Lecture I: Introduction to Data Protection as a Fundamental Right and the GDPR

Lecture I: Introduction to Data Protection as a Fundamental Right and the GDPR

Speaker: MICHAELA STAVRIDOU

Date: December 2025

Lecture Content

  • Privacy and Data Protection
  • Historical Development of Privacy and Data Protection
  • Focus on EU Data Protection and Historical Development
  • The right to Data Protection as a Fundamental Right
  • Introduction to The General Data Protection Regulation (GDPR)

- GDPR - Fundamental Concepts and Definitions

Introduction to Privacy and Data Protection Rights

  • Distinct Rights:

- The right to respect for private life and the right to personal data protection are closely linked but are not identical rights.

Historical Emergence of Privacy Rights

  • Origins in International Human Rights Law:
    • Began with the Universal Declaration of Human Rights (UDHR) in 1948.

- Affirmed in the European Convention on Human Rights (ECHR) in 1950.

Article 8 ECHR

Right to Respect for Private and Family Life

  1. Everyone has the right to respect for his private and family life, his home, and his correspondence.
  2. There shall be no interference by a public authority with the exercise of this right, except as provided by law and necessary in a democratic society for:
    • National security
    • Public safety
    • Economic well-being
    • Prevention of disorder or crime
    • Protection of health or morals

- Protection of the rights and freedoms of others

Article 7 EU Charter of Fundamental Rights

Respect for Private and Family Life

- Everyone has the right to respect for his or her private and family life, home, and communications.

Impact of Technological Development

Technological Advancements:

  • Computers and the internet have enhanced efficiency and productivity but have also introduced new risks to the right to respect for private life.
  • Emergence of Informational Privacy:
    • Developed to address the collection and use of personal information, known as informational privacy or right to informational self-determination in various jurisdictions.

- Emphasizes the individual’s control over personal data.

Development of Data Protection Laws

  • 1970s Legislation:
    • European states began to adopt laws regulating personal information processing by public authorities and large companies.
    • Data Protection Instruments:

- Established to provide personal data protection.

Data Protection as a Fundamental Right in EU Law

Acknowledgement as a Fundamental Right:

  • Article 16 of the Treaty on the Functioning of the EU (TFEU)

- Article 8 of the EU Charter of Fundamental Rights

Article 16 of TFEU

  1. Everyone has the right to the protection of personal data concerning them.
  2. The European Parliament and the Council shall establish rules concerning the protection of individuals regarding the processing of personal data by Union institutions and Member States carrying out activities within the scope of Union law.

3. Compliance is subject to control by independent authorities.

Article 8 of the EU Charter

  1. Everyone has the right to the protection of personal data concerning him or her.
  2. Such data must be processed fairly, for specified purposes, and on the basis of the individual's consent or other legitimate bases as laid down by law.

3. Compliance with these rules is subject to control by an independent authority.

Digital Rights Ireland (Joined Cases C-293/12 & C-594/12)

  • The CJEU examined the validity of Directive 2006/24/EC in relation to fundamental rights for personal data protection and respect for private life.
  • The Court found the directive interfered with personal data protection rights, allowing authorities access to retained personal data which could lead to significant insights into individuals' private lives such as everyday habits and movements.

- The directive was declared invalid due to disproportionate interference with rights.

Comparison of Rights

AspectRight to PrivacyRight to Data Protection
Legal BasisArticle 7 of the EU CharterArticle 8 of the EU Charter
ScopeProtects private and family life, home, communicationsSpecifically addresses the protection of personal data
FocusBroad protection of privacy aspectsEnsures fair and lawful processing of personal data

| Key Elements | Personal relationships, home life, correspondence | Fair processing, specified purposes, consent, etc. |

Data Protection in Primary EU Law

  • Background:
    • The original treaties did not reference human rights protection, focusing instead on economic integration.
  • Principle of Conferral:
    • EU acts within the limits of competences conferred by Member States.

- The CJEU interpreted treaties that grant human rights protection as part of general principles of law.

The Charter of Fundamental Rights of the EU

  • Proclaimed in 2000, originally a political document but became legally binding post-Lisbon Treaty (December 1, 2009).
  • Guarantees respect for private life (Article 7) and establishes personal data protection (Article 8).

- Binds EU institutions and Member States when implementing EU law.

Impact of the Lisbon Treaty

  • A landmark event that elevated the Charter’s status and provided Article 16 as a new legal basis for comprehensive EU data processing legislation.

- Article 16 allows the EU to legislate on data protection matters across all competences, including law enforcement and judicial cooperation.

The General Data Protection Regulation (GDPR)

  • Adopted on April 27, 2016, replacing Directive 95/46/EC, and became applicable in May 2018.
  • The GDPR introduces modernized rules on data protection catering to rights in the digital age.

- Regulations are directly applicable, ensuring consistent data protections across EU member states, promoting legal certainty.

GDPR – Recitals

  • Recital (6): Addresses challenges posed by technological developments and globalization on personal data protection.
  • Recital (7): Emphasizes building a coherent data protection framework to ensure trust in the digital economy.

- Recital (10): Advocates for equivalent protection levels across Member States for the rights of natural persons against data processing.

GDPR – Limitations

  • The right to personal data protection is not absolute and can be limited under specific legal circumstances.

- Article 52(1) allows limitations as long as they are legal, respect the essence of the right, and meet objectives of general interest or other persons' rights.

Conditions for Lawful Limitations under the EU Charter

  1. Provided by Law: Limitations must have a clear legal basis.
  2. Respect the Essence of the Right: Must not compromise the fundamental integrity of the right.

3. Necessity and Proportionality: Limitations must serve a public interest and pass the necessity and proportionality tests, justified by the lesser intrusion for achieving the same goal.

GDPR – Definitions

  • Article 4(1): Defines 'personal data' as any information related to an identified or identifiable natural person. Identification can occur directly or indirectly via identifiers.

- Article 4(2): Defines 'processing' as operations performed on personal data, regardless of whether through automated means.

Types of Data Subjects

  • The individual, whose data is processed, is referred to as the data subject.
  • Data protection laws apply to information concerning identifiable natural persons, regardless of nationality or residence.

- GDPR does not apply to deceased persons unless Member States specify otherwise.

Categories of Personal Information

  1. Internal Knowledge & Belief
  2. Authenticating
  3. Preference
  4. External Identifying
  5. Sensitive categories – racial or ethnic origin, political opinions, etc.
  6. Behavioral – online and offline activities.
  7. Financial – related to an individual’s financial status.
  8. Medical – records concerning health, disabilities, etc.
  9. Criminal – concerning individual’s criminal activity.

10. Social – relationships, family structures, etc.

GDPR - Special Categories of Personal Data

- Article 9 prohibits processing of sensitive data unless specific conditions are met, such as explicit consent.

Relationships in Data Processing

  • Controller: Determines purposes of data processing.
  • Processor: Processes data on behalf of the controller under obligations to comply with GDPR.

- Written contracts are necessary to delineate obligations and liabilities between Controllers and Processors.

  • Article 4(11): Defines 'consent' as a clear indication of the data subject's wishes to agree to processing of personal data.

- Valid consent must be specific, informed, and unambiguous, with the right to withdraw consent at any time. Consent must be presented clearly and not buried in terms of service.

Principles Relating to Processing of Personal Data

- Article 5 GDPR: Outlines principles such as legality, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. Accountability for compliance with these principles ultimately lies with the data controller.

Conclusion

  • The GDPR aims to harmonize data protection laws across Europe, enhancing individual rights in the context of technological advancements.
  • Participation in discussions and workshops on these subjects is encouraged for deeper understanding.