Home > Chapter 1 - General provisions > Art. 1 GDPR – Subject-matter and objectives

Art. 1 GDPR – Subject-matter and objectives

Art. 1(1)This Regulation lays down rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data.subject matter
Art. 1(2)This Regulation protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data.fundamental rights objective
Art. 1(3)The free movement of personal data within the Union shall be neither restricted nor prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data.free movement objective

Official text: Regulation (EU) 2016/679, Article 1, via EUR-Lex.


In short

Article 1 states why the GDPR exists: to protect people when their personal data is processed, and to stop that protection being used as an excuse to block the free flow of data within the EU. It does not itself create an obligation a controller can breach. Instead, it is the fundamental-rights anchor that courts and regulators point to when deciding how broadly to read every other article.

ChapterChapter 1 – General provisions (Art. 1-4)
Applies toInterpretive backdrop for the whole Regulation; not a standalone obligation
Directly finableNo. Article 1 is not an obligation-imposing provision, so no DPA has fined a controller for infringing it
In force since25 May 2018
Explained by recitals1, 2, 3, 4, 10
Closest UK equivalentUK GDPR Art. 1 (identical wording)

Why Article 1 Still Matters, Even Without a Fine Attached

Article 1(2) is the line regulators and courts return to when a newer question does not have a clean answer elsewhere in the Regulation: does this reading protect the individual, or does it leave a gap in that protection? Article 1(3) does the opposite job, it stops a Member State or a company from using “data protection” as a pretext to restrict data flows within the EU for reasons that have nothing to do with protecting people.

How Courts Have Used Article 1

No supervisory authority has fined a controller for breaching Article 1, because it does not impose a compliance duty of its own. What does exist is a small number of CJEU judgments that lean on Article 1’s stated objective to decide how another article should be read. These are judicial interpretation, not enforcement, and the table below marks them accordingly rather than presenting them as fines.

CaseCourtDateRole of Article 1
Meta Platforms Inc. and Others v Bundeskartellamt (C-252/21)CJEU, Grand Chamber4 Jul 2023Article 1’s “high level of protection” objective was used to justify national competition authorities being able to assess GDPR compliance alongside data protection authorities. Discussed / relevant, not infringed.
Schrems v Meta Platforms Ireland (C-446/21)CJEU4 Oct 2024The Court opened its reasoning by anchoring the decision in “the objective pursued by the GDPR, as is set out in Article 1 thereof and in recitals 1 and 10,” before ruling on special-category data and storage limitation. Discussed / relevant, not infringed.

Neither case found Article 1 itself infringed, since it is not a provision capable of being infringed in the way Article 5 or Article 6 are. Both used it as interpretive support for a ruling on a different, operative article.

What This Means in Practice

  • When a newer processing question has no clean answer elsewhere in the GDPR, expect regulators and courts to lean on Article 1(2)’s fundamental-rights framing to favour the more protective reading.
  • Article 1(3) is why “we’re protecting privacy” is not a valid reason to restrict the flow of personal data to another EU Member State; that justification only works in the other direction, against non-EU transfers under Chapter V.

Recitals That Explain Article 1

(1) Data Protection as a Fundamental Right

States the constitutional source Article 1(2) draws on: the protection of natural persons in relation to the processing of their personal data is a fundamental right under Article 8(1) of the EU Charter of Fundamental Rights and Article 16(1) TFEU. This is why Article 1(2) is phrased as protecting a right rather than merely regulating an industry.

(2) Respect of the Fundamental Rights and Freedoms

Sets the Regulation’s dual ambition, matching Article 1’s own two objectives: protecting fundamental rights and freedoms regardless of nationality or residence, while contributing to an area of freedom, security and justice, to the internal market, and to the well-being of natural persons. Data protection and economic integration are framed as complementary, not opposed.

(3) Directive 95/46/EC Harmonisation

Explains the GDPR’s lineage: the 1995 Data Protection Directive already sought to harmonise fundamental-rights protection while ensuring free data flow between Member States. The GDPR inherits and strengthens that same twin aim, which is exactly what Article 1’s three paragraphs restate as binding rules rather than a directive Member States could implement unevenly.

(4) Data Protection in Balance with Other Fundamental Rights

Qualifies Article 1(2)’s fundamental-rights framing: the right to data protection is not absolute. It must be weighed against its function in society and balanced proportionately against other rights the Charter protects, including private life, freedom of expression, freedom to conduct a business, and the right to a fair trial. This is the recital courts reach for when Article 1 is used to favour a protective reading, since it confirms that reading still has limits.

(10) Harmonised Level of Data Protection Despite National Scope

Grounds Article 1(3)’s free-movement guarantee: to remove obstacles to data flows within the Union, the level of protection has to be equivalent across every Member State, applied consistently rather than left to national variation. The CJEU cited this recital together with Article 1 itself in Schrems v Meta Platforms Ireland (C-446/21) when anchoring its reasoning in the Regulation’s stated objective.

Related Recitals

(39) Principles of Data Processing
(40) Lawfulness of Data Processing
(41) Legal Basis or Legislative Measures
(42) Burden of Proof and Requirements for Consent
(43) Freely Given Consent
(44) Performance of a Contract
(45) Fulfillment of Legal Obligations
(46) Vital Interests of the Data Subject
(47) Overriding Legitimate Interest
(48) Overriding Legitimate Interest Within Group of Undertakings
(49) etwork and Information Security as Overriding Legitimate Interest
(50) Further Processing of Personal Data
(171) Repeal of Directive 95/46/EC and Transitional Provisions

Frequently Asked Questions about Article 1

+ What is the purpose of Article 1 GDPR?
Article 1 sets out the subject matter and objectives of the GDPR. It establishes rules for protecting individuals when their personal data is processed and protects the free movement of personal data within the EU.
+ Does the GDPR protect data or people?
The GDPR protects natural persons in relation to the processing of their personal data, treating data protection as a fundamental right. It is not designed to protect data itself, but the individuals the data relates to.
+ Can the free movement of personal data be restricted under the GDPR?
No. Article 1 states that the free movement of personal data within the EU cannot be restricted or prohibited for reasons connected with the protection of individuals regarding their data.
+ Has any regulator ever fined a company for breaching Article 1?
No. Article 1 states the Regulation’s purpose rather than imposing an obligation, so it is not a provision that can be found infringed. Courts have instead cited it to support how they interpret other, operative articles.
Scroll to Top