Skip to main content
Category: Data Transfers

Derogations

Also known as: Derogation, Derogation clause
Simply put

A derogation is a legal mechanism that allows a rule or part of a rule to be set aside, applied differently, or not applied at all in defined circumstances. In practice it functions as a permitted exception, letting a party depart from a general requirement where the law specifically allows it. The scope and conditions of any derogation depend on the specific legal instrument in which it appears.

Formal definition

In legal usage, a derogation is a term of art referring to the partial or complete suspension, limitation, or differentiated application of a provision within a legal measure under conditions expressly permitted by that measure. Derogations may take the form of a treaty clause allowing a signatory to opt out of certain obligations, or, more broadly, a taking away from or detraction from the force of a law. The precise conditions, limits, and permissibility of a given derogation are governed entirely by the instrument that authorizes it, and readers should verify the relevant provisions against the current official text of the applicable legal instrument, as terms and scope can vary between instruments and jurisdictions.

Why it matters

Derogations shape how a general legal rule actually applies in practice, because they define the specific circumstances in which a party may depart from an obligation that would otherwise bind them. For privacy and data protection professionals, understanding whether a derogation exists, and what conditions attach to it, is often the difference between a lawful departure from a default rule and a breach of it. Because a derogation is a permitted exception rather than a free-standing right, its force depends entirely on the instrument that authorizes it.

The practical significance lies in the fact that derogations narrow or suspend obligations only within tightly defined limits. Treating a derogation as broader than its authorizing provision allows is a common source of risk, since the exception typically carries its own conditions, thresholds, and safeguards. In most cases, the burden falls on the party relying on a derogation to demonstrate that the specific conditions are met, rather than assuming the exception applies by default.

Derogations also vary between instruments and jurisdictions, so a mechanism that permits departure from a rule in one legal measure may have no equivalent, or a materially different scope, in another. Readers should verify the precise conditions against the current official text of the applicable instrument, as the terms and scope of any given derogation can change and can differ across jurisdictions.

Who it's relevant to

Data protection officers and compliance leads
DPOs and compliance leads need to identify when a general obligation can lawfully be set aside and to document the specific conditions that justify relying on a derogation. Because the burden of demonstrating that conditions are met typically rests on the party invoking the exception, careful mapping of the authorizing provision is essential.
Privacy and data protection lawyers
Lawyers advising on privacy matters must distinguish a genuine derogation, and its precise limits, from a broader default rule. As derogations are terms of art whose scope is defined solely by the instrument that creates them, counsel should verify the exact wording and conditions against the current official text before advising that a departure is permitted.
Engineers and product teams implementing controls
Technical teams building systems around legal requirements need to understand where a derogation permits a rule to be applied differently or not at all, so that controls reflect the actual permitted exceptions rather than assumptions. Because the scope of a derogation can vary between instruments and jurisdictions, implementation decisions should be confirmed with legal or compliance colleagues.

Inside Derogations

Article 49 specific situation derogations
GDPR provides derogations that may permit certain international transfers of personal data in the absence of an adequacy decision or appropriate safeguards such as Standard Contractual Clauses or Binding Corporate Rules. These are exceptions rather than routine transfer tools and are generally interpreted narrowly by regulators.
Explicit consent for the transfer
One derogation relies on the data subject having explicitly consented to the proposed transfer after being informed of the possible risks of transferring data absent an adequacy decision and appropriate safeguards. This is distinct from consent as an Article 6 legal basis for processing and is subject to the general conditions and revocability of consent.
Necessity for a contract
Certain derogations may apply where a transfer is necessary for the performance of a contract between the data subject and the controller, or for pre-contractual steps taken at the data subject's request, or for a contract concluded in the data subject's interest. The necessity requirement is assessed strictly.
Important reasons of public interest
A transfer may be permitted where necessary for important reasons of public interest that are recognized in EU or member state law. The scope of what qualifies can be affected by national implementing law and member state derogations.
Legal claims, vital interests, and public registers
Further derogations may cover transfers necessary for the establishment, exercise, or defence of legal claims, transfers necessary to protect the vital interests of the data subject or others where the data subject is incapable of giving consent, and transfers made from a register intended to provide public information, subject to conditions.
Compelling legitimate interests fallback
Where no other derogation or transfer tool applies, a limited fallback may permit a non-repetitive transfer concerning a limited number of data subjects where necessary for compelling legitimate interests, subject to an assessment of the circumstances and additional safeguards and notification obligations. This is regarded as a last resort and is interpreted very restrictively.

Common questions

Answers to the questions practitioners most commonly ask about Derogations.

