The GDPR (Regulation (EU) 2016/679) applies to research the same way it applies to any other processing of personal data — but it also contains a specific, deliberately-built set of accommodations for research, spread across several articles rather than collected in one place. Researchers and research offices often encounter GDPR either as a generic corporate-compliance document or as a vague sense that “you need consent,” neither of which reflects how the regulation actually treats research. This guide works through the provisions that are specific to research — the Article 89 safeguards and derogations, the lawful bases actually available to research controllers, the Article 9 special-category rules for health/genetic/biometric data, and pseudonymisation — and connects each one to the practical Data Management Plan (DMP) and data-governance decisions a study team has to make.
When GDPR applies to a research project
GDPR applies to the processing of personal data — “any information relating to an identified or identifiable natural person” (Article 4(1)) — carried out in the context of an establishment in the EU/EEA, or by a controller/processor outside the EU/EEA that offers goods or services to, or monitors the behaviour of, individuals in the EU/EEA (Article 3). For research this means: a US university running a multi-site trial with EU participants, or an EU institution processing any identifiable participant data, is in scope regardless of where the data ultimately gets analysed. The UK’s parallel regime (UK GDPR plus the Data Protection Act 2018) is structurally the same law post-Brexit, with UK-specific procedural detail (see CASRAI’s GDPR dictionary entry for both references).
Two scoping points matter disproportionately in research design:
- Purpose limitation has a built-in research exception. Article 5(1)(b) normally requires data to be collected for specified purposes and not “further processed” in an incompatible way — but it explicitly states that further processing for archiving in the public interest, scientific or historical research, or statistical purposes “shall… not be considered to be incompatible with the initial purposes,” provided the Article 89(1) safeguards are in place. This is the legal basis for a common research pattern: reusing a dataset collected for one study (or for clinical care) in a later research project, without needing to argue the original purpose already covered it.
- Anonymous data is outside GDPR entirely; pseudonymised data is not. Recital 26 states the principles of data protection “should not apply to anonymous information… or to personal data rendered anonymous in such a manner that the data subject is not or no longer identifiable.” True anonymisation is a high bar — it has to survive “all the means reasonably likely to be used” to re-identify someone, not just removal of obvious direct identifiers. Pseudonymised data — defined at Article 4(5) as data processed “in such a manner that the personal data can no longer be attributed to a specific data subject without the use of additional information” — remains personal data under GDPR precisely because that additional information (a key, a code list) still exists somewhere, even if the researcher handling the working dataset never sees it.
Lawful bases: public interest vs. consent
Every processing activity needs one of the six lawful bases in Article 6(1). Two do almost all the work for research:
- Public task (Article 6(1)(e)) — processing “necessary for the performance of a task carried out in the public interest.” Public universities and public research institutes commonly rely on this basis for research that sits within their institutional mission, without needing individual consent for the processing itself. Article 6(1) also carves out legitimate interests (6(1)(f)) as unavailable to public authorities performing their official tasks — a frequent point of confusion, since legitimate interest is the default fallback basis in commercial contexts but is specifically closed off here.
- Consent (Article 6(1)(a)) — required where the public-task basis doesn’t apply (private research organisations without a public-interest mandate, or processing that goes beyond an institution’s public task), and it’s the basis that interacts most directly with a study’s ethics approval. GDPR consent and research-ethics informed consent are related but legally distinct requirements that commonly get satisfied through the same participant-facing process — a well-drafted participant information sheet and consent form can cover both, but a research-ethics board approving a consent form is not the same act as establishing a GDPR lawful basis, and each should be checked against its own criteria.
Recital 33 addresses a practical problem with consent as a lawful basis for research specifically: “it is often not possible to fully identify the purpose of personal data processing for scientific research purposes at the time of data collection.” It permits broad consent — consent “to certain areas of scientific research when in keeping with recognised ethical standards for scientific research” — rather than requiring a fully specified purpose upfront, while still preserving the data subject’s option to consent only to specific areas or parts of a research programme. Institutions still need to be able to demonstrate the consent was informed and specific enough to be meaningful; “we might use this data for future research” with no further detail is a weaker position than a defined, if broad, research programme description.
Special-category data under Article 9: health, genetic, and biometric data
Most human-subjects research processes data that GDPR treats as a “special category” under Article 9(1): data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, plus genetic data, biometric data used for identification, health data, and data concerning sex life or sexual orientation. Processing any of these is prohibited by default — Article 6 alone is not sufficient to process special-category data; a separate Article 9(2) condition is also required.
The relevant condition for most research is Article 9(2)(j): processing is permitted where it’s “necessary for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1),” and is “based on Union or Member State law” that is “proportionate to the aim pursued,” “respect[s] the essence of the right to data protection,” and provides “suitable and specific measures to safeguard the fundamental rights and the interests of the data subject.” That last clause is the practical catch: Article 9(2)(j) is not self-executing — it requires an underlying national (or EU) legal basis. In the UK, this is provided by the Data Protection Act 2018, Schedule 1, Part 1, condition 4 (“research etc.”), which additionally requires the processing to be carried out in accordance with a documented “appropriate policy document.” EU member states have their own equivalent implementing provisions, which is why the same research activity can face different procedural requirements depending on which member state’s law applies — a real, non-trivial point for multi-country studies to check per site rather than assume harmonised.
