CHAPTER IGENERAL PROVISIONS

Article 1Subject-matter and objectives

Official text

(1)This Regulation lays down rules relating to the protection of natural persons with regard to the processing of personal data and rules relating to the free movement of personal data.

(2)This Regulation protects fundamental rights and freedoms of natural persons and in particular their right to the protection of personal data.

(3)The free movement of personal data within the Union shall be neither restricted nor prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data.

Commentary

Commentary

Article 1 is the foundation provision of the GDPR. It explains what the GDPR is meant to achieve and why the Regulation exists. Although Article 1 does not usually impose a direct operational obligation like maintaining records, giving notices, or responding to access requests, it is extremely important because it guides the interpretation of the entire GDPR. Whenever there is doubt about how a GDPR provision should be read, Article 1 helps identify the broader purpose: protecting individuals while allowing lawful and secure movement of personal data within the EU.

Article 1 must be read especially with Recitals 1 to 12. These Recitals explain that data protection is a fundamental right, that individuals should have control over their personal data, that technological development has increased risks, and that the EU wanted a harmonised data protection framework across Member States.

Article 1(1): Protection of individuals and free movement of personal data

Article 1(1) states the two core purposes of the GDPR:

  • to protect natural persons in relation to processing of their personal data; and
  • to regulate the free movement of personal data.

This means the GDPR is not only a privacy law. It is also an internal market law. The EU wanted to avoid a situation where each Member State had very different data protection standards, because that would make cross-border business and administration difficult.

Example

assume a company in Spain wants to use a cloud service provider in Ireland. If Spain had strict rules blocking transfers to Ireland, and Ireland had different or weaker standards, cross-border data movement would become difficult. The GDPR solves this by creating a common EU-wide standard. Once data is processed under GDPR rules, it can generally move across the EU/EEA without being blocked merely because of data protection concerns.

This objective is closely connected with Recital 3, which refers to the earlier Directive 95/46/EC and the EU's aim of harmonisation. It is also linked to Recital 9, which recognises that fragmented national rules previously created uncertainty and uneven protection. Recital 10 then clarifies the GDPR's goal of ensuring a consistent and high level of protection across the Union.

The first part of Article 1(1), however, is equally important: the GDPR protects natural persons, not legal entities. This is linked to Recital 14, which expressly states that the GDPR does not apply to data concerning legal persons, such as companies. However, information about a company may still become personal data where it identifies or relates to an individual.

Illustration

Article 1(2): Protection of fundamental rights and freedoms

Article 1(2) explains the deeper constitutional purpose of the GDPR. It protects the fundamental rights and freedoms of natural persons, particularly the right to protection of personal data. This provision must be read with Recital 1, which refers to Article 8 of the Charter of Fundamental Rights of the European Union. Article 8 recognises data protection as a fundamental right. It is also connected with Recital 2, which explains that data processing should serve mankind and respect human dignity, freedom, democracy, equality and the rule of law. The right to data protection is closely linked with the right to privacy under Article 7 of the Charter, but both rights are not identical. Privacy protects private and family life, home and communications. Data protection is broader in some ways: it regulates how information relating to a person is collected, used, stored, shared, corrected and deleted.

Illustration

Illustration

This is why Recital 4 is important. It states that the processing of personal data should be designed to serve mankind. It also recognises that the right to data protection is not absolute and must be balanced against other rights. However, this does not mean that controllers can freely override GDPR obligations by arguing commercial convenience. The GDPR itself already contains balancing mechanisms, such as legitimate interests under Article 6(1)(f), journalistic exemptions under Article 85, and restrictions permitted under Article 23. The Court of Justice of the European Union has repeatedly interpreted EU data protection law in light of fundamental rights. Cases such as Digital Rights Ireland, Schrems I, and Schrems II show that data protection rules must be read in a way that ensures a high level of protection. For example, in Schrems II, the Court emphasised that international transfers must be assessed in light of Articles 7, 8 and 47 of the Charter, including privacy, data protection and effective judicial remedy.

Article 1(3): Free movement of personal data within the Union

Article 1(3) prevents Member States from restricting or banning the free movement of personal data within the EU for data protection reasons. This provision is connected with the EU internal market objective. The logic is simple: if all Member States follow the GDPR, one Member State should not normally block transfers to another Member State by claiming that its own data protection law is stricter. This supports cross-border business, banking, healthcare, cloud services, employment administration and public cooperation.

Illustration

Illustration