|  Date  |  Kategorie: GPRS-News

EU e-Privacy Regulation: a new challenge

GDPR-Series #2 | September 2019

Since May 2018 companies in Europe are required to implement the EU General Data Protection Regulation (GDPR). In order to be well on time for the fixed date 25/05/2018 many companies put in a great deal of effort into the implementation of this new European law. Other companies are only now acquainting with the data protection after heavy penalties have already been imposed because of data protection violations. One prominent example is Google, who were fined EUR 50 million at the beginning of 2019 owing to an ostensible lack of transparency in data processing.

However, many points in the GDPR remain unclear and we are still waiting for annotations of this regulation which may include a more practical focus. While until now not all companies have yet completed the realization of the innovations, the next data protection legislation, effecting the whole of Europe, is already imminent: the EU e-Privacy Directive (ePR).

When will it come into force, what changes and requirements does it entail?

This article provides an outlook. This Regulation should actually have come into force at the same time as the GDPR. It is meant to complement the GDPR and relates to electronic communication. Its aim is to protect privacy in electronic communication in general and it also includes important provisions for websites. A draft of this regulation has been available to the European Commission since January 2017.
Already the title of the new regulation in itself is quite unspeakable and promises important things: “REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL concerning the respect for private life and the protection of personal data in electronic communications and repealing Directive 2002/58/EC (Regulation of Privacy and Electronic Communications)”

In contrast to the GDPR, the aim of the ePR is to protect natural and legal entities in the provision and use of electronic communication services, and in particular to protect natural persons in the processing of personal data (Art. 1 (1) of the draft). The regulation applies to all communication provided in Europe, regardless of where the headquarter of the company providing the service is located. Art. 3(2) of the present draft even stipulates that the operators of electronic communication services which are not located in the European Union must in writing designate a representative in the European Union.
The regulation is intended to apply to the processing of electronic communication data and for information in relation to the end user’s terminal equipment (Art. 2 of the draft). Communication services which are not publicly accessible do not fall under the scope of this regulation.

Both the communication content and the communication metadata will be considered electronic communication data. Electronic communication contents are contents which are communicated by means of electronic communication services, e.g. text messages, speech, videos, images and audio. Communication metadata are data which are generated in connection with the provision of electronic communication services such as for example data concerning the location of the device as well as the date, time, duration and type of communication.

Conditions are being determined under which communication data, contents and metadata, can be processed. This also includes the user’s express consent to the processing of communication content. Communication data should in principle be deleted as soon as the intended recipient has received the electronic communication content.

Any use of the processing and save functions of terminal equipment not made by the end user in question as well as any collection of information from the end user’s terminal equipment, including its software and hardware, is prohibited unless it is based on well-defined grounds, e.g. the user’s consent.

Art. 10 of the ePR (draft) stipulates that software which permits electronic communication must offer the option of preventing third parties from simply saving information on an end user’s terminal equipment (e.g. server) or processing information which is already saved. In simple words, this means that websites must also function without cookies in future. Section 3 of the draft adds information regarding the display of the telephone number and its suppression, of the caller and the call recipients. Furthermore the regulation defines information requirements in the event of security breaches.

It is the responsibility of the data protection supervisory authority to monitor  compliance with the regulation. The penal provisions are organised as in the GDPR. Even this short extract from the first draft of the law shows how problematic it could be and how much room for interpretation any implementation of the ePR will entail.

On the other hand, the author also believes that the regulation draft in its current form fails to provide information concerning how security/data security should be materially established since no concrete statements have been made to date regarding the encryption of emails.

It is therefore highly likely that this will result in great uncertainty and thus a significant economic burden for all companies while implementing the requirements. From the consumer’s point of view, regulations which result in a real improvement in data protection would certainly be desirable. It is especially electronic communication that is of particular importance and will continue to play a more central role in communication between companies and private individuals. Unfortunately, in the opinion of experts, the GDPR has until now resulted in only a few improvements for consumers along with its flood of information leaflets and emails (information in accordance with Art. 13 and 14 of the GDPR).

Since the first draft of the ePR, the various European Committees have been working on amendments. The European Data Protection Board (EDPB), which replaced the Article 29 Working Party on 25 May 2018, has been vehemently advocating for the implementation of the regulation. If the regulation should come into force, a transition period of two years is expected.

Let us hope that the legislative procedure leads to further improvements in the clarity of this regulation and its expected implementation; this would be a major step towards minimising the burden for companies caused by the need to implement the ePR, presumably in 2020. This companies already struggled in their organisation when the GDPR became their new reality.