# Judgment of the Court (Grand Chamber) of 6 October 2020.#La Quadrature du Net and Others v Premier ministre and Others.#Requests for a preliminary ruling from the Conseil d'État (France) and Cour constitutionnelle (Belgium).#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Providers of electronic communications services – Hosting service providers and Internet access providers – General and indiscriminate retention of traffic and location

- Type: Case Law
- Source: Court of Justice of the European Union
- Identifier: 62018CJ0511
- Date: 2020-10-06
- Original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0511
- Canonical: https://overview.legal/posts/593397

## Full text

JUDGMENT OF THE COURT (Grand Chamber)
6 October 2020 (
*1
)
[Text rectified by order of 16 November 2020]
Table of Contents
Legislative framework
EU law
Directive 95/46
Directive 97/66
Directive 2000/31
Directive 2002/21
Directive 2002/58
Regulation 2016/679
French law
Code de la sécurité intérieure (Internal Security Code)
The CPCE
Loi no 2004‑575 du 21 juin 2004 pour la confiance dans l’économie numérique (Law No 2004‑575 of 21 June 2004 to promote trust in the digital economy)
Decree No 2011‑219
Belgian law
The disputes in the main proceedings and the questions referred for a preliminary ruling
Case C‑511/18
Case C‑512/18
Case C‑520/18
Procedure before the Court
Consideration of the questions referred
Question 1 in Cases C‑511/18 and C‑512/18 and questions 1 and 2 in Case C‑520/18
Preliminary remarks
Scope of Directive 2002/58
Interpretation of Article 15(1) of Directive 2002/58
– Legislative measures providing for the preventive retention of traffic and location data for the purpose of safeguarding national security
– Legislative measures providing for the preventive retention of traffic and location data for the purposes of combating crime and safeguarding public security
– Legislative measures providing for the preventive retention of IP addresses and data relating to civil identity for the purposes of combating crime and safeguarding public security
– Legislative measures providing for the expedited retention of traffic and location data for the purpose of combating serious crime
Questions 2 and 3 in Case C‑511/18
Automated analysis of traffic and location data
Real-time collection of traffic and location data
Notification of persons whose data has been collected or analysed
Question 2 in Case C‑512/18
Question 3 in Case C‑520/18
Costs
(Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Providers of electronic communications services – Hosting service providers and Internet access providers – General and indiscriminate retention of traffic and location data – Automated analysis of data – Real-time access to data – Safeguarding national security and combating terrorism – Combating crime – Directive 2002/58/EC – Scope – Article 1(3) and Article 3 – Confidentiality of electronic communications – Protection – Article 5 and Article 15(1) – Directive 2000/31/EC – Scope – Charter of Fundamental Rights of the European Union – Articles 4, 6, 7, 8 and 11 and Article 52(1) – Article 4(2) TEU)
In Joined Cases C‑511/18, C‑512/18 and C‑520/18,
REQUESTS for a preliminary ruling under Article 267 TFEU from the Conseil d’État (Council of State, France), made by decisions of 26 July 2018, received at the Court on 3 August 2018 (C‑511/18 and C‑512/18), and from the Cour constitutionnelle (Constitutional Court, Belgium), made by decision of 19 July 2018, received at the Court on 2 August 2018 (C‑520/18), in the proceedings
La Quadrature du Net (C‑511/18 and C‑512/18),
French Data Network (C‑511/18 and C‑512/18),
Fédération des fournisseurs d’accès à Internet associatifs (C‑511/18 and C‑512/18),
Igwan.net (C‑511/18)
v
Premier ministre (C‑511/18 and C‑512/18),
Garde des Sceaux, ministre de la Justice (C‑511/18 and C‑512/18),
Ministre de l’Intérieur (C‑511/18),
Ministre des Armées (C‑511/18),
interveners:
Privacy International (C‑512/18),
Center for Democracy and Technology (C‑512/18),
and
Ordre des barreaux francophones et germanophone,
Académie Fiscale ASBL,
UA,
Liga voor Mensenrechten ASBL,
Ligue des Droits de l’Homme ASBL,
VZ,
WY,
XX
v
Conseil des ministres,
interveners:
Child Focus (C‑520/18),
THE COURT (Grand Chamber),
composed of K. Lenaerts, President, R. Silva de Lapuerta, Vice-President, J.‑C. Bonichot, A. Arabadjiev, A. Prechal, M. Safjan, P.G. Xuereb and L.S. Rossi, Presidents of Chambers, J. Malenovský, L. Bay Larsen, T. von Danwitz (Rapporteur), C. Toader, K. Jürimäe, C. Lycourgos and N. Piçarra, Judges,
Advocate General: M. Campos Sánchez-Bordona,
Registrar: C. Strömholm, Administrator,
having regard to the written procedure and further to the hearing on 9 and 10 September 2019,
after considering the observations submitted on behalf of:
–
La Quadrature du Net, the Fédération des fournisseurs d’accès à Internet associatifs, Igwan.net and the Center for Democracy and Technology, by A. Fitzjean Ò Cobhthaigh, avocat,
–
French Data Network, by Y. Padova, avocat,
–
Privacy International, by H. Roy, avocat,
–
the Ordre des barreaux francophones et germanophone, by E. Kiehl, P. Limbrée, E. Lemmens, A. Cassart and J.‑F. Henrotte, avocats,
–
the Académie Fiscale ASBL and UA, by J.‑P. Riquet,
–
the Liga voor Mensenrechten ASBL, by J. Vander Velpen, avocat,
–
the Ligue des Droits de l’Homme ASBL, by R. Jespers and J. Fermon, avocats,
–
VZ, WY and XX, by D. Pattyn, avocat,
–
Child Focus, by N. Buisseret, K. De Meester and J. Van Cauter, avocats,
–
the French Government, initially by D. Dubois, F. Alabrune, D. Colas, E. de Moustier and A.‑L. Desjonquères, then by D. Dubois, F. Alabrune, E. de Moustier and A.‑L. Desjonquères, acting as Agents,
–
the Belgian Government, by J.‑C. Halleux, P. Cottin and C. Pochet, acting as Agents, and by J. Vanpraet, Y. Peeters, S. Depré and E. de Lophem, avocats,
–
the Czech Government, by M. Smolek, J. Vláčil and O. Serdula, acting as Agents,
–
the Danish Government, initially by J. Nymann-Lindegren, M. Wolff and P. Ngo, then by J. Nymann-Lindegren and M. Wolff, acting as Agents,
–
the German Government, initially by J. Möller, M. Hellmann, E. Lankenau, R. Kanitz and T. Henze, then by J. Möller, M. Hellmann, E. Lankenau and R. Kanitz, acting as Agents,
–
the Estonian Government, by N. Grünberg and A. Kalbus, acting as Agents,
–
Ireland, by A. Joyce, M. Browne and G. Hodge, acting as Agents, and by D. Fennelly, Barrister-at-Law,
–
the Spanish Government, initially by L. Aguilera Ruiz and A. Rubio González, then by L. Aguilera Ruiz, acting as Agent,
–
the Cypriot Government, by E. Neofytou, acting as Agent,
–
the Latvian Government, by V. Soņeca, acting as Agent,
–
the Hungarian Government, initially by M.Z. Fehér and Z. Wagner, then by M.Z. Fehér, acting as Agent,
–
the Netherlands Government, by M.K. Bulterman and M.A.M. de Ree, acting as Agents,
–
the Polish Government, by B. Majczyna, J. Sawicka and M. Pawlicka, acting as Agents,
–
the Swedish Government, initially by H. Shev, H. Eklinder, C. Meyer-Seitz and A. Falk, then by H. Shev, H. Eklinder, C. Meyer-Seitz and J. Lundberg, acting as Agents,
–
the United Kingdom Government, by S. Brandon, acting as Agent, and by G. Facenna QC and C. Knight, Barrister,
–
[indent deleted by order of 16 November 2020],
–
the European Commission, initially by H. Kranenborg, M. Wasmeier and P. Costa de Oliveira, then by H. Kranenborg and M. Wasmeier, acting as Agents,
–
the European Data Protection Supervisor, by T. Zerdick and A. Buchta, acting as Agents,
after hearing the Opinion of the Advocate General at the sitting on 15 January 2020,
gives the following
Judgment
1
These requests for a preliminary ruling concern the interpretation of Article 15(1) of Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) (OJ 2002 L 201, p. 37), as amended by Directive 2009/136/EC of the European Parliament and of the Council of 25 November 2009 (OJ 2009 L 337, p. 11) (‘Directive 2002/58’), and of Articles 12 to 15 of Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market (‘Directive on electronic commerce’) (OJ 2000 L 178, p. 1), read in the light of Articles 4, 6, 7, 8 and 11 and Article 52(1) of the Charter of Fundamental Rights of the European Union (‘the Charter’) and Article 4(2) TEU.
2
The request in Case C‑511/18 has been made in proceedings between La Quadrature du Net, French Data Network, the Fédération des fournisseurs d’accès à Internet associatifs and Igwan.net, on the one hand, and the Premier ministre (Prime Minister, France), the Garde des Sceaux, ministre de la Justice (Keeper of the Seals, Minister for Justice, France), the ministre de l’Intérieur (Minister for the Interior, France) and the ministre des Armées (Minister for the Armed Forces, France), on the other, concerning the lawfulness of: décret no 2015‑1185 du 28 septembre 2015 portant désignation des services spécialisés de renseignement (Decree No 2015‑1185 of 28 September 2015 designating specialised intelligence services) (Journal Officiel de la République Française (JORF) of 29 September 2015, text 1 of 97; ‘Decree No 2015‑1185’); décret no 2015‑1211 du 1er octobre 2015 relatif au contentieux de la mise en œuvre des techniques de renseignement soumises à autorisation et des fichiers intéressant la sûreté de l’État (Decree No 2015‑1211 of 1 October 2015 on litigation relating to the implementation of intelligence techniques subject to authorisation and files on matters of State security) (JORF of 2 October 2015, text 7 of 108; ‘Decree No 2015‑1211’), décret no 2015‑1639 du 11 décembre 2015 relatif à la désignation des services autres que les services spécialisés de renseignement, autorisés à recourir aux techniques mentionnées au titre V du livre VIII du code de la sécurité intérieure, pris en application de l’article L. 811‑4 du code de la sécurité intérieure (Decree No 2015‑1639 of 11 December 2015 on the designation of services other than the specialist intelligence services which are authorised to use the techniques referred to in Title V of Book VIII of the Internal Security Code, adopted pursuant to Article L. 811‑4 thereof) (JORF of 12 December 2015, text 28 of 127; ‘Decree No 2015‑1639’), and décret no 2016‑67 du 29 janvier 2016 relatif aux techniques de recueil de renseignement (Decree No 2016‑67 of 29 January 2016 on intelligence gathering techniques) (JORF of 31 January 2016, text 2 of 113; ‘Decree No 2016‑67’).
3
The request in Case C‑512/18 has been made in proceedings between French Data Network, La Quadrature du Net and the Fédération des fournisseurs d’accès à Internet associatifs, on the one hand, and the Prime Minister (France) and the Keeper of the Seals, Minister for Justice (France), on the other, concerning the lawfulness of Article R. 10‑13 of the code des postes et des communications électroniques (Post and Electronic Communications Code; ‘the CPCE’) and décret no 2011‑219 du 25 février 2011 relatif à la conservation et à la communication des données permettant d’identifier toute personne ayant contribué à la création d’un contenu mis en ligne (Decree No 2011‑219 of 25 February 2011 on the retention and communication of data that can be used to identify any person having assisted in the creation of content posted online) (JORF of 1 March 2011, text 32 of 170; ‘Decree No 2011‑219’).
