GDPR Articles 85–91: Specific Processing Situations

A comprehensive practitioner guide to Chapter IX — Provisions Relating to Specific Processing Situations — covering exception management, governance obligations, and compliance frameworks for banks, insurers, investment firms, and fintechs.

Introduction: Chapter IX in Context

Articles 85–91 GDPR comprise Chapter IX, "Provisions Relating to Specific Processing Situations." Unlike the core GDPR provisions governing lawful processing, transparency, security, and data subject rights, these articles address specialised processing contexts where privacy rights must be balanced against competing societal, legal, constitutional, or institutional interests.

These include freedom of expression, public access to official records, national identifiers, employment processing, scientific research, professional secrecy, and religious organisations.

Chapter IX Covers

01

Freedom of Expression

Art. 85 — Journalistic, academic, artistic, literary

02

Public Access to Records

Art. 86 — Official documents and transparency

03

National Identifiers

Art. 87 — NI numbers, TINs, passport numbers

04

Employment Processing

Art. 88 — Monitoring, HR, investigations

05

Research & Statistics

Art. 89 — Archiving, AI, fraud analytics

06

Professional Secrecy

Art. 90 — Legal privilege, banking secrecy

07

Religious Organisations

Art. 91 — Pre-GDPR frameworks

Article 85

Processing and Freedom of Expression and Information

Legal Purpose

Article 85 requires Member States to reconcile the fundamental right to personal data protection with the fundamental right to freedom of expression and information. It specifically covers journalistic, academic, artistic, and literary expression. Member States may create exemptions from various GDPR obligations where necessary to preserve freedom of expression.

Banking Example

A bank publishes an investigative report describing a major sanctions evasion network. The report includes names of sanctioned individuals, historical transactions, and corporate ownership information. The bank may rely on legal exemptions created under national implementations of Article 85 when disclosure serves legitimate public interest objectives.

Why This Matters to Banks and Firms

Corporate Journalism

Internal investigative publications and market intelligence reports

Research Publications

Academic partnerships and public-interest research outputs

Historical Archives

Archival records and investigative compliance publications

Whistleblower Disclosures

Published disclosures in the public interest

Required Processes

  • Freedom-of-expression balancing assessments
  • Publication review boards
  • Legal review before disclosure of personal data
  • Records demonstrating necessity and proportionality
  • National law mapping for each jurisdiction

Intersecting Articles

Art. 5 (Principles) · Art. 6 (Lawfulness) · Art. 9 (Special category) · Arts. 12–22 (Data subject rights) · Art. 17 (Erasure) · Art. 21 (Objection) · Art. 24 (Accountability)

Article 86

Processing and Public Access to Official Documents

Legal Purpose

Article 86 recognises that public access laws and transparency laws may require disclosure of documents containing personal data. The Article permits disclosure where national law authorises access and appropriate balancing occurs between transparency and privacy rights.

Why This Matters to Financial Institutions

Although primarily directed toward public authorities, Article 86 affects:

State-Owned Banks

Central Banks

Public Pension Administrators

Government-Backed Lenders

Firms Under Regulatory Investigation

Example

A national regulator receives a freedom-of-information request concerning enforcement activity against a financial institution. Documents contain employee names, investigation records, and correspondence. The regulator must balance transparency obligations against privacy protections.

Required Processes

  • FOI request procedures and disclosure review workflows
  • Redaction standards and public-interest balancing tests
  • Legal review checkpoints

Intersecting Articles: Art. 5 · Art. 6 · Art. 14 · Art. 15 · Art. 17 · Art. 32

Article 87

Processing of National Identification Numbers

Legal Purpose

Article 87 allows Member States to establish specific rules governing national identification numbers, national identifiers, and equivalent identification systems. Banks routinely process National Insurance Numbers, Social Security Numbers, Tax Identification Numbers, national ID card numbers, and passport numbers.

Banking Example

A bank uses national identifiers across customer onboarding, AML verification, KYC checks, and credit assessment. Article 87 requires compliance with both GDPR and national restrictions governing such identifiers.

