# Scientific Research — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/scientific-research
> Sources are cited per item. Verify against the official texts before relying on them.

Processing for scientific research purposes

## Overview

## Legal Framework

Scientific research processing is primarily governed by Article 89 GDPR, which requires controllers to establish appropriate safeguards for data processed for scientific research purposes. These safeguards must include both technical and organizational measures, such as pseudonymization, to minimize intrusion into data subjects' privacy. Article 89(2) permits Member States to derogate from certain data subject rights — specifically the right of access (Article 15), right to rectification (Article 16), and right to restriction (Article 18) — provided that such derogations are necessary and the data are processed solely for statistical or scientific purposes with appropriate safeguards in place.

Under the Dutch UAVG (Article 44), this derogation is operationalized: where processing is carried out by institutions or services for scientific research or statistics, and measures have been taken to ensure data are used exclusively for those purposes, the controller may set aside Articles 15, 16, and 18 GDPR. The legal basis for processing typically relies on Article 6(1)(e) GDPR (public interest or official authority) or Article 6(1)(f) (legitimate interests), combined with Article 9(2)(j) GDPR for special category data, which expressly permits processing for scientific research with appropriate safeguards.

The AI Act further reinforces the protection of scientific freedom. Recital 25 excludes AI systems and models developed solely for scientific research and development from the Act's scope, and Recital 109 exempts non-professional and scientific research model providers from general-purpose AI compliance obligations, though voluntary compliance is encouraged.

## Key Developments

The CJEU's decision in *Rynes* established that the exemption from the obligation to provide information to data subjects applies specifically where providing such information proves impossible or would involve disproportionate effort — a threshold directly relevant to large-scale scientific research datasets. This sets a practical standard: controllers must assess whether individual notification is feasible before invoking the exemption.

The Dutch DPA's enforcement against municipalities (including Ede and Eindhoven, each fined €25,000) signals that public-sector data sharing with third parties — even for research-like purposes — requires a valid legal basis and cannot simply rely on broad mandates. The *Raad van State* ruling (202004638/1/A3) confirmed that data subjects retain objection rights under Article 21 GDPR when their data are transferred to industry organizations, and such transfers require careful legal grounding.

The EDPB has prioritized scientific research guidance, with a dedicated study on secondary use of personal data in research contexts and planned guidelines expected in 2026. A leaked version of these guidelines surfaced in March 2026, with public consultation opened in May 2026, indicating imminent regulatory clarification on permissible secondary processing.

## Practical Guidance

- **Establish Article 89 safeguards before processing begins**: Implement pseudonymization or anonymization as default technical measures, and document organizational controls such as access restrictions, data minimization protocols, and purpose limitation boundaries in a processing register.

- **Restrict derogations from data subject rights to what is strictly necessary**: Under Article 44 UAVG, derogations from Articles 15, 16, and 18 GDPR apply only when data are exclusively used for scientific or statistical purposes. Ensure that no commercial or administrative use runs in parallel, as this would void the derogation.

- **Assess disproportionate effort on a documented, case-by-case basis**: Following *Rynes*, controllers invoking the information exemption must record why individual notification is impossible or disproportionate — vague references to dataset size will not suffice.

- **Secure a valid legal basis for special category data**: For health, genetic, or biometric data in research, rely on Article 9(2)(j) GDPR and ensure the national implementing law permits the specific research activity. Verify that the research institution qualifies under applicable Member State law.

- **Monitor the EDPB's 2026 guidelines on secondary use**: The forthcoming guidance will likely set new expectations for secondary processing in research, including transparency obligations and compatibility assessments under Article 6(4) GDPR. Review existing research protocols against the leaked draft to identify compliance gaps early.

## Legislation (full text of key provisions)

### Recital 159 — scientific research personal data processing

*Source: GDPR, gdpr-rec-159-en, 2016-04-27 — https://overview.legal/posts/91833*

Where personal data are processed for scientific research purposes, this Regulation should also apply to that processing. For the purposes of this Regulation, the processing of personal data for scientific research purposes should be interpreted in a broad manner including for example technological development and demonstration, fundamental research, applied research and privately funded research. In addition, it should take into account the Union's objective under Article 179(1) TFEU of achieving a European Research Area. Scientific research purposes should also include studies conducted in the public interest in the area of public health. To meet the specificities of processing personal data for scientific research purposes, specific conditions should apply in particular as regards the publication or otherwise disclosure of personal data in the context of scientific research purposes. If the result of scientific research in particular in the health context gives reason for further measures in the interest of the data subject, the general rules of this Regulation should apply in view of those measures.

