CHAPTER XIFINAL PROVISIONS

Article 94Repeal of Directive 95/46/EC

Official text

(1)Directive 95/46/EC is repealed with effect from 25 May 2018.

(2)References to the repealed Directive shall be construed as references to this Regulation. References to the Working Party on the Protection of Individuals with regard to the Processing of Personal Data established by Article 29 of Directive 95/46/EC shall be construed as references to the European Data Protection Board established by this Regulation.

Commentary

Article 94 GDPR is a transitional provision that formally repealed the Data Protection Directive 95/46/EC (the "Data Protection Directive" or "DPD") and replaced it with the GDPR. While seemingly straightforward, Article 94 performs an important constitutional and practical function: it ensures continuity between the old EU data protection regime and the GDPR, while managing the transition from one legal framework to another.

The provision must be read together with:

  • Article 99 GDPR (entry into force and application),

  • Recital 171 GDPR (transition from the Directive to the GDPR),

  • Directive 95/46/EC (the predecessor EU data protection framework),

  • Articles 68-76 GDPR (European Data Protection Board).

1. Purpose of Article 94

Before the GDPR, EU data protection law was primarily governed by Directive 95/46/EC, adopted in 1995.

The Directive established common principles for:

  • lawful processing;

  • data subject rights;

  • international transfers;

  • supervisory authorities;

  • security obligations.

However, as a directive, it required implementation into national law by Member States. This resulted in varying national approaches and differing interpretations across the EU.

The GDPR replaced this model with a directly applicable regulation intended to create a more uniform framework.

Article 94 achieves this by:

  1. formally repealing Directive 95/46/EC;

  2. ensuring references to the Directive are interpreted as references to the GDPR;

  3. replacing references to the Article 29 Working Party with references to the European Data Protection Board (EDPB).


2. Relationship with Article 99 GDPR

A distinction must be drawn between:

  • entry into force, and

  • date of application.

Entry into Force

Under Article 99(1) GDPR, the Regulation entered into force on:

24 May 2016

(or, more precisely, twenty days after publication in the Official Journal on 4 May 2016).

Application Date

Under Article 99(2) GDPR, the GDPR became applicable on:

25 May 2018

Thus, a two-year transition period existed between 2016 and 2018.

Article 94 links the repeal of Directive 95/46/EC to the same date on which the GDPR became applicable.


3. Article 94(1): Repeal of Directive 95/46/EC

Directive 95/46/EC is repealed with effect from 25 May 2018.

This provision formally abolished the Data Protection Directive from the date the GDPR became applicable.


From 25 May 2018 onwards:

  • the GDPR became the principal EU data protection instrument;

  • the Directive ceased to apply;

  • national laws implementing the Directive could no longer operate insofar as they conflicted with the GDPR.


5. Practical Consequence

Any processing occurring on or after 25 May 2018 is assessed under the GDPR rather than the Directive.

Illustration

Suppose a company collected customer data:

  • in 2016;
  • continued processing in 2017;
  • continued processing after 25 May 2018. The lawfulness of processing after 25 May 2018 must be assessed under the GDPR, even though the processing began during the Directive era.

6. Why Repeal Was Necessary

The GDPR was designed to replace fragmentation caused by national implementations of the Directive.

Repeal was therefore necessary to:

  • prevent parallel application of two EU data protection frameworks;

  • ensure uniformity;

  • eliminate legal uncertainty;

  • support the GDPR's goal of full harmonisation.


7. Article 94(2): References to the Directive

References to the repealed Directive shall be construed as references to this Regulation.

This provision is a continuity clause.

Its purpose is to ensure that existing laws, regulations, contracts, decisions, guidance documents, and administrative acts do not become obsolete simply because they refer to Directive 95/46/EC.


8. Practical Effect

After 25 May 2018:

A reference to the Directive is generally interpreted as a reference to the corresponding provision of the GDPR.

This avoids the need to immediately amend countless legislative and administrative texts across the European Union.


9. Illustration

A national law adopted before 2018 may contain wording such as:

"in accordance with Directive 95/46/EC."

Following Article 94(2), such wording is generally interpreted as referring to the GDPR.

This allows legal continuity pending formal legislative updates.


10. Replacement of the Article 29 Working Party

Article 94(2) also addresses references to the former Article 29 Working Party (WP29).


11. What Was WP29?

The Article 29 Working Party was established under Article 29 of Directive 95/46/EC.

It consisted of representatives from:

  • national data protection authorities;

  • the European Data Protection Supervisor;

  • the European Commission.

