CHAPTER XIFINAL PROVISIONS

Article 98Review of other Union legal acts on data protection

Official text

The Commission shall, if appropriate, submit legislative proposals with a view to amending other Union legal acts on the protection of personal data, in order to ensure uniform and consistent protection of natural persons with regard to processing. This shall in particular concern the rules relating to the protection of natural persons with regard to processing by Union institutions, bodies, offices and agencies and on the free movement of such data.

Commentary

Article 98 GDPR requires the European Commission to consider whether other European Union legal instruments dealing with personal data should be amended so that individuals receive uniform and consistent protection across the EU legal order. The provision addresses a structural problem: the GDPR is the general EU framework for personal data protection, but it is not the only EU instrument governing the processing of personal data.

Numerous EU legislative acts contain sector-specific data protection rules. These may concern EU institutions, financial regulation, criminal justice, law enforcement, border control, migration, telecommunications, healthcare, transport, anti-money laundering, or cooperation through EU agencies. If those rules use different concepts, provide weaker safeguards, or conflict with the GDPR’s principles, the overall EU data protection framework can become fragmented.

Article 98 therefore gives the Commission a legislative-review function. Where appropriate, the Commission must propose amendments to other EU acts so that they operate consistently with the GDPR.

The provision is particularly connected with:

  • Article 2(3) GDPR, concerning processing by EU institutions, bodies, offices and agencies;

  • Recital 17 GDPR, concerning the adaptation of Regulation (EC) No 45/2001;

  • Article 95 and Recital 173 GDPR, concerning the relationship with the ePrivacy Directive;

  • Article 97 GDPR, concerning periodic review of the GDPR itself;

  • the principles in Article 5 GDPR;

  • the fundamental rights guaranteed by Articles 7, 8 and 47 of the Charter of Fundamental Rights of the European Union.

1. Purpose of Article 98

The central objective of Article 98 is to prevent the EU from maintaining separate and inconsistent levels of data protection under different legislative instruments.

The GDPR seeks to establish a coherent framework based on principles such as:

  • lawfulness, fairness and transparency;

  • purpose limitation;

  • data minimisation;

  • accuracy;

  • storage limitation;

  • integrity and confidentiality;

  • accountability.

It also creates rights relating to access, rectification, erasure, restriction, objection, portability, and automated decision-making. If another EU act authorises personal data processing without equivalent safeguards, the effectiveness of the GDPR could be undermined.

Illustration

Suppose an older EU regulation allows an EU agency to retain personal data indefinitely, while Article 5(1)(e) GDPR requires data to be retained only for as long as necessary. Article 98 requires the Commission to consider whether the older regulation should be amended to introduce defined retention periods, periodic review, and deletion requirements. Article 98 does not automatically invalidate older EU legislation. Nor does it directly amend another EU act. Instead, it requires the Commission to review relevant legislation and, where appropriate, submit legislative proposals through the proper EU legislative process.


Article 98 applies to Union legal acts, meaning legal instruments adopted at EU level. These may include:

  • regulations;

  • directives;

  • decisions;

  • sector-specific legislative measures;

  • legal instruments governing EU bodies or agencies.

The provision does not primarily concern domestic laws adopted independently by Member States. National legislation must comply with the GDPR and EU law through other mechanisms, but Article 98 specifically addresses the consistency of the EU’s own legislative framework.

The phrase “other Union legal acts on the protection of personal data” should be interpreted functionally. It is not necessarily limited to legislation whose main title or principal purpose is data protection. It may also cover legislation that authorises, requires, structures or limits personal data processing in a particular sector.

Illustration

An EU instrument governing anti-money laundering may primarily regulate financial crime prevention, but it may also require financial institutions to collect identity documents, beneficial ownership information, transaction records and risk profiles. Those processing rules may be relevant to Article 98 because they directly affect the protection of personal data. A narrow interpretation limited only to legislation expressly labelled “data protection law” would reduce the practical value of Article 98. Personal data processing occurs throughout the EU legal system, including legislation whose primary purpose is unrelated to privacy.


