Skip to main content
Category: Scope & Exemptions

Scientific or Historical Research Purposes

Also known as: Research Purposes, Scientific Research Purposes, Historical Research Purposes
Simply put

Under the GDPR and UK GDPR, this refers to processing personal data in order to carry out scientific or historical research, such as work that aims to advance knowledge in a field. When organisations process data for these purposes, the law allows certain flexibilities but also requires specific safeguards to protect the individuals whose data is used. It is one of a related group of purposes that also includes archiving in the public interest and statistical purposes.

Formal definition

Scientific or historical research purposes is one of the specially treated processing purposes addressed in Article 89 of the GDPR (and the corresponding UK GDPR provisions), alongside archiving purposes in the public interest and statistical purposes. Where personal data are processed for these purposes, Union or Member State law (or, in the UK, the UK GDPR and national implementing law) may provide for derogations from certain data subject rights, subject to appropriate safeguards being in place to protect the rights and freedoms of data subjects. The precise scope of what qualifies as 'scientific or historical research' is not exhaustively defined in the Article text and is elaborated in Recital 156 and in regulator guidance (for example, the ICO); this creates recognised interpretive uncertainty, and the availability and extent of specific derogations can vary between member states and between the EU and UK regimes. This term concerns the applicable safeguards and possible derogations under Article 89; it does not itself supply a lawful basis under Article 6 or a condition for special category data under Article 9, which must be identified separately. Readers should verify the current official text and applicable national provisions, as scope and derogations are subject to assessment and evolving guidance.

Why it matters

Scientific and historical research often depends on access to personal data at scale, and without dedicated provisions much valuable research could be difficult to conduct in a data protection-compliant way. The GDPR and UK GDPR recognise this by treating research alongside archiving in the public interest and statistical purposes as specially situated processing under Article 89, potentially allowing Union or Member State (or UK) law to provide derogations from certain data subject rights. This creates a framework intended to enable research while still requiring protective safeguards, so the individuals whose data is used are not left exposed.

The practical significance lies in the balance the provisions strike. Researchers and their institutions may benefit from flexibilities, but these are conditional on appropriate safeguards being in place, and the derogations do not automatically apply everywhere or to the same extent. Because the availability and scope of specific derogations can vary between member states and between the EU and UK regimes, organisations cannot assume that a permissible approach in one jurisdiction transfers cleanly to another.

A further reason this term matters is the recognised interpretive uncertainty around what actually qualifies as 'scientific or historical research'. The Article text does not exhaustively define the concept; it is elaborated in Recital 156 and in regulator guidance such as the ICO's. Mischaracterising an activity as research in order to claim flexibilities, without meeting the substantive expectations and safeguards, is a compliance risk. Organisations should therefore treat the research designation as something to be assessed and documented rather than assumed.

Who it's relevant to

Academic and institutional researchers
Universities, research institutes, and individual researchers processing personal data to advance knowledge should understand that the research provisions may offer flexibilities but require appropriate safeguards. They also need to separately establish a lawful basis under Article 6 and, where relevant, an Article 9 condition for special category data, rather than treating the research designation as sufficient on its own.
Data protection officers and compliance leads
DPOs advising research-active organisations need to assess whether a given activity genuinely qualifies as scientific or historical research, given the interpretive uncertainty in the Article text and the reliance on Recital 156 and regulator guidance. They should document the safeguards relied upon and confirm which specific derogations are available under the applicable EU member state or UK provisions.
Multi-jurisdictional organisations
Bodies conducting research across the EU and UK should not assume uniformity. The availability and extent of derogations can vary between member states and between the EU and UK regimes, so an approach permissible in one jurisdiction may not transfer directly to another and should be verified against local implementing law.
Data protection lawyers and advisers
Legal advisers structuring research programmes or agreements need to distinguish the Article 89 safeguards-and-derogations framework from the separate requirements for lawful basis and special category conditions, and to advise clients that scope and derogations are subject to assessment and evolving guidance requiring verification against current official text.

Inside Scientific or Historical Research Purposes

Research purpose privileging
The GDPR affords a distinct treatment to processing carried out for scientific or historical research purposes, which can include, subject to conditions, certain flexibilities regarding purpose limitation, storage limitation, and data subject rights. The precise scope is shaped by Article 89 safeguards and by member state law, so the position can vary across jurisdictions.
Article 89 safeguards
Processing for research purposes is generally expected to be subject to appropriate safeguards for the rights and freedoms of data subjects. These typically include technical and organisational measures such as data minimisation and, where feasible, pseudonymisation. The safeguards are a condition for benefiting from the associated flexibilities.
Compatibility with the original purpose
Further processing for scientific or historical research purposes is, in most cases and subject to Article 89 safeguards, not treated as incompatible with the purposes for which the data were initially collected. This does not remove the need for a lawful basis for the processing itself.
Legal basis still required
The research characterisation does not supply a legal basis on its own. A basis under Article 6 (and, for special category data, an additional condition under Article 9) must still be identified. Consent is one possible route but is not a universal requirement; other bases such as public task or legitimate interests may apply depending on context.
Special category data and derogations
Where research involves special category data, an Article 9 condition is needed in addition to an Article 6 basis. Member states may provide derogations and further conditions for research, so practitioners should verify the applicable national implementing law and any divergence between the EU GDPR and the UK GDPR.
Scope boundary, personal data only
The research provisions concern personal data of individuals. Where data are genuinely anonymised, the GDPR generally no longer applies. Anonymisation and pseudonymisation are distinct: pseudonymised data typically remain personal data and stay within scope.

