Chapter 1 of 16
Why the European Union Adopted the GDPR
Regulation (EU) 2016/679 is a directly applicable legislative act issued by the European Parliament and the Council, but its opening recitals reveal the problems it was designed to solve. This module situates the document within Union law while tracing its fundamental-rights, technological, enforcement, and internal-market foundations.
1. Reading the GDPR's Opening Recitals
A Regulation with reasons
Recitals (1) to (25) explain why the EU adopted the GDPR. They are introduced by "Whereas:" and provide context, purposes, and interpretive framing.
Do not upgrade recital language
A recital's should remains non-mandatory in this lesson. Recitals are not the same as operative Articles, where the Regulation may use binding terms such as shall.
The constitutional basis
Recital (12) links the GDPR to Article 16(2) TFEU, which mandates Parliament and Council to lay down data-protection and data-movement rules.
The central tension
Picture a bridge: one side is protection of people; the other is the internal market's free movement of data. The opening recitals build both sides at once.
2. A Fundamental Right, But Not an Absolute One
The starting proposition
Recital (1): "The protection of natural persons in relation to the processing of personal data is a fundamental right."
Rights regardless of status
Recital (2) says data-protection principles and rules should respect fundamental rights and freedoms whatever the person's nationality or residence.
Not an absolute right
Recital (4): "The right to the protection of personal data is not an absolute right; it must be considered in relation to its function in society and be balanced against other fundamental rights, in accordance with the principle of proportionality."
What can be balanced?
Recital (4) refers to privacy, expression and information, business freedom, fair trial and effective remedy, plus cultural, religious and linguistic diversity.
3. Applying Proportionality: Data Protection in Social Context
Scenario
A university logs who enters hazardous laboratories and when. The information concerns natural persons and therefore engages the rights rationale in Recital (1).
A social function does not end the analysis
Safety can illustrate data processing's function in society. But Recital (4) does not say that a useful purpose permits unlimited collection.
Compare the scale
Logging entry to one hazardous laboratory differs from tracking every student's movements across campus. Proportionality asks why the scale and intrusiveness matter.
Stay within the recitals
Recitals (1) to (25) do not state the university's legal basis, retention schedule, or security measures. Those details must not be invented here.
4. Technology, Globalisation, and the Need for Trust
More cross-border data
Recital (5) links internal-market integration to substantially increased cross-border data flows among public and private actors across the Union.
Technology changed scale
Recital (6) says rapid technological developments and globalisation increased collection and sharing significantly, including use by companies and public authorities on an unprecedented scale.
Trust and control
Recital (7): "Natural persons should have control of their own personal data." The recital connects strong, coherent protection and enforcement to trust in the digital economy.
National specifications
Under Recital (8), where the GDPR provides for Member State specifications or restrictions, Member States may incorporate elements into national law where necessary for coherence and comprehensibility.
Quiz 1: The GDPR's Core Rationale
Choose the answer that most accurately reflects Recitals (1) to (7) of Regulation (EU) 2016/679.
Which statement is most accurate?
- The GDPR treats data protection as a fundamental right, while requiring it to be balanced against other fundamental rights according to proportionality.
- The GDPR treats data protection as an absolute right that always overrides freedom of expression and business freedom.
- The GDPR says technology should stop cross-border data flows in order to protect people.
- The GDPR says natural persons must personally control every use of their data.
Show Answer
Answer: A) The GDPR treats data protection as a fundamental right, while requiring it to be balanced against other fundamental rights according to proportionality.
Recital (1) calls protection of natural persons in relation to processing of personal data a fundamental right. Recital (4) says that right is not absolute and must be balanced against other fundamental rights according to proportionality. Recital (7) says natural persons **should** have control; it does not use "must" in this recital.
5. From Fragmentation to a Union-Wide Regulation
The earlier Directive
Recital (3) says Directive 95/46/EC sought harmonised rights protection and free data flow. Recital (9) says its objectives and principles remained sound.
