eu-charter

EU Charter of Fundamental Rights

Article 8 - Protection of personal data

Article 8 - Protection of personal data

1. Everyone has the right to the protection of personal data concerning him or her.
2. Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified.
3. Compliance with these rules shall be subject to control by an independent authority.

Explanations

  • Text:

    This Article has been based on Article 286 of the Treaty establishing the European Community and Directive 95/46/EC of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data and on the free movement of such data (OJ L 281, 23.11.1995, p. 31) as well as on Article 8 of the ECHR and on the Council of Europe Convention of 28 January 1981 for the Protection of Individuals with regard to Automatic Processing of Personal Data, which has been ratified by all the Member States. Article 286 of the EC Treaty is now replaced by Article 16 of the Treaty on the Functioning of the European Union and Article 39 of the Treaty on European Union. Reference is also made to Regulation (EC) No 45/2001 of the European Parliament and of the Council on the protection of individuals with regard to the processing of personal data by the Community institutions and bodies and on the free movement of such data (OJ L 8, 12.1.2001, p. 1). The above-mentioned Directive and Regulation contain conditions and limitations for the exercise of the right to the protection of personal data.

    Source:
    Official Journal of the European Union C 303/17 - 14.12.2007
    Preamble - Explanations relating to the Charter of Fundamental Rights:
    These explanations were originally prepared under the authority of the Praesidium of the Convention which drafted the Charter of Fundamental Rights of the European Union. Although they do not as such have the status of law, they are a valuable tool of interpretation intended to clarify the provisions of the Charter.

Case Law References

National Constitutional Law

68 results found

  • Sweden / Instrument of Government
    Country:
    Sweden

    Chapter 2 - Fundamental rights and freedoms:

    Article 3 No record in a public register concerning a Swedish citizen may be based without his or her consent solely on his or her political opinions;

    Article 6 Everyone shall likewise be protected against body searches, house searches and other such invasions of privacy, against examination of mail or other confidential correspondence, and against eavesdropping and the recording of telephone conversations or other confidential communications. In addition to what is laid down in paragraph one, everyone shall be protected in their relations with the public institutions against significant invasions of their personal privacy, if these occur without their consent and involve the surveillance or systematic monitoring of the individual’s personal circumstances.

  • 1992. évi LXIII. törvény a személyes adatok védelméről és a közérdekű adatok nyilvánosságáról
    Country:
    Hungary
  • Act LXIII Of 1992 On the Protection of Personal Data and the Publicity of Data of Public Interest
    Country:
    Hungary
  • Act n°78-17 of 6 January 1978 on Data Processing, Data Files and Individual Liberties
    Country:
    France

    Article 1Information technology should be at the service of every citizen. Its development shall take place in the context of international co-operation. It shall not violate human identity, human rights, privacy, or individual or public liberties. Article 2 This Act shall apply to automatic processing of personal data as well as non-automatic processing of personal data that is or may be contained in a personal data filing system, with the exception of processing carried out for the exercise of exclusively private activities, where the data controller meets the conditions provided for in Article 5 (...)

  • Act No. 428 of 2002 on personal data protection
    Country:
    Slovakia

    Section 1(1) This Act regulatesa) protection of personal data of natural persons in the course of their processing, b) principles of personal data processing, c) security of personal data, d) protection of the rights of data subjects, e) transborder personal data flow, f) registration and keeping of records of filing systems, g) establishment, status and scope of powers of the Office for Personal Data Protection of the Slovak Republic (hereinafter the “Office”) (...)

  • Act of 8 December 1992 on the protection of privacy in relation to the processing of personal data
    URL:
    Country:
    Belgium

     

     

     

  • Act of August 29, 1997 on the Protection of Personal Data
    Country:
    Poland

    Article 1 1. Any person has a right to have his/her personal data protected. 2. The processing of personal data can be carried out in the public interest, the interest of the data subject, or the interest of any third party, within the scope and subject to the procedure provided for by the Act.

