# GDPR Subject-Matter and Objectives — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/gdpr-subject-matter-objectives
> Sources are cited per item. Verify against the official texts before relying on them.

This content is specifically about the introductory provisions establishing the subject-matter and objectives of the GDPR, which is a distinct topic from general scope/definitions that deserves its own classification for regulatory framework documentation.

## Overview

## Legal Framework

The GDPR's subject-matter and objectives are established in Article 1, which sets out two interrelated goals: the protection of natural persons with regard to the processing of personal data and the free movement of such data within the Union. These twin objectives operate as a single regulatory bargain — data protection must not become a pretext for restricting cross-border data flows, and conversely, the internal market must not erode fundamental rights to privacy and data protection.

Article 44 reinforces this framework by establishing the general principle for international transfers: personal data may be transferred to third countries or international organisations only where the conditions in Chapter V are met, ensuring that the level of protection guaranteed by the Regulation is not undermined. Article 98 complements this by tasking the Commission with reviewing and, where appropriate, proposing amendments to other Union legal acts on data protection to achieve uniform and consistent protection across the EU institutional landscape.

The doctrinal commentary underscores that the Regulation's objectives are operationalised through the data protection principles in Article 5 — lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, and integrity. These principles are not aspirational; controllers must implement appropriate technical and organisational measures under Article 25 to ensure their effective application. The commentary also highlights that special categories of data under Article 9 now expressly include genetic and biometric data, reflecting the Regulation's evolving protective scope, while criminal data is separately governed under Article 10.

## Key Developments

The CJEU's judgment in *Digital Rights Ireland Ltd v. Ireland* established that data retention obligations constituting interference with Article 7 CFR must satisfy strict necessity and proportionality requirements — a principle that directly shapes how the GDPR's objectives translate into Member State legislation. Blanket retention without targeted safeguards fails the proportionality test.

In *Worten-Equipamentos para o Lar SA v. ACT*, the CJEU confirmed that processing personal data for compliance with a legal obligation under what is now Article 6(1)(c) GDPR is lawful only where genuinely necessary, and access must be restricted to authorities with monitoring competence. This sets a practical threshold: necessity is not abstract but tied to the specific regulatory purpose pursued.

The EDPB has continued to develop guidance operationalising these objectives, including Guidelines 9/2020 on relevant and motivated objections, which clarify how data subjects can effectively exercise rights — a core objective of the Regulation. Recent EDPB attention to challenges in implementing the right to erasure signals ongoing enforcement focus on whether controllers are meeting the Regulation's protective aims in practice.

## Practical Guidance

- Map all processing activities against the Article 5 principles and document how each is satisfied, treating this as the foundational compliance artefact rather than a tick-box exercise.
- Implement Article 25 data protection by design and by default at the system architecture level — build technical and organisational measures into processing systems before deployment, not as retrofit.
- For international transfers under Article 44, conduct transfer impact assessments that evaluate whether the third-country legal framework provides essentially equivalent protection, particularly post-*Schrems II*.
- Restrict access to special category data under Article 9 and criminal data under Article 10 to strictly necessary personnel, with documented justification for each access role.
- Establish a mechanism for monitoring regulatory developments under Article 98, as the Commission's ongoing review of Union legal acts may alter sector-specific obligations that interact with your processing operations.

## Legislation (full text of key provisions)

### General principle for transfers

*Source: GDPR, gdpr-art-44-en, 2016-04-27 — https://overview.legal/posts/90853*

Any transfer of personal data which are undergoing processing or are intended for processing after transfer to a third country or to an international organisation shall take place only if, subject to the other provisions of this Regulation, the conditions laid down in this Chapter are complied with by the controller and processor, including for onward transfers of personal data from the third country or an international organisation to another third country or to another international organisation. All provisions in this Chapter shall be applied in order to ensure that the level of protection of natural persons guaranteed by this Regulation is not undermined.

### Review of other Union legal acts on data protection

*Source: GDPR, gdpr-art-98-en, 2016-04-27 — https://overview.legal/posts/91509*

The Commission shall, if appropriate, submit legislative proposals with a view to amending other Union legal acts on the protection of personal data, in order to ensure uniform and consistent protection of natural persons with regard to processing. This shall in particular concern the rules relating to the protection of natural persons with regard to processing by Union institutions, bodies, offices and agencies and on the free movement of such data.