4
The request in Case C‑520/18 has been made in proceedings between the Ordre des barreaux francophones et germanophone, the Académie Fiscale ASBL, UA, the Liga voor Mensenrechten ASBL, the Ligue des Droits de l’Homme ASBL, VZ, WY and XX, on the one hand, and the Conseil des ministres (Council of Ministers, Belgium), on the other, concerning the lawfulness of the loi du 29 mai 2016 relative à la collecte et à la conservation des données dans le secteur des communications électroniques (Law of 29 May 2016 on the collection and retention of data in the electronic telecommunications sector) (Moniteur belge of 18 July 2016, p. 44717; ‘the Law of 29 May 2016’).
Legislative framework
EU law
Directive 95/46
5
Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (OJ 1995 L 281, p. 31) was repealed with effect from 25 May 2018 by Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46 (OJ 2016 L 119, p 1). Article 3(2) of Directive 95/46 provided:
‘This Directive shall not apply to the processing of personal data:
–
in the course of an activity which falls outside the scope of Community law, such as those provided for by Titles V and VI of the Treaty on European Union and in any case to processing operations concerning public security, defence, State security (including the economic well-being of the State when the processing operation relates to State security matters) and the activities of the State in areas of criminal law,
–
by a natural person in the course of a purely personal or household act.’
6
Article 22 of Directive 95/46, which is in Chapter III of that directive, headed ‘Judicial remedies, liability and sanctions’, was worded as follows:
‘Without prejudice to any administrative remedy for which provision may be made, inter alia before the supervisory authority referred to in Article 28, prior to referral to the judicial authority, Member States shall provide for the right of every person to a judicial remedy for any breach of the rights guaranteed him by the national law applicable to the processing in question.’
Directive 97/66
7
Under Article 5 of Directive 97/66/EC of the European Parliament and of the Council of 15 December 1997 concerning the processing of personal data and the protection of privacy in the telecommunications sector (OJ 1998 L 24, p. 1), headed ‘Confidentiality of the communications’:
‘1. Member States shall ensure via national regulations the confidentiality of communications by means of a public telecommunications network and publicly available telecommunications services. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications, by others than users, without the consent of the users concerned, except when legally authorised, in accordance with Article 14(1).
2. Paragraph 1 shall not affect any legally authorised recording of communications in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.’
Directive 2000/31
8
Recitals 14 and 15 of Directive 2000/31 provide:
‘(14)
The protection of individuals with regard to the processing of personal data is solely governed by Directive [95/46] and Directive [97/66] which are fully applicable to information society services; these Directives already establish a Community legal framework in the field of personal data and therefore it is not necessary to cover this issue in this Directive in order to ensure the smooth functioning of the internal market, in particular the free movement of personal data between Member States; the implementation and application of this Directive should be made in full compliance with the principles relating to the protection of personal data, in particular as regards unsolicited commercial communication and the liability of intermediaries; this Directive cannot prevent the anonymous use of open networks such as the Internet.
(15)
The confidentiality of communications is guaranteed by Article 5 Directive [97/66]; in accordance with that Directive, Member States must prohibit any kind of interception or surveillance of such communications by others than the senders and receivers, except when legally authorised.’
9
Article 1 of Directive 2000/31 is worded as follows:
‘1. This Directive seeks to contribute to the proper functioning of the internal market by ensuring the free movement of information society services between the Member States.
2. This Directive approximates, to the extent necessary for the achievement of the objective set out in paragraph 1, certain national provisions on information society services relating to the internal market, the establishment of service providers, commercial communications, electronic contracts, the liability of intermediaries, codes of conduct, out-of-court dispute settlements, court actions and cooperation between Member States.
3. This Directive complements Community law applicable to information society services without prejudice to the level of protection for, in particular, public health and consumer interests, as established by Community acts and national legislation implementing them in so far as this does not restrict the freedom to provide information society services.
…
5. This Directive shall not apply to:
…
(b)
questions relating to information society services covered by Directives [95/46] and [97/66];
…’
10
Article 2 of Directive 2000/31 is worded as follows:
‘For the purpose of this Directive, the following terms shall bear the following meanings:
(a)
“information society services”: services within the meaning of Article 1(2) of Directive 98/34/EC [of the European Parliament and of the Council of 22 June 1998 laying down a procedure for the provision of information in the field of technical standards and regulations (OJ 1998 L 204, p. 37)] as amended by Directive 98/48/EC [of the European Parliament and of the Council of 20 July 1998 (OJ 1998 L 217, p. 18)];
…’
11
Article 15 of Directive 2000/31 provides:
‘1. ‘Member States shall not impose a general obligation on providers, when providing the services covered by Articles 12, 13 and 14, to monitor the information which they transmit or store, nor a general obligation actively to seek facts or circumstances indicating illegal activity.
2. Member States may establish obligations for information society service providers promptly to inform the competent public authorities of alleged illegal activities undertaken or information provided by recipients of their service or obligations to communicate to the competent authorities, at their request, information enabling the identification of recipients of their service with whom they have storage agreements.’
Directive 2002/21
12
Recital 10 of Directive 2002/21/EC of the European Parliament and of the Council of 7 March 2002 on a common regulatory framework for electronic communications networks and services (Framework Directive) (OJ 2002 L 108, p. 33) states:
‘The definition of “information society service” in Article 1 of Directive [98/34, as amended by Directive 98/48,] spans a wide range of economic activities which take place on-line. Most of these activities are not covered by the scope of this Directive because they do not consist wholly or mainly in the conveyance of signals on electronic communications networks. Voice telephony and electronic mail conveyance services are covered by this Directive. The same undertaking, for example an Internet service provider, can offer both an electronic communications service, such as access to the Internet, and services not covered under this Directive, such as the provision of web-based content.’
13
Article 2 of Directive 2002/21 provides:
‘For the purposes of this Directive:
…
(c)
“electronic communications service” means a service normally provided for remuneration which consists wholly or mainly in the conveyance of signals on electronic communications networks, including telecommunications services and transmission services in networks used for broadcasting, but exclude services providing, or exercising editorial control over, content transmitted using electronic communications networks and services; it does not include information society services, as defined in Article 1 of Directive [98/34], which do not consist wholly or mainly in the conveyance of signals on electronic communications networks;
…’
Directive 2002/58
14
Recitals 2, 6, 7, 11, 22, 26 and 30 of Directive 2002/58 state:
‘(2)
This Directive seeks to respect the fundamental rights and observes the principles recognised in particular by the [Charter]. In particular, this Directive seeks to ensure full respect for the rights set out in Articles 7 and 8 of that Charter.
…
(6)
The Internet is overturning traditional market structures by providing a common, global infrastructure for the delivery of a wide range of electronic communications services. Publicly available electronic communications services over the Internet open new possibilities for users but also new risks for their personal data and privacy.
(7)
In the case of public communications networks, specific legal, regulatory and technical provisions should be made in order to protect fundamental rights and freedoms of natural persons and legitimate interests of legal persons, in particular with regard to the increasing capacity for automated storage and processing of data relating to subscribers and users.
…
(11)
Like Directive [95/46], this Directive does not address issues of protection of fundamental rights and freedoms related to activities which are not governed by [Union] law. Therefore it does not alter the existing balance between the individual’s right to privacy and the possibility for Member States to take the measures referred to in Article 15(1) of this Directive, necessary for the protection of public security, defence, State security (including the economic well-being of the State when the activities relate to State security matters) and the enforcement of criminal law. Consequently, this Directive does not affect the ability of Member States to carry out lawful interception of electronic communications, or take other measures, if necessary for any of these purposes and in accordance with the European Convention for the Protection of Human Rights and Fundamental Freedoms, [signed in Rome on 4 November 1950,] as interpreted by the rulings of the European Court of Human Rights. Such measures must be appropriate, strictly proportionate to the intended purpose and necessary within a democratic society and should be subject to adequate safeguards in accordance with the European Convention for the Protection of Human Rights and Fundamental Freedoms.
…
(22)
The prohibition of storage of communications and the related traffic data by persons other than the users or without their consent is not intended to prohibit any automatic, intermediate and transient storage of this information in so far as this takes place for the sole purpose of carrying out the transmission in the electronic communications network and provided that the information is not stored for any period longer than is necessary for the transmission and for traffic management purposes, and that during the period of storage the confidentiality remains guaranteed. …
…
(26)
The data relating to subscribers processed within electronic communications networks to establish connections and to transmit information contain information on the private life of natural persons and concern the right to respect for their correspondence or concern the legitimate interests of legal persons. Such data may only be stored to the extent that is necessary for the provision of the service for the purpose of billing and for interconnection payments, and for a limited time. Any further processing of such data … may only be allowed if the subscriber has agreed to this on the basis of accurate and full information given by the provider of the publicly available electronic communications services about the types of further processing it intends to perform and about the subscriber’s right not to give or to withdraw his/her consent to such processing. Traffic data used for marketing communications services … should also be erased or made anonymous …
…
(30)
Systems for the provision of electronic communications networks and services should be designed to limit the amount of personal data necessary to a strict minimum. …’
15
Article 1 of Directive 2002/58, headed ‘Scope and aim’, provides:
‘1. This Directive provides for the harmonisation of the national provisions required to ensure an equivalent level of protection of fundamental rights and freedoms, and in particular the right to privacy and confidentiality, with respect to the processing of personal data in the electronic communication sector and to ensure the free movement of such data and of electronic communication equipment and services in the [European Union].
2. The provisions of this Directive particularise and complement Directive [95/46] for the purposes mentioned in paragraph 1. Moreover, they provide for protection of the legitimate interests of subscribers who are legal persons.
3. This Directive shall not apply to activities which fall outside the scope of the [TFEU], such as those covered by Titles V and VI of the Treaty on European Union, and in any case to activities concerning public security, defence, State security (including the economic well-being of the State when the activities relate to State security matters) and the activities of the State in areas of criminal law.’
16
Article 2 of Directive 2002/58, headed ‘Definitions’, provides:
‘Save as otherwise provided, the definitions in Directive [95/46] and in Directive [2002/21] shall apply.
The following definitions shall also apply:
(a)
“user” means any natural person using a publicly available electronic communications service, for private or business purposes, without necessarily having subscribed to this service;
(b)
“traffic data” means any data processed for the purpose of the conveyance of a communication on an electronic communications network or for the billing thereof;
(c)
“location data” means any data processed in an electronic communications network or by an electronic communications service, indicating the geographic position of the terminal equipment of a user of a publicly available electronic communications service;
(d)
“communication” means any information exchanged or conveyed between a finite number of parties by means of a publicly available electronic communications service. This does not include any information conveyed as part of a broadcasting service to the public over an electronic communications network except to the extent that the information can be related to the identifiable subscriber or user receiving the information;
…’
17
Article 3 of Directive 2002/58, headed ‘Services concerned’, provides:
‘This Directive shall apply to the processing of personal data in connection with the provision of publicly available electronic communications services in public communications networks in the Community, including public communications networks supporting data collection and identification devices.’
18
Article 5 of Directive 2002/58, headed ‘Confidentiality of the communications’, provides:
‘1. Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
…
3. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive [95/46], inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.’