  • Act on the Protection of Personal Data
    Country:
    Portugal
  • Bundesdatenschutzgesetz
    Country:
    Germany

    § 1 BDSG Zweck und Anwendungsbereich des Gesetzes (1) Zweck dieses Gesetzes ist es, den Einzelnen davor zu schützen, dass er durch den Umgang mit seinen personenbezogenen Daten in seinem Persönlichkeitsrecht beeinträchtigt wird. (2) Dieses Gesetz gilt für die Erhebung, Verarbeitung und Nutzung personenbezogener Daten durch 1. öffentliche Stellen des Bundes, 2. öffentliche Stellen der Länder, soweit der Datenschutz nicht durch Landesgesetz geregelt ist und soweit sie a) Bundesrecht ausführen oder b) als Organe der Rechtspflege tätig werden und es sich nicht um Verwaltungsangelegenheiten handelt, 3. nicht-öffentliche Stellen, soweit sie die Daten unter Einsatz von Datenverarbeitungsanlagen verarbeiten, nutzen oder dafür erheben oder die Daten in oder aus nicht automatisierten Dateien verarbeiten, nutzen oder dafür erheben, es sei denn, die Erhebung, Verarbeitung oder Nutzung der Daten erfolgt ausschließlich für persönliche oder familiäre Tätigkeiten. (3) Soweit andere Rechtsvorschriften des Bundes auf personenbezogene Daten einschließlich deren Veröffentlichung anzuwenden sind, gehen sie den Vorschriften dieses Gesetzes vor. Die Verpflichtung zur Wahrung gesetzlicher Geheimhaltungspflichten oder von Berufs- oder besonderen Amtsgeheimnissen, die nicht auf gesetzlichen Vorschriften beruhen, bleibt unberührt. (4) Die Vorschriften dieses Gesetzes gehen denen des Verwaltungsverfahrensgesetzes vor, soweit bei der Ermittlung des Sachverhalts personenbezogene Daten verarbeitet werden. (5) Dieses Gesetz findet keine Anwendung, sofern eine in einem anderen Mitgliedstaat der Europäischen Union oder in einem anderen Vertragsstaat des Abkommens über den Europäischen Wirtschaftsraum belegene verantwortliche Stelle personenbezogene Daten im Inland erhebt, verarbeitet oder nutzt, es sei denn, dies erfolgt durch eine Niederlassung im Inland. Dieses Gesetz findet Anwendung, sofern eine verantwortliche Stelle, die nicht in einem Mitgliedstaat der Europäischen Union oder in einem anderen Vertragsstaat des Abkommens über den Europäischen Wirtschaftsraum belegen ist, personenbezogene Daten im Inland erhebt, verarbeitet oder nutzt. Soweit die verantwortliche Stelle nach diesem Gesetz zu nennen ist, sind auch Angaben über im Inland ansässige Vertreter zu machen. Die Sätze 2 und 3 gelten nicht, sofern Datenträger nur zum Zweck des Transits durch das Inland eingesetzt werden. § 38 Abs. 1 Satz 1 bleibt unberührt.

  • Constitution of Finland
    Country:
    Finland

    Section 10 The right to privacy Everyone's private life, honour and the sanctity of the home are guaranteed. More detailed provisions on the protection of personal data are laid down by an Act. (...)

  • Constitution of the Hellenic Republic
    Country:
    Greece

    Article 9A All persons have the right to be protected from the collection, processing and use, especially by electronic means, of their personal data, as specified by law. The protection of personal data is ensured by an independent authority, which is constituted and operates as specified by law.

  • Constitution of the Republic of Estonia
    Country:
    Estonia

    Article 42. Government agencies, local authorities, and their officials may not gather or store information about the beliefs of a citizen of Estonia against the citizen’s free will.
    Article 44. (…) Pursuant to a procedure provided by law, any citizen of Estonia is entitled to access information about himself or herself held by government agencies and local authorities and in government and local authority archives. This right may be circumscribed pursuant to law to protect the rights and freedoms of others, to protect the confidentiality of a child’s filiation, and in the interests of preventing a criminal offence, apprehending the offender, or of ascertaining the truth in a criminal case.
    Unless otherwise provided by law, citizens of foreign states and stateless persons in Estonia enjoy the rights specified in paragraphs two and three of this section equally with citizens of Estonia.

  • Constitution of the Republic of Lithuania
    Country:
    Lithuania

    Article 22. Private life shall be inviolable. Personal correspondence, telephone conversations, telegraph messages, and other communications shall be inviolable. Information concerning the private life of a person may be collected only upon a justified court decision and only according to the law. The law and courts shall protect everyone from arbitrary or unlawful interference with his private and family life, as well as from encroachment upon his honour and dignity.