Article 89: the safeguards and the derogations
Article 89 is the hinge that Articles 5(1)(b), 6, and 9(2)(j) all point back to. It works in two parts:
- Paragraph 1 — safeguards, always required. Research processing “shall be subject to appropriate safeguards… for the rights and freedoms of the data subject,” with technical and organisational measures ensuring data-minimisation compliance in particular. The article names pseudonymisation specifically as an example measure, and states that further processing which doesn’t permit or no longer permits identification of data subjects should be preferred “where those purposes can be fulfilled in that manner.” This is not optional scaffolding — it’s the condition the Article 5(1)(b), 6(1)(e)/9(2)(j) accommodations are premised on. A research project that skips pseudonymisation or minimisation without a documented reason is on weaker ground claiming the research exemptions elsewhere in the Regulation.
- Paragraphs 2-3 — optional derogations from data subject rights, only where EU/Member State law provides for them. Where research safeguards under paragraph 1 are in place, Member States may derogate from specific data subject rights — the right of access (Article 15), rectification (16), restriction of processing (18), and objection (21) for research generally, plus the right to erasure/”right to be forgotten” (17) and data portability (20) for archiving in the public interest — but only “in so far as such rights are likely to render impossible or seriously impair the achievement of the specific purposes, and such derogations are necessary for the fulfilment of those purposes.” This is a genuinely narrow test, not a blanket research exemption: an institution has to be able to explain, for a specific right and a specific study, why honouring it would seriously impair the research — for example, why deleting a participant’s record on request would corrupt a longitudinal cohort’s statistical validity — and document that reasoning, typically in the study’s data-protection documentation and participant information. CASRAI’s Data Subject Rights (GDPR) entry covers the individual-rights side of this in more depth.
A frequent misreading is treating Article 89 as “research is exempt from GDPR.” It is not — Article 89 conditions a set of narrow accommodations on the presence of real safeguards, and the derogations from individual rights require an actual Member State (or UK) implementing provision, assessed right-by-right and study-by-study, not asserted generically.
Cross-border transfers
Collaborative research routinely moves personal data to institutions outside the EU/EEA — a common trigger point separate from the research-specific rules above. Where the destination country doesn’t have a European Commission adequacy decision, Article 46 requires an additional safeguard, most commonly the European Commission’s modernised Standard Contractual Clauses (adopted June 2021). For transfers to the United States specifically, the EU-US Data Privacy Framework (adequacy decision adopted July 2023) is a further, narrower option — but it only covers transfers to US organisations that are actually certified under it, and as of mid-2026 the framework’s adequacy status is subject to an active legal challenge before the CJEU, with commentators flagging a related concern arising from a June 2026 US Supreme Court ruling affecting the FTC’s independence (one of the institutional safeguards the original adequacy decision relied on). The Commission’s decision remains formally in force unless and until repealed or annulled, so it can still be relied on, but institutions doing cross-border research data transfers to the US should treat this as an area to monitor rather than a settled question, and should document a contingency plan (e.g., readiness to fall back on Standard Contractual Clauses) rather than depend on the DPF alone for a long-running study. This is exactly the kind of provision that belongs in a study’s data-sharing agreement, not just its DMP — see CASRAI’s guide to data sharing agreements between collaborators and institutions for the contract-level mechanics (Article 28 controller/processor terms, Article 46 transfer clauses).
Connecting GDPR compliance to research data management practice
GDPR compliance is not a separate workstream from research data management — the two are supposed to be worked out together, and a Data Management Plan is one of the natural places to document the decisions above:
- Data minimisation and pseudonymisation plans belong in the DMP. A DMP’s data-collection and processing sections should state what identifiers are collected, when and how pseudonymisation happens (at collection, or at a defined point afterward), who holds the re-identification key, and how long the key itself is retained — the Article 89(1) safeguard, made concrete and auditable rather than asserted as a generic intention.
- A Data Protection Impact Assessment (DPIA) is a distinct but related document, required under GDPR (separately from a DMP, though the two should stay consistent) where processing is “likely to result in a high risk to the rights and freedoms of natural persons” — large-scale processing of special-category data is a standard trigger. See CASRAI’s DPIA dictionary entry for the operational definition.
- Consent management and withdrawal need an operational answer, not just a policy statement. If a participant exercises withdrawal of consent, the DMP (or an associated data-governance document) should already specify what happens to data already collected, already pseudonymised, or already shared with a collaborator — this is exactly the situation Article 89’s rights derogations are meant to address for genuinely ongoing research, but only where the institution has documented why full erasure would seriously impair the study. Using dynamic consent mechanisms can make this more tractable operationally, though it doesn’t change the underlying legal analysis.