19
Article 6 of Directive 2002/58, headed ‘Traffic data’, provides:
‘1. Traffic data relating to subscribers and users processed and stored by the provider of a public communications network or publicly available electronic communications service must be erased or made anonymous when it is no longer needed for the purpose of the transmission of a communication without prejudice to paragraphs 2, 3 and 5 of this Article and Article 15(1).
2. Traffic data necessary for the purposes of subscriber billing and interconnection payments may be processed. Such processing is permissible only up to the end of the period during which the bill may lawfully be challenged or payment pursued.
3. For the purpose of marketing electronic communications services or for the provision of value added services, the provider of a publicly available electronic communications service may process the data referred to in paragraph 1 to the extent and for the duration necessary for such services or marketing, if the subscriber or user to whom the data relate has given his or her prior consent. Users or subscribers shall be given the possibility to withdraw their consent for the processing of traffic data at any time.
…
5. Processing of traffic data, in accordance with paragraphs 1, 2, 3 and 4, must be restricted to persons acting under the authority of providers of the public communications networks and publicly available electronic communications services handling billing or traffic management, customer enquiries, fraud detection, marketing electronic communications services or providing a value added service, and must be restricted to what is necessary for the purposes of such activities.
…’
20
Article 9(1) of that directive, that article being headed ‘Location data other than traffic data’, provides:
‘Where location data other than traffic data, relating to users or subscribers of public communications networks or publicly available electronic communications services, can be processed, such data may only be processed when they are made anonymous, or with the consent of the users or subscribers to the extent and for the duration necessary for the provision of a value added service. The service provider must inform the users or subscribers, prior to obtaining their consent, of the type of location data other than traffic data which will be processed, of the purposes and duration of the processing and whether the data will be transmitted to a third party for the purpose of providing the value added service. …’
21
Article 15 of that directive, headed ‘Application of certain provisions of Directive [95/46]’, states:
‘1. Member States may adopt legislative measures to restrict the scope of the rights and obligations provided for in Article 5, Article 6, Article 8(1), (2), (3) and (4), and Article 9 of this Directive when such restriction constitutes a necessary, appropriate and proportionate measure within a democratic society to safeguard national security (i.e. State security), defence, public security, and the prevention, investigation, detection and prosecution of criminal offences or of unauthorised use of the electronic communication system, as referred to in Article 13(1) of Directive [95/46]. To this end, Member States may, inter alia, adopt legislative measures providing for the retention of data for a limited period justified on the grounds laid down in this paragraph. All the measures referred to in this paragraph shall be in accordance with the general principles of [Union] law, including those referred to in Article 6(1) and (2) of the Treaty on European Union.
…
2. The provisions of Chapter III on judicial remedies, liability and sanctions of Directive [95/46] shall apply with regard to national provisions adopted pursuant to this Directive and with regard to the individual rights derived from this Directive.
…’
Regulation 2016/679
22
Recital 10 of Regulation 2016/679 states:
‘In order to ensure a consistent and high level of protection of natural persons and to remove the obstacles to flows of personal data within the Union, the level of protection of the rights and freedoms of natural persons with regard to the processing of such data should be equivalent in all Member States. Consistent and homogenous application of the rules for the protection of the fundamental rights and freedoms of natural persons with regard to the processing of personal data should be ensured throughout the Union. …’
23
Article 2 of that regulation provides:
‘1. This Regulation applies to the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system or are intended to form part of a filing system.
2. This Regulation does not apply to the processing of personal data:
(a)
in the course of an activity which falls outside the scope of Union law;
(b)
by the Member States when carrying out activities which fall within the scope of Chapter 2 of Title V of the TEU;
…
(d)
by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security.
…
4. This Regulation shall be without prejudice to the application of Directive [2000/31], in particular of the liability rules of intermediary service providers in Articles 12 to 15 of that Directive.’
24
Article 4 of that regulation reads as follows:
‘For the purposes of this Regulation:
(1)
“personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;
(2)
“processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction;
…’
25
Article 5 of Regulation 2016/679 provides:
‘1. Personal data shall be:
(a)
processed lawfully, fairly and in a transparent manner in relation to the data subject (“lawfulness, fairness and transparency”);
(b)
collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes; further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes shall, in accordance with Article 89(1), not be considered to be incompatible with the initial purposes (“purpose limitation”);
(c)
adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed (“data minimisation”);
(d)
accurate and, where necessary, kept up to date; every reasonable step must be taken to ensure that personal data that are inaccurate, having regard to the purposes for which they are processed, are erased or rectified without delay (“accuracy”);
(e)
kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed; personal data may be stored for longer periods in so far as the personal data will be processed solely for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Article 89(1) subject to implementation of the appropriate technical and organisational measures required by this Regulation in order to safeguard the rights and freedoms of the data subject (“storage limitation”);
(f)
processed in a manner that ensures appropriate security of the personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical or organisational measures (“integrity and confidentiality”).
…’
26
Article 6 of that regulation reads as follows:
‘1. Processing shall be lawful only if and to the extent that at least one of the following applies:
…
(c)
processing is necessary for compliance with a legal obligation to which the controller is subject;
…
3. The basis for the processing referred to in point (c) and (e) of paragraph 1 shall be laid down by:
(a)
Union law; or
(b)
Member State law to which the controller is subject.
The purpose of the processing shall be determined in that legal basis … That legal basis may contain specific provisions to adapt the application of rules of this Regulation, inter alia: the general conditions governing the lawfulness of processing by the controller; the types of data which are subject to the processing; the data subjects concerned; the entities to, and the purposes for which, the personal data may be disclosed; the purpose limitation; storage periods; and processing operations and processing procedures, including measures to ensure lawful and fair processing such as those for other specific processing situations as provided for in Chapter IX. The Union or the Member State law shall meet an objective of public interest and be proportionate to the legitimate aim pursued.
…’
27
Article 23 of that regulation provides:
‘1. Union or Member State law to which the data controller or processor is subject may restrict by way of a legislative measure the scope of the obligations and rights provided for in Articles 12 to 22 and Article 34, as well as Article 5 in so far as its provisions correspond to the rights and obligations provided for in Articles 12 to 22, when such a restriction respects the essence of the fundamental rights and freedoms and is a necessary and proportionate measure in a democratic society to safeguard:
(a)
national security;
(b)
defence;
(c)
public security;
(d)
the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security;
(e)
other important objectives of general public interest of the Union or of a Member State, in particular an important economic or financial interest of the Union or of a Member State, including monetary, budgetary and taxation … matters, public health and social security;
(f)
the protection of judicial independence and judicial proceedings;
(g)
the prevention, investigation, detection and prosecution of breaches of ethics for regulated professions;
(h)
a monitoring, inspection or regulatory function connected, even occasionally, to the exercise of official authority in the cases referred to in points (a) to (e) and (g);
(i)
the protection of the data subject or the rights and freedoms of others;
(j)
the enforcement of civil law claims.
2. In particular, any legislative measure referred to in paragraph 1 shall contain specific provisions at least, where relevant, as to:
(a)
the purposes of the processing or categories of processing;
(b)
the categories of personal data;
(c)
the scope of the restrictions introduced;
(d)
the safeguards to prevent abuse or unlawful access or transfer;
(e)
the specification of the controller or categories of controllers;
(f)
the storage periods and the applicable safeguards taking into account the nature, scope and purposes of the processing or categories of processing;
(g)
the risks to the rights and freedoms of data subjects; and
(h)
the right of data subjects to be informed about the restriction, unless that may be prejudicial to the purpose of the restriction.’
28
Under Article 79(1) of that regulation:
‘Without prejudice to any available administrative or non-judicial remedy, including the right to lodge a complaint with a supervisory authority pursuant to Article 77, each data subject shall have the right to an effective judicial remedy where he or she considers that his or her rights under this Regulation have been infringed as a result of the processing of his or her personal data in non-compliance with this Regulation.’
29
Article 94 of Regulation 2016/679 provides:
‘1. Directive [95/46] is repealed with effect from 25 May 2018.
2. References to the repealed Directive shall be construed as references to this Regulation. References to the Working Party on the Protection of Individuals with regard to the Processing of Personal Data established by Article 29 of Directive [95/46] shall be construed as references to the European Data Protection Board established by this Regulation.’
30
Article 95 of that regulation provides:
‘This Regulation shall not impose additional obligations on natural or legal persons in relation to processing in connection with the provision of publicly available electronic communications services in public communication networks in the Union in relation to matters for which they are subject to specific obligations with the same objective set out in Directive [2002/58].’
French law
Code de la sécurité intérieure (Internal Security Code)
31
Book VIII of the legislative part of the code de la sécurité intérieure (Internal Security Code; ‘the CSI’) lays down rules relating to intelligence in Articles L. 801‑1 to L. 898‑1.
32
Article L. 811‑3 of the CSI states:
‘For the sole performance of their respective tasks, the specialised intelligence services may use the techniques referred to in Title V of this Book in order to gather intelligence relating to the protection and promotion of the following fundamental State interests:
1.
National independence, territorial integrity and national defence;
2.
Major foreign policy interests, the implementation of France’s European and international commitments and the prevention of all forms of foreign interference;
3.
France’s major economic, industrial and scientific interests;
4.
The prevention of terrorism;
5.
The prevention of:
(a)
attacks against the republican nature of the institutions;
(b)
actions designed to maintain or rebuild groups that have been disbanded under Article L. 212‑1;
(c)
collective violence liable to cause serious disruption to the maintenance of law and order;
6.
The prevention of organised crime;
7.
The prevention of the proliferation of weapons of mass destruction.’
33
Article L. 811‑4 of the CSI provides:
‘A decree adopted in the Conseil d’État (Council of State, France) following consultation of the Commission nationale de contrôle des techniques de renseignement (Commission for the Oversight of Intelligence Techniques, France) shall designate the services, other than the specialised intelligence services, within the purview of the Ministers for Defence, the Interior and Justice and the ministers responsible for economic affairs, the budget and customs, which may be authorised to use the techniques referred to in Title V of the present Book under the conditions laid down in this Book. It shall specify, for each service, the purposes mentioned in Article L. 811‑3 and the techniques which may be authorised.’
34
The first paragraph of Article L. 821‑1 of the CSI is worded as follows:
‘The implementation on national territory of the intelligence gathering techniques referred to in Chapters I to IV of Title V of this Book shall be subject to prior authorisation from the Prime Minister following consultation of the Commission for the Oversight of Intelligence Techniques.’
35
Article L. 821‑2 of the CSI provides:
‘The authorisation mentioned in Article L. 821‑1 shall be issued upon a written and reasoned application from the Minister for Defence, the Minister for the Interior, the Minister for Justice or the ministers responsible for economic affairs, the budget or customs. Each minister may delegate that power individually only to immediate staff with clearance to handle confidential material relating to national defence.
The application shall state:
1. the technique(s) to be implemented;
2. the service for which it is submitted;
3. the purpose(s) pursued;
4. the reason(s) for the measures;
5. the period of validity of the authorisation;
6. the person(s), place(s) or vehicle(s) concerned.
In respect of point 6, persons whose identity is not known may be designated by their identifiers or status and places or vehicles may be designated by reference to the persons who are the subject of the application.
…’
36
Under the first paragraph of Article L. 821‑3 of the CSI:
‘The application shall be sent to the President or, failing that, to one of the members of the Commission for the Oversight of Intelligence Techniques mentioned in points 2 and 3 of Article L. 831‑1, who shall provide the Prime Minister with an opinion within 24 hours. If the application is examined by the select panel or the full panel of the Commission, the Prime Minister shall be informed forthwith and the opinion shall be issued within 72 hours.’
