Skip to main content
Category: Legal Framework & Instruments

Charter of Fundamental Rights

Also known as: CFR, Charter of Fundamental Rights of the European Union, EU Charter of Fundamental Rights, the Charter
Simply put

The Charter of Fundamental Rights of the European Union is a legally binding document that sets out a list of human rights recognised within the EU. It is applied by courts across the EU and gives individuals a framework of protections against how EU institutions and, in certain circumstances, member states exercise their powers.

Formal definition

The Charter of Fundamental Rights of the European Union is a legally binding instrument (published in the Official Journal, OJ C 326, 26.10.2012) that codifies fundamental rights recognised within the EU legal order, including rights such as freedom of thought, conscience and religion. It has binding legal force and is applied by courts across the EU, including the Court of Justice of the European Union. In the data protection context, the Charter is frequently cited as the constitutional-level source underpinning the rights to respect for private life and to the protection of personal data, which inform the interpretation of secondary legislation such as the GDPR. Note that the Charter's precise scope of application to member states (as opposed to EU institutions) is defined by its own general provisions and by case law; practitioners should verify the current consolidated text and relevant Court of Justice jurisprudence, as the interaction between the Charter, the GDPR, and national implementing law is context-dependent and evolving.

Why it matters

The Charter of Fundamental Rights sits at the constitutional level of the EU legal order and is frequently cited as the foundational source for the rights that underpin EU data protection law. In particular, the Charter is commonly invoked as the higher-level basis for the right to respect for private life and the right to the protection of personal data, both of which inform how secondary legislation such as the GDPR is interpreted. Because the Charter has binding legal force and is applied by courts across the EU, including the Court of Justice of the European Union, arguments and rulings about data protection often reach back to Charter provisions rather than resting solely on the text of the GDPR.

For practitioners, this matters because the interpretation of GDPR obligations can be shaped by how courts read the Charter. When the Court of Justice assesses the lawfulness of a processing activity, a transfer mechanism, or a surveillance regime, it may weigh the fundamental rights recognised in the Charter against other interests. This means that compliance analysis is not always confined to the operative articles of the GDPR; the constitutional framing supplied by the Charter can influence outcomes, particularly in areas that involve balancing competing rights.

The Charter's precise reach is itself a subject of careful legal assessment. Its general provisions and the relevant case law define when it applies to member state action as opposed to the acts of EU institutions, and this boundary is context-dependent and evolving. Practitioners should therefore treat the Charter as a live source of interpretive authority rather than a static checklist, and should verify the current consolidated text and applicable Court of Justice jurisprudence when relying on it.

Who it's relevant to

Data protection lawyers and litigators
Lawyers arguing or advising on data protection matters may need to trace GDPR obligations back to their Charter foundations, particularly the rights to private life and to the protection of personal data. Because the Court of Justice applies the Charter when interpreting EU law, its provisions can shape the outcome of disputes over processing, transfers, or surveillance. Practitioners should confirm the current consolidated text and relevant case law, as the Charter's scope of application is context-dependent and evolving.
Data protection officers and compliance leads
Those responsible for compliance programs benefit from understanding that GDPR requirements rest on constitutional-level rights recognised in the Charter. This framing can be relevant when assessing activities that involve balancing competing interests, where regulators and courts may look beyond the operative GDPR text. The Charter should be treated as a source of interpretive authority rather than a fixed compliance checklist.
Policy and regulatory affairs professionals
Individuals engaging with EU institutions or tracking regulatory developments will find the Charter relevant because it provides a binding framework of fundamental rights applied across the EU. Its interaction with the GDPR and national implementing law is context-dependent, so those working in this space should monitor Court of Justice jurisprudence and verify the current position rather than relying on a single snapshot.
Engineers and product teams handling EU personal data
Technical teams designing systems that process personal data of individuals in the EU should be aware that the legal requirements they implement ultimately connect to fundamental rights recognised in the Charter. While engineers will work primarily from GDPR obligations, understanding that these rights carry constitutional weight helps explain why certain safeguards are treated as non-negotiable in legal assessment. Where scope or applicability is uncertain, they should defer to legal guidance.

Inside CFR

Article 7 - Respect for private and family life
Guarantees respect for an individual's private and family life, home, and communications. This provision underpins much of EU data protection reasoning and is frequently read alongside Article 8 by the Court of Justice of the European Union.
Article 8 - Protection of personal data
Establishes protection of personal data as a distinct fundamental right, requiring that data be processed fairly, for specified purposes, and on a legitimate basis laid down by law or the consent of the person concerned. It also includes rights of access and rectification and oversight by an independent authority. The GDPR gives detailed effect to this right, but the Charter provision is the higher-level constitutional source rather than the operational rulebook.
Independent supervisory authority requirement
Article 8 references compliance being subject to control by an independent authority. This principle informs the role of data protection authorities, though the specific powers and structures are set out in the GDPR and national implementing law rather than in the Charter itself.
Scope and legal status
The Charter applies to EU institutions and to member states when they are implementing EU law. It does not create a free-standing general competence, and its application in a given case turns on whether the matter falls within the scope of EU law. Practitioners should verify the scope position against the current official text and relevant case law.
Relationship to the GDPR
The GDPR operationalises the fundamental rights recognised in Articles 7 and 8, but the Charter and the Regulation are distinct instruments. Rights under the Charter are interpreted by the CJEU and can shape how GDPR provisions are read, particularly in balancing exercises.

