Art. 1 GDPR – Subject-matter and objectives
| Art. 1(1) | This Regulation lays down rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data. | subject matter |
| Art. 1(2) | This Regulation protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data. | fundamental rights objective |
| Art. 1(3) | The free movement of personal data within the Union shall be neither restricted nor prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data. | free movement objective |
Official text: Regulation (EU) 2016/679, Article 1, via EUR-Lex.
Article 1 states why the GDPR exists: to protect people when their personal data is processed, and to stop that protection being used as an excuse to block the free flow of data within the EU. It does not itself create an obligation a controller can breach. Instead, it is the fundamental-rights anchor that courts and regulators point to when deciding how broadly to read every other article.
| Chapter | Chapter 1 – General provisions (Art. 1-4) |
| Applies to | Interpretive backdrop for the whole Regulation; not a standalone obligation |
| Directly finable | No. Article 1 is not an obligation-imposing provision, so no DPA has fined a controller for infringing it |
| In force since | 25 May 2018 |
| Explained by recitals | 1, 2, 3, 4, 10 |
| Closest UK equivalent | UK GDPR Art. 1 (identical wording) |
Why Article 1 Still Matters, Even Without a Fine Attached
Article 1(2) is the line regulators and courts return to when a newer question does not have a clean answer elsewhere in the Regulation: does this reading protect the individual, or does it leave a gap in that protection? Article 1(3) does the opposite job, it stops a Member State or a company from using “data protection” as a pretext to restrict data flows within the EU for reasons that have nothing to do with protecting people.
How Courts Have Used Article 1
No supervisory authority has fined a controller for breaching Article 1, because it does not impose a compliance duty of its own. What does exist is a small number of CJEU judgments that lean on Article 1’s stated objective to decide how another article should be read. These are judicial interpretation, not enforcement, and the table below marks them accordingly rather than presenting them as fines.
| Case | Court | Date | Role of Article 1 |
|---|---|---|---|
| Meta Platforms Inc. and Others v Bundeskartellamt (C-252/21) | CJEU, Grand Chamber | 4 Jul 2023 | Article 1’s “high level of protection” objective was used to justify national competition authorities being able to assess GDPR compliance alongside data protection authorities. Discussed / relevant, not infringed. |
| Schrems v Meta Platforms Ireland (C-446/21) | CJEU | 4 Oct 2024 | The Court opened its reasoning by anchoring the decision in “the objective pursued by the GDPR, as is set out in Article 1 thereof and in recitals 1 and 10,” before ruling on special-category data and storage limitation. Discussed / relevant, not infringed. |
Neither case found Article 1 itself infringed, since it is not a provision capable of being infringed in the way Article 5 or Article 6 are. Both used it as interpretive support for a ruling on a different, operative article.
What This Means in Practice
- When a newer processing question has no clean answer elsewhere in the GDPR, expect regulators and courts to lean on Article 1(2)’s fundamental-rights framing to favour the more protective reading.
- Article 1(3) is why “we’re protecting privacy” is not a valid reason to restrict the flow of personal data to another EU Member State; that justification only works in the other direction, against non-EU transfers under Chapter V.
Recitals That Explain Article 1
(1) Data Protection as a Fundamental Right
States the constitutional source Article 1(2) draws on: the protection of natural persons in relation to the processing of their personal data is a fundamental right under Article 8(1) of the EU Charter of Fundamental Rights and Article 16(1) TFEU. This is why Article 1(2) is phrased as protecting a right rather than merely regulating an industry.
(2) Respect of the Fundamental Rights and Freedoms
Sets the Regulation’s dual ambition, matching Article 1’s own two objectives: protecting fundamental rights and freedoms regardless of nationality or residence, while contributing to an area of freedom, security and justice, to the internal market, and to the well-being of natural persons. Data protection and economic integration are framed as complementary, not opposed.
(3) Directive 95/46/EC Harmonisation
Explains the GDPR’s lineage: the 1995 Data Protection Directive already sought to harmonise fundamental-rights protection while ensuring free data flow between Member States. The GDPR inherits and strengthens that same twin aim, which is exactly what Article 1’s three paragraphs restate as binding rules rather than a directive Member States could implement unevenly.
(4) Data Protection in Balance with Other Fundamental Rights
Qualifies Article 1(2)’s fundamental-rights framing: the right to data protection is not absolute. It must be weighed against its function in society and balanced proportionately against other rights the Charter protects, including private life, freedom of expression, freedom to conduct a business, and the right to a fair trial. This is the recital courts reach for when Article 1 is used to favour a protective reading, since it confirms that reading still has limits.
(10) Harmonised Level of Data Protection Despite National Scope
Grounds Article 1(3)’s free-movement guarantee: to remove obstacles to data flows within the Union, the level of protection has to be equivalent across every Member State, applied consistently rather than left to national variation. The CJEU cited this recital together with Article 1 itself in Schrems v Meta Platforms Ireland (C-446/21) when anchoring its reasoning in the Regulation’s stated objective.
Related Recitals
(39) Principles of Data Processing
(40) Lawfulness of Data Processing
(41) Legal Basis or Legislative Measures
(42) Burden of Proof and Requirements for Consent
(43) Freely Given Consent
(44) Performance of a Contract
(45) Fulfillment of Legal Obligations
(46) Vital Interests of the Data Subject
(47) Overriding Legitimate Interest
(48) Overriding Legitimate Interest Within Group of Undertakings
(49) etwork and Information Security as Overriding Legitimate Interest
(50) Further Processing of Personal Data
(171) Repeal of Directive 95/46/EC and Transitional Provisions