Banner2.png

Article 1 GDPR

From GDPRhub
Revision as of 15:23, 2 September 2021 by SR (talk | contribs) (→‎Commentary)
Article 1: Subject-matter and objectives
Gdpricon.png

Legal Text


Article 1: Subject-matter and objectives

1. This Regulation lays down rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data.

2. This Regulation protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data.

3. The free movement of personal data within the Union shall be neither restricted nor prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data.

Relevant Recitals

Recital 1: The Right to Data Protection as a Fundamental Right

Recital 2: Respect of Fundamental Rights and Freedoms

Recital 3: Directive 95/46/EC Harmonisation Goal

Recital 4: Balance Against Other Fundamental Rights

Recital 5: Cross-Border Cooperation for the Exchange of Personal Data

Recital 6: Technological Transformation to Ensure a High Level of Protection

Recital 7: Control Over Own Personal Data

Recital 8: National Implementation

Recital 9: Fragmentation under Directive 95/46/EC

Recital 10: Equivalent Level of Protection and Homogeneous Application

Recital 11: Strengthening of Rights and Enforcement

Recital 12: Article 16(2) TFEU Mandate

Commentary

Article 1 GDPR draws a first general framework regarding the processing of personal data in Europe. Paragraph 1 defines the two main objectives of the Regulation which are, on the one hand, the protection of the individual's personal data and, on the other, the facilitation of the principle of the free movement of such data. Paragraph 2 enshrines the protection of the individual's fundamental rights and freedoms, especially if connected to their personal data. Finally, Paragraph 3 clarifies that the free movement of personal data may not be prohibited or restricted for reasons relating to the protection of personal data.

(1) Subject-Matter

Article 1(1) establishes the GDPR's two main aims. From one side, it aims at protecting natural persons with regard to the processing of their personal data. On the other side, it recognizes the EU internal market interest in the free movement of such data.

These aims can function as guiding principles to interpreting the GDPR, together with the data processing principles established in Article 5.[1] Article 1(1) also clarifies that the GDPR applies to the processing of personal data concerning natural persons. It follows that the Regulation does not apply to the processing of data belonging to companies or other legal entities.

(2) Protecting Fundamental Rights

Article 1(2) specifically states that the GDPR protects natural persons' fundamental right to the protection of personal data. This is operationalized in more specific Articles throughout GDPR, for example in Article 35, which lays down the obligation to conduct a Data Protection Impact Assessment. The obligation to implement adequate technical safeguards to protect personal data can be found in Article 32. The rights provided in Chapter III can also be seen as a prerequisite for natural persons to ensure that their fundamental rights are being respected.

The fundamental right of a natural person to the protection of their personal data can be found in Article 8 of the Charter of Fundamental Rights of the European Union ('the Charter') and Article 8 ECHR.

The Charter, which is EU primary law, provides in Article 8(1) for “the right to the protection of personal data” of a natural person. Some requirements to the processing of this data follow from Article 8(2) of the Charter, which explicitly mentions the principles of fairness and purpose limitation, as well as states that processing must be pursuant to a lawful basis such as consent.

The impact of the Charter on the drafting of the GDPR can be observed from the changes made to the draft version of Article 6(4) GDPR following criticism from the Working Party 29. The Council had proposed that a controller could further process data, even if the purpose of the processing was incompatible with the original purpose, as long as the controller had an overriding interest – something the Working Party 29 objected to by pointing out that the principle of purpose limitation is part of primary law. [2]

Data protection pursuant to Article 8 of the Charter is closely connected to Article 7 of the Charter, which concerns the right to respect for “private and family life” and “communications”.

(3) Free Movement of Personal Data

The requirement for the free movement of personal data within the EU reflects the aim of European integration. Article 1(3) recognizes that personal data is part of the European single market and that personal data is a good that can be traded. It aims to facilitate the trading of personal data in the European single market, and is thus in line with the free movement of goods, capital, services and labour within the EU.

Article 1(3) also facilitates the harmonization of data protection across EU, as well as Iceland, Liechtenstein and Norway as part of the European Economic Area (EEA). Restrictions to transfers to non-EU/EEA countries (third countries) follow from Chapter V GDPR.

Decisions

→ You can find all related decisions in Category:Article 1 GDPR

References

  1. Hornung and Spiecker in Simitis, Hornung, Spiecker gen. Döhmann, Datenschutzrecht, Article 1 GDPR, margin number 1 (Beck 2019) (accessed 2 September 2021);
  2. WP29, Press release on Chapter II of the draft regulation for the March JHA Council, 17 March 2015.