### Recital 33 — consent for scientific research areas

*Source: GDPR, gdpr-rec-33-en, 2016-04-27 — https://overview.legal/posts/91581*

It is often not possible to fully identify the purpose of personal data processing for scientific research purposes at the time of data collection. Therefore, data subjects should be allowed to give their consent to certain areas of scientific research when in keeping with recognised ethical standards for scientific research. Data subjects should have the opportunity to give their consent only to certain areas of research or parts of research projects to the extent allowed by the intended purpose.

### Recital 161 — scientific research consent in clinical trials

*Source: GDPR, gdpr-rec-161-en, 2016-04-27 — https://overview.legal/posts/91837*

For the purpose of consenting to the participation in scientific research activities in clinical trials, the relevant provisions of Regulation (EU) No 536/2014 of the European Parliament and of the Council (15) should apply.

### Recital 97 — researcher data access framework

*Source: DSA, dsa-rec-97-en, 2022-10-19 — https://overview.legal/posts/95591*

This Regulation therefore provides a framework for compelling access to data from very large online platforms and very large online search engines to vetted researchers affiliated to a research organisation within the meaning of Article 2 of Directive (EU) 2019/790, which may include, for the purpose of this Regulation, civil society organisations that are conducting scientific research with the primary goal of supporting their public interest mission. All requests for access to data under that framework should be proportionate and appropriately protect the rights and legitimate interests, including the protection of personal data, trade secrets and other confidential information, of the very large online platform or of the very large online search engine and any other parties concerned, including the recipients of the service. However, to ensure that the objective of this Regulation is achieved, consideration of the commercial interests of providers should not lead to a refusal to provide access to data necessary for the specific research objective pursuant to a request under this Regulation. In this regard, whilst without prejudice to Directive (EU) 2016/943 of the European Parliament and of the Council (32), providers should ensure appropriate access for researchers, including, where necessary, by taking technical protections such as through data vaults. Data access requests could cover, for example, the number of views or, where relevant, other types of access to content by recipients of the service prior to its removal by the providers of very large online platforms or of very large online search engines.

### Recital 157 — registry research value and safeguards

*Source: GDPR, gdpr-rec-157-en, 2016-04-27 — https://overview.legal/posts/91829*

By coupling information from registries, researchers can obtain new knowledge of great value with regard to widespread medical conditions such as cardiovascular disease, cancer and depression. On the basis of registries, research results can be enhanced, as they draw on a larger population. Within social science, research on the basis of registries enables researchers to obtain essential knowledge about the long-term correlation of a number of social conditions such as unemployment and education with other life conditions. Research results obtained through registries provide solid, high-quality knowledge which can provide the basis for the formulation and implementation of knowledge-based policy, improve the quality of life for a number of people and improve the efficiency of social services. In order to facilitate scientific research, personal data can be processed for scientific research purposes, subject to appropriate conditions and safeguards set out in Union or Member State law.

### Recital 25 — research and development exclusion

*Source: AI Act, aiact-rec-25-en, 2024-06-12 — https://overview.legal/posts/93732*

This Regulation should support innovation, should respect freedom of science, and should not undermine research and development activity. It is therefore necessary to exclude from its scope AI systems and models specifically developed and put into service for the sole purpose of scientific research and development. Moreover, it is necessary to ensure that this Regulation does not otherwise affect scientific research and development activity on AI systems or models prior to being placed on the market or put into service. As regards product-oriented research, testing and development activity regarding AI systems or models, the provisions of this Regulation should also not apply prior to those systems and models being put into service or placed on the market. That exclusion is without prejudice to the obligation to comply with this Regulation where an AI system falling into the scope of this Regulation is placed on the market or put into service as a result of such research and development activity and to the application of provisions on AI regulatory sandboxes and testing in real world conditions. Furthermore, without prejudice to the exclusion of AI systems specifically developed and put into service for the sole purpose of scientific research and development, any other AI system that may be used for the conduct of any research and development activity should remain subject to the provisions of this Regulation. In any event, any research and development activity should be carried out in accordance with recognised ethical and professional standards for scientific research and should be conducted in accordance with applicable Union law.