### Recital 12 — TFEU personal data protection rules

*Source: GDPR, gdpr-rec-12-en, 2016-04-27 — https://overview.legal/posts/91539*

Article 16(2) TFEU mandates the European Parliament and the Council to lay down the rules relating to the protection of natural persons with regard to the processing of personal data and the rules relating to the free movement of personal data.

### Recital 13 — consistent Union-wide data protection regulation

*Source: GDPR, gdpr-rec-13-en, 2016-04-27 — https://overview.legal/posts/91541*

In order to ensure a consistent level of protection for natural persons throughout the Union and to prevent divergences hampering the free movement of personal data within the internal market, a Regulation is necessary to provide legal certainty and transparency for economic operators, including micro, small and medium-sized enterprises, and to provide natural persons in all Member States with the same level of legally enforceable rights and obligations and responsibilities for controllers and processors, to ensure consistent monitoring of the processing of personal data, and equivalent sanctions in all Member States as well as effective cooperation between the supervisory authorities of different Member States. The proper functioning of the internal market requires that the free movement of personal data within the Union is not restricted or prohibited for reasons connected with the protection of natural persons with regard to the processing of personal data. To take account of the specific situation of micro, small and medium-sized enterprises, this Regulation includes a derogation for organisations with fewer than 250 employees with regard to record-keeping. In addition, the Union institutions and bodies, and Member States and their supervisory authorities, are encouraged to take account of the specific needs of micro, small and medium-sized enterprises in the application of this Regulation. The notion of micro, small and medium-sized enterprises should draw from Article 2 of the Annex to Commission Recommendation 2003/361/EC (5).

### Recital 2 — personal data protection fundamental rights

*Source: GDPR, gdpr-rec-2-en, 2016-04-27 — https://overview.legal/posts/91519*

The principles of, and rules on the protection of natural persons with regard to the processing of their personal data should, whatever their nationality or residence, respect their fundamental rights and freedoms, in particular their right to the protection of personal data. This Regulation is intended to contribute to the accomplishment of an area of freedom, security and justice and of an economic union, to economic and social progress, to the strengthening and the convergence of the economies within the internal market, and to the well-being of natural persons.

### Recital 9 — fragmented data protection across Member States

*Source: GDPR, gdpr-rec-9-en, 2016-04-27 — https://overview.legal/posts/91533*

The objectives and principles of Directive 95/46/EC remain sound, but it has not prevented fragmentation in the implementation of data protection across the Union, legal uncertainty or a widespread public perception that there are significant risks to the protection of natural persons, in particular with regard to online activity. Differences in the level of protection of the rights and freedoms of natural persons, in particular the right to the protection of personal data, with regard to the processing of personal data in the Member States may prevent the free flow of personal data throughout the Union. Those differences may therefore constitute an obstacle to the pursuit of economic activities at the level of the Union, distort competition and impede authorities in the discharge of their responsibilities under Union law. Such a difference in levels of protection is due to the existence of differences in the implementation and application of Directive 95/46/EC.

### Recital 10 — consistent personal data protection across Union

*Source: GDPR, gdpr-rec-10-en, 2016-04-27 — https://overview.legal/posts/91535*

In order to ensure a consistent and high level of protection of natural persons and to remove the obstacles to flows of personal data within the Union, the level of protection of the rights and freedoms of natural persons with regard to the processing of such data should be equivalent in all Member States. Consistent and homogenous application of the rules for the protection of the fundamental rights and freedoms of natural persons with regard to the processing of personal data should be ensured throughout the Union. Regarding the processing of personal data for compliance with a legal obligation, for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller, Member States should be allowed to maintain or introduce national provisions to further specify the application of the rules of this Regulation. In conjunction with the general and horizontal law on data protection implementing Directive 95/46/EC, Member States have several sector-specific laws in areas that need more specific provisions. This Regulation also provides a margin of manoeuvre for Member States to specify its rules, including for the processing of special categories of personal data (‘sensitive data’). To that extent, this Regulation does not exclude Member State law that sets out the circumstances for specific processing situations, including determining more precisely the conditions under which the processing of personal data is lawful.

