Skip to content
Topic Contested in court

Professional Secrecy

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Confidentiality obligations for data protection personnel

120 linked items 7 Laws35 Case Law25 Guidance39 Enforcement13 News

Overview

25 sources · Sep 8, 2026

Legal Framework

Professional secrecy under the GDPR operates across at least four provisions, each targeting a different actor in the data-protection ecosystem. The most direct obligation falls on Data Protection Officers. Article 38(5) imposes a binding confidentiality duty on the DPO with respect to the performance of their tasks, anchored in Union or Member State law:

"The data protection officer shall be bound by secrecy or confidentiality concerning the performance of his or her tasks, in accordance with Union or Member State law."
— GDPR Art. 38(5)

This duty is reinforced by the DPO's independence guarantees under Article 38(3): the DPO receives no instructions and cannot be dismissed or penalised for performing their tasks. The secrecy obligation thus operates as a corollary of independence — the DPO must be free to advise without external pressure, and must simultaneously protect the confidential information encountered in that role.

A parallel but distinct obligation applies to supervisory authority members and staff under Article 54(2), extending professional secrecy both during and after their term of office, with particular emphasis on protecting whistleblower reports.

Professional secrecy also functions as a processing safeguard. Article 9(3) permits processing of special-category data by persons under a professional secrecy obligation regulated by Union or Member State law. Separately, Article 14(5)(d) exempts controllers from the transparency obligation where personal data must remain confidential subject to such an obligation.

Key Developments

Dutch courts have grappled with the tension between professional secrecy and data-subject access rights, producing a practical mechanism for judicial review without breaching confidentiality. In a case involving the dean of the bar refusing access to complaint files under the Advocatenwet secrecy obligation, the court held that secrecy need not block judicial oversight entirely:

"Zij kan bij het overleggen van die stukken de rechtbank verzoeken om toepassing te geven aan artikel 8:29 van de Awb."
— Rechtbank, Verzoeken om inzage ¶5.5

This establishes a procedural threshold: professional secrecy is respected by routing disputed documents through a confidentiality chamber, which determines whether restricted judicial inspection is justified. The same mechanism was invoked in the Geheimhoudingszaak before the Gerechtshof, where the tax inspector sought limited inspection of BRP-derived address data to avoid violating third-party privacy rights under the GDPR.

At the enforcement level, the EDPB's breach-notification guidelines explicitly recognise loss of confidentiality of professionally secret data as a form of significant harm:

"loss of confidentiality of personal data protected by professional secrecy"
— EDPB Guidelines 9/2022 §24

This means that a breach involving professionally secret data triggers heightened risk-assessment obligations under Article 34 — the controller must evaluate whether such loss rises to the level of high risk requiring notification to affected data subjects.

Status of the Debate

This topic is actively contested in court. The core tension — professional secrecy versus data-subject access rights — remains unresolved at the EU level because the GDPR defers the content of secrecy obligations to Member State law, producing divergent national implementations. Dutch courts have developed the Article 8:29 Awb confidentiality-chamber procedure as a practical workaround, but no CJEU ruling has yet harmonised how Article 15 access rights interact with Article 38(5) DPO secrecy or Article 9(3) processing safeguards. A preliminary reference clarifying whether Member State secrecy rules can categorically override GDPR access rights would resolve the principal open question.

Practical Guidance

  • Bind your DPO contractually to secrecy. Article 38(5) requires confidentiality "in accordance with Union or Member State law" — ensure the DPO's employment or service contract explicitly references the applicable national secrecy regime and defines the scope of protected information.

  • Establish a confidentiality-chamber protocol for access requests. Following the Dutch court approach, when a data subject requests access to information protected by professional secrecy, route the disputed materials to a designated internal reviewer or court mechanism rather than outright refusal.

  • Treat professionally secret data as a breach-risk multiplier. Under the EDPB guidelines, loss of such data constitutes significant harm. Incorporate this into your Article 34 risk assessments — a breach involving professionally secret personal data likely triggers individual notification obligations.

  • Audit conflict-of-interest risks for DPOs with dual roles. Article 38(6) requires that other tasks do not create conflicts; a DPO who also holds a role bound by a different secrecy regime (e.g., legal counsel) must navigate potentially incompatible confidentiality duties.

Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Can the roles of DPO and whistleblowing officer be merged? > Personal data protection and whistleblowing are two different topics — different regulations with different purposes, scope and requirements. But, in fact, they are closer than… News IAPP Mar 2023 confidentiality duties
why this is here
Confidentiality and personal integrity: Without the personal integrity, credibility and confidentiality of the DPO or whistleblowing officer, none of these processes can fully work.

Discusses confidentiality obligations relevant to both roles, though not specifically professional secrecy under GDPR Article 90.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

This is the top of each pile — all 35 Case Law · all 25 Guidance · all 39 Enforcement