Scientific research under the GDPR

Legal News
The Danish Data Protection Agency (Datatilsynet) has recently published a decision focusing on the concept of "scientific research" under the GDPR. In its decision, the Danish Data Protection Agency confirmed that the qualification of a processing activity as scientific research modifies the application of several core GDPR principles. Taken together with the recent guidelines by the European Data Protection Board ("EDPB") i.e., Guidelines 1/2026 on processing of personal data for scientific research purposes, the concept of scientific research is now more operationally described and of likely relevance to many actors within the space of artificial intelligence, life science and digital health, among others.

This article explains why the qualification of "scientific research" matters, how the concept has evolved, what types of activities may fall within it, and how organisations should use the guidance in practice.

Why the classification matters

The GDPR affords a special regime for processing carried out for "scientific research purposes" in accordance with Recital 159 GDPR. The underlying rationale is that the characteristics of genuine scientific research are difficult to reconcile with the precision and finality that ordinary data protection principles assume. The GDPR research regime therefore creates a set of specific flexibilities when the processing is genuinely scientific. The table below sets out these flexibilities, and its practical consequence for research controllers.

 

Accordingly, the definition of scientific research is significant, as it will in many cases provide increased flexibility for research projects that are genuinely scientific. 

The Danish Data Protection Agency has in a recent case confirmed this approach. In a decision of 16 July, regarding the University of Copenhagen's disclosure of a former employees' personal data. The University wished to disclose the employees' data to the Department of Occupational and Environmental Medicine at Bispebjerg Hospital, which conducts research into the impact of the working and surrounding environment on health. The Danish Data Protection Agency criticised the University for not following its own internal deletion guidelines and thereby failed to observe the storage limitation principle in Article 5(1)(e) GDPR. 

Notwithstanding this, the Danish Data Protection Agency held that the data could still be retained, because a new purpose had arisen for keeping it, namely to enable disclosure to the hospital for research purposes, and that this research purpose could outweigh the interest in deletion in accordance with the last part of Article 5(1)(e) GDPR. 

In regards to the disclosure itself, the Danish Data Protection Agency confirmed that further processing for scientific research purposes is not considered incompatible with the original purpose given the presumption of compatibility in the last part of Article 5(1)(b) GDPR. 

This case highlights the importance of the qualification of scientific research, offering flexibility for controllers under the GDPR. 

How the concept has evolved

The GDPR does not provide a firm definition of the term scientific research purposes. However, in recital 159 of the GDPR it is stated that:

"For the purposes of this Regulation, the processing of personal data for scientific research purposes should be interpreted in a broad manner including for example technological development and demonstration, fundamental research, applied research and privately funded research. [...] Scientific research purposes should also include studies conducted in the public interest in the area of public health. To meet the specificities of processing personal data for scientific research purposes, specific conditions should apply in particular as regards the publication or otherwise disclosure of personal data in the context of scientific research purposes."


Accordingly, the GDPR seems to assume a broad interpretation of research, which includes technological development, applied research and privately funded research as well as disclosure and publication of personal data. 

However, the European Data Protection Supervisor (EDPS), in its 6 January 2020 Preliminary Opinion on data protection and scientific research, emphasised that scientific research should not be regarded as a "carte blanche" for extensive data processing. Such activities must be conducted in accordance with recognised methodological and ethical standards aimed at contributing to "society's collective knowledge and wellbeing", as opposed to serving primarly private interests. 

That early EDPS approach could be read as a warning against projects that merely invoke scientific language to justify data accumulation for private gains. In practice, however, framing scientific research primarily by reference to the absence of private interests' risks creating uncertainty for legitimate research carried out by commercial entities. Such an approach sits uneasily with the text of Recital 159 GDPR, which calls for scientific research to be interpreted broadly, explicitly including technological development, applied research and, importantly, privately funded research.

The EDPB Guidelines 1/2026 now make this more explicit. The guidelines state that scientific research may be conducted by public and private entities alike and, crucially, may be conducted for profit. They include examples of a pharmaceutical company conducting a clinical trial for a rare disease and a start-up conducting research into bias in generative artificial intelligence models. In both cases, the commercial context does not disqualify the project. What matters is that the research is methodical, ethically reviewed and capable of contributing to scientific knowledge.

The evolution is therefore best understood as a move from institutional status to operational substance. The decisive question is not whether the controller is a university, a hospital or a company, but whether the processing is genuinely motivated by scientific research purposes and is governed accordingly. 