### Recital 117 — independent national supervisory authorities

*Source: GDPR, gdpr-rec-117-en, 2016-04-27 — https://overview.legal/posts/91749*

The establishment of supervisory authorities in Member States, empowered to perform their tasks and exercise their powers with complete independence, is an essential component of the protection of natural persons with regard to the processing of their personal data. Member States should be able to establish more than one supervisory authority, to reflect their constitutional, organisational and administrative structure.

### Recital 15 — technologically neutral personal data protection

*Source: GDPR, gdpr-rec-15-en, 2016-04-27 — https://overview.legal/posts/91545*

In order to prevent creating a serious risk of circumvention, the protection of natural persons should be technologically neutral and should not depend on the techniques used. The protection of natural persons should apply to the processing of personal data by automated means, as well as to manual processing, if the personal data are contained or are intended to be contained in a filing system. Files or sets of files, as well as their cover pages, which are not structured according to specific criteria should not fall within the scope of this Regulation.

### Recital 101 — personal data transfers to third countries

*Source: GDPR, gdpr-rec-101-en, 2016-04-27 — https://overview.legal/posts/91717*

Flows of personal data to and from countries outside the Union and international organisations are necessary for the expansion of international trade and international cooperation. The increase in such flows has raised new challenges and concerns with regard to the protection of personal data. However, when personal data are transferred from the Union to controllers, processors or other recipients in third countries or to international organisations, the level of protection of natural persons ensured in the Union by this Regulation should not be undermined, including in cases of onward transfers of personal data from the third country or international organisation to controllers, processors in the same or another third country or international organisation. In any event, transfers to third countries and international organisations may only be carried out in full compliance with this Regulation. A transfer could take place only if, subject to the other provisions of this Regulation, the conditions laid down in the provisions of this Regulation relating to the transfer of personal data to third countries or international organisations are complied with by the controller or processor.

## Case law

### Data Protection Commissioner v. Schrems and Facebook

*Source: CJEU, 2015-10-06 — https://overview.legal/posts/6145 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362&ref=6145*

Necessity/proportionality: The Decision does not contain any finding regarding US rules intended to limit the interference when they pursue legitimate objectives such as national security, nor refer to effective legal protection against such interference. FTC procedures and private dispute resolution mechanisms concern compliance with safe harbor principles (against US organizations) and cannot be applied with respect to measures originating from the State. Moreover, the Commission found that if

### VOLKER UND MARKUS SCHECKE GBR V. LAND HESSEN, EIFERT V. LAND HESSEN AND BUNDESANSTALT FUR LANDWIRTSCHAFT UND ERNAHRUNG, 9.Nov.2010 (“SCHECKE”)

*Source: CJEU, 2010-11-09 — https://overview.legal/posts/5976 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0092&ref=5976*

Interference with the fundamental rights of privacy and data protection: Chapter of Fundamental Rights (CFR) Article 52(1) accepts that limitations may be imposed on fundamental rights, as long as they are provided by law, respect the essence of those rights and are proportionate (necessary and genuinely meet objectives of general interest recognized by the EU or the need to protect the rights and freedoms of others.) The CJEU concluded that by imposing an obligation to publish personal data rel

### Peter Puškár v Finančné riaditeľstvo Slovenskej republiky and Kriminálny úrad finančnej správy

*Source: CJEU, 2017-09-27 — https://overview.legal/posts/6138 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62015CJ0073&ref=6138*

Lawful Basis (Public Interest): Article 7(e) Directive 95/46 must be interpreted as not precluding the processing of personal data by the authorities of a Member State for the purpose of collecting tax and combating tax fraud such as that effected by drawing up the contested list in the main proceedings, without the consent of the data subjects, “provided that, first, those authorities were invested by the national legislation with tasks carried out in the public interest within the meaning of t

### DIGITAL RIGHTS IRELAND LTD V. IRELAND,

*Source: CJEU, 2014-04-08 — https://overview.legal/posts/5964 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0293*

Article 7 CFR: The obligation on providers of publicly available electronic communications services or public communications networks to retain data relating to a person’s private life and his communications in itself constitutes an interference with Article 7. Access of competent national authorities to the data constitutes a further interference with that right. Any limitation on the exercise of rights and freedoms laid down by the CFR must be provided by law, respect their essence and, subjec