The problem of fragmentation
Recital (9) identifies fragmented implementation, legal uncertainty, perceived online risks, obstacles to data flows, distorted competition, and impeded public authorities.
The response
Recital (10) seeks equivalent protection and consistent, homogeneous application throughout the Union, while allowing specified national provisions in stated areas.
The internal-market rule
"The proper functioning of the internal market requires that the free movement of personal data within the Union is not restricted or prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data."
6. Why Fragmentation Matters: A Cross-Border Service
A patchwork problem
For a platform serving multiple Member States, fragmented implementation can mean uncertainty for the platform and uneven practical protection for users.
Why the Union cared
Recital (9) links divergent protection levels to barriers to data flows, obstacles to Union-wide economic activity, distorted competition, and difficulties for authorities.
Why use a Regulation?
Recital (13) presents a Regulation as necessary for legal certainty, the same enforceable rights and responsibilities, consistent monitoring, equivalent sanctions, and cooperation.
External currency note
COM(2025) 501 final is still proposed as of July 25, 2026. Its possible Article 30(5) change is not in force; it does not alter the GDPR's current law today.
7. Who and What the GDPR Covers
Natural persons, not legal persons
"The protection afforded by this Regulation should apply to natural persons, whatever their nationality or place of residence, in relation to the processing of their personal data."
Technology-neutral protection
Recital (15): "the protection of natural persons should be technologically neutral and should not depend on the techniques used." It addresses automated and certain manual filing-system processing.
A filing-system boundary
Manual processing is included where data are contained, or intended to be contained, in a filing system. Unstructured files not organised by specific criteria should not fall within scope.
Important exclusions and interfaces
Recitals (16) to (21) address national security, Union institutions, criminal-law enforcement, judicial capacity, and the continued application of Directive 2000/31/EC.
8. Scope Sorting Activity
Sort each situation using Recitals (14) to (21)
For each scenario, identify the recital that gives the most direct starting point. Then state the qualifier that prevents an overbroad conclusion.
- A person's spreadsheet of relatives' addresses is stored in a carefully organised folder system. Do not jump immediately to Recital (15). Consider Recital (18), which addresses a natural person's purely personal or household activity and its connection, or lack of connection, to professional or commercial activity.
- A company uses a new AI tool rather than an older database to analyse customer records. Start with Recital (15): protection should be technologically neutral and should not depend on techniques used. The point is not whether the tool is fashionable or automated; scope still depends on the recital's stated conditions.
- A government body processes information solely for national-security activity. Begin with Recital (16), which says the Regulation does not apply to activities falling outside Union law, such as national security.
- A court processes personal data while acting in its judicial capacity. Recital (20) does not say the GDPR disappears. It says the competence of supervisory authorities should not cover that processing, to safeguard judicial independence.
- A police authority processes data to investigate criminal offences. Recital (19) directs attention to the specific Union legal act, Directive (EU) 2016/680, for those purposes. But the same authority can have other tasks; processing for those other purposes can fall within the GDPR's scope in so far as it is within Union law.
After sorting, ask: did you preserve each condition? Scope analysis is often decided by phrases such as "purely personal or household," "judicial capacity," and "in so far as it is within the scope of Union law."
9. Household Activity and Establishment in the Union
The household exemption
"This Regulation does not apply to the processing of personal data by a natural person in the course of a purely personal or household activity and thus with no connection to a professional or commercial activity."
Keep the limitation
Correspondence, address-holding, and social networking can be examples only when undertaken within that personal or household context. A professional or commercial connection changes the analysis.
Providers are different
Recital (18) says the GDPR applies to controllers or processors that provide the means for personal or household processing. The exemption is not a blanket exemption for platforms.
Union establishment
Recital (22) covers processing in the context of a Union establishment's activities regardless of whether processing itself takes place within the Union.
10. Non-Union Organisations: Offering and Monitoring
Offering goods or services
Recital (23) concerns non-Union controllers or processors processing data of people who are in the Union where activities relate to offering goods or services, whether or not payment is involved.