Common questions

Answers to the questions practitioners most commonly ask about Scientific or Historical Research Purposes.

Does processing personal data for scientific or historical research purposes exempt me from the GDPR?
No. Research purposes do not remove personal data from the scope of the GDPR. The Regulation provides a specific regime, sometimes described as a research privilege, that can modify or relax certain obligations (for example, in relation to some data subject rights and the compatibility assessment for further processing), typically subject to appropriate safeguards. It is not a blanket exemption, and the extent of any derogations depends heavily on member state implementing law, which can vary. You should verify the position against the applicable national legislation and current official text.
Is consent always the required legal basis for research involving personal data?
No. Consent is one of several possible Article 6 legal bases, and research does not automatically require it. Depending on the context and the nature of the organisation, other bases such as public task or legitimate interests may be relied upon, subject to assessment. Note also that ethical or sector-specific consent requirements can exist independently of the GDPR legal basis. Where special category data is involved, an additional Article 9 condition is needed in addition to the Article 6 basis, and some conditions are tailored to research. The correct basis is context and jurisdiction dependent, so confirm against applicable national rules.
What safeguards are generally expected when relying on the research regime?
The GDPR generally conditions research-related derogations on the presence of appropriate safeguards designed to respect data minimisation. These commonly include technical and organisational measures such as pseudonymisation where it allows the purposes to be met, access controls, and clear governance. The specific safeguards required, and whether particular derogations are available at all, can depend on member state law and regulator guidance. You should document the safeguards you apply and verify expectations against the applicable national implementing provisions.
How does the research purpose interact with the further processing (compatibility) rules?
The GDPR generally treats further processing for scientific or historical research purposes as not incompatible with the original purposes, provided appropriate safeguards are in place. This can support reuse of data collected for another purpose in a research context, subject to assessment and to any conditions in national law. This does not by itself create a legal basis for the further processing or override transparency and other obligations, so those must still be considered separately.
Do data subject rights still apply to research, and can any be restricted?
Data subject rights continue to apply in principle, but the GDPR and member state implementing law can permit certain restrictions or derogations for research purposes, typically where those rights are likely to render impossible or seriously impair the achievement of the research and where appropriate safeguards apply. The availability and scope of such restrictions vary by jurisdiction and can be subject to regulator guidance, so you should confirm which rights can be limited under the applicable national rules and document the justification.
Should a Data Protection Impact Assessment be carried out for a research project?
A DPIA under Article 35 may be required where the processing is likely to result in a high risk to individuals, and many research activities involving sensitive data, large datasets, or novel techniques can meet that threshold, subject to assessment. Even where not strictly mandatory, a DPIA can help demonstrate accountability and identify appropriate safeguards. Whether a DPIA is required in a given case depends on the risk profile and any national supervisory authority lists, which you should check against current guidance.

Common misconceptions

Labelling a project as research means the GDPR no longer applies or that consent is always the required basis.
The research characterisation does not exempt processing from the GDPR, nor does it default to consent. A lawful basis under Article 6 must still be identified, with an additional Article 9 condition for special category data, and the applicable safeguards must be in place.
The research provisions allow indefinite retention and free reuse of any data.
Flexibilities regarding storage limitation and further use are generally conditional on appropriate Article 89 safeguards, such as data minimisation and pseudonymisation where feasible, and on any conditions set by member state law. They are not an unqualified licence.
The rules for research are uniform across the EU and the UK.
Member states may adopt derogations and additional conditions, and the UK GDPR position can diverge from the EU GDPR. The precise scope of any flexibility should be assessed against the applicable national implementing law and current guidance.

Best practices

Identify and document a specific legal basis under Article 6 for the research processing, and an additional Article 9 condition where special category data are involved, rather than relying on the research label alone.
Implement and record appropriate Article 89 safeguards, including data minimisation and, where feasible, pseudonymisation, and be able to demonstrate why the measures are proportionate to the risks.
Check the applicable member state implementing law or, for UK activities, the UK GDPR, since derogations and conditions for research can vary between jurisdictions.
Before treating further processing as compatible with the original purpose, confirm the research conditions and safeguards are met and document that assessment.
Distinguish clearly in your documentation between anonymised data (generally outside GDPR scope) and pseudonymised data (which typically remain in scope), and avoid overstating the effect of your measures.
Verify any article references, national derogations, and evolving guidance against the current official text before relying on them in a compliance program.