Guidelines 03/2020 on the processing of data concerning health for the purpose of scientific research in the context of the COVID-19 outbreak
Subparagraph 18.104.22.168 Obtaining or disclosure is expressly laid down by Union or Member State law
41. Article 14 (5) (c) GDPR allows for a derogation of the information requirements in Articles14 (1), (2) and (4) insofar as the obtaining or disclosure of personal data “is expressly laid down by Union or Member State law to which the controller is subject”. This exemption is conditional upon the law in question providing “appropriate measures toprotect the data subject’s legitimate interests”. As stated in the above mentioned Transparency Guidelines, such law must directly address the data controller and the obtaining or disclosure in question should be mandatory upon the datacontroller. When relying on this exemption, the EDPB recalls that the data controller must be able to demonstrate how the law in question applies to them and requires them to either obtain or disclose the personal data in question.