Skip to main content
Category: Legal Framework & Instruments

Union or Member State Law

Also known as: Union law, Member State law, EU or national law
Simply put

This phrase appears throughout the GDPR to point to the legal rules that can apply alongside the Regulation itself: either laws made at the level of the European Union or laws made by an individual EU country. It is used because the GDPR does not stand entirely alone; in many situations it relies on, or permits, additional rules set either centrally by the EU or by each country's own legislature. Where you see it, it generally signals that the precise position may depend on which country's law applies and can therefore vary.

Formal definition

In the GDPR, 'Union or Member State law' is a recurring formulation used to identify the body of law that supplements, conditions, or is cross-referenced by the Regulation, distinguishing between (a) Union-level sources of law (EU legislation and, more broadly, EU legal instruments) and (b) the national law of individual EU Member States, including their domestic implementing and derogating provisions. The Regulation frequently ties the availability or scope of a provision to such law, for example where a legal basis rests on a legal obligation or a public-task ground, or where Member State derogations are expressly permitted; because the GDPR leaves defined 'opening clauses' to national legislatures, the effective rule can diverge between Member States. Practitioners should note that the concept is scope-sensitive: it references EU and Member State law specifically, and the analogous position under the UK GDPR and UK domestic legislation must be assessed separately following UK divergence. The evidence packet does not supply reliable article-level citations for the numerous provisions using this phrase, and readers should verify the specific article, the exact wording, and any relevant national implementing measure against the current official text.

Why it matters

The phrase "Union or Member State law" is one of the most consequential formulations in the GDPR because it signals that the Regulation rarely operates as a self-contained rulebook. In many situations the availability, scope, or precise conditions of a GDPR provision depend on a separate body of law made either at the EU level or by an individual Member State. For compliance teams this means that identifying the correct legal position often requires two steps: reading the Regulation and then locating the applicable supplementary or derogating law. Missing that second step can lead an organisation to assume a uniform, pan-European answer where none exists.

The practical significance is that outcomes can diverge between countries. Because the GDPR leaves defined "opening clauses" to national legislatures, a processing activity that is permissible or requires particular safeguards in one Member State may be treated differently in another. This is especially relevant where a legal basis rests on a legal obligation or a public-task ground, or where a Member State has enacted specific derogations. An organisation operating across several EU jurisdictions cannot safely rely on a single national reading as if it were the settled position everywhere.

Scope also matters. The phrase refers specifically to EU and Member State law, so the analogous position under the UK GDPR and UK domestic legislation must be assessed separately in light of UK divergence. Practitioners should treat any general statement about this concept as a starting point and verify the specific article, its exact wording, and any relevant national implementing measure against the current official text before relying on it in a compliance program.

Who it's relevant to

Data Protection Officers and Compliance Leads
DPOs and compliance leads need to recognise when a GDPR provision defers to Union or Member State law, because that deferral often means the position is not uniform across the EU. When mapping legal bases or processing conditions, they should check for applicable national implementing or derogating measures rather than assuming a single pan-European answer.
Privacy and Data Protection Lawyers
Lawyers advising on cross-border activities must read the GDPR alongside the relevant EU or national law it references, and should account for divergence created by Member State opening clauses. They should also assess the UK position separately, since the analogous concept under the UK GDPR and UK domestic legislation follows its own path after UK divergence.
Multinational Organisations and Their Governance Teams
Organisations operating in more than one EU country cannot rely on one Member State's reading as if it applied everywhere. Governance teams should build country-specific checks into their processes wherever the Regulation ties a provision to Union or Member State law, and verify the applicable national measure against the current official text.
Controllers Relying on Legal Obligation or Public-Task Grounds
Where a controller's legal basis rests on a legal obligation or a public-task ground, that basis generally depends on Union or Member State law. Such controllers should identify the specific supplementary law underpinning their basis, as its existence and scope can determine whether the processing is lawful in a given jurisdiction.

Inside Union or Member State Law

Union law
Legal instruments adopted at the EU level, including regulations, directives, and decisions. Where the GDPR refers to 'Union law' as a basis or condition, it points to obligations or authorizations arising from this body of law rather than from any single member state.
Member State law
The domestic law of an individual EU member state, including national statutes and implementing legislation enacted to give effect to or supplement the GDPR. The specific content can differ between member states, so the applicable position generally depends on which member state's law governs a given processing activity.
Function as a legal basis
Union or Member State law is referenced in the GDPR in connection with certain Article 6 lawfulness grounds, notably where processing is necessary for compliance with a legal obligation or for the performance of a task carried out in the public interest or exercise of official authority. In these cases the underlying obligation or task is typically defined by such law.
Role in derogations and conditions
The GDPR permits member states to introduce more specific provisions or derogations in defined areas, meaning Union or Member State law can shape how certain obligations apply in practice. The precise scope of any derogation should be verified against the relevant national implementing law.
Relationship to special category data
Where processing involves special category data under Article 9, Union or Member State law can supply an additional condition that permits such processing in specified circumstances. This is distinct from the Article 6 legal basis, which is generally still required as well.
UK divergence context
Following the UK's departure from the EU, references to Union or Member State law do not apply in the same way under the UK GDPR and its accompanying national law. Practitioners should treat the EU and UK positions as separate and verify which regime applies.

