Article 89(2) allows derogations from data subject rights where personal data are processed for scientific/historical research or statistical purposes. Article 89(3) allows derogations where data are processed for archiving purposes in the public interest. This Brief only considers provisions relating to scientific research.
Member states may derogate from the rights of access, rectification, restriction and to object. The right to erasure contains its own exemption for processing for scientific purposes (Art. 17(3)(d)). The derogations must only apply to the extent this is necessary to avoid data subject rights making it impossible to conduct the scientific research, or seriously impairing this. Derogations are subject to the conditions and safeguards in Art. 89(1), requiring technical and organizational measures to ensure data minimisation and only permitting use of identifiable data if the research purpose cannot be fulfilled with anonymous or pseudonymous data.
Many member states have used Art. 89(2) to introduce derogations from individual rights and have introduced consequential additional safeguards. In Germany, it must remain impossible to draw direct conclusions about specific persons. In the UK results must not be available in identifiable form. In the Netherlands, research institutions may choose not to apply rights of access, rectification and restriction – provided they ensure that the personal data can only be used for statistical or scientific purposes.
Notwithstanding the general ban on processing special category data, member states can allow processing for scientific research (Art. 9 (2)(j). Art. 89 does not constitute a separate authorization, but the safeguards in Art. 89(1) are also required for such processing and there are often supplemental member state safeguards introduced in connection with Art. 9(2)(j).
In Germany, when processing is based on Art. 9(2)(j), a proportionality test exists to determine whether controllers’ interests significantly outweigh data subjects’ interests. In the UK, the research must be in the public interest, must not be likely to cause damage or distress, and measures concerning a particular data subject can only be taken if approved medical research is being undertaken. Spain also has additional requirements for technical and organisational measures, approvals and documentation.
Lastly, readers should note Art.9(4) authorizing member states to adopt further conditions affecting the processing of genetic, biometric, and health data; such conditions may apply in addition to those outlined above. This may be the topic of another Brief.
Again, processing of data for scientific research remains subject to national rules, which must always be checked.
Ruth Boardman is partner at Bird & Bird LLP and co-heads the International Privacy and Data Protection Group.
Fruzsina Molnar-Gabor is research group leader at the Heidelberg Academy of Sciences and Humanities and lecturer at the Legal Faculty of the Heidelberg University.