GDPR Articles 94–99

Final Provisions, Transitional Governance, Regulatory Continuity, and Enterprise Compliance Implications

Introduction

Articles 94–99 of the GDPR form the concluding provisions of the Regulation. While these articles are often overlooked because they do not contain operational requirements such as lawful basis, consent, security, or breach notification obligations, they are critically important from a governance, regulatory interpretation, legal continuity, and compliance management perspective.

For Advanced Practitioners, These Articles Establish:

  • The legal transition from the former Data Protection Directive 95/46/EC to GDPR
  • The relationship between GDPR and sector-specific privacy legislation
  • The interaction between GDPR and pre-existing international agreements
  • Ongoing regulatory review obligations
  • Future evolution of the European data protection framework
  • The legal applicability and enforceability of GDPR itself

For Financial Institutions and Multinationals

For banks, insurers, payment institutions, investment firms, fintechs, and multinational corporations, Articles 94–99 create governance obligations requiring organisations to:

  • Continuously monitor regulatory change
  • Maintain legal inventories
  • Align controls with evolving interpretations
  • Ensure compliance frameworks remain current

Article 94 – Repeal of Directive 95/46/EC

Legal Meaning

Article 94 formally repealed the Data Protection Directive 95/46/EC on 25 May 2018 and established that all references to the former Directive are to be interpreted as references to GDPR. The Article also replaced references to the former Article 29 Working Party with the European Data Protection Board (EDPB).

The Fundamental Shift

1

From Directive

Implemented differently by each Member State — fragmented national compliance with national guidance

2

To Regulation

Directly applicable — harmonised European requirements with EDPB-led regulatory interpretation

Implications for Firms and Banks

Organisations must ensure:

Policy Updates

Legacy policies referencing Directive 95/46/EC must be updated to reflect GDPR

Documentation

Historic compliance documentation references GDPR, not the repealed Directive

Vendor Contracts

Third-party agreements no longer rely on repealed legal terminology

Legal Registers

Internal legal registers reflect current legal sources and EDPB guidance

Article 94 – Banking Example & Key Considerations

Banking Example

A bank may possess historic outsourcing contracts, legacy privacy notices, and third-party processor agreements. If these continue referencing Directive 95/46/EC without proper interpretation, legal ambiguity may arise during supervisory reviews.

Key Compliance Considerations

Regulatory Inventory

Management of all applicable regulatory sources

Policy Lifecycle

Structured policy review and update management

Legal Document Review

Systematic review programmes for all legal documents

EDPB Integration

Horizon-scanning processes monitoring EDPB guidance

Intersecting GDPR Articles

Art. 5

Accountability

Art. 24

Controller Responsibility

Art. 25

Privacy by Design

Art. 30

Records of Processing

Art. 37–39

DPO Requirements

Article 95 – Relationship with the ePrivacy Directive

Article 95 prevents duplication between GDPR and the ePrivacy Directive (2002/58/EC). Where a provider is already subject to a specific obligation under the ePrivacy regime, GDPR should not create additional obligations for the same matter.

Why This Matters

Many organisations incorrectly assume GDPR is the only privacy law. In reality, both regimes operate simultaneously and must be assessed together.

GDPR

Governs personal data processing generally across all sectors and contexts

ePrivacy

Governs electronic communications specifically — cookies, tracking, and metadata

Key Areas of Overlap

Cookies & Tracking

Analytics, behavioural profiling, and marketing trackers require both GDPR lawful basis and ePrivacy consent

Electronic Marketing

Promotional communications must satisfy GDPR lawful processing and PECR/ePrivacy marketing rules simultaneously

Telecommunications & Metadata

Communications confidentiality and metadata processing governed by both frameworks

Article 95 – Banking Sector Examples & Risks

Mobile Banking Application

A bank deploys analytics cookies, behavioural profiling tools, and marketing trackers. Compliance requires both a GDPR lawful basis assessment and ePrivacy consent requirements. GDPR compliance alone is insufficient.

