The EDPB clarified the scope of GDPR Article 89 in April 2026. Article 89 creates a special regime for processing personal data for scientific research purposes, with reduced compliance obligations and broader retention allowances. For SaaS that does any data analysis, ML training or product research, knowing when this applies and when it does not changes what you can do with user data.

What qualifies as scientific research under Article 89

The EDPB clarified four criteria. All four must be present:

  1. Research methodology following established scientific standards
  2. Publication or sharing of results in a way that contributes to knowledge
  3. Independence: research outcomes are not predetermined by commercial interests
  4. Appropriate safeguards (Article 89.1): pseudonymisation, access controls, purpose limitation

What does NOT qualify

  • A/B testing for product optimization (commercial purpose, not research)
  • Internal analytics for business intelligence
  • ML training to improve a commercial feature
  • User research that does not produce shareable knowledge

Most SaaS internal data work falls outside Article 89. The carve-out is narrower than founders often hope.

When the carve-out genuinely applies

  • Academic partnerships where your SaaS contributes anonymized data to published studies
  • Industry research published in peer-reviewed venues (security, fraud detection, etc.)
  • Public health research using your data with documented IRB approval
ActivityArticle 89 applies?Why
Product A/B testNoCommercial purpose
ML model for recommendationsNoCommercial purpose
Anonymized dataset to university research labYesResearch methodology, publication
Industry-wide fraud pattern reportPossiblyDepends on publication and independence

The Article 89 regime allows longer retention and reduces some compliance obligations, but it requires the safeguards in Article 89.1 (pseudonymisation, access controls). It is not a free pass.

What to add to your privacy policy

If your SaaS participates in genuine research:

  • Section explaining when Article 89 applies and which data is involved
  • Pseudonymisation standard used
  • Researcher access controls
  • User opt-out mechanism (research participation should be optional)

Conclusion

The scientific research carve-out is narrower than its reputation suggests. Most internal SaaS work is commercial and stays under standard GDPR rules. When you do genuinely contribute to research, Article 89 reduces friction. Either way, the policy work is documenting accurately which category your processing falls into.

To generate a privacy policy with the right Article 89 disclosures, try Termerly free.