37
Article L. 821‑4 of the CSI provides:
‘Authorisation to implement the techniques referred to in Chapters I to IV of Title V of this Book shall be issued by the Prime Minister for a maximum period of four months. … The authorisation shall contain the grounds and statements set out in points 1 to 6 of Article L. 821‑2. All authorisations shall be renewable under the same conditions as those laid down in this Chapter.
Where the authorisation is issued after obtaining an unfavourable opinion from the Commission for the Oversight of Intelligence Techniques, it shall state the reasons why that opinion was not followed.
…’
38
Article L. 833‑4 of the CSI, which appears in Chapter III of Title III, provides:
‘The Commission shall – on its own initiative or after receiving a complaint from any person wishing to verify that no intelligence techniques have been unlawfully implemented against him or her – conduct a review of the technique or techniques referred to with a view to determining whether they have been or are being implemented in accordance with this Book. It shall notify the complainant that the necessary investigations have been carried out, without confirming or denying their implementation.’
39
The first and second paragraphs of Article L. 841‑1 of the CSI read as follows:
‘Subject to the special provisions set out in Article L. 854‑9 of this Code, the Conseil d’État (Council of State, France) shall have jurisdiction to hear, under the conditions laid down in Chapter III bis of Title VII of Book VII of the code de justice administrative (Code of Administrative Justice), actions concerning the implementation of the intelligence techniques referred to in Title V of this Book.
An action may be brought before it by:
1. any person wishing to verify that no intelligence techniques have been unlawfully implemented against him or her and who can demonstrate that the procedure provided for in Article L. 833‑4 has been conducted beforehand;
2. the Commission for the Oversight of Intelligence Techniques, under the conditions laid down in Article L. 833‑8.’
40
Title V of Book VIII of the legislative part of the CSI, concerning ‘intelligence gathering techniques subject to authorisation’, includes, inter alia, Chapter I, headed ‘Access of the administrative authorities to connection data’, containing Articles L. 851‑1 to L. 851‑7 of the CSI.
41
Article L. 851‑1 of the CSI provides:
‘Subject to the conditions laid down in Chapter I of Title II of this Book, the collection of information or documents processed or retained by their networks or electronic communications services, including technical data relating to the identification of the subscription or connection numbers to electronic communications services, the inventorying of the subscription and connection numbers of a specified person, the location of the terminal equipment used and the communications of a subscriber, namely the list of numbers called and calling and the duration and date of the communications, may be authorised from electronic communications operators and the persons referred to in Article L. 34‑1 of the [CPCE] as well as from the persons referred to in Article 6(I)(1) and (2) of Loi n.° 2004‑575 du 21 juin 2004 pour la confiance dans l’économie numérique (Law No 2004‑575 of 21 June 2004 to promote trust in the digital economy) [(JORF of 22 June 2004, p. 11168)].
By way of derogation from Article L. 821‑2, written and reasoned applications for technical data relating to the identification of subscription or connection numbers to electronic communications services, or the inventorying of all the subscription or connection numbers of a specified person, shall be sent directly to the Commission for the Oversight of Intelligence Techniques by individually designated and authorised agents of the intelligence services referred to in Articles L. 811‑2 and L. 811‑4. The Commission shall issue its opinion under the conditions laid down in Article L. 821‑3.
A department reporting to the Prime Minister shall be responsible for gathering information or documents from the operators and persons referred to in the first paragraph of this article. The Commission for the Oversight of Intelligence Techniques shall have permanent, complete, direct and immediate access to the information or documents collected.
The detailed rules for the application of this article shall be laid down by decree adopted in the Conseil d’État (Council of State, France) following consultation of the Commission nationale de l’informatique et des libertés (Data Protection Authority, France) and the Commission for the Oversight of Intelligence Techniques.’
42
Article L. 851‑2 of the CSI provides:
‘I. Under the conditions laid down in Chapter I of Title II of this Book, and for the sole purpose of preventing terrorism, the collection in real time, on the networks of the operators and persons referred to in Article L. 851‑1, of the information or documents referred to in that article relating to a person previously identified as potentially having links to a threat, may be individually authorised. Where there are substantial grounds for believing that one or more persons belonging to the circle of the person to whom the authorisation relates are capable of providing information in respect of the purpose for which the authorisation was granted, authorisation may also be granted individually for each of those persons.
I bis. The maximum number of authorisations issued under this article in force at the same time shall be determined by the Prime Minister following consultation of the Commission for the Oversight of Intelligence Techniques. The decision establishing that quota and how it is to be allocated between the ministers referred to in the first paragraph of Article L. 821‑2, together with the number of interception authorisations issued, shall be forwarded to the Commission.
…’
43
Article L. 851‑3 of the CSI provides:
‘I. Under the conditions laid down in Chapter I of Title II of this Book, and for the sole purpose of preventing terrorism, the operators and persons referred to in Article L. 851‑1 may be required to implement on their networks automated data processing practices designed, within the parameters laid down in the authorisation, to detect links that might constitute a terrorist threat.
Such automated processing shall exclusively use the information or documents referred to in Article L. 851‑1 and shall not collect any data other than data meeting the design parameters or allow the identification of the persons to whom the information or documents relate.
In accordance with the principle of proportionality, the authorisation of the Prime Minister shall specify the technical scope of the implementation of those processing practices.
II. The Commission for the Oversight of Intelligence Techniques shall issue an opinion on the application for authorisation for automated processing and the chosen detection parameters. It shall have permanent, complete and direct access to those processing practices and to the information and data collected. It shall be informed of any changes to the processing practices and parameters and may issue recommendations.
The first authorisation for the implementation of automated processing practices provided for in point I of this article shall be issued for a period of two months. The authorisation shall be renewable under the conditions on duration laid down in Chapter I of Title II of this Book. The application for renewal shall include a record of the number of identifiers flagged by the automated processing and an analysis of the relevance of that flagging.
III. The conditions laid down in Article L. 871‑6 are applicable to the physical operations performed by the operators and persons referred to in Article L. 851‑1 for the purpose of implementing such processing.
IV. Where the processing practices mentioned in point I of this article detect data likely to point to the existence of a terrorist threat, the Prime Minister or one of the persons delegated by him or her may – following consultation of the Commission for the Oversight of Intelligence Techniques under the conditions laid down in Chapter I of Title II of this Book – authorise the identification of the person or persons concerned and the collection of the related data. The data shall be used within 60 days of collection and shall be destroyed upon expiry of that period, unless there are substantial grounds confirming the existence of a terrorist threat associated with one or more of the persons concerned.
…’
44
Article L. 851‑4 of the CSI reads as follows:
‘Under the conditions laid down in Chapter I of Title II of this Book, technical data relating to the location of the terminal equipment used, as mentioned in Article L. 851‑1, may be collected upon request from the network and transmitted in real time by the operators to a department reporting to the Prime Minister.’
45
Article R. 851‑5 of the CSI, which appears in the regulatory part of that code, provides:
‘I. The information or documents referred to in Article L. 851‑1 are – excluding the content of the correspondence or the information consulted – as follows:
1. Those listed in Articles R. 10‑13 and R. 10‑14 of the [CPCE] and in Article 1 of Decree [No 2011‑219];
2. Technical data other than the data mentioned in point 1:
(a) enabling terminal equipment to be located;
(b) relating to access by terminal equipment to online public communication networks or services;
(c) relating to the conveyance of electronic communications by networks;
(d) relating to the identification and authentication of a user, a connection, a network or an online public communication service;
(e) relating to the characteristics of terminal equipment and the configuration data of their software.
II. Only the information and documents referred to in point I(1) may be collected pursuant to Article L. 851‑1. Such collection shall take place in non-real time.
The information listed in point I(2) may be collected only pursuant to Articles L. 851‑2 and L. 851‑3 under the conditions and within the limits laid down in those articles and subject to the application of Article R. 851‑9.’
The CPCE
46
Article L. 34‑1 of the CPCE states:
‘I. This article shall apply to the processing of personal data in the course of the provision to the public of electronic communications services; it shall apply in particular to networks that support data collection and identification devices.
II. Electronic communications operators, in particular persons whose business is to provide access to online public communication services, shall erase or render anonymous any data relating to traffic, subject to the provisions contained in points III, IV, V and VI.
Persons who provide electronic communications services to the public shall, with due regard for the provisions contained in the preceding paragraph, establish internal procedures for responding to requests from the competent authorities.
Persons who, as a principal or ancillary business activity, provide to the public a connection allowing online communication via access to the network shall, including where this is offered free of charge, be subject to compliance with the provisions applicable to electronic communications operators under this article.
III. For the purposes of investigating, detecting and prosecuting criminal offences or a failure to fulfil an obligation laid down in Article L. 336‑3 of the code de la propriété intellectuelle (Intellectual Property Code) or for the purposes of preventing breaches of automated data processing systems as provided for and punishable under Articles 323‑1 to 323‑3‑1 of the Code pénal (Criminal Code), and for the sole purpose of making information available, as necessary, to the judicial authority or high authority mentioned in Article L. 331‑12 of the Intellectual Property Code or to the national authority for the security of information systems mentioned in Article L. 2321‑1 of the code de la défense (Defence Code), operations designed to erase or render anonymous certain categories of technical data may be deferred for a maximum period of one year. A decree adopted in the Conseil d’État (Council of State, France) following consultation of the Data Protection Authority shall, within the limits laid down in point VI, determine the categories of data involved and the period for which they are to be retained, depending on the business of the operators, the nature of the communications and the methods of offsetting any identifiable and specific additional costs associated with the services provided for these purposes by operators at the request of the State.
…
VI. Data retained and processed under the conditions set out in points III, IV and V shall relate exclusively to the identification of persons using the services provided by operators, the technical characteristics of the communications provided by the latter and the location of terminal equipment.
Under no circumstance may such data relate to the content of the correspondence or the information consulted, in any form whatsoever, as part of those communications.
The retention and processing of such data shall be effected with due regard for the provisions of loi no 78‑17 du 6 janvier 1978 relative à l’informatique, aux fichiers et aux libertés (Law No 78‑17 of 6 January 1978 on information technology, files and freedoms).
Operators shall take any measures necessary to prevent such data from being used for purposes other than those provided for in this article.’
47
Article R. 10‑13 of the CPCE reads as follows:
‘I. Pursuant to point III of Article L. 34‑1, electronic communications operators shall retain the following data for the purposes of investigating, detecting and prosecuting criminal offences:
(a) Information identifying the user;
(b) Data relating to the communications terminal equipment used;
(c) The technical characteristics and date, time and duration of each communication;
(d) Data relating to the additional services requested or used and the providers of those services;
(e) Data identifying the addressee or addressees of the communication.
II. In the case of telephony activities, the operator shall retain the data referred to in point II and, additionally, data enabling the origin and location of the communication to be identified.
III. The data referred to in this article shall be retained for one year from the date of registration.
IV. Identifiable and specific additional costs borne by operators which have been ordered by judicial authorities to provide data falling within the categories mentioned in this article shall be offset in accordance with the methods laid down in Article R. 213‑1 of the code de procédure pénale (Code of Criminal Procedure).’
