Charter of Fundamental Rights
The Charter of Fundamental Rights of the European Union is a legally binding document that sets out a list of human rights recognised within the EU. It is applied by courts across the EU and gives individuals a framework of protections against how EU institutions and, in certain circumstances, member states exercise their powers.
The Charter of Fundamental Rights of the European Union is a legally binding instrument (published in the Official Journal, OJ C 326, 26.10.2012) that codifies fundamental rights recognised within the EU legal order, including rights such as freedom of thought, conscience and religion. It has binding legal force and is applied by courts across the EU, including the Court of Justice of the European Union. In the data protection context, the Charter is frequently cited as the constitutional-level source underpinning the rights to respect for private life and to the protection of personal data, which inform the interpretation of secondary legislation such as the GDPR. Note that the Charter's precise scope of application to member states (as opposed to EU institutions) is defined by its own general provisions and by case law; practitioners should verify the current consolidated text and relevant Court of Justice jurisprudence, as the interaction between the Charter, the GDPR, and national implementing law is context-dependent and evolving.
Why it matters
The Charter of Fundamental Rights sits at the constitutional level of the EU legal order and is frequently cited as the foundational source for the rights that underpin EU data protection law. In particular, the Charter is commonly invoked as the higher-level basis for the right to respect for private life and the right to the protection of personal data, both of which inform how secondary legislation such as the GDPR is interpreted. Because the Charter has binding legal force and is applied by courts across the EU, including the Court of Justice of the European Union, arguments and rulings about data protection often reach back to Charter provisions rather than resting solely on the text of the GDPR.
For practitioners, this matters because the interpretation of GDPR obligations can be shaped by how courts read the Charter. When the Court of Justice assesses the lawfulness of a processing activity, a transfer mechanism, or a surveillance regime, it may weigh the fundamental rights recognised in the Charter against other interests. This means that compliance analysis is not always confined to the operative articles of the GDPR; the constitutional framing supplied by the Charter can influence outcomes, particularly in areas that involve balancing competing rights.
The Charter's precise reach is itself a subject of careful legal assessment. Its general provisions and the relevant case law define when it applies to member state action as opposed to the acts of EU institutions, and this boundary is context-dependent and evolving. Practitioners should therefore treat the Charter as a live source of interpretive authority rather than a static checklist, and should verify the current consolidated text and applicable Court of Justice jurisprudence when relying on it.
Who it's relevant to
Inside CFR
Common questions
Answers to the questions practitioners most commonly ask about CFR.