# Confidentiality Obligations and Requirements — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/confidentiality-obligations
> Sources are cited per item. Verify against the official texts before relying on them.

This topic is needed to comprehensively address confidentiality as a distinct data protection principle in the AI Act and GDPR, covering obligations, requirements, and implementation measures specific to maintaining confidentiality of personal and sensitive data.

## Overview

## Confidentiality Obligations and Requirements

## Legal Framework

Confidentiality obligations in EU data protection law operate across multiple instruments. Article 39 GDPR imposes independence and confidentiality requirements on the Data Protection Officer (DPO), who must perform tasks without receiving instructions from the controller or processor and cannot be dismissed or penalized for how those tasks are carried out. The DPO must possess sufficient professional expertise in data protection law and practice, calibrated to the processing activities and the level of protection required for the data involved. Any additional duties held by the DPO must not create conflicts of interest — meaning senior management positions involving determination of processing purposes and means are incompatible with the DPO role.

Article 90 GDPR addresses professional secrecy obligations, while Article 84 of the Digital Services Act (DSA) imposes professional secrecy on the Commission, the Board, competent national authorities, and all persons working under their supervision, including auditors and experts appointed under Article 72(2) DSA. These provisions prevent disclosure of information obtained or exchanged under the respective regulations where that information falls within the scope of professional secrecy.

Under the AI Act, confidentiality requirements extend to the protection of personal and sensitive data used in AI system training, testing, and deployment, reinforcing the GDPR's confidentiality architecture.

## Key Developments

The case law reveals a structured approach to confidentiality conflicts. In the Dutch bar association complaint proceedings, the dean refused data subject access requests by invoking the confidentiality obligation under Article 45a(2) of the Advocatenwet, illustrating how statutory secrecy duties can override GDPR access rights. The court confirmed that judicial review remains possible through Article 8:29 of the General Administrative Law Act (Awb), which allows a confidentiality chamber to restrict disclosure to the court alone — preserving both effective judicial control and secrecy obligations.

In the tax inspector case, the inspector successfully invoked Article 8:29 Awb to restrict access to address history records, grounding the request in both GDPR privacy rights and statutory confidentiality duties. The court accepted that disclosure would violate third parties' privacy and breach professional secrecy.

The company doctor case established that a functional privilege against testifying (functioneel verschoningsrecht) under Article 165(2)(b) of the Dutch Code of Civil Procedure applies to persons bound by professional secrecy. Notably, the employee's waiver of confidentiality did not automatically dissolve the privilege — the court retains discretion to assess whether grounds exist to uphold it, reflecting the broader public interest in maintaining professional secrecy.

The EDPS ruling against the European Parliament confirmed that transferring medical data to a third party — even another EU institution — constitutes an interference with Article 8 ECHR rights, requiring justification under the necessity test.

## Practical Guidance

- **Ensure DPO independence structurally**: Document that the DPO receives no instructions regarding task performance and holds no conflicting roles; avoid assigning DPO duties to positions that determine processing purposes or means, as this violates Article 39 GDPR.

- **Map statutory confidentiality duties against GDPR access rights**: Where sectoral secrecy obligations (legal, medical, tax) conflict with data subject requests under Articles 15–17 GDPR, use procedural mechanisms such as Article 8:29 Awb or equivalent national tools to allow judicial review without breaching confidentiality.

- **Implement confidentiality-by-design for AI systems**: Training data, test outputs, and human review logs containing personal data must be subject to access controls and secrecy protocols that satisfy both GDPR Article 32 security requirements and AI Act confidentiality provisions.

- **Train personnel on functional privilege boundaries**: Staff bound by professional secrecy must understand that individual data subject consent does not automatically waive confidentiality obligations — courts retain discretion to uphold secrecy in the broader public interest.

- **Restrict cross-institutional data transfers**: Transferring sensitive personal data between entities requires a documented necessity assessment; mere institutional affiliation does not suffice to justify the interference with privacy rights.