The EDPB's six key factors 

The EDPB has identified six key indicative factors of scientific research. If the activity meets all six, it can be presumed to constitute processing scientific research purposes in accordance with GDPR recital 159. If it does not meet all six, the controller must be able to explain why it should still be treated as scientific research. The more factors that are present, the stronger the case. The factors are as following: 

 

The EDPB also recognises that ancillary processing operations may be motivated by scientific research purposes. These can include identifying potential participants, processing contact details for recruitment, extracting relevant data, filtering, categorisation, anonymisation and pseudonymisation before the data is used in the individual research project.

This is practically important, as in many projects, the most sensitive data protection questions arise earlier, when patients are screened, biological material is sequenced, data is harmonised or datasets are combined, etc. Those activities may fall within the scientific research purpose if they have a clear research objective and are necessary for the scientific project proper. 

Use cases 

In practical terms, this means that a lot of activities associated with R&D may be conducted for scientific research purposes. Among others, the EDPB mentions inter alia: 

  • Clinical research

    A pharmaceutical company initiates a clinical trial to investigate the side effects of a new pharmaceutical for a rare disease. The trial is conducted by academically qualified researchers under a research plan drawn up in accordance with good clinical practice, reviewed by an ethics committee, and the results are published in a scientific journal.
     

  • AI research

    A start-up applies for external funding to study bias in generative AI models. The funding conditions require established scientific methods, ethical review and public availability of results. The start-up partners with a university faculty, the joint research group is reviewed by an independent ethical board, and the completed project results in a peer-reviewed publication benefiting the wider research community
     

  • Research data infrastructures

    A public agency with a statutory task to monitor education quality makes pseudonymised pupil data (grades, gender, teacher diaries on behaviour and well-being) available to external researchers through a secure access-controlled environment. Access requires submission of a detailed research plan conducted by qualified researchers, with results made publicly available. Access to special category data (e.g. pupil health data) additionally requires ethical approval. Researchers cannot download personal data and are bound by confidentiality obligations.

On the other hand, the research regime should not be used for activities that are only internal analytics. The EDPB gives the example of a retail company analysing sales data to inform its marketing strategy. Because the analysis is not independent, not open to scientific scrutiny, not designed to contribute to knowledge and not subject to review, it does not qualify as scientific research.

The same caution applies to the "research" arms of companies where experiments are conducted on users primarily to gain insight into different categories of customers, increase engagement or improve commercial metrics. Such projects may deploy sophisticated methods and generate useful internal data, but they do not constitute scientific research. Their results are not designed to be verifiable and are not disclosed beyond the organisation. They carry no apparent potential to advance existing scientific knowledge or apply it in novel ways. Most fundamentally, their purpose is to serve the company's commercial interests rather than to contribute to the growth of society's collective knowledge and wellbeing. Where those conditions are absent, the scientific research regime under the GDPR is not available.

Legal basis, transparency and Article 89 safeguards

Once the controller has established that the activity is genuinely scientific, the controller still needs to identify a legal basis under Article 6 GDPR, and, where special category data is involved, a condition under Article 9 GDPR. The controller must also address transparency in accordance with Article 13-14 GDPR, plan for the exercise of data subject rights pursuant to Article 15-22 GDPR and implement the safeguards required under Article 89 GDPR.

In addition, where the research happens within the area of clinical or medical research a data protection impact assessment pursuant to Article 35 GDPR will often be needed, as well as it will often be necessary to clarify whether parties act as controllers, joint controllers or processors, and preparing the necessary data-sharing, joint-controller or processor agreements.

The following timeline can be used as a practical project management tool.

How Plesner can assist

Plesner advises clients on all matters relating to data protection, life sciences and clinical trials, including the interactions with ethics committees and data protection authorities and the creation of data protection impact assessments (DPIA) in the context of clinical trials and AI research. 

Want to know more?

If your organisation is planning a research project, reusing existing data, building a research infrastructure, designing clinical trial transparency materials or assessing whether a data-driven project can rely on the scientific research regime, please contact Plesner’s Data Protection team.

Disclaimer 

This article is intended as general information and does not constitute legal advice. The correct analysis will depend on the specific research design, data categories, jurisdictions, institutional roles and applicable national law and approvals. Please contact us before relying on the above legal analysis.