CIPP/E Mastery in 21 Days
EU Legal Framework
The Bedrock of EU Privacy Rights
In the European Union, data protection isn't just good practice; it's a fundamental right. This principle is anchored directly into the EU's primary legal documents. Think of these as the constitution of the EU, providing the ultimate authority for all other laws, including the GDPR.
The first pillar is the of the European Union. Specifically, Article 8 guarantees everyone the right to the protection of their personal data. It explicitly states that data must be processed fairly for specified purposes and on the basis of consent or another legitimate legal basis. It also establishes the right to access and rectify one's data and confirms that compliance is subject to control by an independent authority.
Article 8 of the Charter of Fundamental Rights:
- Everyone has the right to the protection of personal data concerning him or her.
- Such data must be processed fairly for specified purposes and on the basis of the consent of the person concerned or some other legitimate basis laid down by law. Everyone has the right of access to data which has been collected concerning him or her, and the right to have it rectified.
- Compliance with these rules shall be subject to control by an independent authority.
The second pillar is the Treaty on the Functioning of the European Union (TFEU). Article 16 of the TFEU reinforces the right found in the Charter. It provides the specific legal basis for the EU Parliament and Council to create data protection laws that apply across the Union. Essentially, Article 8 of the Charter establishes the right, and Article 16 of the TFEU provides the power to legislate and enforce that right through regulations like the GDPR.
How EU Laws Are Made
Understanding how a law like the GDPR comes into being is crucial. The standard path for most EU legislation is the (OLP). It's a system of checks and balances involving three main institutions:
- The European Commission: This is the executive branch. It proposes new legislation. Think of it as the starting point of the process. For the GDPR, the Commission proposed the initial draft to update the 1995 Directive.
- The European Parliament: Members of the European Parliament (MEPs) are directly elected by EU citizens. The Parliament debates, amends, and votes on the proposed law. It acts as a co-legislator, representing the voice of the people.
- The Council of the European Union: This body represents the governments of the individual member states. Ministers from each country meet to discuss, amend, and vote on the legislation. It ensures national interests are considered.
For a law to pass, the Parliament and the Council must both agree on the exact same text. This process ensures that new laws have broad support from both citizens and national governments.
A Tale of Two Laws
The GDPR doesn't operate in a vacuum. It works alongside other, more specific pieces of legislation. The most important one to know for the CIPP/E exam is the ePrivacy Directive (soon to be the ePrivacy Regulation).
The GDPR is a law of general application; it covers the processing of personal data in almost all contexts. The ePrivacy Directive, however, is more focused. It deals specifically with the privacy of electronic communications, covering topics like cookies, unsolicited marketing emails (spam), and the confidentiality of communications services.
The EU AI Act explicitly clarifies that the GDPR always applies when personal data is processed by AI systems.
This creates a situation where both laws might seem to apply. How do we resolve this? The answer lies in a legal principle known as lex specialis derogat legi generali, which means "a specific law overrides a general law."
In practice, this means that if a situation is covered by a specific rule in the ePrivacy Directive (e.g., rules on consent for cookies), that rule takes precedence over the more general rules in the GDPR. However, for any aspect not specifically covered by the ePrivacy Directive, the GDPR's rules still apply. The GDPR acts as a safety net, filling in the gaps.
The Ultimate Interpreter
What happens when there's a dispute over what these laws mean? That's where the (CJEU) comes in. Located in Luxembourg, the CJEU is the EU's highest court. Its primary role in this context is to ensure that EU law is interpreted and applied the same way in every member state.
National courts can (and sometimes must) refer questions about the interpretation of EU law, like the GDPR, to the CJEU. The CJEU then delivers a binding ruling. These rulings can have massive implications. Famous cases like Schrems II, which invalidated the EU-US Privacy Shield, demonstrate the court's power to shape the entire landscape of data protection. For your exam, understanding that the CJEU is the final authority on the meaning of the GDPR is critical.
By understanding the foundational rights, the legislative process, the interplay between different laws, and the role of the CJEU, you have the complete institutional context for the GDPR.
Which two primary legal documents in the European Union establish data protection as a fundamental right, providing the legal basis for regulations like the GDPR?
Within the EU's Ordinary Legislative Procedure, what is the primary role of the European Commission?