### Recital 109 — proportionate compliance for general-purpose AI providers

*Source: AI Act, aiact-rec-109-en, 2024-06-12 — https://overview.legal/posts/93900*

Compliance with the obligations applicable to the providers of general-purpose AI models should be commensurate and proportionate to the type of model provider, excluding the need for compliance for persons who develop or use models for non-professional or scientific research purposes, who should nevertheless be encouraged to voluntarily comply with these requirements. Without prejudice to Union copyright law, compliance with those obligations should take due account of the size of the provider and allow simplified ways of compliance for SMEs, including start-ups, that should not represent an excessive cost and not discourage the use of such models. In the case of a modification or fine-tuning of a model, the obligations for providers of general-purpose AI models should be limited to that modification or fine-tuning, for example by complementing the already existing technical documentation with information on the modifications, including new training data sources, as a means to comply with the value chain obligations provided in this Regulation.

### Recital 162 — statistical processing of personal data

*Source: GDPR, gdpr-rec-162-en, 2016-04-27 — https://overview.legal/posts/91839*

Where personal data are processed for statistical purposes, this Regulation should apply to that processing. Union or Member State law should, within the limits of this Regulation, determine statistical content, control of access, specifications for the processing of personal data for statistical purposes and appropriate measures to safeguard the rights and freedoms of the data subject and for ensuring statistical confidentiality. Statistical purposes mean any operation of collection and the processing of personal data necessary for statistical surveys or for the production of statistical results. Those statistical results may further be used for different purposes, including a scientific research purpose. The statistical purpose implies that the result of processing for statistical purposes is not personal data, but aggregate data, and that this result or the personal data are not used in support of measures or decisions regarding any particular natural person.

### Recital 105 — general-purpose AI copyright and text data mining

*Source: AI Act, aiact-rec-105-en, 2024-06-12 — https://overview.legal/posts/93892*

General-purpose AI models, in particular large generative AI models, capable of generating text, images, and other content, present unique innovation opportunities but also challenges to artists, authors, and other creators and the way their creative content is created, distributed, used and consumed. The development and training of such models require access to vast amounts of text, images, videos and other data. Text and data mining techniques may be used extensively in this context for the retrieval and analysis of such content, which may be protected by copyright and related rights. Any use of copyright protected content requires the authorisation of the rightsholder concerned unless relevant copyright exceptions and limitations apply. Directive (EU) 2019/790 introduced exceptions and limitations allowing reproductions and extractions of works or other subject matter, for the purpose of text and data mining, under certain conditions. Under these rules, rightsholders may choose to reserve their rights over their works or other subject matter to prevent text and data mining, unless this is done for the purposes of scientific research. Where the rights to opt out has been expressly reserved in an appropriate manner, providers of general-purpose AI models need to obtain an authorisation from rightsholders if they want to carry out text and data mining over such works.

## Case law

### Meta Platforms v noyb

*Source: CJEU, C-252/21, 2023-01-12 — https://overview.legal/posts/51484 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0252*

GDPR consent requirements and lead supervisory authority mechanism.

### HvJ EU: Privacy Shield ongeldig verklaard (Schrems II)

*Source: Hof van Justitie EU, 2020-07-16 — https://overview.legal/posts/1 — original: https://eur-lex.europa.eu/legal-content/NL/TXT/?uri=CELEX:62018CJ0311*

Het Hof van Justitie verklaart het Privacy Shield-akkoord ongeldig wegens onvoldoende waarborgen voor Europese burgers tegen toegang door Amerikaanse inlichtingendiensten.

### Bundesverband der Verbraucherzentralen v Planet49 GmbH

*Source: CJEU, C-673/17, 2019-10-01 — https://overview.legal/posts/51473 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0673&ref=51473*

Pre-ticked checkboxes do not constitute valid consent. Consent must be active.

### Österreichische Datenschutzbehörde v CRIF

*Source: CJEU, C-487/21, 2023-10-26 — https://overview.legal/posts/51486 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0487*

Right of access includes obtaining a copy in commonly used electronic form.

