Final Provisions, Transitional Governance, Regulatory Continuity, and Enterprise Compliance Implications
Articles 94–99 of the GDPR form the concluding provisions of the Regulation. While these articles are often overlooked because they do not contain operational requirements such as lawful basis, consent, security, or breach notification obligations, they are critically important from a governance, regulatory interpretation, legal continuity, and compliance management perspective.
For banks, insurers, payment institutions, investment firms, fintechs, and multinational corporations, Articles 94–99 create governance obligations requiring organisations to:
Article 94 formally repealed the Data Protection Directive 95/46/EC on 25 May 2018 and established that all references to the former Directive are to be interpreted as references to GDPR. The Article also replaced references to the former Article 29 Working Party with the European Data Protection Board (EDPB).
Implemented differently by each Member State — fragmented national compliance with national guidance
Directly applicable — harmonised European requirements with EDPB-led regulatory interpretation
Organisations must ensure:
Legacy policies referencing Directive 95/46/EC must be updated to reflect GDPR
Historic compliance documentation references GDPR, not the repealed Directive
Third-party agreements no longer rely on repealed legal terminology
Internal legal registers reflect current legal sources and EDPB guidance
A bank may possess historic outsourcing contracts, legacy privacy notices, and third-party processor agreements. If these continue referencing Directive 95/46/EC without proper interpretation, legal ambiguity may arise during supervisory reviews.
Management of all applicable regulatory sources
Structured policy review and update management
Systematic review programmes for all legal documents
Horizon-scanning processes monitoring EDPB guidance
Accountability
Controller Responsibility
Privacy by Design
Records of Processing
DPO Requirements
Article 95 prevents duplication between GDPR and the ePrivacy Directive (2002/58/EC). Where a provider is already subject to a specific obligation under the ePrivacy regime, GDPR should not create additional obligations for the same matter.
Many organisations incorrectly assume GDPR is the only privacy law. In reality, both regimes operate simultaneously and must be assessed together.
Governs personal data processing generally across all sectors and contexts
Governs electronic communications specifically — cookies, tracking, and metadata
Analytics, behavioural profiling, and marketing trackers require both GDPR lawful basis and ePrivacy consent
Promotional communications must satisfy GDPR lawful processing and PECR/ePrivacy marketing rules simultaneously
Communications confidentiality and metadata processing governed by both frameworks
A bank deploys analytics cookies, behavioural profiling tools, and marketing trackers. Compliance requires both a GDPR lawful basis assessment and ePrivacy consent requirements. GDPR compliance alone is insufficient.
A retail bank sends promotional SMS messages. Requirements include GDPR lawful processing, PECR/ePrivacy marketing rules, consent management, and opt-out mechanisms — all must be satisfied concurrently.
Lawful Basis
Consent
Transparency
Right to Object
Privacy by Design & Security
Article 96 preserves certain international agreements entered into by Member States before GDPR came into force, provided those agreements remain consistent with Union law.
Organisations operating internationally often rely upon:
Article 96 acknowledges these existing legal commitments and their continued validity.
Banks frequently participate in anti-money laundering investigations, sanctions reporting, cross-border regulatory cooperation, and international supervisory reporting. Organisations must determine:
Whether transfers rely upon GDPR transfer mechanisms such as SCCs or adequacy decisions
Whether transfers rely upon international treaties and whether those obligations remain legally valid
International Transfers
Legal Obligation
Public Interest
Transfer Derogations
Article 97 requires the European Commission to periodically evaluate and report on GDPR implementation and effectiveness. This provision creates a formal review mechanism ensuring GDPR evolves with technology, digital markets, artificial intelligence, cross-border data flows, and emerging privacy risks.

Organisations must expect regulatory interpretations to evolve, new guidance to emerge, supervisory expectations to mature, and enforcement priorities to shift.
Systematic tracking of EDPB guidance, Commission reports, and supervisory authority decisions
Structured processes to assess and implement regulatory changes across the organisation
Periodic review of DPIAs and processing activities against evolving regulatory expectations
Regular governance reporting ensuring senior leadership oversight of regulatory evolution
Article 98 requires the Commission to review other EU legislation involving personal data processing and determine whether amendments are necessary to ensure consistency with GDPR. Data protection obligations are embedded across numerous legal regimes, and Article 98 ensures harmonisation across those frameworks.

Banks operate within multiple overlapping regulatory regimes simultaneously. Compliance teams must understand that GDPR never operates in isolation. Transaction monitoring systems may process personal data because AML legislation requires it — organisations must simultaneously satisfy AML obligations, GDPR requirements, data minimisation principles, and retention requirements.
Comprehensive maps of all applicable regulatory obligations across jurisdictions
Maintained registers of all legal obligations driving personal data processing
Structured assessments identifying conflicts and synergies between regulatory regimes
Unified control frameworks addressing requirements across all applicable regulations
GDPR entered into force on 24 May 2016, beginning the two-year implementation period
GDPR became fully applicable on 25 May 2018, establishing legal enforceability across all Member States
The two-year window allowed organisations to build programmes, update systems, and establish governance
Article 99 remains important because it establishes legal enforceability, marks the start date for accountability obligations, and is relevant in litigation concerning historic processing activities.
A regulator investigating customer profiling practices must determine whether processing occurred before GDPR applicability and whether GDPR requirements applied at the relevant time. This temporal analysis is critical in enforcement proceedings and litigation.
Organisations should view Articles 94–99 as creating a meta-governance layer over GDPR compliance — a constitutional framework that governs how the Regulation functions within the broader European legal ecosystem.
For financial institutions, these obligations are particularly significant because privacy requirements intersect with:
AML, sanctions, and fraud controls
Capital and risk regulation
Consumer protection and MiFID II
Cloud governance and third-party risk
DORA and operational resilience frameworks
The following controls collectively support compliance with Articles 94–99 and their associated governance obligations across the enterprise.
Articles 94–99 are not operational privacy controls — they are constitutional and governance provisions governing how GDPR functions within the broader European legal ecosystem.
Transition from the former Directive regime to a directly applicable Regulation
Structured relationship with ePrivacy requirements preventing duplication
Recognition of international legal obligations and pre-existing treaty commitments
Formal mechanisms ensuring GDPR evolves with technology and supervisory expectations
Harmonisation with other EU legal frameworks across financial and sectoral regulation
The legal authority and applicability of GDPR itself through Article 99

This is particularly important for banks and large financial institutions whose compliance obligations span multiple regulatory domains and jurisdictions — where privacy intersects with financial crime, prudential regulation, conduct requirements, and operational resilience at every level of the enterprise.
The material within this site is provided for general guidance only and does not constitute legal, regulatory, or professional advice. Datari accepts no liability for any actions taken or not taken based on this content. Organisations should seek their own independent advice before making decisions.
GDPR Articles 94–99