48
Article R. 10‑14 of the CPCE provides:
‘I. Pursuant to point IV of Article L. 34‑1, electronic communications operators are authorised to retain technical data identifying the user and the data mentioned in Article R. 10‑13(I)(b), (c) and (d) for the purposes of their billing and payment operations.
II. In the case of telephony activities, operators may retain, in addition to the data mentioned in point I, technical data relating to the location of the communication and the identification of the addressee or addressees of the communication and data for billing purposes.
III. The data mentioned in points I and II of this article may be retained only if it is necessary for billing purposes and for the payment of services rendered. Its retention shall be limited to the time strictly necessary for that purpose and shall not exceed one year.
IV. Operators may retain the following data for a period not exceeding three months to ensure the security of networks and facilities:
(a) Data identifying the origin of the communication;
(b) The technical characteristics and date, time and duration of each communication;
(c) Technical data identifying the addressee or addressees of the communication;
(d) Data relating to the additional services requested or used and the providers of those services.’
Loi no 2004‑575 du 21 juin 2004 pour la confiance dans l’économie numérique (Law No 2004‑575 of 21 June 2004 to promote trust in the digital economy)
49
Article 6 of Loi no 2004‑575 du 21 juin 2004 pour la confiance dans l’économie numérique (Law No 2004‑575 of 21 June 2004 to promote trust in the digital economy) (JORF of 22 June 2004, p. 11168; ‘the LCEN’) provides:
‘I. 1. Persons whose business is to provide access to online public communication services shall inform their subscribers of the existence of technical tools enabling access to some services to be restricted or for a selection of those services to be made and shall offer them at least one of those tools.
…
2. Natural or legal persons who, even free of charge, and for provision to the public via online public communications services, store signals, writing, images, sounds or messages of any kind provided by recipients of those services, may not incur any civil liability for the activities or information stored at the request of a recipient of those services if they had no actual knowledge of either the unlawful nature of the activities or information in question or of the facts and circumstances pointing to their unlawful nature, or if, as soon as they became aware of that unlawful nature, they acted expeditiously to remove the data at issue or block access to them.
…
II. The persons referred to in point I(1) and (2) shall keep and retain the data in such a way as to make it possible to identify anyone who has assisted in the creation of all or part of the content of the services of which they are the providers.
They shall provide persons who publish an online public communication service with technical tools enabling them to satisfy the identification conditions laid down in point III.
A judicial authority may require the service providers mentioned in point I(1) and (2) to communicate the data referred to in the first paragraph.
The provisions of Articles 226‑17, 226‑21 and 226‑22 of the Criminal Code shall apply to the processing of that data.
A decree adopted in the Conseil d’État (Council of State, France) following consultation of the Data Protection Authority shall define the data referred to in the first paragraph and determine the period for which, and the methods by which, that data is to be retained.
…’
Decree No 2011‑219
50
Chapter I of Decree No 2011‑219, adopted on the basis of the last paragraph of Article 6(II) of the LCEN, contains Articles 1 to 4 of that decree.
51
Article 1 of Decree No 2011‑219 provides:
‘The following data is the data referred to in Article 6(II) of the [LCEN], which persons are required to retain under that provision:
1. For the persons referred to in point I(1) of that article and for each connection of their subscribers:
(a)
The connection identifier;
(b)
The identifier assigned by those persons to the subscriber;
(c)
The identifier of the terminal used for the connection when they have access to it;
(d)
The date and time of the start and end of the connection;
(e)
The characteristics of the subscriber’s line.
2. For the persons referred to in point I(2) of that article and for each creation operation:
(a)
The identifier of the connection giving rise to the communication;
(b)
The identifier assigned by the information system to the content forming the subject of the operation;
(c)
The types of protocols used to connect to the service and transfer the content;
(d)
The nature of the operation;
(e)
The date and time of the operation;
(f)
The identifier used by the author of the operation where provided by the author.
3. For the persons referred to in point I(1) and (2) of that article, the information provided by a user when signing up to a contract or creating an account:
(a)
The identifier of the connection at the time when the account was created;
(b)
The first name and surname or business name;
(c)
The associated postal addresses;
(d)
The pseudonyms used;
(e)
The associated email or account addresses;
(f)
The telephone numbers;
(g)
The updated password and the data for verifying or changing it.
4. For the persons referred to in point I(1) and (2) of that article, where the signing up to the contract or the account is subject to payment, the following information relating to the payment, for each payment operation:
(a)
The type of payment used;
(b)
The payment reference;
(c)
The amount;
(d)
The date and time of the transaction.
The data mentioned in points 3 and 4 shall be retained only to the extent that the persons ordinarily collect such data.’
52
Article 2 of that decree reads as follows:
‘Contributing to the creation of content involves the following operations:
(a)
Initial content creation;
(b)
Changes to content and content-related data;
(c)
Content erasure.’
53
Article 3 of that decree provides:
‘The data referred to in Article 1 shall be retained for one year from the date of:
(a)
creation of the content, for each operation contributing to the creation of content as defined in Article 2, as regards the data mentioned in points 1 and 2;
(b)
termination of the contract or closure of the account, as regards the data mentioned in point 3;
(c)
issue of the bill or the payment operation, for each bill or payment operation, as regards the data mentioned in point 4.’
Belgian law
54
The Law of 29 May 2016 amended, in particular, the loi du 13 juin 2005 relative aux communications électroniques (Law of 13 June 2005 on electronic communications) (Moniteur belge of 20 June 2005, p. 28070; ‘the Law of 13 June 2005’), the code d’instruction criminelle (Code of Criminal Procedure) and the loi du 30 novembre 1998 organique des services de renseignement et de sécurité (Basic Law of 30 November 1998 on the intelligence and security services) (Moniteur belge of 18 December 1998, p. 40312; ‘the Law of 30 November 1998’).
55
Article 126 of the Law of 13 June 2005, as amended by the Law of 29 May 2016, provides:
‘1. Without prejudice to the Loi du 8 décembre 1992 relative à la protection de la vie privée à l’égard des traitements de données à caractère personnel (Law of 8 December 1992 on the protection of privacy with respect to the processing of personal data), providers to the public of telephony services, including via the Internet, Internet access and Internet-based email, operators providing public electronic communications networks and operators providing any of those services shall retain the data referred to in paragraph 3 where that data is generated or processed by them in the course of providing the communications services concerned.
This article shall not concern the content of communications.
The obligation to retain the data referred to in paragraph 3 shall also apply to unsuccessful call attempts, provided that that data is, in the course of providing the communications services concerned:
(1) generated or processed by operators of publicly available electronic communications services or of a public electronic communications network, so far as concerns telephony data, or
(2) logged by those providers, so far as concerns Internet data.
2. Data retained under this article may be obtained, by simple request, from the providers and operators referred to in the first subparagraph of paragraph 1, for the purposes and under the conditions listed below, only by the following authorities:
(1) judicial authorities, with a view to the investigation, detection and prosecution of offences, in order to execute the measures referred to in Articles 46bis and 88bis of the Code of Criminal Procedure and under the conditions laid down in those articles;
(2) under the conditions laid down in this law, intelligence and security services, in order to carry out intelligence missions employing the data-gathering methods referred to in Articles 16/2, 18/7 and 18/8 of the Basic Law of 30 November 1998 on the intelligence and security services;
(3) any judicial police officer attached to the [Institut belge des services postaux et des télécommunications (Belgian Institute for Postal Services and Telecommunications)], with a view to the investigation, detection and prosecution of offences contrary to Articles 114 and 124 and this article;
(4) emergency services providing on-site assistance, in the case where, after having received an emergency call, they cannot obtain from the provider or operator concerned the data identifying the person having made the emergency call using the database referred to in the third subparagraph of Article 107(2), or obtain incomplete or incorrect data. Only the data identifying the caller may be requested and the request must be made no later than 24 hours after the call;
(5) any judicial police officer attached to the Missing Persons Unit of the Federal Police, in the course of his or her task of providing assistance to persons in danger, searching for persons whose disappearance is a cause for concern and in cases where there are serious presumptions or indications that the physical well-being of the missing person is in imminent danger. Only the data referred to in the first and second subparagraphs of paragraph 3, relating to the missing person, and retained during the 48 hours prior to the data request, may be requested from the operator or provider concerned via a police service designated by the King;
(6) the Telecommunications Ombudsman, with a view to identifying a person who has misused an electronic communications network or service, in accordance with the conditions laid down in Article 43bis(3)(7) of the loi du 21 mars 1991 portant réforme de certaines entreprises publiques économiques (Law of 21 March 1991 on the reform of certain public commercial undertakings). Only the identification data may be requested.
The providers and operators referred to in the first subparagraph of paragraph 1 shall ensure that the data referred to in paragraph 3 are accessible without restriction from Belgium and that that data and any other necessary information concerning that data may be transmitted without delay and only to the authorities referred to in this paragraph.
Without prejudice to other legal provisions, the providers and operators referred to in the first subparagraph of paragraph 1 may not use the data retained under paragraph 3 for any other purposes.
3. Data that can be used to identify the user or subscriber and the means of communication, other than the data specifically provided for in the second and third subparagraphs, shall be retained for 12 months as from the date on which communication was last able to be made using the service employed.
Data relating to the terminal devices’ access and connection to the network and the service, and to the location of those devices, including the network termination point, shall be retained for 12 months as from the date of the communication.
Communication data other than content, including the origin and destination thereof, shall be retained for 12 months as from the date of the communication.
The King shall, by decree deliberated in the Council of Ministers and on a proposal from the Minister for Justice and the Minister [with responsibility for matters relating to electronic communications], and after obtaining the opinion of the Committee for the Protection of Privacy and the Institute, determine the data to be retained by category type as referred to in the first to third subparagraphs and the requirements which that data must satisfy.
…’
The disputes in the main proceedings and the questions referred for a preliminary ruling
Case C‑511/18
56
By applications lodged on 30 November 2015 and 16 March 2016, joined in the main proceedings, La Quadrature du Net, French Data Network, the Fédération des fournisseurs d’accès à Internet associatifs and Igwan.net brought actions before the Conseil d’État (Council of State, France) for the annulment of Decrees No 2015‑1185, No 2015‑1211, No 2015‑1639 and No 2016‑67, on the ground, inter alia, that they infringe the French Constitution, the European Convention for the Protection of Human Rights and Fundamental Freedoms (‘the ECHR’) and Directives 2000/31 and 2002/58, read in the light of Articles 7, 8 and 47 of the Charter.
57
As regards, in particular, the pleas alleging infringement of Directive 2000/31, the referring court states that the provisions of Article L. 851‑3 of the CSI require electronic communications operators and technical service providers to ‘implement on their networks automated data processing practices designed, within the parameters laid down in the authorisation, to detect links that might constitute a terrorist threat’. That technique is intended only to facilitate the collection, for a limited period and from all of the connection data processed by those operators and service providers, of such data as might be related to a serious offence of this kind. In those circumstances, those provisions, which do not impose a general obligation of active surveillance, do not, in the view of the referring court, infringe Article 15 of Directive 2000/31.
58
As regards the pleas alleging infringement of Directive 2002/58, the referring court considers that it follows, inter alia, from the provisions of that directive and from the judgment of 21 December 2016, Tele2 Sverige and Watson and Others (C‑203/15 and C‑698/15, EU:C:2016:970; ‘Tele2’), that national provisions imposing obligations on providers of electronic communications services, such as the general and indiscriminate retention of the traffic and location data of their users and subscribers, for the purposes stated in Article 15(1) of that directive, which include safeguarding national security, defence and public security, fall within the scope of that directive since those rules govern the activity of those providers. That also applies to rules governing access to and use of data by national authorities.