Marketing SMS Campaigns

A retail bank sends promotional SMS messages. Requirements include GDPR lawful processing, PECR/ePrivacy marketing rules, consent management, and opt-out mechanisms — all must be satisfied concurrently.

Intersecting GDPR Articles

Art. 6

Lawful Basis

Art. 7

Consent

Art. 12–14

Transparency

Art. 21

Right to Object

Art. 25 & 32

Privacy by Design & Security

Article 96 – Relationship with International Agreements

Article 96 preserves certain international agreements entered into by Member States before GDPR came into force, provided those agreements remain consistent with Union law.

Why This Matters

Organisations operating internationally often rely upon:

  • Mutual legal assistance treaties
  • International financial reporting agreements
  • Law enforcement cooperation frameworks
  • Cross-border regulatory information sharing arrangements

Article 96 acknowledges these existing legal commitments and their continued validity.

Implications for Financial Institutions

Banks frequently participate in anti-money laundering investigations, sanctions reporting, cross-border regulatory cooperation, and international supervisory reporting. Organisations must determine:

GDPR Mechanisms

Whether transfers rely upon GDPR transfer mechanisms such as SCCs or adequacy decisions

Treaty Obligations

Whether transfers rely upon international treaties and whether those obligations remain legally valid

Intersecting GDPR Articles

Art. 44–50

International Transfers

Art. 6(1)(c)

Legal Obligation

Art. 6(1)(e)

Public Interest

Art. 49

Transfer Derogations

Article 97 – Commission Reports

Legal Meaning

Article 97 requires the European Commission to periodically evaluate and report on GDPR implementation and effectiveness. This provision creates a formal review mechanism ensuring GDPR evolves with technology, digital markets, artificial intelligence, cross-border data flows, and emerging privacy risks.

Compliance Is Not Static

Organisations must expect regulatory interpretations to evolve, new guidance to emerge, supervisory expectations to mature, and enforcement priorities to shift.

Governance Requirements

Regulatory Monitoring Programmes

Systematic tracking of EDPB guidance, Commission reports, and supervisory authority decisions

Legal Change Management

Structured processes to assess and implement regulatory changes across the organisation

Privacy Impact Reassessment Cycles

Periodic review of DPIAs and processing activities against evolving regulatory expectations

Board-Level Compliance Reporting

Regular governance reporting ensuring senior leadership oversight of regulatory evolution

Article 98 – Review of Other Union Legal Acts

Article 98 requires the Commission to review other EU legislation involving personal data processing and determine whether amendments are necessary to ensure consistency with GDPR. Data protection obligations are embedded across numerous legal regimes, and Article 98 ensures harmonisation across those frameworks.

Banking Implications

Banks operate within multiple overlapping regulatory regimes simultaneously. Compliance teams must understand that GDPR never operates in isolation. Transaction monitoring systems may process personal data because AML legislation requires it — organisations must simultaneously satisfy AML obligations, GDPR requirements, data minimisation principles, and retention requirements.

Governance Expectations

Regulatory Mapping Inventories

Comprehensive maps of all applicable regulatory obligations across jurisdictions

Legal Obligation Registers

Maintained registers of all legal obligations driving personal data processing

Cross-Regulatory Assessments

Structured assessments identifying conflicts and synergies between regulatory regimes

Enterprise Control Frameworks

Unified control frameworks addressing requirements across all applicable regulations

Article 99 – Entry into Force and Application

24 May

Entry into Force

GDPR entered into force on 24 May 2016, beginning the two-year implementation period

25 May

Became Applicable

GDPR became fully applicable on 25 May 2018, establishing legal enforceability across all Member States

2 Years

Implementation Period

The two-year window allowed organisations to build programmes, update systems, and establish governance

Current Relevance

Article 99 remains important because it establishes legal enforceability, marks the start date for accountability obligations, and is relevant in litigation concerning historic processing activities.

