Union or Member State Law
This phrase appears throughout the GDPR to point to the legal rules that can apply alongside the Regulation itself: either laws made at the level of the European Union or laws made by an individual EU country. It is used because the GDPR does not stand entirely alone; in many situations it relies on, or permits, additional rules set either centrally by the EU or by each country's own legislature. Where you see it, it generally signals that the precise position may depend on which country's law applies and can therefore vary.
In the GDPR, 'Union or Member State law' is a recurring formulation used to identify the body of law that supplements, conditions, or is cross-referenced by the Regulation, distinguishing between (a) Union-level sources of law (EU legislation and, more broadly, EU legal instruments) and (b) the national law of individual EU Member States, including their domestic implementing and derogating provisions. The Regulation frequently ties the availability or scope of a provision to such law, for example where a legal basis rests on a legal obligation or a public-task ground, or where Member State derogations are expressly permitted; because the GDPR leaves defined 'opening clauses' to national legislatures, the effective rule can diverge between Member States. Practitioners should note that the concept is scope-sensitive: it references EU and Member State law specifically, and the analogous position under the UK GDPR and UK domestic legislation must be assessed separately following UK divergence. The evidence packet does not supply reliable article-level citations for the numerous provisions using this phrase, and readers should verify the specific article, the exact wording, and any relevant national implementing measure against the current official text.
Why it matters
The phrase "Union or Member State law" is one of the most consequential formulations in the GDPR because it signals that the Regulation rarely operates as a self-contained rulebook. In many situations the availability, scope, or precise conditions of a GDPR provision depend on a separate body of law made either at the EU level or by an individual Member State. For compliance teams this means that identifying the correct legal position often requires two steps: reading the Regulation and then locating the applicable supplementary or derogating law. Missing that second step can lead an organisation to assume a uniform, pan-European answer where none exists.
The practical significance is that outcomes can diverge between countries. Because the GDPR leaves defined "opening clauses" to national legislatures, a processing activity that is permissible or requires particular safeguards in one Member State may be treated differently in another. This is especially relevant where a legal basis rests on a legal obligation or a public-task ground, or where a Member State has enacted specific derogations. An organisation operating across several EU jurisdictions cannot safely rely on a single national reading as if it were the settled position everywhere.
Scope also matters. The phrase refers specifically to EU and Member State law, so the analogous position under the UK GDPR and UK domestic legislation must be assessed separately in light of UK divergence. Practitioners should treat any general statement about this concept as a starting point and verify the specific article, its exact wording, and any relevant national implementing measure against the current official text before relying on it in a compliance program.
Who it's relevant to
Inside Union or Member State Law
Common questions
Answers to the questions practitioners most commonly ask about Union or Member State Law.