A comprehensive practitioner guide to Chapter IX — Provisions Relating to Specific Processing Situations — covering exception management, governance obligations, and compliance frameworks for banks, insurers, investment firms, and fintechs.
Articles 85–91 GDPR comprise Chapter IX, "Provisions Relating to Specific Processing Situations." Unlike the core GDPR provisions governing lawful processing, transparency, security, and data subject rights, these articles address specialised processing contexts where privacy rights must be balanced against competing societal, legal, constitutional, or institutional interests.
These include freedom of expression, public access to official records, national identifiers, employment processing, scientific research, professional secrecy, and religious organisations.
Art. 85 — Journalistic, academic, artistic, literary
Art. 86 — Official documents and transparency
Art. 87 — NI numbers, TINs, passport numbers
Art. 88 — Monitoring, HR, investigations
Art. 89 — Archiving, AI, fraud analytics
Art. 90 — Legal privilege, banking secrecy
Art. 91 — Pre-GDPR frameworks
Article 85 requires Member States to reconcile the fundamental right to personal data protection with the fundamental right to freedom of expression and information. It specifically covers journalistic, academic, artistic, and literary expression. Member States may create exemptions from various GDPR obligations where necessary to preserve freedom of expression.
A bank publishes an investigative report describing a major sanctions evasion network. The report includes names of sanctioned individuals, historical transactions, and corporate ownership information. The bank may rely on legal exemptions created under national implementations of Article 85 when disclosure serves legitimate public interest objectives.
Internal investigative publications and market intelligence reports
Academic partnerships and public-interest research outputs
Archival records and investigative compliance publications
Published disclosures in the public interest
Art. 5 (Principles) · Art. 6 (Lawfulness) · Art. 9 (Special category) · Arts. 12–22 (Data subject rights) · Art. 17 (Erasure) · Art. 21 (Objection) · Art. 24 (Accountability)

Article 86 recognises that public access laws and transparency laws may require disclosure of documents containing personal data. The Article permits disclosure where national law authorises access and appropriate balancing occurs between transparency and privacy rights.
Although primarily directed toward public authorities, Article 86 affects:
A national regulator receives a freedom-of-information request concerning enforcement activity against a financial institution. Documents contain employee names, investigation records, and correspondence. The regulator must balance transparency obligations against privacy protections.
Intersecting Articles: Art. 5 · Art. 6 · Art. 14 · Art. 15 · Art. 17 · Art. 32
Article 87 allows Member States to establish specific rules governing national identification numbers, national identifiers, and equivalent identification systems. Banks routinely process National Insurance Numbers, Social Security Numbers, Tax Identification Numbers, national ID card numbers, and passport numbers.
A bank uses national identifiers across customer onboarding, AML verification, KYC checks, and credit assessment. Article 87 requires compliance with both GDPR and national restrictions governing such identifiers.
Art. 5(1)(c) Data minimisation · Art. 6 · Art. 9 · Art. 25 · Art. 32 · Art. 35
Collect only what is strictly necessary for the processing purpose
Replace identifiers with non-sensitive tokens in operational systems
Strong encryption at rest and in transit for all national identifiers
Least-privilege enforcement with masking for non-authorised roles
Defined retention schedules aligned to legal and regulatory requirements
Article 88 allows Member States to establish more specific employment privacy rules. This is among the most important GDPR provisions for large enterprises, affecting recruitment, employee monitoring, HR systems, performance management, remote working surveillance, diversity programmes, and internal investigations.
Calls, emails, Bloomberg chats, and trading activity are routinely captured and reviewed.
Monitoring must satisfy necessity, proportionality, and national employment privacy rules in each jurisdiction.
Employee communications may be analysed to detect market abuse, insider dealing, and collusion.
Such processing must remain proportionate, documented, and subject to DPIA review.
Clear, accessible notices explaining monitoring scope and legal basis
Documented policies covering all monitoring channels and technologies
Consultation with employee representatives where required by national law
Data Protection Impact Assessments for all high-risk monitoring activities
Documented procedures with access controls and privilege protections
Intersecting Articles: Art. 5 · Art. 6 · Art. 9 · Art. 13 · Art. 14 · Art. 24 · Art. 30 · Art. 32 · Art. 35
Article 89 permits certain derogations from GDPR rights where processing supports archiving in the public interest, scientific research, historical research, or statistical purposes. The Article requires appropriate safeguards, particularly technical and organisational measures.
A bank analyses ten years of historical fraud records to identify emerging attack patterns. Data subject rights may be restricted under national implementations if research objectives would otherwise be impaired and appropriate safeguards exist.
Historical transaction data are used to improve fraud detection models. Appropriate safeguards become mandatory, and the processing must be documented within the Article 30 record.
Intersecting Articles: Art. 5 · Art. 6 · Art. 9(2)(j) · Art. 25 · Art. 30 · Art. 32 · Art. 35