Intersecting Articles

Art. 5(1)(c) Data minimisation · Art. 6 · Art. 9 · Art. 25 · Art. 32 · Art. 35

Required Technical Controls

Identifier Minimisation

Collect only what is strictly necessary for the processing purpose

Tokenisation

Replace identifiers with non-sensitive tokens in operational systems

Encryption

Strong encryption at rest and in transit for all national identifiers

Role-Based Access Control

Least-privilege enforcement with masking for non-authorised roles

Data Retention Controls

Defined retention schedules aligned to legal and regulatory requirements

Article 88

Processing in the Context of Employment

Article 88 allows Member States to establish more specific employment privacy rules. This is among the most important GDPR provisions for large enterprises, affecting recruitment, employee monitoring, HR systems, performance management, remote working surveillance, diversity programmes, and internal investigations.

Example 1: Trading Floor Monitoring

What Is Monitored

Calls, emails, Bloomberg chats, and trading activity are routinely captured and reviewed.

What Must Be Satisfied

Monitoring must satisfy necessity, proportionality, and national employment privacy rules in each jurisdiction.

Example 2: Insider Trading Surveillance

What Is Analysed

Employee communications may be analysed to detect market abuse, insider dealing, and collusion.

Compliance Requirement

Such processing must remain proportionate, documented, and subject to DPIA review.

Required Processes

Employee Privacy Notices

Clear, accessible notices explaining monitoring scope and legal basis

Workforce Monitoring Policies

Documented policies covering all monitoring channels and technologies

Works Council Engagement

Consultation with employee representatives where required by national law

Monitoring DPIAs

Data Protection Impact Assessments for all high-risk monitoring activities

Internal Investigations Procedures

Documented procedures with access controls and privilege protections

Intersecting Articles: Art. 5 · Art. 6 · Art. 9 · Art. 13 · Art. 14 · Art. 24 · Art. 30 · Art. 32 · Art. 35

Article 89

Processing for Archiving, Research, Historical Research and Statistics

Legal Purpose

Article 89 permits certain derogations from GDPR rights where processing supports archiving in the public interest, scientific research, historical research, or statistical purposes. The Article requires appropriate safeguards, particularly technical and organisational measures.

Example 1: Fraud Research

A bank analyses ten years of historical fraud records to identify emerging attack patterns. Data subject rights may be restricted under national implementations if research objectives would otherwise be impaired and appropriate safeguards exist.

Example 2: AI Model Training

Historical transaction data are used to improve fraud detection models. Appropriate safeguards become mandatory, and the processing must be documented within the Article 30 record.

Intersecting Articles: Art. 5 · Art. 6 · Art. 9(2)(j) · Art. 25 · Art. 30 · Art. 32 · Art. 35

Required Safeguards

Pseudonymisation

Replace direct identifiers before research processing begins

Data Minimisation

Limit data to what is strictly necessary for the research objective

Segregation of Identifiers

Separate identifying data from analytical datasets

Research Governance Boards

Independent oversight of research programmes and data use

Re-identification Controls

Documented authorisation required for any re-identification activity

Article 90

Obligations of Secrecy

Legal Purpose

Article 90 permits Member States to maintain professional secrecy obligations that apply to controllers and processors where necessary to reconcile privacy rights with confidentiality duties.

Banking Relevance

This provision directly affects legal privilege, banking secrecy, professional confidentiality, compliance investigations, and internal audit functions.

Example

A customer submits an access request seeking legal investigation records. Certain records may be protected by legal professional privilege, banking secrecy obligations, or statutory confidentiality requirements.

Required Processes

  • Privilege review procedures
  • Confidentiality classification schemes
  • Legal hold processes
  • Disclosure review workflows

Intersecting Articles: Art. 15 · Art. 17 · Art. 23 · Art. 32

Article 91

Existing Data Protection Rules of Churches and Religious Associations

Legal Purpose

Article 91 permits churches and religious organisations that maintained comprehensive privacy frameworks before GDPR to continue operating those frameworks if aligned with GDPR principles and subject to independent oversight.