### Judgment of the Court (Third Chamber) of 11 December 2019.#TK v Asociaţia de Proprietari bloc M5A-ScaraA.#Request for a preliminary ruling from the Tribunalul Bucureşti.#Reference for a preliminary ruling — Protection of individuals with regard to the processing of personal data — Charter of Fundamental Rights of the European Union — Articles 7 and 8 — Directive 95/46/EC — Article 6(1)(c) and Article 7(f) — Making the processing of personal data legitimate — National legislation allowing video s

*Source: Court of Justice of the European Union, C-708/18, 2019-12-11 — https://overview.legal/posts/132336 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0708*

In Case C-708/18, the Court of Justice of the European Union (Third Chamber) issued a preliminary ruling on a reference from the Tribunalul București (Romania) in proceedings between TK and Asociaţia de Proprietari bloc M5A-ScaraA concerning the installation of video surveillance cameras in the common areas of a residential building without the data subject's consent. The Court interpreted Directive 95/46/EC and Articles 7 and 8 of the EU Charter of Fundamental Rights, holding that national legislation may permit processing of personal data based on the pursuit of legitimate interests under Article 7(f) of the Directive, but only if the processing is necessary

### Fashion ID GmbH & Co. KG v Verbraucherzentrale NRW eV

*Source: CJEU, C-40/17, 2019-07-29 — https://overview.legal/posts/51478 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62017CJ0040*

Website operators using Facebook Like button are joint controllers for data collection.

### Peter Nowak v Data Protection Commissioner

*Source: CJEU, C-434/16, 2017-12-20 — https://overview.legal/posts/51480 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62016CJ0434&ref=51480*

Examination scripts constitute personal data of the candidate.

### Patrick Breyer v Bundesrepublik Deutschland

*Source: CJEU, C-582/14, 2016-10-19 — https://overview.legal/posts/51479 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0582&ref=51479*

Dynamic IP addresses can be personal data when holder can identify the person.

### Maximillian Schrems v Data Protection Commissioner

*Source: CJEU, C-362/14, 2015-10-06 — https://overview.legal/posts/51471 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=51471*

Invalidated Safe Harbor adequacy decision. National supervisory authorities can examine adequacy decisions.

### RYNES V. ÚŘAD PRO OCHRANU OSOBNICH ÚDAJŮ, 11.12.2014 (“RYNES”)

*Source: CJEU, 2014-12-11 — https://overview.legal/posts/6155 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62013CJ0212&ref=6155*

Personal data: The image of a person recorded by a camera constitutes personal data because it makes it possible to identify the person concerned. (¶ 22)

### Digital Rights Ireland Ltd v Minister for Communications

*Source: CJEU, C-293/12, 2014-04-08 — https://overview.legal/posts/51474 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0293&ref=51474*

Invalidated Data Retention Directive as incompatible with fundamental rights.

### Meta Platforms and Others v Bundeskartellamt

*Source: CJEU, C-601/21, 2023-07-04 — https://overview.legal/posts/51482 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0601*

Competition authorities can assess GDPR compliance in context of competition law proceedings.

## Guidance

### EDPB Document on response to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research

*Source: EDPB, edpb-document-on-response-to-the-request-from-the-european-commission-for-en, 2021-02-02 — https://overview.legal/posts/126069 — original: https://www.edpb.europa.eu/documents/other-guidance/edpb-document-on-response-to-the-request-from-the-european-commission-for_en*

EDPB Document on r esponse to the request from the European Commission for clarifications on the consistent application of the GDPR, focusing on health research Adopted on 2 February 2021 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 70.1.b of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and…

### Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak

*Source: EDPB, guidelines-032020-on-the-processing-of-data-concerning-health-for-the-purpose-en, 2020-04-21 — https://overview.legal/posts/126170 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-032020-on-the-processing-of-data-concerning-health-for-the-purpose_en*

Adopted 1 Guidelines 03 /2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID - 19 outbreak Adopted on 21 April 2020 Adopted 2 Version history Version 1.1 30 April 2020 Minor corrections Version 1. 0 21 April 2020 Adoption of the Guidelines Adopted 3 Adopted 4 The European Data Protection Board Having regard to Article 70 (1) (e) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the…