- Cross-institutional sharing needs both a DMP and, once data actually moves, a signed agreement — a DMP describes intent for a funder; it isn’t itself a binding contract between institutions. Where personal data crosses an institutional or national boundary, see CASRAI’s guide to data sharing agreements for what the contract itself needs to contain.
- US-funded studies with EU participants (or vice versa) need to reconcile two regimes. NIH and NSF data-management-and-sharing requirements (see CASRAI’s NIH vs. NSF Data Management Plans comparison) don’t reference GDPR at all, but a study funded by either agency that includes EU participants is fully subject to GDPR regardless of the funder’s own policy — the DMP needs to satisfy both sets of requirements simultaneously, not treat GDPR as an optional add-on once the funder’s own template is complete. Where US health data specifically is also involved, HIPAA’s Privacy Rule runs in parallel to, not instead of, GDPR — see CASRAI’s HIPAA Privacy Rule entry for how the two relate.
A practical starting checklist
None of the following substitutes for institutional data-protection-office or legal review, but it’s the set of questions a study team should be able to answer before data collection starts:
- Which lawful basis applies — public task, or consent — and is that documented separately from the ethics-approval consent form?
- Does the data include any Article 9 special category (health, genetic, biometric-for-identification, or the other listed categories)? If so, which national implementing provision (e.g., DPA 2018 Schedule 1 Part 1 in the UK) supports the Article 9(2)(j) condition, and does it require a documented “appropriate policy document” or equivalent?
- What are the Article 89(1) safeguards for this specific study — pseudonymisation approach, key custody, data minimisation — and are they written down somewhere a reviewer (or a regulator) could actually check?
- Is a DPIA required, and has it been completed and kept consistent with the DMP?
- If any data subject right needs to be limited for the study to remain valid (e.g., erasure on request breaking a longitudinal design), is there a documented, right-specific, study-specific justification — not a blanket assertion that “research is exempt”?
- Does data cross an institutional or national border? If so, is there a signed data sharing agreement with the correct Article 28/46 terms, and — for transfers outside the EU/EEA — a current, monitored transfer mechanism?
Frequently asked questions
Does GDPR apply to research conducted outside the EU?
It can. Article 3 extends GDPR to processing by a controller or processor established outside the EU/EEA where the processing relates to offering goods or services to, or monitoring the behaviour of, individuals in the EU/EEA. A non-EU university running a study that recruits or monitors EU-based participants is generally in scope for that processing, even though the institution itself sits outside the EU/EEA.
Is pseudonymised research data still subject to GDPR?
Yes. Pseudonymisation (Article 4(5)) reduces risk and is one of the safeguards Article 89(1) specifically calls out, but pseudonymised data remains personal data under GDPR as long as a re-identification key or equivalent additional information exists anywhere. Only genuinely anonymised data — where re-identification is not reasonably possible by any means likely to be used — falls outside GDPR’s scope entirely, per Recital 26.
Do I need participant consent under GDPR if my study already has research-ethics approval?
Ethics-committee approval and a GDPR lawful basis are separate requirements. Many research institutions rely on the public-task basis (Article 6(1)(e)) rather than GDPR consent for research within their institutional mission, in which case ethics-approved informed consent still governs the research-ethics side of participation, but isn’t necessarily also the GDPR lawful basis. Where consent is used as the GDPR basis, it needs to independently meet Article 6/7 consent requirements (freely given, specific, informed, unambiguous), which a well-designed participant information sheet and consent process can satisfy alongside the ethics requirement, but the two should be checked against their own separate criteria rather than assumed to be automatically the same act.
Can research data be shared with collaborators outside the EU under GDPR?
Yes, but a transfer mechanism is required unless the destination has a European Commission adequacy decision. The current default is the European Commission’s modernised Standard Contractual Clauses (Article 46); for the US specifically, the EU-US Data Privacy Framework is an available adequacy-based route for transfers to certified US organisations, though its status is subject to an active legal challenge as of 2026 and should be monitored rather than relied on as permanently settled for a long-running project.
What’s the difference between a Data Protection Impact Assessment and a Data Management Plan?
A DPIA is a GDPR-specific risk assessment, required where processing is likely to result in a high risk to individuals’ rights and freedoms — it exists to identify and mitigate privacy risk. A DMP is a broader research-data-lifecycle planning document, commonly required by a funder, covering data types, standards, storage, sharing, and preservation well beyond privacy risk alone. A GDPR-in-scope study commonly needs both, and they should be kept consistent with each other rather than drafted independently.
For the broader compliance landscape this fits into, see CASRAI’s Research Integrity & Compliance cluster hub. For how these GDPR-specific decisions feed into the data-planning document itself, see the Research Data Management cluster hub and CASRAI’s Data Management Plan dictionary entry.







