Logo RGPD
RGPD.click
/
  1. Home
  2. Resources
  3. Data Protection and Fundamental Rights
Courses Guides Blog Resources News
Français (Belgique / France) English Nederlands (België / Nederland)
EU Legal Reference📚 Legal Doctrine Synthesis✓ Controlled Official Sources

Data Protection and Fundamental Rights: Foundations of the GDPR

Editorial legal synthesis · Controlled official sources

⚡ In 30 seconds:

The GDPR gives practical effect to an autonomous fundamental right, distinct from but complementary to privacy. This guide traces its European foundations, operational consequences and interaction with other rights.

An Autonomous Fundamental Right

Personal data protection is not merely a technical rule. Article 8 of the Charter of Fundamental Rights of the European Union and Article 16 TFEU establish it as an autonomous right. The GDPR organises its practical exercise while safeguarding the free movement of data within the Union.

This right remains closely connected with respect for private life under Article 7 of the Charter, but is not identical to it: it governs every operation involving personal data, even where no separate intrusion into intimacy has been demonstrated.

From Privacy to Data Protection

European protection developed in layers: Article 8 ECHR has protected private and family life since 1950; Council of Europe Convention 108 became the first binding international treaty specifically devoted to automated data processing in 1981; the EU Charter then distinguished privacy and data protection in Articles 7 and 8.

Amending Protocol CETS No. 223 modernises Convention 108. Its general entry-into-force status must nevertheless be checked against the Council of Europe's official treaty table before making a definitive statement.

  • 1950: protection of private life under Article 8 ECHR;
  • 1981: Convention 108 on automated processing of personal data;
  • 2000–2009: proclamation and then binding legal value of the Charter;
  • 2016–2018: adoption and full application of the GDPR.

Privacy and Data: Complementary Protections

Article 7 protects private and family life, the home and communications. Article 8 requires fair processing for specified purposes on a legitimate basis, recognises rights of access and rectification, and requires supervision by an independent authority.

The GDPR develops these requirements through the Article 5 principles, Article 6 legal bases, Articles 12–22 rights, the independence and powers of supervisory authorities under Articles 51–59, and remedies under Articles 77–79.

A Right to Be Balanced, Not an Absolute Right

Recital 4 GDPR states that data protection must be balanced against other fundamental rights in accordance with proportionality. This does not permit the GDPR to be set aside automatically in the name of freedom of expression, nor a right to be applied mechanically without examining its context.

Schrems II illustrates the requirement of essentially equivalent protection for international transfers. Legal Newsdesk Sweden clarifies that paid publication of criminal judgments is not journalistic as a matter of principle. Jautiva confirms that rights and restrictions must be assessed within the precise framework established by EU law.

Operational Effect: Lawfulness, Necessity and Proportionality

Each purpose must be linked to an Article 6 legal basis, data must be limited to what is necessary, retention must be justified, and rights must be made effective. Special-category data, criminal data, journalism, research and archives are governed by specific conditions or balancing rules.

Accountability turns the constitutional foundation into operational evidence: records, risk assessments, notices, contracts, security measures and, where high risk so requires, a data protection impact assessment.

  • Identify purpose and legal basis before collection;
  • Document necessity, minimisation and retention;
  • Organise rights and effective remedies;
  • Reassess proportionality when context or technology changes.

How to Read the Sources

The explanations relating to the Charter are an official interpretative reference, not autonomous legislation. The ECHR and Convention 108 belong to the Council of Europe framework; they illuminate the legal lineage without being confused with EU secondary law.

A legal synthesis must therefore distinguish binding law, official explanations, case law and an instrument whose entry into force still requires verification.

Consequences for Compliance

Compliance is not the accumulation of forms: design choices must demonstrably respect individuals. The more intrusive, large-scale, opaque or irreversible the processing, the stronger its justification, safeguards and oversight must be.

Reading the GDPR through fundamental rights makes it possible to resolve novel cases without reducing data protection to a fixed checklist.

