Professional Secrecy
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Confidentiality obligations for data protection personnel
Overview
23 sources · Jul 23, 2026Professional Secrecy
Legal Framework
Professional secrecy obligations in the data protection context arise from multiple legal instruments. Article 84 of the Digital Services Act imposes a binding confidentiality duty on the Commission, the Board, Member States' competent authorities, their officials, and any other natural or legal persons involved in regulatory activities — including auditors and experts appointed under Article 72(2) DSA. These actors must not disclose information acquired or exchanged pursuant to the Regulation that falls within the scope of professional secrecy.
Under the GDPR, the Data Protection Officer's independence is structurally protected through Article 39. The DPO must perform tasks without receiving instructions from the controller or processor regarding how those tasks are carried out. The DPO cannot be dismissed or penalized for the manner in which they discharge their duties. This independence is reinforced by a conflict-of-interest prohibition: the DPO may hold other functions, but the controller must ensure those do not conflict with DPO responsibilities. Senior management positions — such as CEO, CFO, or roles involving determining the purposes and means of data processing — are inherently incompatible with the DPO role.
Article 90 GDPR provides a specific confidentiality framework, though its implementation varies by Member State. The rationale across these provisions is consistent: persons entrusted with sensitive data protection information must be shielded from both external disclosure pressure and internal organizational conflicts that could compromise their objectivity.
Key Developments
Dutch case law illustrates the practical tension between professional secrecy and data subject access rights. In a case involving the Dean of the Bar, the court confirmed that the statutory confidentiality obligation under Article 45a(2) of the Advocatenwet justified refusing to disclose complaint file materials to the data subject. However, the court established a critical procedural mechanism: the holder of the secrecy obligation can invoke Article 8:29 of the General Administrative Law Act (Awb), requesting that the court review documents in a restricted "secrecy chamber" — allowing judicial supervision without breaching confidentiality.
A separate tax case reinforced that privacy rights under the GDPR and professional secrecy obligations can jointly justify withholding documents from interested parties, with the court accepting restricted-knowledge procedures as an adequate safeguard.
The functional privilege against testifying was addressed in a 2023 appellate decision involving a company physician. The court applied Article 165(2)(b) of the Dutch Code of Civil Procedure, evaluating whether a functional right to refuse testimony exists for professionals bound by secrecy obligations. Notably, the patient's explicit waiver — stating the physician could disclose everything — did not automatically extinguish the privilege, as the court weighed the broader public interest underlying professional secrecy.
The EDPS decision against the European Parliament underscored that transferring medical data to another EU institution constitutes an interference with Article 8 ECHR rights, regardless of the recipient's identity or intended use.
Practical Guidance
Establish formal secrecy protocols for DPOs and data protection personnel that mirror Article 39 GDPR independence requirements, including written confirmation that the DPO will not receive instructions on task execution and cannot face dismissal or penalty for their advisory conclusions.
Screen DPO candidates for conflict of interest before appointment and periodically thereafter — any role involving determining processing purposes or means, or senior management responsibility, disqualifies the individual under Article 39.
Implement restricted-access procedures for DSAR responses involving confidential materials — where secrecy obligations conflict with access requests, use judicial review mechanisms (such as the Awb Article 8:29 secrecy chamber procedure) rather than blanket refusals, to preserve both confidentiality and judicial oversight.
Train personnel on the limits of consent-based waivers — a data subject's consent to disclosure does not necessarily override functional secrecy obligations, particularly where broader institutional or third-party interests are at stake.
Review AI tool deployments against confidentiality requirements — emerging risks from AI-assisted document processing can compromise professional secrecy where sensitive regulatory or complaint data is exposed to third-party models without adequate contractual and technical safeguards.