  • Constitution of the Republic of Poland
    Country:
    Poland

    Article 47 Everyone shall have the right to legal protection of his private life and family life, of his honour and good reputation and to make decisions about his personal life. Article 51 1. No one may be obliged, except on the basis of statute, to disclose information concerning his person. 2. Public authorities shall not acquire, collect or make accessible information on citizens other than that which is necessary in a democratic state ruled by law. 3. Everyone shall have a right of access to official documents and data collections concerning him. Limitations upon such rights may be established by statute. 4. Everyone shall have the right to demand the correction or deletion of untrue or incomplete information, or information acquired by means contrary to statute. 5. Principles and procedures for collection of and access to information shall be specified by statute. 

  • Czechia / Charter of Fundamental Rights and Freedoms
    Country:
    Czechia

    Article 10 (3) Everyone has the right to be protected from the unauthorized gathering, public revelation,
    or other misuse of her personal data.

  • Data Protection (Amendment) Act 2003
    Country:
    Ireland
  • Data Protection Act 1988
    Country:
    Ireland
  • Data Protection Act, Cap. 440 of the Laws of Malta, 2002
    Country:
    Malta

    3. The provisions of this Act shall apply to the processing of personal data, wholly or partly, by automated means and to such processing other than by automated means where such personal data forms part of a filing system or is intended to form part of a filing system..

  • Datenschutzgesetz 2000 - DSG 2000
    Country:
    Austria

    § 1. (1) Jedermann hat, insbesondere auch im Hinblick auf die Achtung seines Privat- und Familienlebens, Anspruch auf Geheimhaltung der ihn betreffenden personenbezogenen Daten, soweit ein schutzwürdiges Interesse daran besteht. Das Bestehen eines solchen Interesses ist ausgeschlossen, wenn Daten infolge ihrer allgemeinen Verfügbarkeit oder wegen ihrer mangelnden Rückführbarkeit auf den Betroffenen einem Geheimhaltungsanspruch nicht zugänglich sind. (2) Soweit die Verwendung von personenbezogenen Daten nicht im lebenswichtigen Interesse des Betroffenen oder mit seiner Zustimmung erfolgt, sind Beschränkungen des Anspruchs auf Geheimhaltung nur zur Wahrung überwiegender berechtigter Interessen eines anderen zulässig, und zwar bei Eingriffen einer staatlichen Behörde nur auf Grund von Gesetzen, die aus den in Art. 8 Abs. 2 der Europäischen Konvention zum Schutze der Menschenrechte und Grundfreiheiten (EMRK), BGBl. Nr. 210/1958, genannten Gründen notwendig sind. Derartige Gesetze dürfen die Verwendung von Daten, die ihrer Art nach besonders schutzwürdig sind, nur zur Wahrung wichtiger öffentlicher Interessen vorsehen und müssen gleichzeitig angemessene Garantien für den Schutz der Geheimhaltungsinteressen der Betroffenen festlegen. Auch im Falle zulässiger Beschränkungen darf der Eingriff in das Grundrecht jeweils nur in der gelindesten, zum Ziel führenden Art vorgenommen werden. (3) Jedermann hat, soweit ihn betreffende personenbezogene Daten zur automationsunterstützten Verarbeitung oder zur Verarbeitung in manuell, dh. ohne Automationsunterstützung geführten Dateien bestimmt sind, nach Maßgabe gesetzlicher Bestimmungen 1. das Recht auf Auskunft darüber, wer welche Daten über ihn verarbeitet, woher die Daten stammen, und wozu sie verwendet werden, insbesondere auch, an wen sie übermittelt werden; 2. das Recht auf Richtigstellung unrichtiger Daten und das Recht auf Löschung unzulässigerweise verarbeiteter Daten. (4) Beschränkungen der Rechte nach Abs. 3 sind nur unter den in Abs. 2 genannten Voraussetzungen zulässig. (5) Gegen Rechtsträger, die in Formen des Privatrechts eingerichtet sind, ist, soweit sie nicht in Vollziehung der Gesetze tätig werden, das Grundrecht auf Datenschutz mit Ausnahme des Rechtes auf Auskunft auf dem Zivilrechtsweg geltend zu machen. In allen übrigen Fällen ist die Datenschutzkommission zur Entscheidung zuständig, es sei denn, daß Akte der Gesetzgebung oder der Gerichtsbarkeit betroffen sind.