Are derogations a routine, everyday way to justify international data transfers?
No. Derogations are generally intended for exceptional or occasional situations rather than as a standard, ongoing transfer mechanism. Regulators have typically indicated that where transfers are regular, repetitive, or systematic, an appropriate transfer tool (such as an adequacy decision, Standard Contractual Clauses, or Binding Corporate Rules) should be used instead. Relying on derogations for routine transfers risks being treated as a misuse of their exceptional nature. You should verify the current position against the applicable Regulation text and up-to-date regulatory guidance, as interpretation can evolve.
Does relying on a derogation mean you have no other conditions or safeguards to worry about?
No. A derogation addresses only the specific question of whether a transfer to a third country may proceed in the absence of an adequacy decision or an appropriate transfer tool. It does not remove the need for a valid Article 6 legal basis for the underlying processing, nor does it satisfy any additional condition required for special category data under Article 9. Other obligations, such as transparency, data minimisation, and accountability, continue to apply. In short, a derogation is not a blanket exemption from the wider framework.
How should an organisation decide whether a derogation applies rather than a transfer tool?
As a general approach, transfer tools such as adequacy decisions, Standard Contractual Clauses, or Binding Corporate Rules are typically considered first, with derogations examined only where no such tool is available or appropriate and the situation fits the exceptional character the derogations are designed for. The analysis is fact-specific and should be documented. Because the boundary between an occasional and a systematic transfer can be uncertain, and regulators may diverge in their views, you should assess each case against the current official text and applicable guidance.
What should be documented when relying on a derogation?
Consistent with the accountability principle, it is generally advisable to record which derogation is being relied upon, why an adequacy decision or appropriate transfer tool was not used, the exceptional or occasional nature of the transfer, and how the specific conditions of that derogation are met. Where the derogation depends on the individual, records relating to the relevant information provided or the basis relied upon may also be relevant. The precise expectations can vary between regulators, so confirm requirements against current guidance.
How does relying on a derogation interact with the legal basis for the processing?
The two are distinct and both must be addressed. A derogation concerns the lawfulness of transferring personal data to a third country, while the Article 6 legal basis concerns the lawfulness of the processing itself. Selecting a derogation does not establish or replace the legal basis, and for special category data an additional Article 9 condition is also required. These assessments should be carried out separately and, subject to the facts, may involve different considerations.
Can a derogation be used as a long-term solution for ongoing transfers?
In most cases this is not the intended use. Derogations are generally framed for situations that are not regular or systematic, so treating them as a durable, long-term arrangement can be inconsistent with their exceptional character. Where transfers are expected to continue over time, organisations typically move toward an appropriate transfer tool, potentially supported by supplementary measures where needed. Because transfer mechanisms and expectations evolve, any long-term arrangement should be kept under review against the current official position.

Common misconceptions

Derogations are an equivalent alternative to Standard Contractual Clauses or Binding Corporate Rules for ongoing transfers.
Derogations are exceptions for specific situations and are generally not intended for repetitive, systematic, or large-scale transfers. In most cases regulators expect a transfer tool with appropriate safeguards, or an adequacy decision, to be used first, with derogations reserved for genuinely exceptional circumstances.
Consent to a transfer works the same way as consent as a legal basis for processing.
The consent derogation requires explicit consent given after the data subject is informed of the specific risks arising from the absence of an adequacy decision and appropriate safeguards. It carries its own informational and revocability implications and should not be assumed to be interchangeable with an Article 6 consent basis for the underlying processing.
The compelling legitimate interests derogation can support routine business transfers.
This fallback is a last resort that applies only to non-repetitive transfers involving a limited number of data subjects, subject to a documented assessment, additional safeguards, and notification duties. Regulators interpret it very narrowly, and it is generally unsuitable for ongoing operational data flows.

Best practices

Treat derogations as exceptions of last resort and first assess whether an adequacy decision or an appropriate safeguard such as Standard Contractual Clauses or Binding Corporate Rules is available for the transfer.
Document the specific derogation relied upon and record the reasoning showing why it applies, including the necessity assessment and the exceptional or non-repetitive nature of the transfer.
Where relying on explicit consent, ensure the data subject is informed of the possible risks of transferring without an adequacy decision and appropriate safeguards, and account for the ability to withdraw consent.
Confirm whether any relevant member state implementing law or derogation affects concepts such as important reasons of public interest, since the position can vary between jurisdictions.
Verify the current status of applicable transfer mechanisms and any supplementary measures against the latest official GDPR text and regulator guidance, as adequacy decisions and transfer tools can evolve.
Avoid using derogations to justify repetitive, systematic, or large-scale transfers, and seek specific advice before relying on the compelling legitimate interests fallback.