Skip to main content
Category: Scope & Exemptions

Derogation Under National Law

Also known as: national derogation, member state derogation
Simply put

A derogation is a legal mechanism that allows a rule to be applied differently, or not at all, in specific circumstances defined by law. In a data protection context, it generally refers to the ability of an individual country to vary, restrict, or supplement how certain provisions apply within its own legal system. Because the exact scope of any derogation depends on the specific national law involved, its effect can differ from one country to another.

Formal definition

Derogation is a legal term of art referring to the suspension, suppression, or modified application of part or all of a provision in a legal measure under defined conditions. As a general legal concept, it allows a rule to be applied differently, or not at all, in certain cases. In the data protection field, 'derogation under national law' is used to describe situations where a member state exercises latitude expressly permitted under an EU instrument to adapt, restrict, or add conditions to how particular obligations apply domestically; the availability and scope of such derogations are determined by the governing instrument and the implementing national law. The evidence packet supplied here addresses derogation as a general legal and human-rights concept (including derogation from human rights treaties in states of emergency) rather than any specific GDPR article, so practitioners should verify the precise legal basis, permitted subject matter, and conditions against the current official text of the relevant instrument and the applicable national implementing law. Because member state positions can diverge, the practical effect of a derogation is jurisdiction-specific and subject to assessment.

Why it matters

Derogation is one of the mechanisms by which EU-wide data protection rules can produce different practical outcomes in different countries. Although an instrument such as the GDPR sets out common obligations, it also expressly permits member states, in defined areas, to vary, restrict, or supplement how certain provisions apply within their own legal systems. This means that a compliance position that holds in one member state may not hold identically in another, so practitioners cannot assume that a single reading of the harmonized text captures the full picture for any given jurisdiction.

Understanding derogations matters because they directly affect how obligations are scoped, what additional conditions apply, and whether particular activities are permissible in a specific country. Overlooking a national derogation can lead an organization to under-comply with local requirements or, conversely, to apply restrictions that do not in fact bind it. Because member state positions can diverge, and because the availability and scope of any derogation are set by the governing instrument together with the applicable national implementing law, the practical effect is jurisdiction-specific and subject to assessment.

Who it's relevant to

Data Protection Officers and Compliance Leads
Those responsible for mapping obligations across multiple jurisdictions need to identify where national derogations vary the position, so that local requirements are neither missed nor over-applied. Because member state positions can diverge, a harmonized policy typically needs to be checked against each relevant country's implementing law.
Privacy and Data Protection Lawyers
Advisers assessing whether a given processing activity is permissible in a specific country should confirm the precise legal basis, permitted subject matter, and conditions of any applicable derogation against the current official text and national implementing law, rather than relying on the harmonized instrument alone.
Multinational Organizations and Their Governance Functions
Organizations operating across several member states must account for the possibility that the practical effect of the same rule differs by jurisdiction. Governance frameworks generally benefit from flagging derogation-sensitive areas for local legal review, since the position is subject to assessment and can change as national laws evolve.

Inside Derogation Under National Law

Legislative basis for national variation
A derogation under national law refers to provisions of the GDPR that expressly permit or require EU member states to introduce, maintain, or specify national rules within defined limits. These are sometimes described as 'opening clauses' or 'flexibility clauses' because they leave room for member state legislation rather than imposing a single harmonised rule.
Defined scope of discretion
Each derogation operates only within the boundaries set by the relevant GDPR provision. Member states may adapt or specify the position for particular processing situations, but generally cannot exceed the parameters the Regulation lays down. The precise scope depends on the specific provision, which should be verified against the current official text.
Common areas of national variation
Derogations frequently arise in areas such as processing of special category data, employment-context processing, processing for research, archiving, journalistic and other expressive purposes, national identification numbers, and the age of consent for information society services offered to children. The exact position varies by member state and by the specific opening clause relied upon.
National implementing law
Where a member state exercises a derogation, the operative rule is typically found in that state's implementing or supplementary legislation rather than in the GDPR text alone. Practitioners must therefore read the GDPR provision together with the applicable national law to determine the position in a given jurisdiction.
Interaction with legal bases and conditions
Some derogations relate to the conditions for processing special category data under Article 9 or specify additional safeguards; others interact with the Article 6 legal bases, particularly the public task and legal obligation bases, which can require a basis in Union or member state law. The precise interaction depends on the derogation invoked.