Common questions

Answers to the questions practitioners most commonly ask about CFR.

Does the Charter of Fundamental Rights only protect the right to data protection?
No. The Charter is a broad instrument of EU primary law covering a wide range of civil, political, economic, and social rights. In the data protection context, two provisions are most frequently cited: the right to respect for private and family life and the right to the protection of personal data, which the Charter treats as related but distinct rights. Treating the Charter as a data-protection-only document understates its scope, and treating the two rights as identical misstates how the Court of Justice of the EU has generally analysed them as separate but overlapping guarantees.
Is the Charter the same thing as the GDPR, so that complying with the GDPR automatically satisfies the Charter?
No. The Charter is EU primary law that sits above secondary legislation such as the GDPR, whereas the GDPR is a regulation that gives detailed effect to Charter rights in the data protection field. The GDPR is generally interpreted in light of the Charter, and Charter rights can inform how GDPR provisions are read and whether restrictions are proportionate. Compliance with the text of the GDPR does not, on its own, guarantee that the underlying Charter rights have been fully respected, and courts may assess proportionality by reference to the Charter directly. Note that the Charter applies to member states only when they are implementing EU law, so its field of application has boundaries you should verify against current case law.
How does the Charter affect the way we interpret specific GDPR obligations?
In practice, the Charter is typically used as an interpretive backdrop rather than a standalone compliance checklist. Where a GDPR provision is ambiguous, or where a restriction on data subject rights is being considered, decision-makers and courts generally read the obligation in a way that gives effect to the relevant Charter rights and to the principle of proportionality. For an implementation team, this means documenting why a chosen approach is proportionate and rights-respecting, not just that it maps to an article. Because interpretation evolves through case law, you should check current judgments and regulatory guidance rather than relying on a fixed reading.
When does the Charter apply to our organisation's activities?
The Charter's field of application is generally limited to situations where EU institutions act, or where member states are implementing EU law. For a typical private organisation, the Charter is most relevant indirectly, through how EU and national data protection law is interpreted and applied, and through how courts and authorities assess the lawfulness and proportionality of measures. Whether it applies directly in a given scenario can be a legally nuanced question, so where the boundary matters for a decision you should obtain a case-specific legal assessment and verify against current authority.
Should our Data Protection Impact Assessment reference the Charter?
A DIA under Article 35 focuses on assessing risks to the rights and freedoms of individuals, and those rights and freedoms are informed by the Charter, including the rights to private life and to protection of personal data. It can be helpful to frame the risk and proportionality analysis in a way that reflects those underlying rights, particularly for high-risk or intrusive processing. This should be treated as good analytical practice rather than a rigid formal requirement to cite the Charter, and you should follow current regulatory guidance on DIA content, which can vary between authorities.
How does the Charter feature in disputes over cross-border data transfers?
The Charter's rights to private life and to protection of personal data, together with the right to an effective remedy, have featured prominently in EU case law examining whether transfer mechanisms provide adequate protection. Courts have assessed transfer tools and any supplementary measures by reference to whether individuals continue to enjoy protection essentially equivalent to that guaranteed within the EU, an analysis grounded in Charter rights. Because adequacy decisions, transfer tools, and the surrounding case law evolve, you should treat any given position as a snapshot and verify the current status of the relevant mechanisms and judgments.

Common misconceptions

The Charter is just another name for the GDPR, or the two are interchangeable.
They are distinct instruments. The Charter is a primary-law source setting out fundamental rights, while the GDPR is secondary legislation giving detailed effect to the right to data protection. The Charter typically informs interpretation of the GDPR rather than replacing or duplicating it.
The Charter applies to all activity within the EU in every context.
The Charter generally applies to EU institutions and to member states when they act within the scope of EU law. Whether it applies to a particular matter depends on that scope, and its reach is not unlimited. The precise boundary should be assessed case by case and verified against the current text and case law.
Article 8 requires consent for all processing of personal data.
Article 8 refers to processing on a legitimate basis laid down by law or the consent of the person concerned. Consent is one route among others, and the detailed legal bases are set out in the GDPR (Article 6), where consent is not a universal requirement. Special category data typically needs an additional condition under Article 9.

Best practices

Treat Articles 7 and 8 of the Charter as the constitutional backdrop when interpreting GDPR obligations, particularly in balancing and proportionality assessments, rather than as an operational compliance checklist.
Before relying on the Charter in a specific matter, confirm that the situation falls within the scope of EU law, since the Charter's application generally depends on that threshold.
Distinguish the fundamental right to data protection under Article 8 from the detailed rules in the GDPR, and cite the correct instrument for the point you are making.
Do not assume Article 8's reference to consent means consent is always required; identify the applicable GDPR legal basis and, for special category data, the additional Article 9 condition.
Follow CJEU case law, as the Charter is interpreted by the Court and its reasoning can materially affect how GDPR provisions are applied.
Verify the current status, scope, and any UK or national-law divergence against the official text before relying on the Charter in a compliance program, and note where the position is uncertain.