3. The Commission’s obligation

Article 98 states that the Commission shall, “if appropriate,” submit legislative proposals.

This wording creates a two-stage responsibility.

Stage one: review and assessment

The Commission must consider whether another EU legal act remains consistent with the GDPR’s framework.

Stage two: legislative proposal

If the Commission concludes that amendment is appropriate, it must submit a proposal through the applicable EU legislative procedure.

The phrase “if appropriate” gives the Commission discretion. Article 98 does not require an amendment merely because another EU act contains specialised rules. Differences may be justified by the nature of the sector, the purpose of processing, or the applicable constitutional framework.

For example, processing by law enforcement authorities cannot be treated identically to routine customer marketing. Specialised legal rules may therefore be legitimate. The relevant question is whether the differences preserve an appropriate and consistent level of fundamental-rights protection.

Illustration

An EU law governing epidemic surveillance may permit processing of health information for public-health purposes. That special rule does not necessarily conflict with the GDPR merely because it differs from ordinary commercial processing. The Commission should assess whether the legislation defines the purpose, limits the data collected, establishes retention rules, controls access, and provides effective safeguards.


4. “Uniform and consistent protection”

Article 98 does not demand that every EU legal instrument reproduce the GDPR word for word. Its objective is uniform and consistent protection, not mechanical textual identity.

Uniform protection

Individuals should not receive substantially weaker protection merely because their data is processed under a specialised EU instrument rather than directly under the GDPR.

Consistent protection

Different rules should operate coherently. Concepts such as personal data, processing, controller, processor, consent, security and data subject rights should not contradict one another without a valid justification.

Consistency may require examination of:

  • lawful grounds for processing;

  • categories of data collected;

  • purpose limitations;

  • access permissions;

  • storage periods;

  • security requirements;

  • independent supervision;

  • data subject rights;

  • complaint and judicial remedies;

  • international transfer safeguards;

  • automated decision-making;

  • restrictions on rights.

Illustration

If one EU instrument defines personal data more narrowly than Article 4(1) GDPR and excludes online identifiers without justification, persons affected by that legislation may receive weaker protection. Article 98 allows the Commission to consider an amendment aligning the specialised definition with the GDPR. Uniformity does not mean that every right must apply without exception. Restrictions may be justified, but they should be clear, necessary and proportionate, particularly where fundamental rights under the Charter are affected.


5. Special focus on EU institutions, bodies, offices and agencies

Article 98 expressly states that the review should particularly concern rules governing processing by:

  • EU institutions;

  • EU bodies;

  • EU offices;

  • EU agencies.

This reflects Article 2(3) GDPR andRecital 17.

The GDPR primarily regulates controllers and processors within its general scope. Personal data processing by EU institutions was historically governed by a separate legal instrument, Regulation (EC) No 45/2001. Article 98 required that institutional framework and other relevant EU acts to be adapted to the GDPR’s principles.

The objective was to avoid a situation in which private organisations and Member State authorities were subject to modern GDPR standards while EU institutions continued to operate under an outdated framework.

Illustration

If the European Commission collects personal data from applicants for an EU programme, those individuals should receive protection broadly consistent with the standards applicable when a national administration collects comparable information. This includes transparency, security, defined purposes, retention limits, enforceable rights and independent supervision. Special institutional rules may still be required because EU institutions have distinct legal structures and functions. The point is not that the GDPR must directly govern every institutional activity. The point is that the separate framework should reflect equivalent principles and safeguards.


6. Role of Recital 17

Recital 17 explains the intended adaptation of Regulation (EC) No 45/2001 and other EU acts applicable to institutional processing.

It provides three important interpretative points.

First, separate rules for EU institutions were expected to continue operating. The GDPR did not simply absorb all institutional processing into its ordinary framework.

Second, those separate rules had to be adapted to the GDPR’s principles and interpreted in light of the GDPR.

Third, the objective was a strong and coherent data protection framework across the Union.