Replace direct identifiers before research processing begins
Limit data to what is strictly necessary for the research objective
Separate identifying data from analytical datasets
Independent oversight of research programmes and data use
Documented authorisation required for any re-identification activity
Article 90 permits Member States to maintain professional secrecy obligations that apply to controllers and processors where necessary to reconcile privacy rights with confidentiality duties.
This provision directly affects legal privilege, banking secrecy, professional confidentiality, compliance investigations, and internal audit functions.
A customer submits an access request seeking legal investigation records. Certain records may be protected by legal professional privilege, banking secrecy obligations, or statutory confidentiality requirements.
Intersecting Articles: Art. 15 · Art. 17 · Art. 23 · Art. 32
Article 91 permits churches and religious organisations that maintained comprehensive privacy frameworks before GDPR to continue operating those frameworks if aligned with GDPR principles and subject to independent oversight.
Direct relevance is generally limited. Indirect relevance includes:
Handling of special-category religious data within HR or customer systems
Credit unions and cooperative banks with religious governance structures
Processing religious data in the context of workplace accommodation programmes
A faith-based credit union maintains historical member records containing religious affiliation information. Such processing requires compliance with GDPR special-category requirements and any applicable religious-sector governance framework.
Intersecting Articles: Art. 9 · Art. 24 · Art. 30 · Art. 32
The following core GDPR provisions interact with Chapter IX across all seven specialised processing situations. Practitioners must map each derogation back to these foundational obligations.

The following controls address Articles 85–91 compliance across the enterprise. Each control maps to one or more Chapter IX provisions and should be embedded within the firm's broader privacy management framework.
Framework distinguishing confidential, regulated, research, archival, employment, and publication data
Integrated into project governance for all new processing activities
Formal methodology for freedom-of-expression and public-interest assessments
Public-access and FOI review process with redaction standards
Jurisdiction-specific controls for all national identification numbers
Encryption for personal identifiers at rest and in transit
Tokenisation of customer and employee identifiers across operational systems
Infrastructure supporting encryption lifecycle and access governance
Least-privilege enforcement across all sensitive datasets
Fine-grained access control for sensitive and special-category datasets
Between operational, compliance, legal, HR, and research functions
Tamper-resistant retention of access and processing logs
Unauthorised access detection for employee and customer records
Supporting research and statistical processing with re-identification controls
Documented authorisation process for any re-identification activity
Archival management aligned to legal and regulatory requirements
Addressing employment monitoring, research activities, and large-scale analytics
Documenting lawful derogations from data subject rights
Legal privilege and banking secrecy governance framework
Periodic audits, control testing, regulatory horizon scanning, and board-level reporting
Banks should treat Articles 85–91 as governance provisions requiring demonstrable accountability. The central compliance question is rarely whether an exception exists; it is whether the organisation can prove necessity, proportionality, and appropriate safeguards.
Mature organisations implement a formal derogation governance framework that documents:
Applicable national law and GDPR provision relied upon
Documented assessment of why the derogation is necessary
Evidence that the interference with rights is proportionate
Technical and organisational measures in place
Ongoing monitoring and audit evidence
Trading floor monitoring, insider surveillance, and HR processing create the highest operational and regulatory risk exposure.
AI model training, fraud analytics, and research partnerships require robust safeguards and DPIA coverage.
Routine processing of NI numbers, TINs, and passport numbers demands strong technical controls and minimisation.
Legal privilege and banking secrecy governance must be embedded within the enterprise privacy framework.
Primarily create specialised governance and legal-balancing obligations that must be reflected within the firm's enterprise privacy management framework.
The material within this site is provided for general guidance only and does not constitute legal, regulatory, or professional advice. Datari accepts no liability for any actions taken or not taken based on this content. Organisations should seek their own independent advice before making decisions.
GDPR Articles 85–91: Specific Processing Situations