  • Eesti Vabariigi Põhiseadus
    Country:
    Estonia

    § 42. Riigiasutused, kohalikud omavalitsused ja nende ametiisikud ei tohi Eesti kodaniku vaba tahte vastaselt koguda ega talletada andmeid tema veendumuste kohta.
    § 44. (...) Eesti kodanikul on õigus seaduses sätestatud korras tutvuda tema kohta riigiasutustes ja kohalikes omavalitsustes ning riigi ja kohalike omavalitsuste arhiivides hoitavate andmetega. Seaduse alusel võib seda õigust piirata teiste inimeste õiguste ja vabaduste ning lapse põlvnemise saladuse kaitseks, samuti kuriteo tõkestamise, kurjategija tabamise või kriminaalmenetluses tõe väljaselgitamise huvides. (...)

EU Law

37 results found

  • Directive 2010/13/EU of the European Parliament and of the Council of 10 March 2010 on the coordination of certain provisions laid down by law, regulation or administrative action in Member States concerning the provision of audiovisual media services

    Preamble 
    (16) This Directive enhances compliance with fundamental rights and is fully in line with the principles recognised by the Charter of Fundamental Rights of the European Union (12), in particular Article 11 thereof. In this regard, this Directive should not in any way prevent Member States from applying their constitutional rules relating to freedom of the press and freedom of expression in the media.


    (48) Television broadcasting rights for events of high interest to the public may be acquired by broadcasters on an exclusive basis. However, it is essential to promote pluralism through the diversity of news production and programming across the Union and to respect the principles recognised by Article 11 of the Charter of Fundamental Rights of the European Union.


    (60) Measures taken to protect the physical, mental and moral development of minors and human dignity should be carefully balanced with the fundamental right to freedom of expression as laid down in the Charter on Fundamental Rights of the European Union. The aim of those measures, such as the use of personal identification numbers (PIN codes), filtering systems or labelling, should thus be to ensure an adequate level of protection of the physical, mental and moral development of minors and human dignity, especially with regard to on-demand audiovisual media services. The Recommendation on the protection of minors and human dignity and on the right of reply already recognised the importance of filtering systems and labelling and included a number of possible measures for the benefit of minors, such as systematically supplying users with an effective, updatable and easy-to-use filtering system when they subscribe to an access provider or equipping the access to services specifically intended for children with automatic filtering systems.

  • Regulation (EU) 2022/991 of the European Parliament and of the Council of 8 June 2022 amending Regulation (EU) 2016/794, as regards Europol’s cooperation with private parties, the processing of personal data by Europol in support of criminal investigation

    (57) This Regulation fully respects the fundamental rights and safeguards, and observes the principles recognised in particular by the Charter of Fundamental Rights of the European Union (‘the Charter’), in particular the right to respect for private and family life and the right to the protection of personal data as provided for by Articles 7 and 8 of the Charter, as well as by Article 16 TFEU. Given the importance of the processing of personal data for the work of law enforcement in general, and for the support provided by Europol in particular, this Regulation should include enhanced safeguards, democratic oversight and accountability mechanisms, to ensure that the activities and tasks of Europol are carried out in full compliance with fundamental rights as enshrined in the Charter, in particular the rights to equality before the law, to non-discrimination, and to an effective remedy before the competent national court against any of the measures taken pursuant to this Regulation. Any processing of personal data under this Regulation should be limited to that which is strictly necessary and proportionate, and subject to clear conditions, strict requirements and effective supervision by the EDPS.

  • Regulation (EU) 2017/746 of the European Parliament and of the Council of 5 April 2017 on in vitro diagnostic medical devices and repealing Directive 98/79/EC and Commission Decision 2010/227/EU

    (68) An electronic system should be set up at Union level to ensure that every interventional clinical performance study and other performance study involving risks for the subjects of the studies is recorded and reported in a publicly accessible database. To protect the right to protection of personal data, recognised by Article 8 of the Charter of Fundamental Rights of the European Union (‘the Charter’), no personal data of subjects participating in a performance study should be recorded in the electronic system. To ensure synergies with the area of clinical trials on medicinal products, the electronic system on performance studies should be interoperable with the EU database to be set up for clinical trials on medicinal products for human use.

    [...]