### V & EDPS v. EUROPEAN PARLAMENT

*Source: CJEU, ECLI:EU:F:2011:101, 2011-07-05 — https://overview.legal/posts/5975 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62009CJ0092*

Article 8 (Respect for Private Life) of the ECHR: Article 8 ECHR on private life relates to a fundamental right which covers the right to secrecy of one’s medical state. The transfer of that data to a third party, even another EU institution, is an interference with that right, whatever the final use. Such interference may be justified if it is “in accordance with the law and is necessary in a democratic society in the interests of national security, public safety or the economic well-being of t

### WORTEN-EQUIPAMENTOS PARA O LAR SA V. ACT (AUTHORITY FOR WORKING CONDITIONS), 30.5.2013 (“WORTEN”)

*Source: CJEU, 2013-05-30 — https://overview.legal/posts/5968 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62011CJ0342*

Necessity/proportionality: Collection and processing of personal data contained in the record of working time to ensure compliance with national legislation relating to working conditions is lawful if it is necessary for compliance with a legal obligation to which the controller is subject. Access should be grated only to authorities having powers of monitoring compliance with legal requirements. An obligation to provide immediate access to the record could be necessary if it contributes to the

### DENNEKAMP V. EUROPEAN PARLIAMENT, 23.11.2011 (“DENNEKAMPI”)

*Source: CJEU, 2011-11-23 — https://overview.legal/posts/5973 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62010TJ0082*

Balancing fundamental rights: Regulation 1049/2001 (access to documents) and Regulation 45/2001 (data protection) do not contain any provisions granting one primacy over the other, therefore full application of both should, in principle, be ensured. (¶¶ 23-24)

### COMMISSION V. GERMANY, 9.Mar.2010 (“GERMANY”)

*Source: CJEU, 2010-03-09 — https://overview.legal/posts/5978 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62007CJ0518*

Independence of Supervisory Authorities: Independence means a status which ensures that the body concerned can act completely freely, without taking any instructions or being put under any pressure. The requirement of independence does not only concern the relationship between the supervisory authorities and the bodies subject to that supervision. The adjective “complete” implies a decision-making power independent of any direct or indirect external influence on the supervisory authority. DPAs m

### RECHNUNGSHOF V. OSTER REICHISCHER RUNDFUNK, 20.5.2003 (“RUNDFUNK”)

*Source: CJEU, 2003-05-20 — https://overview.legal/posts/5987 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62001CJ0101*

Direct applicability of Directive 95/46: Wherever provisions of a directive appear to be unconditional and sufficiently precise, they may, in the absence of implementing measures adopted within the prescribed period, be relied on against any incompatible national provision, or insofar as they define rights which individuals are able to assert against the State. (¶ 98)

### UNABHäNGIGES LANDESZENTRUM FüR DATENSCHUTZ SCHLESWIG-HOLSTEIN v. WIRTSCHAFTSAKADEMIE SCHLESWIG-HOLDSTEIN GmbH

*Source: CJEU, 2018-06-05 — https://overview.legal/posts/6135 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62016CJ0210&ref=6135*

Joint controllers: The administrator of a fan page hosted on Facebook is a controller as it is “taking part, by its definition of parameters depending in particular on its target audience and the objectives of managing and promoting its activities, in the determination of the purposes and means of processing the personal data of the visitors to its fan page.” The fact that an administrator uses the platform provided by Facebook in order to benefit from the associated services cannot exempt it fr

## Guidance

### Guidelines 1/2019 on Codes of Conduct and Monitoring Bodies under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-codes-of-conduct-and-monitoring-bodies, 2019-06-04 — https://overview.legal/posts/38051 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-12019-on-codes-of-conduct-and-monitoring-bodies-under-regulation_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the framework for codes of conduct and monitoring bodies under Articles 40 and 41 of the GDPR. The guidelines address the admissibility, content, and approval requirements for draft codes of conduct, as well as the criteria and accreditation process for monitoring bodies responsible for verifying compliance with such codes. This version (2.0) was adopted on 4 June 2019 following public consultation.