### Opinion 12/2024 on the draft decision of the French Supervisory Authority regarding the “Code of Conduct for Service Providers in Clinical Research” submitted by EUCROF

*Source: EDPB, opinion-122024-on-the-draft-decision-of-the-french-en, 2024-06-18 — https://overview.legal/posts/125740 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-122024-on-the-draft-decision-of-the-french_en*

1 Adopted Opinion 12 /202 4 on the draft decision of the French Supervisory Authority regarding the “ Code of Conduct for Service Providers in Clinical Research” submitted by EUCROF Adopted on 18 June 2024 2 Adopted 3 Adopted The European Data Protection Board Having regard to Article 63, Article 64(1)( b ) and Article 4 0 of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal…

### Opinion 3/2019 concerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR)

*Source: EDPB, opinion-32019-concerning-the-questions-and-answers-on-the-interplay-en, 2019-01-23 — https://overview.legal/posts/126252 — original: https://www.edpb.europa.eu/documents/legislative-opinion/opinion-32019-concerning-the-questions-and-answers-on-the-interplay_en*

1 Opinion 3/ 2 019 c oncerning the Questions and Answers on the interplay between the Clinical Trials Regulation (CTR) and the General Data Protection regulation (GDPR) (art. 70. 1. b)) Adopted on 23 January 2019 2 3 The European Data Protection Board Having regard to Article 70.1.b of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data,…

### Guidelines 05/2020 on consent under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-consent, 2020-05-04 — https://overview.legal/posts/38053 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-052020-on-consent-under-regulation-2016679_en*

The European Data Protection Board (EDPB) adopted Guidelines 05/2020 on consent under Regulation 2016/679 to provide detailed interpretive guidance on the requirements for valid consent under the GDPR, including the elements of freely given, specific, informed, and unambiguous consent, as well as the conditions for explicit consent and the obligation to demonstrate consent. The guidelines address practical issues such as power imbalances, conditionality, granularity, detriment, and the minimum content requirements for informing data subjects. No fines are imposed, as this is a guidance document rather than an enforcement decision.

### EDPB-EDPS Joint Opinion 03/2021 on the Proposal for a regulation of the European Parliament and of the Council on European data governance (Data Governance Act)

*Source: EDPB, edpb-edps-joint-opinion-032021-on-the-proposal-for-a-regulation-of-en, 2021-03-11 — https://overview.legal/posts/126050 — original: https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-032021-on-the-proposal-for-a-regulation-of_en*

1 Adopted EDPB - EDPS Joint Opinion 03 /2021 on the Proposal for a regulation of the European Parliament and of the Coun cil on European data governance (Data Governance Act) Version 1.1 2 Adopted Version history Version 1.1 09 June 2021 Minor editorial changes Version 1.0 10 March 2021 Adoption of the Joint Opinion 3 Adopted 5 Adopted The European Data Protection Board and the European Data Protection Supervisor Having regard to Article 42(2) of the Regulation 2018/1725 of 23 October 2018 on…

### Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025

*Source: EDPB, report-on-stakeholder-event-on-anonymisation-and-en, 2026-02-18 — https://overview.legal/posts/125688 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/report-on-stakeholder-event-on-anonymisation-and_en*

Report on stakeholder event on anonymisation and pseudonymisation of 12 December 2025 1. Background The EDPB organise d a remote stakeholder event on 12 December 2025 to collect stakeholders’ input on anonymisation and pseudonymisation , following the Court of Justice of the European Union ( “ CJEU ” ) judgment in case EDPS v SRB 1 . The objective was to engage with stakeholders to inform the EDPB’s ongoing work on its guidelines 01/2025 on pseudonymisation and f orthcoming guidelines on…

### EDPB Work Programme 2024-2025

*Source: EDPB, edpb-work-programme-2024-2025-en, 2024-10-09 — https://overview.legal/posts/125711 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-work-programme-2024-2025_en*

The European Data Protection Board (EDPB) is an independent European body established by the General Data Protection Regulation (GDPR). The EDPB has the following main tasks: 1. In line with the Article 29 of the EDPB Rules of Procedure. This Work Programme is valid from 8 October 2024 until 31 December 2025 and supersedes, for the remaining part of 2024, the previous Work Programme 2023–2024. 2. https://www.edpb.europa.eu/system/files/2024-04/edpb_strategy_2024-2027_en.pdf EDPB Work Programme…