Verified Official Sources

⚖️ Binding Source
Regulation (EU) 2016/679 (GDPR) · CELEX: 32016R0679 · 2016-04-27

General Data Protection Regulation — EU Reference Legal Framework

Consult official source →
⚖️ Binding Source
Charte des droits fondamentaux de l'Union européenne · CELEX: 12016P/TXT · 2016-06-07

Articles 7, 8, 11, 47 et 52 : vie privée, protection des données, liberté d'expression, recours effectif et proportionnalité

Consult official source →
⚖️ Binding Source
Traité sur le fonctionnement de l'Union européenne — Article 16 · CELEX: 12008E016 · 2008-05-09

Droit de toute personne à la protection des données à caractère personnel et base juridique de l'action de l'Union

Consult official source →
📚 Official Explanation
Explications relatives à la Charte des droits fondamentaux · CELEX: 32007X1214(01) · 2007-12-14

Outil officiel d'interprétation de la Charte, notamment l'explication relative à l'Article 8 sur la protection des données

Consult official source →
⚖️ Binding Source
Convention européenne des droits de l'homme — Article 8 · 1950-11-04

Droit au respect de la vie privée et familiale, du domicile et de la correspondance

Consult official source →
⚖️ Binding Source
Convention 108 pour la protection des personnes à l'égard du traitement automatisé des données · 1981-01-28

Premier instrument international contraignant spécifiquement consacré à la protection des données personnelles

Consult official source →
⏳ Protocol — Status to Verify
Protocole d'amendement à la Convention 108 (Convention 108+) · 2018-10-10

Modernisation de la Convention 108 ; statut des signatures, ratifications et condition d'entrée en vigueur à vérifier dans le registre officiel

Consult official source →
⚖️ Binding Source
Schrems II (16 juil. 2020) · ECLI: ECLI:EU:C:2020:559

Invalidation du Privacy Shield, exigence d'évaluation d'impact des transferts (TIA) et mesures supplémentaires pour les CCT

Consult official source →
⚖️ Binding Source
Legal Newsdesk Sweden (9 juil. 2026) · ECLI: ECLI:EU:C:2026:564 · 2026-07-09

Mise à disposition en ligne, contre rémunération, de décisions relatives à des condamnations pénales : cette activité ne relève pas, en principe, de fins journalistiques (Art. 85) ; les voies de recours prévues par le RGPD demeurent applicables (Art. 77 à 82).

Consult official source →
⚖️ Binding Source
Jautiva (3 sept. 2026) · ECLI: ECLI:EU:C:2026:679 · 2026-09-03

Publication en ligne de données d'actionnaires (Art. 5.1.c, 6.1.c/e et 6.3 RGPD, directive 2017/1132) : l'accès inconditionnel du public sur Internet aux données d'actionnaires minoritaires excède ce qui est strictement nécessaire et proportionné.

Consult official source →

See Also in the Legal Framework

Article 5 GDPR Official Text

Article 5 GDPR: Cardinal Processing Principles & Accountability

Legal analysis of the cardinal principles in Article 5 GDPR: lawfulness, fairness, transparency, purpose limitation, dat...

View document
Article 6 GDPR Official Text

Article 6 GDPR: The Six Lawful Grounds for Lawful Processing

Legal analysis of Article 6 GDPR: the six alternative legal bases for lawfulness of processing, valid consent criteria, ...

View document
CJEU Schrems II CJEU Case Law

CJEU C-311/18 Schrems II: Regime of International Data Transfers Outside the EU

CJEU judgment of 16 July 2020 (Schrems II): invalidation of Privacy Shield, conditional validity of SCCs and mandatory T...

View document
CJEU Legal Newsdesk Sweden CJEU Case Law

CJEU C-199/24 Legal Newsdesk Sweden: Criminal Convictions Data and Article 85 GDPR

CJEU judgment of 9 July 2026 (ECLI:EU:C:2026:564): commercial publication of criminal conviction records does not fall, ...

View document
CJEU Jautiva CJEU Case Law

CJEU C-798/24 Jautiva : Public Disclosure of Data and Proportionality

CJEU judgment of 3 September 2026 (ECLI:EU:C:2026:679): unrestricted online disclosure of minority shareholders' persona...

View document
← Explore this topic in the interactive RGPD.click knowledge base
Reviewed date: 2026-09-09 Last modified: 2026-09-09

Independent legal reference documentation on Regulation (EU) 2016/679 (GDPR).

Home · Resources Index · Privacy Policy · Legal Notice