### Guidelines 10/2020 on restrictions under Article 23 GDPR

*Source: EDPB, edpb-guidelines-on-restrictions-under-article-23-gdpr, 2021-10-13 — https://overview.legal/posts/38062 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-102020-on-restrictions-under-article-23-gdpr_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the scope and application of Article 23 of the GDPR, which allows Member States to restrict certain data subject rights and controller obligations. The guidelines outline the necessary conditions and safeguards, emphasizing that any restrictions must respect the essence of fundamental rights and be implemented via foreseeable, proportionate legislative measures. This document serves as authoritative guidance for interpreting the specific grounds and requirements under which Member States may legally impose such limitations.

### Guidelines 06/2020 on the interplay of the Second Payment Services Directive and the GDPR

*Source: EDPB, edpb-guidelines-on-the-interplay-of-the-second-payment-services-directive-and-the-gdpr, 2020-12-15 — https://overview.legal/posts/38139 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-062020-on-the-interplay-of-the-second-payment-services-directive-and_en*

The European Data Protection Board (EDPB) adopted Guidelines 06/2020 to clarify the interplay between the Second Payment Services Directive (PSD2) and the GDPR. The guidelines analyze the lawful grounds for processing personal data in payment services, the relationship between explicit consent under Article 94(2) PSD2 and GDPR consent requirements,

### Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020

*Source: EDPB, edpb-guidelines-on-data-protection-by-design-and-by-default, 2020-10-20 — https://overview.legal/posts/38054 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-42019-on-article-25-data-protection-by-design-and-by-default_en*

The European Data Protection Board (EDPB) adopted these guidelines (Version 2.0) to provide interpretive guidance on Article 25 of the GDPR, which mandates data protection by design and by default. The guidelines address controllers' obligations to implement appropriate technical and organizational measures and necessary safeguards into processing operations, including the dimensions of data minimization required by default. No fines or enforcement actions are at issue, as this is a guidance document intended to assist controllers in complying with their Article 25 obligations.

### Guidelines 05/2020 on consent under Regulation 2016/679

*Source: EDPB, edpb-guidelines-on-consent, 2020-05-04 — https://overview.legal/posts/38053 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-052020-on-consent-under-regulation-2016679_en*

The European Data Protection Board (EDPB) adopted Guidelines 05/2020 on consent under Regulation 2016/679 to provide detailed interpretive guidance on the requirements for valid consent under the GDPR, including the elements of freely given, specific, informed, and unambiguous consent, as well as the conditions for explicit consent and the obligation to demonstrate consent. The guidelines address practical issues such as power imbalances, conditionality, granularity, detriment, and the minimum content requirements for informing data subjects. No fines are imposed, as this is a guidance document rather than an enforcement decision.

### Guidelines 1/2018 on certification and identifying certification criteria in accordance with Articles 42 and 43 of the Regulation

*Source: EDPB, edpb-guidelines-on-certification-and-identifying-certification-criteria, 2019-06-04 — https://overview.legal/posts/38048 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-12018-on-certification-and-identifying-certification-criteria-in_en*

The EDPB issued Guidelines 1/2018 to clarify the framework for data protection certification and the identification of certification criteria under Articles 42 and 43 of the GDPR. The guidelines address key concepts such as the interpretation of "certification," the roles of supervisory authorities and certification bodies, and the process for approving certification criteria. This document provides practical guidance to stakeholders on how GDPR certification mechanisms, seals, and marks should be established and operated.

### Guidelines 01/2022 on data subject rights - Right of access

*Source: EDPB, edpb-guidelines-on-data-subject-rights---right-of-access, 2023-04-17 — https://overview.legal/posts/38055 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-012022-on-data-subject-rights-right-of-access_en*

The right of access of data subjects is enshrined in Art. 8 of the EU Charter of Fundamental Rights. It has been a part of the European data protection legal framework since its beginning and is now further developed by more specified and precise rules in Art. 15 GDPR.

### Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1)

*Source: EDPB, edpb-guidelines-on-the-criteria-of-the-right-to-be-forgotten-in-the-search-engines-cases-under-th, 2020-07-07 — https://overview.legal/posts/38070 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-52019-on-the-criteria-of-the-right-to-be-forgotten-in-the-search_en*

The European Data Protection Board (EDPB) issued these guidelines to clarify the criteria and grounds for exercising the right to erasure (right to be forgotten) specifically in the context of search engine cases under the GDPR. The document details the six grounds under Article 17(1) that allow data subjects to request delisting, alongside the relevant exceptions, such as the right to freedom of expression and information. As a guidance instrument, it does not impose administrative fines but instead aims to harmonize how search engine providers handle and balance delisting requests across the EU.