    Article 1

    Subject matter and scope

    10. Nothing in this Regulation shall restrict the freedom of the press or the freedom of expression in the media in so far as those freedoms are guaranteed in the Union and in the Member States, in particular under Article 11 of the Charter of Fundamental Rights of the European Union.

  • Regulation (EU) No 603/2013 of the European Parliament and of the Council of 26 June 2013 on the establishment of 'Eurodac' for the comparison of fingerprints for the effective application of Regulation (EU) No 604/2013

    Preamble

    (50) This Regulation respects the fundamental rights and observes the principles recognised in particular by the Charter. In particular, this Regulation seeks to ensure full respect for the protection of personal data and for the right to seek international protection, and to promote the application of Articles 8 and 18 of the Charter. This Regulation should therefore be applied accordingly.

    Article 1- Purpose of "Eurodac" 
    [...]
    ‘2. This Regulation also lays down the conditions under which Member States' designated authorities and the European Police Office (Europol) may request the comparison of fingerprint data with those stored in the Central System for law enforcement purposes. 
    3.   Without prejudice to the processing of data intended for Eurodac by the Member State of origin in databases set up under the latter's national law, fingerprint data and other personal data may be processed in Eurodac only for the purposes set out in this Regulation and Article 34(1) of Regulation (EU) No 604/2013.‘ 
    Article 23 - Responsibility for data processing
    [...]
    ‘2. In accordance with Article 34, the Member State of origin shall ensure the security of the data referred to in paragraph 1 before and during transmission to the Central System as well as the security of the data it receives from the Central System.‘
    Article 27 - Access to, and correction or erasure of, data recorded in Eurodac
    [...]
    ‘4.   If a Member State or the Agency has evidence to suggest that data recorded in the Central System are factually inaccurate, it shall advise the Member State of origin as soon as possible.
    If a Member State has evidence to suggest that data were recorded in the Central System in breach of this Regulation, it shall advise the Agency, the Commission and the Member State of origin as soon as possible. The Member State of origin shall check the data concerned and, if necessary, amend or erase them without delay.‘
    Article 33 - Protection of personal data for law enforcement purposes
    [...]
    ‘3.   The processing of personal data by Europol pursuant to this Regulation shall be in accordance with Decision 2009/371/JHA and shall be supervised by an independent external data protection supervisor. Articles 30, 31 and 32 of that Decision shall be applicable to the processing of personal data by Europol pursuant to this Regulation. The independent external data protection supervisor shall ensure that the rights of the individual are not violated.‘ 

  • Regulation (EU) 2017/1128 of the European Parliament and of the Council of 14 June 2017 on cross-border portability of online content services in the internal market

    [...]

    (30) This Regulation respects fundamental rights and observes the principles recognised in the Charter of Fundamental Rights of the European Union (‘Charter’). Accordingly, this Regulation should be interpreted and applied in accordance with those rights and principles, in particular the right to respect for private and family life, the right to protection of personal data, the right to freedom of expression, the freedom to conduct a business and the right to property, including intellectual property. Any processing of personal data under this Regulation should respect fundamental rights, including the right to respect for private and family life and the right to protection of personal data under Articles 7 and 8 of the Charter, and it is essential that such processing be in compliance with Directives 95/46/EC and 2002/58/EC. In particular, providers of online content services should ensure that any processing of personal data under this Regulation is necessary, reasonable and proportionate in order to achieve the relevant purpose. Where authentication of a subscriber is sufficient in order to provide the service, identification of the subscriber should not be required. Data collected pursuant to this Regulation for the purposes of verification of the Member State of residence should not be stored by the provider longer than necessary to complete such verification. Such data should be immediately and irreversibly destroyed after the verification is completed. However, this is without prejudice to the storage of data which was collected for another legitimate purpose, subject to applicable data protection rules, including rules concerning the storage of that data.

    [...]

  • Regulation (EU) 2021/784 of the European Parliament and of the Council of 29 April 2021 on addressing the dissemination of terrorist content online

    Preamble 


    (20) It should be possible for the competent authority of the Member State where the hosting service provider has its main establishment or where its legal representative resides or is established to scrutinise the removal order issued by competent authorities of another Member State to determine whether it seriously or manifestly infringes this Regulation or the fundamental rights enshrined in the Charter. Both the content provider and the hosting service provider should have the right to request such scrutiny by the competent authority in the Member State where the hosting service provider has its main establishment or where its legal representative resides or is established. Where such a request is made, that competent authority should adopt a decision on whether the removal order comprises such an infringement. Where that decision finds such an infringement, the removal order should cease to have legal effects. The scrutiny should be carried out swiftly so as to ensure that erroneously removed or disabled content is reinstated as soon as possible.