Article 98 is the legislative mechanism supporting that objective. Recital 17 supplies the policy justification, while Article 98 empowers and requires the Commission to consider legislative proposals.

7. Relationship with the ePrivacy Directive and Recital 173

Recital 173 anticipated a review of Directive 2002/58/EC, the ePrivacy Directive, to ensure consistency with the GDPR.

The ePrivacy Directive contains specialised rules on matters such as:

  • confidentiality of communications;

  • traffic and location data;

  • electronic marketing;

  • cookies and access to terminal equipment.

Article 95 explains how the GDPR and ePrivacy Directive interact where both regulate the same matter. Article 98 addresses a different issue: whether other EU legislation should itself be revised to fit the GDPR framework more coherently.

Illustration

If an electronic communications rule uses an older concept of consent, the Commission may need to consider whether the legislation should be updated so that consent aligns with Articles 4(11) and 7 GDPR. Accordingly, Article 95 manages overlap under existing law, while Article 98 supports possible legislative alignment.


7. Types of inconsistency that may require review

The Commission may need to consider amendment where another EU act:

  1. uses outdated terminology;

  2. permits broader processing than necessary;

  3. lacks defined storage periods;

  4. provides inadequate security duties;

  5. omits transparency requirements;

  6. restricts data subject rights without sufficient justification;

  7. lacks independent supervision;

  8. provides no effective complaint or judicial remedy;

  9. allows transfers without adequate safeguards;

  10. enables extensive profiling without appropriate protections.

Illustration

An older EU instrument may require a central database but fail to specify when records must be erased. Even if the database serves a legitimate purpose, the absence of retention controls may conflict with storage limitation. The Commission could propose an amendment establishing maximum periods and periodic necessity reviews.


8. Relationship with Article 97

Articles 97 and 98 serve related but distinct purposes.

  • Article 97 requires periodic evaluation of the GDPR itself.

  • Article 98 concerns amendment of other EU legal acts to ensure consistency with the GDPR.

An Article 97 review may reveal that difficulties arise not from the GDPR but from conflicting sector-specific legislation. Article 98 provides the pathway for addressing those external inconsistencies.

Illustration

If the Commission’s GDPR review finds that individuals receive different access rights depending on which EU agency processes their data, the appropriate response may be amendment of the agency’s governing legislation under Article 98 rather than amendment of Article 15 GDPR.


9. Article 98 does not itself amend legislation

Article 98 does not give the Commission unilateral power to rewrite other EU laws. The Commission may submit a legislative proposal, but adoption normally requires participation by the European Parliament and Council in accordance with the applicable Treaty procedure.

The ordinary sequence is:

  1. Commission identifies an inconsistency;

  2. Commission conducts legal and policy assessment;

  3. Commission prepares a legislative proposal;

  4. Parliament and Council examine the proposal;

  5. amendments may be negotiated;

  6. the new act is adopted and enters into force.

This preserves the institutional balance of the EU. Article 98 gives the Commission an initiative and review role, not unrestricted legislative authority.


10. Practical Summary

Article 98 is a coherence provision for the wider EU data protection framework. It requires the Commission to consider amendments to other EU legislation where this is needed to maintain uniform and consistent protection.

Its principal elements are:

  • it concerns EU legal acts beyond the GDPR;

  • it supports alignment rather than automatic displacement;

  • it applies particularly to legislation governing EU institutions and agencies;

  • it may cover sector-specific acts even where data protection is not their primary subject;

  • it requires consistency in principles, safeguards, rights, supervision and remedies;

  • it allows justified specialised rules, provided they preserve effective fundamental-rights protection;

  • it requires legislative proposals where amendment is appropriate;

  • it does not permit the Commission to amend legislation without the applicable legislative process.

In substance, Article 98 recognises that the GDPR cannot deliver coherent protection if the remainder of EU law operates under conflicting or outdated data protection standards. It therefore provides a basis for maintaining the GDPR as the central reference point within a broader, internally consistent EU data protection system.