Its main role was to issue:

  • opinions;

  • recommendations;

  • interpretative guidance.

Although influential, it did not possess the stronger institutional role now assigned to the EDPB.


12. Transition to the EDPB

The GDPR abolished WP29 and replaced it with the:

European Data Protection Board (EDPB)

under Article 68 GDPR.

Therefore, Article 94(2) provides that references to WP29 should be understood as references to the EDPB.


13. Illustration

A pre-2018 legal instrument might state:

"the Article 29 Working Party may issue guidance."

After application of Article 94(2), this is generally understood as referring to the EDPB.


14. Recital 171: Transitional Arrangements

Recital 171 explains how processing that already existed before 25 May 2018 should be treated.

The Recital serves as a bridge between:

  • the Directive era; and

  • the GDPR era.


15. Existing Processing Operations

Recital 171 recognises that many processing operations already existed when the GDPR became applicable.

The GDPR did not require organisations to terminate and restart those activities.

Instead, controllers were expected to bring existing processing into GDPR compliance.


16. Illustration

A company operating a customer database since 2010 could continue using that database after 25 May 2018.

However, it had to ensure compliance with GDPR requirements relating to:

  • transparency;

  • legal basis;

  • rights;

  • retention;

  • security;

  • accountability.


17. Treatment of Existing Consents

One of the most important aspects of Recital 171 concerns consent obtained before 25 May 2018.

The Recital states that fresh consent is not automatically required.


18. General Rule

Consent collected under Directive 95/46/EC may continue to be relied upon if it satisfies GDPR standards.

Accordingly:

✅ No re-consent required if the original consent already met GDPR requirements.

❌ Re-consent required if the prior consent failed to meet GDPR standards.

Example

Valid Legacy Consent A company obtained consent through:

  • a clear opt-in mechanism;
  • specific purpose descriptions;
  • an informed choice;
  • freely given consent. Such consent would likely satisfy GDPR requirements and remain valid.

19. Example: Invalid Legacy Consent

A company relied on:

  • pre-ticked boxes;

  • bundled consent;

  • vague disclosures;

  • implied consent from inactivity.

These mechanisms generally fail GDPR standards.

In such circumstances controllers would need a new legal basis or would need to obtain fresh GDPR-compliant consent.


20. Existing Commission Decisions and Supervisory Authorisations

Recital 171 further provides that decisions and authorisations adopted under the Directive should generally remain effective.

Examples

include:

  • adequacy decisions;
  • transfer authorisations;
  • supervisory approvals;
  • administrative decisions. These remain in force unless:
  • amended;
  • replaced;
  • repealed.

21. Purpose of This Rule

Without such a provision, numerous legal instruments would have become invalid immediately on 25 May 2018.

This would have caused considerable disruption to:

  • international transfers;

  • approved data-sharing mechanisms;

  • binding corporate rules;

  • supervisory practices.

Recital 171 therefore promotes legal certainty.


22. Practical Significance Today

Article 94 played a crucial role during the 2016-2018 transition period.

Its most enduring significance today lies in:

1. Historical Interpretation

Many older laws, guidance documents, contracts, and court decisions refer to Directive 95/46/EC.

Article 94 helps interpret those references in a GDPR context.

2. Legacy Consents

Questions occasionally still arise regarding consent obtained before May 2018.

Recital 171 provides the framework for assessing whether those consents remain valid.

3. Continuity of Guidance

Many WP29 opinions continue to be cited by regulators, courts, and commentators because the EDPB has endorsed or adopted substantial portions of that guidance.

Article 94 provides the legal bridge for that continuity.


23. Key Takeaways

  • Article 94 formally repealed Directive 95/46/EC with effect from25 May 2018.

  • The GDPR entered into force in 2016 but became applicable on 25 May 2018, creating a two-year transition period.

  • References to the old Directive are generally interpreted as references to the GDPR.

  • References to the Article 29 Working Party (WP29) are interpreted as references to theEuropean Data Protection Board (EDPB).

  • Existing processing activities did not need to stop, but had to be brought into GDPR compliance.

  • Pre-GDPR consent remains valid only if it satisfies GDPR consent requirements.

  • Existing Commission decisions and supervisory authorisations adopted under the Directive generally remained in force until amended, replaced, or repealed.

  • Article 94 is therefore a continuity and transition provision, ensuring a smooth legal shift from the 1995 Data Protection Directive regime to the GDPR framework that applies today.