## Recent developments

### EDPB calls for legal basis for cross-regulatory information sharing

*Source: European Data Protection Board, 2026-07-17 — https://overview.legal/posts/125636 — original: https://www.edpb.europa.eu/news/edpb-calls-for-legal-basis-for-cross-regulatory-information-sharing_en*

Dublin, 17 July– At a high-level meeting in Dublin on 16 and 17 July 2026, the European Data Protection Board (EDPB) called for a clear legal basis for the sharing of information among regulators with different competences. The Board also discussed how to further expand efforts to support a consistent application of the General Data Protection Regulation (GDPR), including through more intense cooperation between Data Protection Authorities (DPAs).A clear legal basis for efficient cross-regulator

### Why the Digital Omnibus puts GDPR and ePrivacy at risk

*Source: European Digital Rights, 2025-11-19 — https://overview.legal/posts/49196 — original: https://edri.org/our-work/why-the-digital-omnibus-puts-gdpr-and-eprivacy-at-risk/*

On 19 November, the European Commission has published two Omnibus proposals: one that rewrites key parts of the General Data Protection Regulation (GDPR) and ePrivacy rules, along with other data-related laws, and another that amends the AI Act. This article focuses on the first proposal. It explains how the changes would weaken core rights to data protection and the confidentiality of communications, and why the combined effect risks reshaping long-standing safeguards for people in the EU. The

### Why the "Digital Omnibus" threatens privacy regulations (GDPR and ePrivacy).

*Source: European Digital Rights, 2025-11-19 — https://overview.legal/posts/52074*

On November 19th, the European Commission published two so-called "omnibus" proposals: one revising key aspects of the General Data Protection Regulation (GDPR) and the ePrivacy rules, along with other data-related laws, and the other an amendment to the AI Act. This article focuses on the first proposal. It explains how the proposed changes could weaken fundamental rights related to data protection and the confidentiality of communications, and why the combined effect risks undermining long-standing safeguards for individuals within the EU.

### Europol told to hand over personal data to Dutch activist

*Source: Fair Trials, 2022-09-15 — https://overview.legal/posts/6280 — original: https://www.fairtrials.org/articles/news/fair-trials-welcomes-a-decision-by-the-european-data-protection-supervisor-edps-ordering-europol-to-hand-over-personal-data-to-dutch-activist-frank-van-der-linde/#entry-356*

The European Data Protection Supervisor ordered Europol to hand over personal data to Dutch activist Frank van der Linde. The decision is the result of a two-year investigation into Europol's possession and storage of van der Linde's personal data.

### Europol wordt gevraagd om persoonlijke gegevens over te dragen aan een Nederlandse activist.

*Source: Fair Trials, 2022-09-15 — https://overview.legal/posts/51821*

De Europese Toezichthouder op de Bescherming van Persoonsgegevens heeft Europol opgedragen om persoonlijke gegevens over te dragen aan de Nederlandse activist Frank van der Linde. Dit besluit is het resultaat van een onderzoek van twee jaar naar de manier waarop Europol de persoonlijke gegevens van Van der Linde bewaart en verwerkt.

## Literature

### Technical Documentation Obligations in Data Protection, Technology, and Cybersecurity Law

*Source: Computer Law Review International, 2026-03-01 — https://overview.legal/posts/132593 — original: https://doi.org/10.9785/cri-2026-270104*

Abstract The article examines the obligation to prepare technical documentation under the GDPR, the CRA, and the AI Act, conducts a comparative analysis to explore synergies, overlaps, and divergences between the technical documentation obligations under the three frameworks, and assesses the feasibility of developing joint technical documentation.

## Related topics

- **Professional Secrecy** — https://overview.legal/topics/professional-secrecy
  Confidentiality obligations for data protection personnel
- **Artificial Intelligence** — https://overview.legal/topics/ai
  AI systems and their implications for data protection
- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Cookies** — https://overview.legal/topics/cookies
  Online tracking technologies and consent requirements
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Monitoring** — https://overview.legal/topics/monitoring
  Systematic observation and tracking of individuals

---
Generated by overview.legal · https://overview.legal/topics/confidentiality-obligations · 2026-08-22