    (23) When putting in place specific measures, hosting service providers should ensure that users’ right to freedom of expression and information as well as the freedom and pluralism of the media as protected under the Charter are preserved. In addition to any requirement laid down in the law, including legislation on the protection of personal data, hosting service providers should act with due diligence and implement safeguards, where appropriate, including human oversight and verifications, to avoid any unintended or erroneous decision leading to the removal of or disabling of access to content that is not terrorist content.

    Article 1: Subject matter and scope

    1. This Regulation lays down uniform rules to address the misuse of hosting services for the dissemination to the public of terrorist content online, in particular on:

    (a) reasonable and proportionate duties of care to be applied by hosting service providers in order to address the dissemination to the public of terrorist content through their services and ensure, where necessary, the expeditious removal of or disabling of access to such content;

    (b) the measures to be put in place by Member States, in accordance with Union law and subject to suitable safeguards to protect fundamental rights, in particular the freedom of expression and information in an open and democratic society, in order to:

    (i) identify and ensure the expeditious removal of terrorist content by hosting service providers; and

    (ii) facilitate cooperation among the competent authorities of Member States, hosting service providers and, where appropriate, Europol.

    2. This Regulation applies to hosting service providers offering services in the Union, irrespective of their place of main establishment, insofar as they disseminate information to the public.

    3. Material disseminated to the public for educational, journalistic, artistic or research purposes or for the purposes of preventing or countering terrorism, including material which represents an expression of polemic or controversial views in the course of public debate, shall not be considered to be terrorist content. An assessment shall determine the true purpose of that dissemination and whether material is disseminated to the public for those purposes.

    4. This Regulation shall not have the effect of modifying the obligation to respect the rights, freedoms and principles referred to in Article 6 TEU and shall apply without prejudice to fundamental principles relating to freedom of expression and information, including freedom and pluralism of the media.

    5. This Regulation shall be without prejudice to Directives 2000/31/EC and 2010/13/EU. For audiovisual media services as defined in point (a) of Article 1(1) of Directive 2010/13/EU, Directive 2010/13/EU shall prevail.

    Article 4: Procedure for cross-borders removal orders 

    3.   The competent authority of the Member State where the hosting service provider has its main establishment or where its legal representative resides or is established may, on its own initiative, within 72 hours of receiving the copy of the removal order in accordance with paragraph 1, scrutinise the removal order to determine whether it seriously or manifestly infringes this Regulation or the fundamental rights and freedoms guaranteed by the Charter.

    Where it finds an infringement, it shall, within the same period, adopt a reasoned decision to that effect. 

  • Regulation (EU) 2023/1543 of the European Parliament and of the Council of 12 July 2023 on European Production Orders and European Preservation Orders for electronic evidence in criminal proceedings and for the execution of custodial sentences

    Preamble 


    (13) The respect for private and family life and the protection of natural persons regarding the processing of personal data are fundamental rights. In accordance with Article 7 and Article 8(1) of the Charter, everyone has the right to respect for their private and family life, home and communications and to the protection of personal data concerning them.

    (46) The principle of ne bis in idem is a fundamental principle of law in the Union, as recognised by the Charter and developed by the case law of the Court of Justice of the European Union. Where the issuing authority has grounds to believe that parallel criminal proceedings could be ongoing in another Member State, it should consult the authorities of that Member State in accordance with Council Framework Decision 2009/948/JHA . In any case, a European Production Order or a European Preservation Order is not to be issued where the issuing authority has grounds to believe that this would be contrary to the ne bis in idem principle.

    Article 1: Subject matter

    1. This Regulation lays down the rules under which an authority of a Member State, in criminal proceedings, may issue a European Production Order or a European Preservation Order and thereby order a service provider offering services in the Union and established in another Member State, or, if not established, represented by a legal representative in another Member State, to produce or to preserve electronic evidence regardless of the location of the data. This Regulation is without prejudice to the powers of national authorities to address service providers established or represented on their territory for the purpose of ensuring that they comply with national measures similar to those referred to in the first subparagraph.