## Enforcement decisions

### Job center employee: Insufficient legal basis for data processing

*Source: Data Protection Authority of Berlin, 2022-01-01 — https://overview.legal/posts/48003 — original: https://www.enforcementtracker.com/ETid-1888*

A job center employee had accessed data in the job center database systems for private research purposes

### Job center employee: Insufficient legal basis for data processing

*Source: Data Protection Authority of Berlin, 2021-01-01 — https://overview.legal/posts/47333 — original: https://www.enforcementtracker.com/ETid-1218*

A job center employee had accessed data in social database systems and in the civil register for private research purposes.

### Job center employee: Insufficient legal basis for data processing

*Source: Data Protection Authority of Berlin, 2022-01-01 — https://overview.legal/posts/48004 — original: https://www.enforcementtracker.com/ETid-1889*

A job center employee had accessed data in the civil register for private research purposes.

### Health care worker: Insufficient legal basis for data processing

*Source: Estonian Data Protection Authority (AKI), 2020-08-17 — https://overview.legal/posts/47542 — original: https://www.enforcementtracker.com/ETid-1427*

Acess to personal data in a health database for private research activities.

### Police officer: Insufficient legal basis for data processing

*Source: Data Protection Authority of Saarland, 2020-01-01 — https://overview.legal/posts/47143 — original: https://www.enforcementtracker.com/ETid-1028*

Several cases in which police officers have accessed data in a police database for private research purposes.

### Data Diggers Market Research SRL: Niet-naleving van algemene principes voor gegevensverwerking.

*Source: Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), 2025-05-21 — https://overview.legal/posts/52271*

De Roemeense autoriteit voor gegevensbescherming (DPA) heeft een boete van 12.000 euro opgelegd aan Data Diggers Market Research SRL. De verantwoordelijke partij heeft persoonsgegevens verwerkt zonder voldoende wettelijke basis. Bovendien heeft de verantwoordelijke partij de betrokkenen niet voorzien van de noodzakelijke informatie over de gegevensverwerking. Ten slotte heeft de verantwoordelijke partij niet adequaat gereageerd op verzoeken van betrokkenen om hun rechten uit te oefenen.

### Job center employee: Insufficient legal basis for data processing

*Source: Data Protection Authority of Berlin, 2021-01-01 — https://overview.legal/posts/47332 — original: https://www.enforcementtracker.com/ETid-1217*

A job center employee had accessed data in social database systems and in the civil register for private research purposes. The employee wanted to prove that two of her colleagues had a relationship with each other and checked the registration addresses of both of them.

### Police officer: Insufficient legal basis for data processing

*Source: Data Protection Authority of Berlin, 2021-01-01 — https://overview.legal/posts/47329 — original: https://www.enforcementtracker.com/ETid-1214*

A police officer had accessed data in a police database for private research purposes. The police officer queried his stepson's investigative process in order to prepare him for his testimony and to convince the officer in charge of the case of a different crime sequence.

## Recent developments

### Geef een reactie op de guidelines over wetenschappelijk onderzoek en persoonsgegevens

*Source: Autoriteit Persoonsgegevens, 2026-05-27 — https://overview.legal/posts/53070 — original: https://autoriteitpersoonsgegevens.nl/actueel/geef-een-reactie-op-de-guidelines-over-wetenschappelijk-onderzoek-en-persoonsgegevens*

De European Data Protection Board (EDPB) heeft nieuwe guidelines gemaakt over het gebruik van persoonsgegevens in wetenschappelijk onderzoek. Iedereen mag hierop reageren.

### EU-wetgeving inzake datagovernance definitief vastgesteld

*Source: NL EU Court Expert, 2022-06-08 — https://overview.legal/posts/6302 — original: https://ecer.minbuza.nl/-/eu-wetgeving-inzake-datagovernance-definitief-vastgesteld?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-303*

The new data governance regulation sets out the conditions for the reuse of certain government data. In addition, the regulation provides a notification and oversight framework for the provision of data mediation services. Furthermore, the regulation contains a framework for the voluntary registration of entities that collect and process data made available for altruistic purposes. The rules will apply from September 2023.

