32025L0050#art_23Council Directive (EU) 2025/50

Article 23 — Personal data protection

1. Member States shall, for the purposes of the correct application of this Directive, restrict the scope of the obligations and rights provided for in Articles 13 to 19 of Regulation (EU) 2016/679 to the extent required in order to safeguard the interests referred to in Article 23(1), point (e), of that Regulation in so far as such obligations or the exercise of such rights may jeopardise those interests. 2. When processing personal data, certified financial intermediaries and the competent authorities of Member States shall be considered as controllers, within the meaning of Article 4(7) of Regulation (EU) 2016/679, within the scope of their respective activities under this Directive. 3. Information, including personal data, processed in accordance with this Directive shall not be retained longer than is necessary to achieve the purposes of this Directive, and in any case in accordance with each data controller’s domestic rules on the statute of limitations.

Text as published in the Official Journal, reproduced verbatim (including any typographical quirks of the source). For the authentic version, see EUR-Lex.