59
The referring court concludes from this that both the obligation to retain data resulting from Article L. 851‑1 of the CSI and the access of the administrative authorities to that data, including real-time access, provided for in Articles L. 851‑1, L. 851‑2 and L. 851‑4 of that code, fall within the scope of Directive 2002/58. The same is true, according to that court, of the provisions of Article L. 851‑3 of the CSI, which, although they do not impose a general retention obligation on the operators concerned, do however require them to implement automated processing on their networks that is intended to detect links that might constitute a terrorist threat.
60
On the other hand, the referring court takes the view that the scope of Directive 2002/58 does not extend to the provisions of the CSI referred to in the applications for annulment which relate to intelligence gathering techniques applied directly by the State, but do not regulate the activities of providers of electronic communications services by imposing specific obligations on them. Accordingly, those provisions cannot be regarded as implementing EU law, with the result that the pleas alleging that they infringe Directive 2002/58 cannot validly be relied on.
61
Thus, with a view to settling the disputes concerning the lawfulness of Decrees No 2015‑1185, No 2015‑1211, No 2015‑1639 and No 2016‑67 in the light of Directive 2002/58, in so far as they were adopted to implement Articles L. 851‑1 to L. 851‑4 of the CSI, three questions on the interpretation of EU law arise.
62
As regards the interpretation of Article 15(1) of Directive 2002/58, the referring court is uncertain, in the first place, whether a general and indiscriminate retention obligation, imposed on providers of electronic communications services on the basis of Articles L. 851‑1 and R. 851‑5 of the CSI, is to be regarded in the light, inter alia, of the safeguards and checks to which the access of the administrative authorities to and the use of connection data are subject, as interference justified by the right to security guaranteed in Article 6 of the Charter and by the requirements of national security, responsibility for which falls to the Member States alone pursuant to Article 4 TEU.
63
As regards, in the second place, the other obligations which may be imposed on providers of electronic communications services, the referring court states that the provisions of Article L. 851‑2 of the CSI permit, for the sole purpose of preventing terrorism, the collection of the information or documents referred to in Article L. 851‑1 of that code from the same persons. Such collection, in relation solely to one or more individuals previously identified as potentially having links to a terrorist threat, is to be carried out in real time. The same is true of the provisions of Article L. 851‑4, which authorise the real-time transmission by operators exclusively of technical data relating to the location of terminal equipment. Those techniques regulate the real-time access of the administrative authorities to data retained under the CPCE and the LCEN for various purposes and by various means, without, however, imposing on the providers concerned any additional retention requirement over and above what is necessary for the billing and provision of their services. In the same vein, nor do the provisions of Article L. 851‑3 of the CSI, which require service providers to implement on their networks an automated system for the analysis of connections, entail general and indiscriminate retention.
64
The referring court considers that both general and indiscriminate retention and real-time access to connection data are of unparalleled operational usefulness, against a background of serious and persistent threats to national security, in particular the terrorist threat. General and indiscriminate retention allows the intelligence services to obtain access to communications data before the reasons for believing that the person concerned poses a threat to public security, defence or State security are identified. In addition, real-time access to connection data makes it possible to monitor, with a high level of responsiveness, the conduct of individuals who may pose an immediate threat to public order.
65
Furthermore, the technique provided for in Article L. 851‑3 of the CSI makes it possible to detect, on the basis of criteria specifically defined for that purpose, those individuals whose conduct may, in view of their methods of communication, constitute a terrorist threat.
66
In the third place, as regards access by the competent authorities to retained data, the referring court is unsure whether Directive 2002/58, read in the light of the Charter, is to be interpreted as meaning that it is a prerequisite for the lawfulness of the procedures for the collection of connection data that the data subjects are informed whenever their being so informed is no longer liable to jeopardise the investigations being undertaken by the competent authorities, or whether such procedures may be regarded as lawful taking into account all the other procedural safeguards provided for in national law where those safeguards ensure that the right to a remedy is effective.
67
As regards those other procedural safeguards, the referring court states in particular that any person wishing to verify that no intelligence techniques have been unlawfully implemented against him or her may bring the matter before a specialist panel of the Conseil d’État (Council of State, France), which is responsible for determining – in the light of the information communicated to it outside inter partes proceedings – whether the applicant has been the subject of an intelligence technique and whether that technique was implemented in accordance with Book VIII of the CSI. The powers conferred on that panel to investigate applications ensure that the judicial review conducted by it is effective. Thus, it has jurisdiction to investigate applications, to raise of its own motion any illegalities it may find and to order the authorities to take all appropriate measures to remedy the illegalities found. In addition, it is for the Commission for the Oversight of Intelligence Techniques to check that intelligence gathering techniques are implemented, on national territory, in accordance with the requirements flowing from the CSI. Thus, the fact that the legislative provisions at issue in the main proceedings do not provide for the notification to the persons concerned of the surveillance measures applied to them does not, in itself, constitute excessive interference with the right to respect for private life.
68
It is on that basis that the Conseil d’État (Council of State, France) decided to stay proceedings and to refer the following questions to the Court for a preliminary ruling:
‘(1)
Is the general and indiscriminate retention obligation imposed on providers on the basis of the implementing provisions of Article 15(1) of [Directive 2002/58] to be regarded, against a background of serious and persistent threats to national security, and in particular the terrorist threat, as interference justified by the right to security guaranteed in Article 6 of the [Charter] and the requirements of national security, responsibility for which falls to the Member States alone pursuant to Article 4 [TEU]?
(2)
Is [Directive 2002/58], read in the light of the [Charter], to be interpreted as authorising legislative measures, such as the measures for the real-time collection of the traffic and location data of specified individuals, which, whilst affecting the rights and obligations of the providers of an electronic communications service, do not however require them to comply with a specific obligation to retain their data?
(3)
Is [Directive 2002/58], read in the light of the [Charter], to be interpreted as meaning that it is a prerequisite for the lawfulness of the procedures for the collection of connection data that the data subjects are informed whenever their being so informed is no longer liable to jeopardise the investigations being undertaken by the competent authorities, or may such procedures be regarded as lawful taking into account all the other existing procedural safeguards where those safeguards ensure that the right to a remedy is effective?’
Case C‑512/18
69
By application lodged on 1 September 2015, French Data Network, La Quadrature du Net and the Fédération des fournisseurs d’accès à Internet associatifs brought an action before the Conseil d’État (Council of State, France) for the annulment of the implied rejection decision arising from the Prime Minister’s failure to reply to their application for the repeal of Article R. 10‑13 of the CPCE and Decree No 2011‑219, on the ground, inter alia, that those legislative texts infringe Article 15(1) of Directive 2002/58, read in the light of Articles 7, 8 and 11 of the Charter. Privacy International and the Center for Democracy and Technology were granted leave to intervene in the main proceedings.
70
As regards Article R. 10‑13 of the CPCE and the obligation of general and indiscriminate retention of communications data laid down therein, the referring court, which raises similar considerations to those in Case C‑511/18, observes that such retention allows a judicial authority to access data relating to communications made by an individual before being suspected of having committed a criminal offence, with the result that such retention is of unparalleled usefulness for the investigation, detection and prosecution of criminal offences.
71
As regards Decree No 2011‑219, the referring court considers that Article 6(II) of the LCEN, which imposes an obligation to hold and retain only data relating to the creation of content, does not fall within the scope of Directive 2002/58 since that directive’s scope is limited, in accordance with Article 3(1) thereof, to the provision of publicly available electronic communications services in public communications networks in the European Union. On the other hand, that national provision does fall within the scope of Directive 2000/31.
72
The referring court considers, however, that it follows from Article 15(1) and (2) of Directive 2000/31 that the directive does not establish a prohibition in principle on retaining data relating to the creation of content, from which derogation would be possible only by way of exception. Thus, the question arises whether Articles 12, 14 and 15 of Directive 2000/31, read in the light of Articles 6, 7, 8 and 11 and Article 52(1) of the Charter, are to be interpreted as allowing a Member State to introduce national legislation, such as Article 6(II) of the LCEN, which requires the persons concerned to retain data capable of enabling the identification of anyone who has contributed to the creation of the content or some of the content of the services which they provide, so that a judicial authority may, where appropriate, require the communication of that data with a view to ensuring compliance with the rules on civil and criminal liability.
73
It is on that basis that the Conseil d’État (Council of State, France) decided to stay proceedings and to refer the following questions to the Court for a preliminary ruling:
‘(1)
Is the general and indiscriminate retention obligation imposed on providers on the basis of the implementing provisions of Article 15(1) of [Directive 2002/58] to be regarded, inter alia in the light of the safeguards and checks to which the collection and use of such connection data are then subject, as interference justified by the right to security guaranteed in Article 6 of the [Charter] and the requirements of national security, responsibility for which falls to the Member States alone pursuant to Article 4 [TEU]?
(2)
Are the provisions of [Directive 2000/31], read in the light of Articles 6, 7, 8 and 11 and Article 52(1) of the [Charter], to be interpreted as allowing a State to introduce national legislation requiring the persons, whose activity consists in offering access to online public communications services and the natural or legal persons who, even free of charge, and for provision to the public via online public communications services, store signals, writing, images, sounds or messages of any kind provided by recipients of those services, to retain the data capable of enabling the identification of anyone who has contributed to the creation of the content or some of the content of the services which they provide, so that a judicial authority may, where appropriate, require the communication of that data with a view to ensuring compliance with the rules on civil and criminal liability?’
Case C‑520/18
74
By applications lodged on 10, 16, 17 and 18 January 2017, joined in the main proceedings, the Ordre des barreaux francophones et germanophone, the Académie Fiscale ASBL and UA, the Liga voor Mensenrechten ASBL, the Ligue des Droits de l’Homme ASBL, and VZ, WY and XX brought actions before the Cour constitutionnelle (Constitutional Court, Belgium) for the annulment of the Law of 29 May 2016, on the ground that it infringes Articles 10 and 11 of the Belgian Constitution, read in conjunction with Articles 5, 6 to 11, 14, 15, 17 and 18 of the ECHR, Articles 7, 8, 11 and 47 and Article 52(1) of the Charter, Article 17 of the International Covenant on Civil and Political Rights, which was adopted by the United Nations General Assembly on 16 December 1966 and entered into force on 23 March 1976, the general principles of legal certainty, proportionality and self-determination in relation to information and Article 5(4) TEU.
75
In support of their actions, the applicants in the main proceedings submit, in essence, that the Law of 29 May 2016 is unlawful because, among other things, it goes beyond what is strictly necessary and does not lay down adequate guarantees of protection. In particular, neither its provisions relating to the retention of data nor those governing access by the authorities to retained data satisfy the requirements deriving from the judgments of 8 April 2014, Digital Rights Ireland and Others (C‑293/12 and C‑594/12, EU:C:2014:238; ‘Digital Rights’) and of 21 December 2016, Tele2 (C‑203/15 and C‑698/15, EU:C:2016:970). They contend that those provisions entail a risk that personality profiles will be compiled, which may be misused by the competent authorities, and that they do not establish an appropriate level of security and protection for the retained data. Lastly, that law covers persons who are bound by professional secrecy and persons who are under a duty of confidentiality, and applies to personal communication data that is sensitive, without including specific safeguards to protect such data.