Relevance to Commercial Firms

Direct relevance is generally limited. Indirect relevance includes:

Religious-Affiliation Data Processing

Handling of special-category religious data within HR or customer systems

Faith-Based Financial Organisations

Credit unions and cooperative banks with religious governance structures

Employee Religious Accommodation

Processing religious data in the context of workplace accommodation programmes

Example

A faith-based credit union maintains historical member records containing religious affiliation information. Such processing requires compliance with GDPR special-category requirements and any applicable religious-sector governance framework.

Intersecting Articles: Art. 9 · Art. 24 · Art. 30 · Art. 32

Key GDPR Articles Intersecting Across Articles 85–91

The following core GDPR provisions interact with Chapter IX across all seven specialised processing situations. Practitioners must map each derogation back to these foundational obligations.

Twenty Cross-Cutting Technical and Organisational Controls

The following controls address Articles 85–91 compliance across the enterprise. Each control maps to one or more Chapter IX provisions and should be embedded within the firm's broader privacy management framework.

1

Enterprise Data Classification

Framework distinguishing confidential, regulated, research, archival, employment, and publication data

2

Privacy-by-Design Review

Integrated into project governance for all new processing activities

3

Balancing-Test Methodology

Formal methodology for freedom-of-expression and public-interest assessments

4

Regulatory Disclosure Process

Public-access and FOI review process with redaction standards

5

National Identifier Protection Standard

Jurisdiction-specific controls for all national identification numbers

6

Strong Encryption

Encryption for personal identifiers at rest and in transit

7

Tokenisation

Tokenisation of customer and employee identifiers across operational systems

8

Centralised Key Management

Infrastructure supporting encryption lifecycle and access governance

9

Role-Based Access Control

Least-privilege enforcement across all sensitive datasets

10

Attribute-Based Access Control

Fine-grained access control for sensitive and special-category datasets

1

Segregation of Duties

Between operational, compliance, legal, HR, and research functions

2

Comprehensive Audit Logging

Tamper-resistant retention of access and processing logs

3

Automated Monitoring

Unauthorised access detection for employee and customer records

4

Pseudonymisation Platform

Supporting research and statistical processing with re-identification controls

5

Controlled Re-identification

Documented authorisation process for any re-identification activity

6

Data Retention Programme

Archival management aligned to legal and regulatory requirements

7

DPIA Framework

Addressing employment monitoring, research activities, and large-scale analytics

8

Rights Exception Management

Documenting lawful derogations from data subject rights

9

Professional Secrecy Governance

Legal privilege and banking secrecy governance framework

10

Independent Privacy Assurance

Periodic audits, control testing, regulatory horizon scanning, and board-level reporting

Strategic Lessons

Strategic Lessons for Advanced Practitioners

Banks should treat Articles 85–91 as governance provisions requiring demonstrable accountability. The central compliance question is rarely whether an exception exists; it is whether the organisation can prove necessity, proportionality, and appropriate safeguards.

Derogation Governance Framework

Mature organisations implement a formal derogation governance framework that documents:

Legal Basis

Applicable national law and GDPR provision relied upon

Necessity Analysis

Documented assessment of why the derogation is necessary

Proportionality Assessment

Evidence that the interference with rights is proportionate

Safeguards Implemented

Technical and organisational measures in place

Review and Approval History

Ongoing monitoring and audit evidence

Risk Prioritisation for Financial Services

Highest Risk

Article 88 — Employment

Trading floor monitoring, insider surveillance, and HR processing create the highest operational and regulatory risk exposure.

Highest Risk

Article 89 — Research & Statistics

AI model training, fraud analytics, and research partnerships require robust safeguards and DPIA coverage.

High Risk

Article 87 — National Identifiers

Routine processing of NI numbers, TINs, and passport numbers demands strong technical controls and minimisation.

High Risk

Article 90 — Professional Secrecy

Legal privilege and banking secrecy governance must be embedded within the enterprise privacy framework.

Governance Obligations

Articles 85, 86 & 91

Primarily create specialised governance and legal-balancing obligations that must be reflected within the firm's enterprise privacy management framework.

Datari Home

The material within this site is provided for general guidance only and does not constitute legal, regulatory, or professional advice. Datari accepts no liability for any actions taken or not taken based on this content. Organisations should seek their own independent advice before making decisions.