Lecture I: Introduction to Data Protection as a Fundamental Right and the GDPR
Lecture I: Introduction to Data Protection as a Fundamental Right and the GDPR
Speaker: MICHAELA STAVRIDOU
Date: December 2025
Lecture Content
- Privacy and Data Protection
- Historical Development of Privacy and Data Protection
- Focus on EU Data Protection and Historical Development
- The right to Data Protection as a Fundamental Right
- Introduction to The General Data Protection Regulation (GDPR)
- GDPR - Fundamental Concepts and Definitions
Introduction to Privacy and Data Protection Rights
- The right to respect for private life and the right to personal data protection are closely linked but are not identical rights.
Historical Emergence of Privacy Rights
- Origins in International Human Rights Law:
- Began with the Universal Declaration of Human Rights (UDHR) in 1948.
- Affirmed in the European Convention on Human Rights (ECHR) in 1950.
Article 8 ECHR
Right to Respect for Private and Family Life
- Everyone has the right to respect for his private and family life, his home, and his correspondence.
- There shall be no interference by a public authority with the exercise of this right, except as provided by law and necessary in a democratic society for:
- National security
- Public safety
- Economic well-being
- Prevention of disorder or crime
- Protection of health or morals
- Protection of the rights and freedoms of others
Article 7 EU Charter of Fundamental Rights
Respect for Private and Family Life
- Everyone has the right to respect for his or her private and family life, home, and communications.
Impact of Technological Development
Technological Advancements:
- Computers and the internet have enhanced efficiency and productivity but have also introduced new risks to the right to respect for private life.
- Emergence of Informational Privacy:
- Developed to address the collection and use of personal information, known as informational privacy or right to informational self-determination in various jurisdictions.
- Emphasizes the individual’s control over personal data.
Development of Data Protection Laws
- 1970s Legislation:
- European states began to adopt laws regulating personal information processing by public authorities and large companies.
- Data Protection Instruments:
- Established to provide personal data protection.
Data Protection as a Fundamental Right in EU Law
Acknowledgement as a Fundamental Right:
- Article 16 of the Treaty on the Functioning of the EU (TFEU)
- Article 8 of the EU Charter of Fundamental Rights
Article 16 of TFEU
- Everyone has the right to the protection of personal data concerning them.
- The European Parliament and the Council shall establish rules concerning the protection of individuals regarding the processing of personal data by Union institutions and Member States carrying out activities within the scope of Union law.
3. Compliance is subject to control by independent authorities.
Article 8 of the EU Charter
- Everyone has the right to the protection of personal data concerning him or her.
- Such data must be processed fairly, for specified purposes, and on the basis of the individual's consent or other legitimate bases as laid down by law.
3. Compliance with these rules is subject to control by an independent authority.
Digital Rights Ireland (Joined Cases C-293/12 & C-594/12)
- The CJEU examined the validity of Directive 2006/24/EC in relation to fundamental rights for personal data protection and respect for private life.
- The Court found the directive interfered with personal data protection rights, allowing authorities access to retained personal data which could lead to significant insights into individuals' private lives such as everyday habits and movements.
- The directive was declared invalid due to disproportionate interference with rights.
Comparison of Rights
| Aspect | Right to Privacy | Right to Data Protection |
|---|
| Legal Basis | Article 7 of the EU Charter | Article 8 of the EU Charter |
| Scope | Protects private and family life, home, communications | Specifically addresses the protection of personal data |
| Focus | Broad protection of privacy aspects | Ensures fair and lawful processing of personal data |
| Key Elements | Personal relationships, home life, correspondence | Fair processing, specified purposes, consent, etc. |
Data Protection in Primary EU Law
- Background:
- The original treaties did not reference human rights protection, focusing instead on economic integration.
- Principle of Conferral:
- EU acts within the limits of competences conferred by Member States.
- The CJEU interpreted treaties that grant human rights protection as part of general principles of law.
The Charter of Fundamental Rights of the EU
- Proclaimed in 2000, originally a political document but became legally binding post-Lisbon Treaty (December 1, 2009).
- Guarantees respect for private life (Article 7) and establishes personal data protection (Article 8).
- Binds EU institutions and Member States when implementing EU law.
Impact of the Lisbon Treaty
- A landmark event that elevated the Charter’s status and provided Article 16 as a new legal basis for comprehensive EU data processing legislation.
- Article 16 allows the EU to legislate on data protection matters across all competences, including law enforcement and judicial cooperation.
The General Data Protection Regulation (GDPR)
- Adopted on April 27, 2016, replacing Directive 95/46/EC, and became applicable in May 2018.
- The GDPR introduces modernized rules on data protection catering to rights in the digital age.
GDPR – Recitals
- Recital (6): Addresses challenges posed by technological developments and globalization on personal data protection.
- Recital (7): Emphasizes building a coherent data protection framework to ensure trust in the digital economy.
- Recital (10): Advocates for equivalent protection levels across Member States for the rights of natural persons against data processing.
GDPR – Limitations
- The right to personal data protection is not absolute and can be limited under specific legal circumstances.
- Article 52(1) allows limitations as long as they are legal, respect the essence of the right, and meet objectives of general interest or other persons' rights.
Conditions for Lawful Limitations under the EU Charter
- Provided by Law: Limitations must have a clear legal basis.
- Respect the Essence of the Right: Must not compromise the fundamental integrity of the right.
3. Necessity and Proportionality: Limitations must serve a public interest and pass the necessity and proportionality tests, justified by the lesser intrusion for achieving the same goal.
GDPR – Definitions
- Article 4(1): Defines 'personal data' as any information related to an identified or identifiable natural person. Identification can occur directly or indirectly via identifiers.
- Article 4(2): Defines 'processing' as operations performed on personal data, regardless of whether through automated means.
Types of Data Subjects
- The individual, whose data is processed, is referred to as the data subject.
- Data protection laws apply to information concerning identifiable natural persons, regardless of nationality or residence.
- GDPR does not apply to deceased persons unless Member States specify otherwise.
- Internal Knowledge & Belief
- Authenticating
- Preference
- External Identifying
- Sensitive categories – racial or ethnic origin, political opinions, etc.
- Behavioral – online and offline activities.
- Financial – related to an individual’s financial status.
- Medical – records concerning health, disabilities, etc.
- Criminal – concerning individual’s criminal activity.
10. Social – relationships, family structures, etc.
GDPR - Special Categories of Personal Data
- Article 9 prohibits processing of sensitive data unless specific conditions are met, such as explicit consent.
Relationships in Data Processing
- Controller: Determines purposes of data processing.
- Processor: Processes data on behalf of the controller under obligations to comply with GDPR.
- Written contracts are necessary to delineate obligations and liabilities between Controllers and Processors.
Consent
- Article 4(11): Defines 'consent' as a clear indication of the data subject's wishes to agree to processing of personal data.
Principles Relating to Processing of Personal Data
- Article 5 GDPR: Outlines principles such as legality, fairness, transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality. Accountability for compliance with these principles ultimately lies with the data controller.
Conclusion
- The GDPR aims to harmonize data protection laws across Europe, enhancing individual rights in the context of technological advancements.
- Participation in discussions and workshops on these subjects is encouraged for deeper understanding.