    2. The issuing of a European Production Order or of a European Preservation Order may also be requested by a suspect or an accused person, or by a lawyer on that person’s behalf within the framework of applicable defence rights in accordance with national criminal procedural law.

    3. This Regulation shall not have the effect of modifying the obligation to respect the fundamental rights and legal principles as enshrined in the Charter and in Article 6 TEU, and any obligations applicable to law enforcement authorities or judicial authorities in this respect shall remain unaffected. This Regulation applies without prejudice to fundamental principles, in particular the freedom of expression and information, including the freedom and pluralism of the media, respect for private and family life, the protection of personal data, as well as the right to effective judicial protection.

  • Regulation (EU) 2021/1232 of the European Parliament and of the Council of 14 July 2021 on a temporary derogation from certain provisions of Directive 2002/58/EC as regards the use of technologies by providers

    Article 1

    Subject matter and scope

    1. This Regulation lays down temporary and strictly limited rules derogating from certain obligations laid down in Directive 2002/58/EC, with the sole objective of enabling providers of certain number-independent interpersonal communications services (‘providers’) to use, without prejudice to Regulation (EU) 2016/679, specific technologies for the processing of personal and other data to the extent strictly necessary to detect online child sexual abuse on their services and report it and to remove online child sexual abuse material from their services.

    2. This Regulation does not apply to the scanning of audio communications.

  • Directive (EU) 2022/2381 of the European Parliament and of the Council of 23 November 2022 on improving the gender balance among directors of listed companies and related measures

    Article 1

    Purpose

    This Directive aims to achieve a more balanced representation of women and men among the directors of listed companies by establishing effective measures that aim to accelerate progress towards gender balance, while allowing listed companies sufficient time to make the necessary arrangements for that purpose.

  • Directive (EU) 2019/1937 of the European Parliament and of the Council of 23 October 2019 on the protection of persons who report breaches of Union law

    Article 1

    Purpose

    The purpose of this Directive is to enhance the enforcement of Union law and policies in specific areas by laying down common minimum standards providing for a high level of protection of persons reporting breaches of Union law.

International Law

3 results found

  • European Convention on Human Rights - Article 8

    Article 8 – Right to respect for private and family life

    1. Everyone has the right to respect for his private and family life, his home and his correspondence.

    2. There shall be no interference by a public authority with the exercise of this right except such as is in accordance with the law and is necessary in a democratic society in the interests of national security, public safety or the economic well-being of the country, for the prevention of disorder or crime, for the protection of health or morals, or for the protection of the rights and freedoms of others.

  • Council of Europe, Guidelines on the protection of individuals with regard to the processing of personal data in a world of big data

    ‘The present Guidelines recommend measures that Parties, controllers and processors should take to prevent the potential negative impact of the use of Big Data on human dignity, human rights, and fundamental individual and collective freedoms, in particular with regard to personal data protection.
    Given the nature of Big Data and its uses, the application of some of the traditional principles of data processing (e.g. the principle of data minimisation, purpose limitation, fairness and transparency, and free, specific and informed consent) may be challenging in this technological scenario. These Guidelines therefore suggest a specific application of the principles of Convention 108, to make them more effective in practice in the Big Data context.‘

  • OECD, Guidelines governing the Protection of Privacy and Transborder Flows of Personal Data

    ‘2. These Guidelines apply to personal data, whether in the public or private sectors, which, because of the manner in which they are processed, or because of their nature or the context in which they are used, pose a risk to privacy and individual liberties.‘
    ‘3. The principles in these Guidelines are complementary and should be read as a whole. They should not be interpreted:
    a) as preventing the application of different protective measures to different categories of personal data, depending upon their nature and the context in which they are collected, stored, processed or disseminated; or
    b) in a manner which unduly limits the freedom of expression‘
    ‘7. There should be limits to the collection of personal data and any such data should be obtained by lawful and fair means and, where appropriate, with the knowledge or consent of the data subject.‘
    ‘9. The purposes for which personal data are collected should be specified not later than at the time of data collection and the subsequent use limited to the fulfilment of those purposes or such others as are not incompatible with those purposes and as are specified on each occasion of change of purpose.‘