## Recent developments

### EU-Hof: gegevens waaruit indirect de seksuele geaardheid van een persoon kan worden afgeleid vormen gevoelige gegevens in de zin van de AVG

*Source: NL EU Court Expert, 2022-08-17 — https://overview.legal/posts/6290 — original: https://ecer.minbuza.nl/-/eu-hof-gegevens-waaruit-indirect-de-seksuele-geaardheid-van-een-persoon-kan-worden-afgeleid-vormen-gevoelige-gegevens-in-de-zin-van-de-avg?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-300*

The processing of personal data that may indirectly reveal sensitive information about an individual, such as information about their sexual orientation, may qualify as processing of "special categories of personal data" within the meaning of the AVG. The processing of such sensitive data is prohibited in principle. This is the EU Court's answer to questions from a Lithuanian judge.

### CJEU clarifies GDPR principles of purpose limitation and storage limitation

*Source: NL EU Court Expert, 2022-10-30 — https://overview.legal/posts/6247 — original: https://ecer.minbuza.nl/-/eu-hof-verduidelijkt-de-beginselen-van-doelbinding-en-opslagbeperking-uit-de-avg?redirect=%2Fecer%2Fnieuws%3Fq%3Dprivacy%2520OR%2520avg%26f%3D%26t%3D#entry-1209*

The purpose limitation principle does not preclude a controller from capturing and storing in a test database established for testing and error correction purposes personal data previously collected and stored in another database. However, such "further processing" of personal data must be compatible with the specific purposes for which the personal data were originally collected. The principle of storage limitation precludes the retention of personal data in that test database for longer than n

### EDPB identifies challenges hindering the full implementation of the right to erasure

*Source: European Data Protection Board, 2026-02-18 — https://overview.legal/posts/52724 — original: https://www.edpb.europa.eu/news/news/2026/edpb-identifies-challenges-hindering-full-implementation-right-erasure_en*

Brussels, 18 February - The European Data Protection Board (EDPB) has adopted a report on its Coordinated Enforcement Framework (CEF) action on the right to be forgotten (Art.17 GDPR). The Board selected this topic as it is one of the most frequently exercised GDPR rights and one about which DPAs frequently receive complaints from individuals. The main objectives of this coordinated action are to ensure that the right to erasure is effectively exercised by individuals in Europe and understand ho

### EU-US Privacy Framework needs a long hard look

*Source: EURactiv, 2022-10-14 — https://overview.legal/posts/6256 — original: https://www.euractiv.com/section/data-protection/opinion/eu-us-privacy-framework-needs-a-long-hard-look/#entry-1054*

The Commission has endorsed enthusiastically a recent US order to implement a new framework to protect the privacy of personal data shared between the US and Europe. Dick Roche begs to differ.

https://iapp.org/news/a/the-redress-mechanism-in-the-privacy-shield-successor-on-the-independence-and-effective-powers-of-the-dprc/

### What Happened to the Risk-Based Approach to Data Transfers?

*Source: Future of Privacy Forum, 2022-09-27 — https://overview.legal/posts/6271 — original: https://fpf.org/blog/what-happened-to-the-risk-based-approach-to-data-transfers/#entry-912*

The GDPR incorporates the RBA for all obligations of the controller in the GDPR. Where the transfer rules are stated as obligations of the controller (rather than as absolute principles), the RBA of Article 24 therefore applies. Other than the DPAs assume, this is not contradicted by the ECJ in Schrems II nor by the EDPB recommendations on additional measures following the Schrems II judgment, according to Lokke Moerel, Professor of Global ICT Law at Tilburg University and a Dutch Cyber Security

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **IP Address** — https://overview.legal/topics/ip-adres
  Internet protocol addresses as personal data
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Lawful Basis** — https://overview.legal/topics/lawful-basis-article-6
  This topic is essential as Article 6 GDPR provides the specific legal bases that determine whether processing is lawful, which is the core requirement of the 'L
- **Human Resources** — https://overview.legal/topics/human-resources
  Processing of employee and HR data

---
Generated by overview.legal · https://overview.legal/topics/gdpr-subject-matter-objectives · 2026-08-22