Common questions

Answers to the questions practitioners most commonly ask about Derogation Under National Law.

Does a national derogation mean a member state can simply opt out of the GDPR?
No. A derogation is not a general opt-out from the GDPR. The Regulation is directly applicable across the EU, and derogations only operate where the GDPR itself expressly permits or requires member states to legislate, adjust, or specify certain matters. Outside those defined openings, the GDPR's provisions apply uniformly. Any national measure must remain within the boundary set by the enabling provision and, generally, must respect the GDPR's overall principles and the individual's rights.
Is a national derogation the same as a legal basis for processing under Article 6?
Not exactly. A derogation is a mechanism by which national law fills in, restricts, or specifies matters the GDPR leaves open; it is distinct from the six lawful bases in Article 6. In some cases national law provides detail supporting a basis such as legal obligation or public task, but the derogation itself does not replace the requirement to identify and satisfy an appropriate lawful basis, and, for special category data, an additional Article 9 condition. Readers should verify how their national implementing law interacts with the relevant basis against the current official text.
How do we find out whether a relevant national derogation exists for a particular processing activity?
Generally you should identify the specific GDPR provision that invites or permits member state legislation, then check the national implementing law of each member state whose law applies to your processing. Because derogations can vary between member states, the position may differ across jurisdictions where you operate. Where uncertainty exists, consulting the relevant supervisory authority's guidance and qualified local advice is typically advisable, and any conclusion should be verified against the current national text.
What should we do when national derogations differ across the member states where we operate?
In most cases you should map the applicable national rules jurisdiction by jurisdiction rather than assuming a single EU-wide position. Divergence can affect matters such as processing conditions, retention, or the exercise of data subject rights. Organisations typically document these variations and, subject to assessment, adopt the most protective approach where a consistent group-wide standard is preferred, while noting where local law imposes stricter or more specific requirements.
How do we document reliance on a national derogation for accountability purposes?
Generally you should record the specific GDPR provision that enables the derogation, the relevant national implementing law and provision, and how that national measure applies to the processing in question. This documentation typically forms part of your broader accountability records and can support your position if questioned by a supervisory authority. Because implementing laws can be amended, records should be reviewed periodically and checked against the current official text.
Do national derogations affect how we handle data subject rights requests?
They can. Some GDPR openings allow national law to restrict or specify aspects of certain rights in defined circumstances. Where such measures exist, they may affect how, or to what extent, a particular right applies in a given member state. You should assess each request against both the GDPR and any applicable national restriction, note that the position may differ across jurisdictions, and verify the scope of any restriction against the current national text rather than assuming it applies generally.

Common misconceptions

The GDPR is fully harmonised, so the rules are identical across all EU member states.
While the GDPR harmonises much of EU data protection law, it contains numerous derogations and opening clauses that allow member states to legislate differently in specified areas. As a result, the position can diverge between jurisdictions, and organisations operating in multiple member states should check the applicable national implementing law.
A national derogation lets a member state override or opt out of the GDPR wherever it chooses.
Derogations are not a general opt-out. They generally operate only within the specific boundaries defined by the relevant GDPR provision. A member state's discretion is confined to what the opening clause permits, and rules outside those limits would not typically be valid derogations.
The UK position mirrors the EU derogations exactly.
The UK GDPR, together with UK implementing legislation, is a distinct regime. Areas that the EU GDPR left to member state law may be addressed differently under UK law, so the EU and UK positions should be assessed separately and verified against the current applicable texts.

Best practices

Read the relevant GDPR opening clause alongside the applicable national implementing law before relying on any derogation, rather than assuming a single EU-wide rule.
Map the specific member states where your processing occurs and document how each one's national law addresses the derogations relevant to your activities.
When invoking a derogation for special category data, confirm both the Article 9 condition and any additional national safeguards or requirements attached to it.
Record which provision and which national law you are relying on, using qualified language and noting where the position is subject to assessment or may vary by jurisdiction.
Treat the UK position and any non-EU jurisdictions separately, since national variations and implementing legislation can differ from the EU baseline.
Periodically review reliance on derogations, as national implementing laws and regulatory guidance can change, and verify details against the current official texts.