Publications and data

  • Handbook / Guide / Manual
    19
    August
    2022
    DA, ET, FI, LT, PT, SV versions now available
    30 July 2024
    The Charter of Fundamental Rights of the European Union (CFREU) is the EU’s bill of rights. It always binds the EU institutions and the Member States when they act within the scope of EU law. However, it is far from easy to assess whether a concrete case falls within the scope of EU law. This is why it is necessary to provide training and training material to legal professionals so that they can understand the field of application of the Charter as laid out in its Article 51. This trainer’s manual aims at providing guidance on both the organisation and the implementation of such trainings based on a series of case studies,
    which will be extended in the future.
  • Handbook / Guide / Manual
    25
    May
    2018
    Arabic version now available
    18 July 2024
    The rapid development of information technology has exacerbated the need for robust personal data protection, the right to which is safeguarded by both European Union (EU) and Council of Europe (CoE) instruments. Safeguarding this important right entails new and significant challenges as technological advances expand the frontiers of areas such as surveillance, communication interception and data storage. This handbook is designed to familiarise legal practitioners not specialised in data protection with this emerging area of the law.
  • Fundamental Rights Report
    8
    June
    2022
    All language versions now available
    14 September 2022
    The year 2021 brought both progress and setbacks in terms of fundamental rights protection. FRA’s Fundamental Rights Report 2022 reviews major developments in the field, identifying both achievements and remaining areas of concern. This publication presents FRA’s opinions on the main developments in the thematic areas covered, and a synopsis of the evidence supporting these opinions.
  • Leaflet / Flyer
    16
    January
    2020
    All language versions now available
    16 December 2021
    This leaflet assists officers and authorities to inform asylum applicants and migrants in an understandable and accessible way about the processing of their fingerprints in Eurodac.
  • Report / Paper / Summary
    21
    January
    2021
    All language versions now available
    16 April 2021
    National Human Rights Institutions (NHRIs) are a vital part of the country-level human rights protection system. By raising awareness, providing advice, monitoring and holding authorities to account, they have a central role in navigating the great human rights challenges of our day – tackling both persistent concerns like discrimination and inequality, and novel issues such as the rights implications of artificial intelligence and of the COVID-19 pandemic.
  • Handbook / Guide / Manual
    5
    December
    2018
    Last versions available are EL and NL
    11 March 2021
    This guide explains what profiling is, the legal frameworks that regulate it, and why conducting profiling lawfully is both necessary to comply with fundamental rights and crucial for effective policing and border management. The guide also provides practical guidance on how to avoid unlawful profiling in police and border management operations.
  • Report / Paper / Summary
    3
    September
    2020
    Summary version now available
    21 January 2021
    National Human Rights Institutions (NHRIs) are a vital part of the country-level human rights protection system. This report, published 10 years after FRA’s first in-depth study on NHRIs, looks at such bodies in the EU, as well as the Republic of North Macedonia, the Republic of Serbia, and the United Kingdom of Great Britain and Northern Ireland. It explores relevant developments, challenges to their effectiveness and ways to maximise their impact.
  • Fundamental Rights Report
    11
    June
    2026
    The Fundamental Rights Report: Challenges and Achievements in 2025 is FRA’s flagship annual publication. It provides an overview of the state of fundamental rights in the EU and highlights selected critical developments from 2025. This year, it focuses on four areas: rights protection in a rapidly changing digital environment; the housing crisis and rising homelessness rates; employment challenges for people from non-EU countries; and the implementation of the EU Charter of Fundamental Rights. The publication is a valuable resource for those seeking to stay informed about the EU’s shifting landscape of fundamental rights.
  • In brief / Factsheet
    22
    May
    2026
    This factsheet examines the "right to be forgotten" within the context of EU law and the European Convention on Human Rights. It emphasizes the intersections of these legal frameworks, with particular attention to case law from the Court of Justice of the European Union (CJEU) and the European Court of Human Rights (ECtHR).
  • Report / Paper / Summary
    11
    May
    2026
    The ability to communicate freely and privately online is protected under Article 7 of the EU Charter; it is a crucial enabler of other fundamental rights, particularly as the world becomes increasingly digital. This paper presents results from an EU-wide survey about people’s views on encryption of their private online communication. It looks, for example, at concern regarding access by outside actors to information shared when using private messaging applications. The results indicate that people highly value encryption and at the same time have concerns about online communications being accessed without their knowledge or permission. It provides a timely evidence base to shape policy discussions on internal security and digital privacy.