Source: OJ L 119, 4.5.2016, pp. 1–88 · Consolidated textCurrent language: EN
- General data protection
Basic legislative acts
- GDPR regulation
Article 1 Subject-matter and objectives
Summary What does Article 1 of the GDPR regulation say?
This is the foundational article of the regulation, establishing its dual purpose: protecting natural persons with regard to the processing of their personal data, while simultaneously ensuring that the free movement of personal data within the Union is not impeded.
It frames data protection not as a barrier to the flow of information, but as a framework within which that flow can operate.
The article also anchors the regulation firmly in the context of fundamental rights and freedoms, signalling that the right to data protection is to be treated as a core individual right rather than a purely technical or administrative concern.
Important points:
- The regulation serves two parallel goals: protecting personal data and enabling its free movement across the Union.
- The right to protection of personal data is framed as a fundamental right and freedom of natural persons.
- The free movement of personal data within the Union cannot be restricted or prohibited on data protection grounds alone.
Springlex's summary of the article is a reading aid, not a substitute for the legal text.
This Regulation lays down rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data.
This Regulation protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data.
The free movement of personal data within the Union shall be neither restricted nor prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data.
Relevant recitals
Recital 2 Protection irrespective of nationality
The principles of, and rules on the protection of natural persons with regard to the processing of their personal data should, whatever their nationality or residence, respect their fundamental rights and freedoms, in particular their right to the protection of personal data. This Regulation is intended to contribute to the accomplishment of an area of freedom, security and justice and of an economic union, to economic and social progress, to the strengthening and the convergence of the economies within the internal market, and to the well-being of natural persons.
Recital 12 Legal basis: Article 16(2) TFEU
Article 16(2) TFEU mandates the European Parliament and the Council to lay down the rules relating to the protection of natural persons with regard to the processing of personal data and the rules relating to the free movement of personal data.
Recital 13 Why a Regulation; SME derogation
In order to ensure a consistent level of protection for natural persons throughout the Union and to prevent divergences hampering the free movement of personal data within the internal market, a Regulation is necessary to provide legal certainty and transparency for economic operators, including micro, small and medium-sized enterprises, and to provide natural persons in all Member States with the same level of legally enforceable rights and obligations and responsibilities for controllers and processors, to ensure consistent monitoring of the processing of personal data, and equivalent sanctions in all Member States as well as effective cooperation between the supervisory authorities of different Member States. The proper functioning of the internal market requires that the free movement of personal data within the Union is not restricted or prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data. To take account of the specific situation of micro, small and medium-sized enterprises, this Regulation includes a derogation for organisations with fewer than 250 employees with regard to record-keeping. In addition, the Union institutions and bodies, and Member States and their supervisory authorities, are encouraged to take account of the specific needs of micro, small and medium-sized enterprises in the application of this Regulation. The notion of micro, small and medium-sized enterprises should draw from Article 2 of the Annex to Commission Recommendation 2003/361/EC(5).
Springlex and this text is meant purely as a documentation tool and has no legal effect. No liability is assumed for its content. The authentic version of this act is the one published in the Official Journal of the European Union.
Definition
processing
Definition
controller
Definition
enterprise
Definition
processor
Definition
supervisory authority
Definition
personal data
Footnote 5