive data protection rules already in existence when the GDPR entered into force.

Third, those rules must be sufficiently comprehensive and must be brought into line with the GDPR.

The conditions are therefore restrictive.

Article 91 does not say that churches are outside the GDPR.

It says, in substance, that qualifying organisations may continue to operate their own comprehensive rules where those rules satisfy the conditions established by the provision.


2. Churches, religious associations and communities

The GDPR does not itself provide a detailed definition of “church”, “religious association” or “religious community”.

The interpretation may therefore be informed by broader EU law concerning religion. The source commentary notes the potentially broad conception of religion, including theistic, non-theistic and atheistic beliefs, and refers to the CJEU's treatment of the Jehovah's Witnesses community as a religious association in Jehovan todistajat (C-25/17).

The important point is that Article 91 is concerned with the institutional status and pre-existing regulatory framework of the organisation, not merely with whether a particular activity happens to have a religious character.


3. The temporal requirement

The second condition is particularly significant.

The organisation must already have adopted and applied its own data protection rules before the GDPR's entry into force. The source commentary identifies 25 May 2016 as the relevant date.

This creates a substantial limitation.

A newly established religious organisation cannot simply create its own comprehensive privacy code today and claim the Article 91 regime on that basis. The provision is concerned with continuity of an existing special regime.

This produces an obvious distinction:

Existing qualifying religious organisation with pre-existing rules: potentially eligible.

New religious organisation adopting its own privacy rules after the relevant date: cannot satisfy the temporal condition merely by adopting comprehensive rules now.

The provision can consequently be criticised for favouring historically established religious organisations over newer organisations that did not possess an equivalent legal status or regulatory framework before the GDPR.


4. Practical significance of the temporal condition

The practical impact of this requirement appears to be substantial because relatively few organisations satisfy it.

The source commentary refers to the Jehovah's Witnesses community in Finland, which did not have its own specific data protection rules in place before the relevant date. Its processing was therefore subject to EU data protection law.

The Roman Catholic Church provides another illustration. The special regime may apply in Poland and Italy because specific data protection rules had been adopted there before the GDPR, whereas the same conclusion does not necessarily follow in Member States where such rules had not been adopted.

The consequence is that the same religious institution may effectively operate under different regulatory arrangements depending upon the Member State and the historical legal framework applicable there.


5. The special rules must be comprehensive

The temporal requirement alone is insufficient.

The rules must also be comprehensive.

The GDPR does not prescribe a detailed checklist defining precisely how comprehensive the religious organisation's rules must be. Nevertheless, the source commentary considers that there should be a basic level of equivalence between the organisation's lex specialis and the GDPR, including compliance with fundamental data protection principles and availability of data-subject rights.

This is important because otherwise Article 91 could become an easy mechanism for avoiding GDPR protections.

For example, a religious organisation could not reasonably rely on Article 91 merely because it possesses a short internal privacy policy. The policy must constitute a sufficiently complete data protection framework.


6. Brought into line with the GDPR

The rules must also be brought into line with the GDPR.

This does not necessarily require literal replication of every GDPR provision. The source commentary recognises the possibility of limited divergence where such divergence is necessary to preserve the independence and institutional character of churches and religious associations.

The appropriate question is therefore not:

“Are the religious rules word-for-word identical to the GDPR?”

Rather, it is:

“Do the rules provide an adequate and sufficiently equivalent level of data protection while respecting the legitimate institutional autonomy protected by Article 91?”

This allows Article 91 to operate as a lex specialis without becoming a mechanism for lowering the substantive level of protection.


7. Scope of the special rules

Even where an organisation qualifies under Article 91, the special rules should not necessarily be treated as extending to every processing activity carried out by that organisation.

The source commentary draws a distinction between processing undertaken for strictly religious purposes and processing falling outside those activities. The special rules operate as lex specialis particularly in relation to the former, while processing outside the religious sphere remains subject to the GDPR.

This distinction is significant.

A religious organisation may process personal data for religious membership, worship or related institutional activities. It may also, however, operate schools, hospitals, websites, employment systems, fundraising operations or commercial activities.

The mere fact that the controller is a church does not mean that every one of those activities automatically falls outside the GDPR.


8. Example of religious records

The source commentary refers to a Slovenian case involving a parish of the Roman Catholic Church and a request for erasure from a Baptismal Register. The parish argued that an archival obligation prevented deletion. The Slovenian DPA and subsequently the administrative court upheld the position.

The significance of the example is broader than the outcome.

It demonstrates that the applicable legal framework depends upon the organisation's status and the Member State's legal context. In Slovenia, the relevant church did not satisfy the pre-existing-rules condition and was therefore subject to the GDPR. The dispute then had to be resolved through the GDPR and applicable national law.


9. Independent supervisory authority

Article 91(2) establishes a further safeguard.

Where a church or religious association continues to apply its comprehensive rules under paragraph 1, it must be supervised by an independent supervisory authority. That authority may be a specific authority created for the religious organisation, provided that it satisfies the requirements of Chapter VI GDPR.

This requirement is crucial because otherwise the special regime could become largely self-regulatory.

The organisation may have its own privacy rules, but supervision cannot simply be placed in the hands of an authority lacking the independence required by EU data protection law.


10. Specific religious supervisory authority

Article 91 therefore permits a religious organisation to establish or designate a specific supervisory authority.

The authority may be institution-specific, or the general national or regional DPA may perform the supervisory function. In either case, the requirements of Chapter VI must be satisfied, including independence.

The source commentary gives the Polish Roman Catholic Church as an illustration, where a specific church data protection inspector was established to supervise processing activities.

The institutional model may therefore differ, but the supervisory safeguards cannot simply disappear.


11. Relationship with Article 9

Article 91 is particularly relevant because religious organisations are likely to process information revealing religious or philosophical beliefs, which may fall within the special categories of personal data under Article 9 GDPR.

This helps explain why the provision attempts to reconcile two interests:

protection of sensitive personal data and institutional autonomy of religious organisations.

The existence of Article 91 therefore should not be understood as reducing the importance of data protection within religious organisations. If anything, the nature of the information commonly processed by such organisations makes an adequate regulatory framework particularly important.


12. Conclusion

Article 91 establishes a limited continuity mechanism for churches and religious associations that already possessed comprehensive data protection rules at the time of the GDPR's entry into force.

Its architecture can therefore be expressed as:

qualifying religious organisation + pre-existing rules + comprehensive rules + alignment with GDPR + independent supervision.

Failure to satisfy these requirements means that the organisation remains subject to the GDPR.

The provision therefore protects institutional autonomy without creating a general religious exemption from data protection law. Its underlying balance is between the constitutional and institutional independence of religious organisations on the one hand and the protection of individuals whose personal data they process on the other.