Common questions

Answers to the questions practitioners most commonly ask about Union or Member State Law.

Does the GDPR fully harmonize data protection law across the EU, leaving no room for national variation?
No. While the GDPR is directly applicable across member states, it repeatedly defers to "Union or Member State law" and contains numerous provisions permitting member states to introduce, maintain, or specify national rules. This means the position can diverge between member states in the areas where such derogations or specifications are permitted. The GDPR is best understood as a harmonizing framework that nonetheless leaves defined space for national implementing law, so a practice lawful in one member state is not automatically lawful in another where a national derogation applies.
Is "Member State law" limited to the national statute that implements the GDPR?
Not necessarily. The concept of "Union or Member State law" is typically understood more broadly than a single implementing act. Depending on the provision and the member state, the relevant law may include sector-specific legislation, other national statutes, and in some contexts other instruments recognized as law within that legal order. The precise scope of what counts as "law" for a given GDPR provision can be subject to interpretation and guidance, so the boundary should be confirmed against the applicable national framework rather than assumed to be a single implementing act.
How do we identify when a GDPR provision hands the question over to Union or Member State law?
Generally, you look for explicit references within the relevant GDPR article to "Union or Member State law" or to conditions that member states may specify. Where such wording appears, the GDPR itself signals that the detailed position may be governed or supplemented nationally. Because the exact provisions and their conditions should be read against the current official text, it is advisable to check both the Regulation wording and the applicable national implementing or sector-specific law rather than relying on the GDPR text alone.
Which legal bases under Article 6 most often depend on Union or Member State law in practice?
In most cases, the legal obligation basis and the public task basis are the ones that require a foundation in Union or Member State law, since both typically rest on an obligation or task laid down in law. This distinguishes them from bases such as consent, contract, or legitimate interests, which do not generally require a supporting national or Union legal provision in the same way. The precise conditions and any specifying requirements should be verified against the applicable law, as member state positions can vary.
When processing spans several member states, how should we account for divergent national law?
Because member state derogations and specifications can vary, cross-border processing typically calls for assessing the national position in each relevant member state rather than assuming a single uniform rule. This is particularly relevant where a provision defers to Union or Member State law, such as certain conditions for special category data or public-interest processing. The safer approach is generally to map which national laws apply to which processing activities and to confirm each against the current national text, noting that regulator guidance may differ between jurisdictions.
What should we document to show a processing activity is grounded in Union or Member State law where that is required?
Where a GDPR provision requires a basis in Union or Member State law, it is generally advisable to record the specific legal provision relied upon, how it applies to the processing, and any conditions or safeguards that the law specifies. Because the adequacy of such documentation is context and risk dependent, and because the applicable law may change, the record should be kept current and verified against the official text rather than treated as settled once created.

Common misconceptions

Union or Member State law provides a standalone legal basis that removes the need to identify an Article 6 ground.
Such law generally operates in conjunction with specific Article 6 grounds (for example, the legal obligation or public task grounds) rather than replacing the requirement to identify an appropriate lawful basis. Where special category data is involved, an additional Article 9 condition is typically needed as well.
The requirements are identical across all member states because the GDPR is a single regulation.
Although the GDPR applies directly across the EU, it leaves room for member state derogations and more specific national provisions in certain areas. As a result, the applicable Member State law can vary, and the position should be checked against the relevant national implementing law.
References to Union or Member State law also cover the United Kingdom.
The UK is no longer an EU member state, and the UK GDPR together with UK national law forms a separate regime. References to Union or Member State law in the EU GDPR should not be assumed to extend to the UK.

Best practices

Identify which specific Union instrument or Member State law you are relying on before treating processing as authorized, and document the reference in your records of processing.
Confirm the applicable Article 6 legal basis separately, since reliance on Union or Member State law generally works together with a specific lawfulness ground rather than replacing it.
Where special category data is processed, verify that a distinct Article 9 condition is met in addition to the Article 6 basis, and check whether that condition derives from Union or Member State law.
Check for member state derogations and more specific national provisions that may vary the position, and do not assume uniformity across the EU.
Treat the EU GDPR and UK GDPR as separate regimes, and confirm which applies before relying on references to Union or Member State law.
Periodically re-verify the relevant provisions against the current official text and national implementing law, as national measures and interpretations can change over time.