### CJEU clarifies GDPR principles of purpose limitation and storage limitation

*Source: NL EU Court Expert, 2022-10-30 — https://overview.legal/posts/6247 — original: https://ecer.minbuza.nl/-/eu-hof-verduidelijkt-de-beginselen-van-doelbinding-en-opslagbeperking-uit-de-avg?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-1209*

The purpose limitation principle does not preclude a controller from capturing and storing in a test database established for testing and error correction purposes personal data previously collected and stored in another database. However, such "further processing" of personal data must be compatible with the specific purposes for which the personal data were originally collected. The principle of storage limitation precludes the retention of personal data in that test database for longer than n

### A-G: rechtmatig verzamelde en opgeslagen persoonsgegevens mogen onder voorwaarden tijdelijk in een extra interne databank worden bewaard

*Source: NL EU Court Expert, 2022-04-09 — https://overview.legal/posts/6307 — original: https://ecer.minbuza.nl/-/a-g-rechtmatig-verzamelde-en-opgeslagen-persoonsgegevens-mogen-onder-voorwaarden-tijdelijk-in-een-extra-interne-databank-worden-bewaard?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-306*

Lawfully collected and stored personal data may be retained in an additional internal database, to the extent that it pursues the same data processing purposes as the original data collection. That is the opinion of Advocate General Pikamäe to the EU Court in response to questions from a Hungarian judge.

### In short:

*Source: Government, 2026-01-19 — https://overview.legal/posts/51874*

"The purpose of this research is to identify the need for player data for independent research with social and/or scientific objectives in the field of gambling behavior. The researchers investigated whether this need is currently being met, and if not, what measures are needed to address it."

## Literature

### Can the GDPR make data flow for research easier? Yes it can, by differentiating! A careful reading of the GDPR shows how EU data protection law leaves open some significant flexibilities for data protection-sound research activities

*Source: Computer Law Security Review, 2021-07-01 — https://overview.legal/posts/132526 — original: https://doi.org/10.1016/j.clsr.2021.105539*

### General Data Protection Regulation (GDPR) and implications for research

*Source: Maturitas, 2018-05-01 — https://overview.legal/posts/132413 — original: https://doi.org/10.1016/j.maturitas.2018.01.017*

### If it ain’t broke, don’t fix it? Ten improvements for the upcoming tenth anniversary of the General Data Protection Regulation

*Source: Computer law & security review, 2026-01-23 — https://overview.legal/posts/53843 — original: https://doi.org/10.1016/j.clsr.2025.106251*

As the General Data Protection Regulation (GDPR) approaches its tenth anniversary, the European legislator is considering reforms thereto. This article offers a set of research-based suggestions for what such reforms could look like, based on two assumptions. First, that the GDPR is overall a solid piece of legislation that upholds the enduring objectives and principles of data protection law. Second, that any improvement cannot compromise the level of protection of fundamental rights currently

### Recommendations for Creating Codes of Conduct for Processing Personal Data in Biobanking Based on the GDPR art.40

*Source: Frontiers in Genetics, 2021-11-12 — https://overview.legal/posts/132560 — original: https://doi.org/10.3389/fgene.2021.711614*

Personal data protection has become a fundamental normative challenge for biobankers and scientists researching human biological samples and associated data. The General Data Protection Regulation (GDPR) harmonises the law on protecting personal data throughout Europe and allows developing codes of conduct for processing personal data based on GDPR art. 40. Codes of conduct are a soft law measure to create protective standards for data processing adapted to the specific area, among others, to bi

### GDPR Implementation Series ∙ Hungary: Introduction to the GDPR Application and a Brief History of Data Protection

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132426 — original: https://doi.org/10.21552/edpl/2019/4/11*

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes
- **Public Authority** — https://overview.legal/topics/overheid
  Government bodies and their data processing activities
- **Healthcare** — https://overview.legal/topics/zorg
  Processing of health data and medical information
- **IP Address** — https://overview.legal/topics/ip-adres
  Internet protocol addresses as personal data

---
Generated by overview.legal · https://overview.legal/topics/scientific-research · 2026-08-22