Banking Example

A regulator investigating customer profiling practices must determine whether processing occurred before GDPR applicability and whether GDPR requirements applied at the relevant time. This temporal analysis is critical in enforcement proceedings and litigation.

What the Two-Year Period Enabled

  • Build compliance programmes from the ground up
  • Update systems and technical infrastructure
  • Establish governance structures and DPO functions
  • Train staff across all business lines
  • Implement technical and organisational controls

Cross-Cutting Implications for Firms and Banks

Organisations should view Articles 94–99 as creating a meta-governance layer over GDPR compliance — a constitutional framework that governs how the Regulation functions within the broader European legal ecosystem.

Regulatory Intelligence

  • Regulatory intelligence functions
  • Legal horizon scanning
  • EDPB monitoring processes
  • Automated regulatory alerting

Policy Governance

  • Policy governance frameworks
  • Compliance change management
  • Legal document version control
  • Privacy policy lifecycle management

Legal Inventories

  • Cross-jurisdictional legal inventories
  • Regulatory mapping frameworks
  • Data protection legal inventory
  • Regulatory obligations register

Enterprise Architecture

  • Enterprise compliance architecture
  • Cross-regulatory control frameworks
  • Board-level privacy oversight
  • Continuous compliance monitoring

Intersection with Financial Regulation

For financial institutions, these obligations are particularly significant because privacy requirements intersect with:

Financial Crime

AML, sanctions, and fraud controls

Prudential

Capital and risk regulation

Conduct

Consumer protection and MiFID II

Outsourcing

Cloud governance and third-party risk

Resilience

DORA and operational resilience frameworks

Twenty Cross-Cutting Technical and Organisational Controls

The following controls collectively support compliance with Articles 94–99 and their associated governance obligations across the enterprise.

01

Enterprise Regulatory Change Management Programme

02

Formal Privacy Governance Framework

03

Data Protection Legal Inventory

04

Regulatory Obligations Register

05

EDPB Guidance Monitoring Process

06

Regulatory Horizon-Scanning Capability

07

Privacy Policy Lifecycle Management Process

08

Legal Document Version-Control System

09

Compliance Evidence Repository

10

Enterprise Records Management Framework

01

Data Processing Inventory Management

02

Automated Regulatory Alerting Mechanisms

03

Cross-Border Data Transfer Governance Process

04

Data-Sharing Agreement Management Framework

05

Third-Party Processor Governance Programme

06

Privacy Impact Assessment Review Programme

07

Board-Level Privacy Oversight Reporting

08

Regulatory Compliance Training Programme

09

Internal Privacy Audit Function

10

Continuous Compliance Monitoring and Assurance Programme

Advanced Practitioner Teaching Points

Articles 94–99 are not operational privacy controls — they are constitutional and governance provisions governing how GDPR functions within the broader European legal ecosystem.

What These Articles Establish

Legal Continuity

Transition from the former Directive regime to a directly applicable Regulation

ePrivacy Interaction

Structured relationship with ePrivacy requirements preventing duplication

International Recognition

Recognition of international legal obligations and pre-existing treaty commitments

Continuous Evolution

Formal mechanisms ensuring GDPR evolves with technology and supervisory expectations

EU Framework Alignment

Harmonisation with other EU legal frameworks across financial and sectoral regulation

Legal Authority

The legal authority and applicability of GDPR itself through Article 99

This is particularly important for banks and large financial institutions whose compliance obligations span multiple regulatory domains and jurisdictions — where privacy intersects with financial crime, prudential regulation, conduct requirements, and operational resilience at every level of the enterprise.

Datari Home

The material within this site is provided for general guidance only and does not constitute legal, regulatory, or professional advice. Datari accepts no liability for any actions taken or not taken based on this content. Organisations should seek their own independent advice before making decisions.