Accessibility is insufficient
A merely accessible website, email address, contact details, or a language generally used in the controller's third country is insufficient to show an intention to offer in the Union.
Signals of envisaged offering
Possible indicators include a Member State language or currency with ordering in that language, or references to customers or users who are in the Union.
Monitoring is separate
Recital (24) separately addresses monitoring behaviour of people in the Union, where their behaviour takes place within the Union, including internet tracking and possible profiling.
Quiz 2: Territorial Reach
Apply the wording of Recitals (22) to (24), paying particular attention to conditions and to what is insufficient.
Which fact is expressly described by Recital (23) as insufficient, by itself, to ascertain an intention to offer goods or services to data subjects in the Union?
- A website is merely accessible in the Union.
- The business uses a currency generally used in a Member State and lets customers order in that language.
- The business mentions customers or users who are in the Union.
- The processing is related to offering goods or services to people who are in the Union.
Show Answer
Answer: A) A website is merely accessible in the Union.
Recital (23) specifically says that mere accessibility of a controller's, processor's, or intermediary's website in the Union is insufficient. It lists Member State language or currency with ordering capability and references to Union customers or users as factors that may make the relevant intention apparent.
11. Flashcards: The GDPR's Adoption Logic
Flip each card, then explain the idea aloud using the recital number and the important qualifier.
- Recital (1): What is the starting proposition?
- "The protection of natural persons in relation to the processing of personal data is a fundamental right."
- Recital (4): Is data protection absolute?
- No. It must be considered in relation to its function in society and balanced against other fundamental rights in accordance with proportionality.
- Recital (7): What individual-centred objective is stated?
- "Natural persons should have control of their own personal data." The recital uses should, not shall.
- Recital (13): What is the internal-market rule?
- Free movement of personal data within the Union must not be restricted or prohibited for reasons connected with protecting natural persons regarding processing.
- Recital (15): What does technological neutrality mean here?
- Protection should not depend on the techniques used; it addresses automated processing and qualifying manual filing-system processing.
- Recital (18): What limits the household exemption?
- The activity must be purely personal or household and thus have no connection to professional or commercial activity.
- Recital (22): Does server location alone decide?
- No. Processing in the context of activities of a Union establishment should comply regardless of whether processing itself occurs within the Union.
- Recital (23): Is a website's Union accessibility alone enough to show targeting?
- No. Mere accessibility is insufficient; the recital asks whether it is apparent that offerings to people in one or more Member States are envisaged.
Key Terms
- processor
- A term used in the GDPR's recitals for an entity involved in processing personal data; Recitals (11), (18), and (22) refer to processors alongside controllers.
- controller
- A term used in the GDPR's recitals for an entity that determines processing; Recitals (11), (18), and (22) refer to controllers in explaining the framework and its scope.
- data subject
- A natural person whose personal data are at issue. Recitals (11), (23), and (24) use this term.
- establishment
- Under Recital (22), the effective and real exercise of activity through stable arrangements. Its legal form, such as branch or subsidiary, is not the determining factor.
- filing system
- The Recital (15) condition relevant to manual processing: personal data must be contained, or intended to be contained, in a filing system.
- internal market
- The Union economic setting central to Recitals (5), (9), (10), and (13), including the principle that data movement within the Union should not be restricted or prohibited for data-protection reasons.
- proportionality
- The principle named in Recital (4), under which the right to data protection must be balanced against other fundamental rights.
- Directive 95/46/EC
- The earlier instrument that Recital (3) says sought harmonisation and free data flow, and that Recital (9) says did not prevent fragmented implementation and legal uncertainty.
- household activity
- A purely personal or household activity with no connection to professional or commercial activity, as described in Recital (18).
- monitoring of behaviour
- The Recital (24) route concerning behaviour of data subjects in the Union, in so far as that behaviour takes place within the Union; it can involve internet tracking and profiling.