Scientific Research
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing for scientific research purposes
Overview
16 sources · Jul 15, 2026Legal Framework
Scientific research processing is primarily governed by Article 89 GDPR, which requires controllers to establish appropriate safeguards for data processed for scientific research purposes. These safeguards must include both technical and organizational measures, such as pseudonymization, to minimize intrusion into data subjects' privacy. Article 89(2) permits Member States to derogate from certain data subject rights — specifically the right of access (Article 15), right to rectification (Article 16), and right to restriction (Article 18) — provided that such derogations are necessary and the data are processed solely for statistical or scientific purposes with appropriate safeguards in place.
Under the Dutch UAVG (Article 44), this derogation is operationalized: where processing is carried out by institutions or services for scientific research or statistics, and measures have been taken to ensure data are used exclusively for those purposes, the controller may set aside Articles 15, 16, and 18 GDPR. The legal basis for processing typically relies on Article 6(1)(e) GDPR (public interest or official authority) or Article 6(1)(f) (legitimate interests), combined with Article 9(2)(j) GDPR for special category data, which expressly permits processing for scientific research with appropriate safeguards.
The AI Act further reinforces the protection of scientific freedom. Recital 25 excludes AI systems and models developed solely for scientific research and development from the Act's scope, and Recital 109 exempts non-professional and scientific research model providers from general-purpose AI compliance obligations, though voluntary compliance is encouraged.
Key Developments
The CJEU's decision in Rynes established that the exemption from the obligation to provide information to data subjects applies specifically where providing such information proves impossible or would involve disproportionate effort — a threshold directly relevant to large-scale scientific research datasets. This sets a practical standard: controllers must assess whether individual notification is feasible before invoking the exemption.
The Dutch DPA's enforcement against municipalities (including Ede and Eindhoven, each fined €25,000) signals that public-sector data sharing with third parties — even for research-like purposes — requires a valid legal basis and cannot simply rely on broad mandates. The Raad van State ruling (202004638/1/A3) confirmed that data subjects retain objection rights under Article 21 GDPR when their data are transferred to industry organizations, and such transfers require careful legal grounding.
The EDPB has prioritized scientific research guidance, with a dedicated study on secondary use of personal data in research contexts and planned guidelines expected in 2026. A leaked version of these guidelines surfaced in March 2026, with public consultation opened in May 2026, indicating imminent regulatory clarification on permissible secondary processing.
Practical Guidance
Establish Article 89 safeguards before processing begins: Implement pseudonymization or anonymization as default technical measures, and document organizational controls such as access restrictions, data minimization protocols, and purpose limitation boundaries in a processing register.
Restrict derogations from data subject rights to what is strictly necessary: Under Article 44 UAVG, derogations from Articles 15, 16, and 18 GDPR apply only when data are exclusively used for scientific or statistical purposes. Ensure that no commercial or administrative use runs in parallel, as this would void the derogation.
Assess disproportionate effort on a documented, case-by-case basis: Following Rynes, controllers invoking the information exemption must record why individual notification is impossible or disproportionate — vague references to dataset size will not suffice.
Secure a valid legal basis for special category data: For health, genetic, or biometric data in research, rely on Article 9(2)(j) GDPR and ensure the national implementing law permits the specific research activity. Verify that the research institution qualifies under applicable Member State law.
Monitor the EDPB's 2026 guidelines on secondary use: The forthcoming guidance will likely set new expectations for secondary processing in research, including transparency obligations and compatibility assessments under Article 6(4) GDPR. Review existing research protocols against the leaked draft to identify compliance gaps early.