76
The referring court observes that the data which must be retained by providers of telephony services, including via the Internet, Internet access and Internet-based email and by operators providing public electronic communications networks, under the Law of 29 May 2016, is identical to that listed in Directive 2006/24/EC of the European Parliament and of the Council of 15 March 2006 on the retention of data generated or processed in connection with the provision of publicly available electronic communications services or of public communications networks and amending Directive 2002/58/EC (OJ 2006 L 105, p. 54), without any distinction being made as regards the persons concerned or on the basis of the objective pursued. As regards the latter point, the referring court states that the objective pursued by the legislature by means of that law is not only to combat terrorism and child pornography, but also to enable the use of the retained data in a wide variety of situations in the context of criminal investigations. The referring court also notes that it is apparent from the explanatory memorandum for that law that the national legislature considered it impossible, in the light of the objective pursued, to impose a targeted and selective obligation to retain data, and that it chose to apply strict guarantees to the general and indiscriminate retention obligation, both as regards the data retained and access to that data, in order to keep interference with the right to respect for private life to a minimum.
77
The referring court also states that subparagraphs 1 and 2 of Article 126(2) of the Law of 13 June 2005, as amended by the Law of 29 May 2016, lay down the conditions under which, respectively, judicial authorities and the intelligence and security services may obtain access to retained data, and consequently the review of the lawfulness of that law in the light of the requirements of EU law should be deferred until the Court has adjudicated on two preliminary ruling procedures pending before it concerning such access.
78
Lastly, the referring court states that the Law of 29 May 2016 seeks to ensure an effective criminal investigation and effective penalties in cases involving the sexual abuse of minors and to make it possible to identify the perpetrator of such an offence, even where electronic communications systems are used. In the proceedings before it, attention was drawn in that respect to the positive obligations under Articles 3 and 8 of the ECHR. Those obligations may also arise under the corresponding provisions of the Charter, which may have consequences for the interpretation of Article 15(1) of Directive 2002/58.
79
It is on that basis that the Cour constitutionnelle (Constitutional Court, Belgium) decided to stay proceedings and to refer the following questions to the Court for a preliminary ruling:
‘(1)
Must Article 15(1) of [Directive 2002/58], read in conjunction with the right to security, guaranteed by Article 6 of the [Charter], and the right to respect for personal data, as guaranteed by Articles 7, 8 and 52(1) of the [Charter], be interpreted as precluding national legislation such as that at issue, which lays down a general obligation for operators and providers of electronic communications services to retain the traffic and location data within the meaning of [Directive 2002/58], generated or processed by them in the context of the supply of those services, national legislation whose objective is not only the investigation, detection and prosecution of serious criminal offences but also the safeguarding of national security, the defence of the territory and of public security, the investigation, detection and prosecution of offences other than serious crime or the prevention of the prohibited use of electronic communication systems, or the attainment of another objective identified by Article 23(1) of [Regulation 2016/679] and which, furthermore, is subject to specific safeguards in that legislation in terms of data retention and access to that data?
(2)
Must Article 15(1) of [Directive 2002/58], in conjunction with Articles 4, 7, 8, 11 and 52(1) of the [Charter], be interpreted as precluding national legislation such as that at issue, which lays down a general obligation for operators and providers of electronic communications services to retain the traffic and location data within the meaning of [Directive 2002/58], generated or processed by them in the context of the supply of those services, if the object of that legislation is, in particular, to comply with the positive obligations borne by the authority under Articles 4 and [7] of the Charter, consisting in the provision of a legal framework which allows the effective criminal investigation and the effective punishment of sexual abuse of minors and which permits the effective identification of the perpetrator of the offence, even where electronic communications systems are used?
(3)
If, on the basis of the answer to the first or the second question, the Cour constitutionnelle (Constitutional Court, Belgium) should conclude that the contested law fails to fulfil one or more obligations arising under the provisions referred to in these questions, might it maintain on a temporary basis the effects of [the Law of 29 May 2016] in order to avoid legal uncertainty and to enable the data previously collected and retained to continue to be used for the objectives pursued by the law?’
Procedure before the Court
80
By decision of the President of the Court of 25 September 2018, Cases C‑511/18 and C‑512/18 were joined for the purposes of the written and oral parts of the procedure and the judgment. Case C‑520/18 was joined to those cases by decision of the President of the Court of 9 July 2020 for the purposes of the judgment.
Consideration of the questions referred
Question 1 in Cases C‑511/18 and C‑512/18 and questions 1 and 2 in Case C‑520/18
81
By question 1 in Cases C‑511/18 and C‑512/18 and questions 1 and 2 in Case C‑520/18, which should be considered together, the referring courts essentially ask whether Article 15(1) of Directive 2002/58 must be interpreted as precluding national legislation which imposes on providers of electronic communications services, for the purposes set out in Article 15(1), an obligation requiring the general and indiscriminate retention of traffic and location data.
Preliminary remarks
82
It is apparent from the documents available to the Court that the legislation at issue in the main proceedings covers all electronic communications systems and applies to all users of such systems, without distinction or exception. Furthermore, the data which must be retained by providers of electronic communications services under that legislation is, in particular, the data necessary for locating the source of a communication and its destination, for determining the date, time, duration and type of communication, for identifying the communications equipment used, and for locating the terminal equipment and communications, data which comprises, inter alia, the name and address of the user, the telephone numbers of the caller and the person called, and the IP address for Internet services. By contrast, that data does not cover the content of the communications concerned.
83
Thus, the data which must, under the national legislation at issue in the main proceedings, be retained for a period of one year makes it possible, inter alia, to identify the person with whom the user of an electronic communications system has communicated and by what means, to determine the date, time and duration of the communications and Internet connections and the place from which those communications and connections took place, and to ascertain the location of the terminal equipment without any communication necessarily having been transmitted. In addition, that data enables the frequency of a user’s communications with certain persons over a given period of time to be established. Last, as regards the national legislation at issue in Cases C‑511/18 and C‑512/18, it appears that that legislation, in so far as it also covers data relating to the conveyance of electronic communications by networks, also enables the nature of the information consulted online to be identified.
84
As for the aims pursued, it should be noted that the legislation at issue in Cases C‑511/18 and C‑512/18 pursues, among other aims, the investigation, detection and prosecution of criminal offences in general; national independence, territorial integrity and national defence; major foreign policy interests; the implementation of France’s European and international commitments; France’s major economic, industrial and scientific interests; and the prevention of terrorism, attacks against the republican nature of the institutions and collective violence liable to cause serious disruption to the maintenance of law and order. The objectives of the legislation at issue in Case C‑520/18 are, inter alia, the investigation, detection and prosecution of criminal offences and the safeguarding of national security, the defence of the territory and public security.
85
The referring courts are uncertain, in particular, as to the possible impact of the right to security enshrined in Article 6 of the Charter on the interpretation of Article 15(1) of Directive 2002/58. Similarly, they ask whether the interference with the fundamental rights enshrined in Articles 7 and 8 of the Charter entailed by the retention of data provided for in the legislation at issue in the main proceedings may, in the light of the existence of rules restricting national authorities’ access to retained data, be regarded as justified. In addition, according to the Conseil d’État (Council of State, France), since that question arises in a context characterised by serious and persistent threats to national security, it should also be assessed in the light of Article 4(2) TEU. The Cour constitutionnelle (Constitutional Court, Belgium), for its part, points out that the national legislation at issue in Case C‑520/18 also implements positive obligations flowing from Articles 4 and 7 of the Charter, consisting in the establishment of a legal framework for the effective prevention and punishment of the sexual abuse of minors.
86
While both the Conseil d’État (Council of State, France) and the Cour constitutionnelle (Constitutional Court, Belgium) start from the premiss that the respective national legislation at issue in the main proceedings, which governs the retention of traffic and location data and access to that data by national authorities for the purposes set out in Article 15(1) of Directive 2002/58, such as safeguarding national security, falls within the scope of that directive, a number of parties to the main proceedings and some of the Member States which submitted written observations to the Court disagree on that point, particularly concerning the interpretation of Article 1(3) of that directive. It is therefore necessary to examine, first of all, whether the legislation at issue falls within the scope of that directive.
Scope of Directive 2002/58
87
La Quadrature du Net, the Fédération des fournisseurs d’accès à Internet associatifs, Igwan.net, Privacy International and the Center for Democracy and Technology rely on the Court’s case-law on the scope of Directive 2002/58 to argue, in essence, that both the retention of data and access to retained data fall within that scope, whether that access takes place in non-real time or in real time. Indeed, they contend that since the objective of safeguarding national security is expressly mentioned in Article 15(1) of that directive, the pursuit of that objective does not render that directive inapplicable. In their view, Article 4(2) TEU, mentioned by the referring courts, does not affect that assessment.
88
As regards the intelligence measures implemented directly by the competent French authorities, without regulating the activities of providers of electronic communications services by imposing specific obligations on them, the Center for Democracy and Technology observes that those measures necessarily fall within the scope of Directive 2002/58 and of the Charter, since they are exceptions to the principle of confidentiality guaranteed in Article 5 of that directive. Those measures must therefore comply with the requirements stemming from Article 15(1) of the directive.
89
On the other hand, the Czech and Estonian Governments, Ireland, and the French, Cypriot, Hungarian, Polish, Swedish and United Kingdom Governments submit, in essence, that Directive 2002/58 does not apply to national legislation such as that at issue in the main proceedings, since the purpose of that legislation is to safeguard national security. The intelligence services’ activities, in so far as they relate to the maintenance of public order and to the safeguarding of internal security and territorial integrity, are part of the essential functions of the Member States and, consequently, are within their exclusive competence, as evidenced, in particular, by the third sentence of Article 4(2) TEU.
90
Those governments and Ireland also refer to Article 1(3) of Directive 2002/58, which excludes from the scope of that directive, as the first indent of Article 3(2) of Directive 95/46 did in the past, activities concerning public security, defence and State security. They rely in that regard on the interpretation of the latter provision set out in the judgment of 30 May 2006, Parliament v Council and Commission (C‑317/04 and C‑318/04, EU:C:2006:346).
91
In that regard, it should be stated that, under Article 1(1) thereof, Directive 2002/58 provides, inter alia, for the harmonisation of the national provisions required to ensure an equivalent level of protection of fundamental rights and freedoms, and in particular the right to privacy and confidentiality, with respect to the processing of personal data in the electronic communications sector.
92
Article 1(3) of that directive excludes from its scope ‘activities of the State’ in specified fields, including activities of the State in areas of criminal law and in the areas of public security, defence and State security, including the economic well-being of the State when the activities relate to State security matters. The activities thus mentioned by way of example are, in any event, activities of the State or of State authorities and are unrelated to fields in which individuals are active (judgment of 2 October 2018, Ministerio Fiscal, C‑207/16, EU:C:2018:788, paragraph 32 and the case-law cited).
93
In addition, Article 3 of Directive 2002/58 states that that directive is to apply to the processing of personal data in connection with the provision of publicly available electronic communications services in public communications networks in the European Union, including public communications networks supporting data collection and identification devices (‘electronic communications services’). Consequently, that directive must be regarded as regulating the activities of the providers of such services (judgment of 2 October 2018, Ministerio Fiscal, C‑207/16, EU:C:2018:788, paragraph 33 and the case-law cited).
94
In that context, Article 15(1) of Directive 2002/58 states that Member States may adopt, subject to the conditions laid down, ‘legislative measures to restrict the scope of the rights and obligations provided for in Article 5, Article 6, Article 8(1), (2), (3) and (4), and Article 9 of [that directive]’ (judgment of 21 December 2016, Tele2, C‑203/15 and C‑698/15, EU:C:2016:970, paragraph 71).
95
Article 15(1) of Directive 2002/58 necessarily presupposes that the national legislative measures referred to therein fall within the scope of that directive, since it expressly authorises the Member States to adopt them only if the conditions laid down in the directive are met. Further, such measures regulate, for the purposes mentioned in that provision, the activity of providers of electronic communications services (judgment of 2 October 2018, Ministerio Fiscal, C‑207/16, EU:C:2018:788, paragraph 34 and the case-law cited).
96
It is in the light of, inter alia, those considerations that the Court has held that Article 15(1) of Directive 2002/58, read in conjunction with Article 3 thereof, must be interpreted as meaning that the scope of that directive extends not only to a legislative measure that requires providers of electronic communications services to retain traffic and location data, but also to a legislative measure requiring them to grant the competent national authorities access to that data. Such legislative measures necessarily involve the processing, by those providers, of the data and cannot, to the extent that they regulate the activities of those providers, be regarded as activities characteristic of States, referred to in Article 1(3) of that directive (see, to that effect, judgment of 2 October 2018, Ministerio Fiscal, C‑207/16, EU:C:2018:788, paragraphs 35 and 37 and the case-law cited).
97
In addition, having regard to the considerations set out in paragraph 95 above and the general scheme of Directive 2002/58, an interpretation of that directive under which the legislative measures referred to in Article 15(1) thereof were excluded from the scope of that directive because the objectives which such measures must pursue overlap substantially with the objectives pursued by the activities referred to in Article 1(3) of that same directive would deprive Article 15(1) thereof of any practical effect (see, to that effect, judgment of 21 December 2016, Tele2, C‑203/15 and C‑698/15, EU:C:2016:970, paragraphs 72 and 73).
98
The concept of ‘activities’ referred to in Article 1(3) of Directive 2002/58 cannot therefore, as was noted, in essence, by the Advocate General in point 75 of his Opinion in Joined Cases La Quadrature du Net and Others (C‑511/18 and C‑512/18, EU:C:2020:6), be interpreted as covering the legislative measures referred to in Article 15(1) of that directive.
99
Article 4(2) TEU, to which the governments listed in paragraph 89 of the present judgment have made reference, cannot invalidate that conclusion. Indeed, according to the Court’s settled case-law, although it is for the Member States to define their essential security interests and to adopt appropriate measures to ensure their internal and external security, the mere fact that a national measure has been taken for the purpose of protecting national security cannot render EU law inapplicable and exempt the Member States from their obligation to comply with that law (see, to that effect, judgments of 4 June 2013, ZZ, C‑300/11, EU:C:2013:363, paragraph 38; of 20 March 2018, Commission v Austria (State printing office), C‑187/16, EU:C:2018:194, paragraphs 75 and 76; and of 2 April 2020, Commission v Poland, Hungary and Czech Republic (Temporary mechanism for the relocation of applicants for international protection), C‑715/17, C‑718/17 and C‑719/17, EU:C:2020:257, paragraphs 143 and 170).
100
It is true that, in the judgment of 30 May 2006, Parliament v Council and Commission (C‑317/04 and C‑318/04, EU:C:2006:346, paragraphs 56 to 59), the Court held that the transfer of personal data by airlines to the public authorities of a third country for the purpose of preventing and combating terrorism and other serious crimes did not, pursuant to the first indent of Article 3(2) of Directive 95/46, fall within the scope of that directive, because that transfer fell within a framework established by the public authorities relating to public security.
101
However, having regard to the considerations set out in paragraphs 93, 95 and 96 of the present judgment, that case-law cannot be transposed to the interpretation of Article 1(3) of Directive 2002/58. Indeed, as the Advocate General noted, in essence, in points 70 to 72 of his Opinion in Joined Cases La Quadrature du Net and Others (C‑511/18 and C‑512/18, EU:C:2020:6), the first indent of Article 3(2) of Directive 95/46, to which that case-law relates, excluded, in a general way, from the scope of that directive ‘processing operations concerning public security, defence, [and] State security’, without drawing any distinction according to who was carrying out the data processing operation concerned. By contrast, in the context of interpreting Article 1(3) of Directive 2002/58, it is necessary to draw such a distinction. As is apparent from paragraphs 94 to 97 of the present judgment, all operations processing personal data carried out by providers of electronic communications services fall within the scope of that directive, including processing operations resulting from obligations imposed on those providers by the public authorities, although those processing operations could, where appropriate, on the contrary, fall within the scope of the exception laid down in the first indent of Article 3(2) of Directive 95/46, given the broader wording of that provision, which covers all processing operations concerning public security, defence, or State security, regardless of the person carrying out those operations.
102
Furthermore, it should be noted that Directive 95/46, which was at issue in the case that gave rise to the judgment of 30 May 2006, Parliament v Council and Commission (C‑317/04 and C‑318/04, EU:C:2006:346), has been, pursuant to Article 94(1) of Regulation 2016/679, repealed and replaced by that regulation with effect from 25 May 2018. Although that regulation states, in Article 2(2)(d) thereof, that it does not apply to processing operations carried out ‘by competent authorities’ for the purposes of, inter alia, the prevention and detection of criminal offences, including the safeguarding against and the prevention of threats to public security, it is apparent from Article 23(1)(d) and (h) of that regulation that the processing of personal data carried out by individuals for those same purposes falls within the scope of that regulation. It follows that the above interpretation of Article 1(3), Article 3 and Article 15(1) of Directive 2002/58 is consistent with the definition of the scope of Regulation 2016/679, which is supplemented and specified by that directive.
103
By contrast, where the Member States directly implement measures that derogate from the rule that electronic communications are to be confidential, without imposing processing obligations on providers of electronic communications services, the protection of the data of the persons concerned is covered not by Directive 2002/58, but by national law only, subject to the application of Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ 2016 L 119, p. 89), with the result that the measures in question must comply with, inter alia, national constitutional law and the requirements of the ECHR.
104
It follows from the foregoing considerations that national legislation which requires providers of electronic communications services to retain traffic and location data for the purposes of protecting national security and combating crime, such as the legislation at issue in the main proceedings, falls within the scope of Directive 2002/58.
Interpretation of Article 15(1) of Directive 2002/58
105
It should be noted, as a preliminary point, that it is settled case-law that, in interpreting a provision of EU law, it is necessary not only to refer to its wording but also to consider its context and the objectives of the legislation of which it forms part, and in particular the origin of that legislation (see, to that effect, judgment of 17 April 2018, Egenberger, C‑414/16, EU:C:2018:257, paragraph 44).
106
As is apparent from, inter alia, recitals 6 and 7 thereof, the purpose of Directive 2002/58 is to protect users of electronic communications services from risks for their personal data and privacy resulting from new technologies and, in particular, from the increasing capacity for automated storage and processing of data. In particular, that directive seeks, as is stated in recital 2 thereof, to ensure that the rights set out in Articles 7 and 8 of the Charter are fully respected. In that regard, it is apparent from the Explanatory Memorandum of the Proposal for a Directive of the European Parliament and of the Council concerning the processing of personal data and the protection of privacy in the electronic communications sector (COM (2000) 385 final), which gave rise to Directive 2002/58, that the EU legislature sought to ‘ensure that a high level of protection of personal data and privacy will continue to be guaranteed for all electronic communications services regardless of the technology used’.
107
To that end, Article 5(1) of Directive 2002/58 enshrines the principle of confidentiality of both electronic communications and the related traffic data and requires, inter alia, that, in principle, persons other than users be prohibited from storing, without those users’ consent, those communications and that data.
108
As regards, in particular, the processing and storage of traffic data by providers of electronic communications services, it is apparent from Article 6 and recitals 22 and 26 of Directive 2002/58 that such processing is permitted only to the extent necessary and for the time necessary for the marketing and billing of services and the provision of value added services. Once that period has elapsed, the data that has been processed and stored must be erased or made anonymous. As regards location data other than traffic data, Article 9(1) of that directive provides that that data may be processed only subject to certain conditions and after it has been made anonymous or the consent of the users or subscribers has been obtained (judgment of 21 December 2016, Tele2, C‑203/15 and C‑698/15, EU:C:2016:970, paragraph 86 and the case-law cited).
109
Thus, in adopting that directive, the EU legislature gave concrete expression to the rights enshrined in Articles 7 and 8 of the Charter, so that the users of electronic communications services are entitled to expect, in principle, that their communications and data relating thereto will remain anonymous and may not be recorded, unless they have agreed otherwise.
110
However, Article 15(1) of Directive 2002/58 enables the Member States to introduce exceptions to the obligation of principle, laid down in Article 5(1) of that directive, to ensure the confidentiality of personal data, and to the corresponding obligations, referred to, inter alia, in Articles 6 and 9 of that directive, where such a restriction constitutes a necessary, appropriate and proportionate measure within a democratic society to safeguard national security, defence and public security, and the prevention, investigation, detection and prosecution of criminal offences or of unauthorised use of the electronic communication system. To that end, Member States may, inter alia, adopt legislative measures providing for the retention of data for a limited period justified on one of those grounds.
111
That being said, the option to derogate from the rights and obligations laid down in Articles 5, 6 and 9 of Directive 2002/58 cannot permit the exception to the obligation of principle to ensure the confidentiality of electronic communications and data relating thereto and, in particular, to the prohibition on storage of that data, explicitly laid down in Article 5 of that directive, to become the rule (see, to that effect, judgment of 21 December 2016, Tele2, C‑203/15 and C‑698/15, EU:C:2016:970, paragraphs 89 and 104).
112
As regards the objectives that are capable of justifying a limitation of the rights and obligations laid down, in particular, in Articles 5, 6 and 9 of Directive 2002/58, the Court has previously held that the list of objectives set out in the first sentence of Article 15(1) of that directive is exhaustive, as a result of which a legislative measure adopted under that provision must correspond, genuinely and strictly, to one of those objectives (see, to that effect, judgment of 2 October 2018, Ministerio Fiscal, C‑207/16, EU:C:2018:788, paragraph 52 and the case-law cited).
113
In addition, it is apparent from the third sentence of Article 15(1) of Directive 2002/58 that the Member States are not permitted to adopt legislative measures to restrict the scope of the rights and obligations provided for in Articles 5, 6 and 9 of that directive unless they do so in accordance with the general principles of EU law, including the principle of proportionality, and with the fundamental rights guaranteed in the Charter. In that regard, the Court has previously held that the obligation imposed on providers of electronic communications services by a Member State by way of national legislation to retain traffic data for the purpose of making them available, if necessary, to the competent national authorities raises issues relating to compatibility not only with Articles 7 and 8 of the Charter, relating to the protection of privacy and to the protection of personal data, respectively, but also with Article 11 of the Charter, relating to the freedom of expression (see, to that effect, judgments of 8 April 2014, Digital Rights, C‑293/12 and C‑594/12, EU:C:2014:238, paragraphs 25 and 70, and of 21 December 2016, Tele2, C‑203/15 and C‑698/15, EU:C:2016:970, paragraphs 91and 92 and the case-law cited).
114
Thus, the interpretation of Article 15(1) of Directive 2002/58 must take account of the importance both of the right to pr

---
Generated by overview.legal · https://overview.legal/posts/593397 · 2026-10-11
