Skip to content
Topic Contested in court

Telecommunications

LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.

Processing by telecom providers and eprivacy

747 linked items 26 Laws78 Case Law59 Guidance482 Enforcement52 News

Overview

23 sources · Aug 27, 2026

Legal Framework

Telecommunications providers operate at the intersection of multiple EU regulatory regimes. The ePrivacy Directive (2002/58/EC) governs the processing of personal data and the protection of privacy in the electronic communications sector, sitting alongside the GDPR as a lex specialis instrument. Article 5(3) of the ePrivacy Directive requires user consent for storing or accessing information on terminal equipment, a provision the CJEU interpreted strictly in Planet49 (C-673/17). The Court confirmed that pre-ticked checkboxes do not constitute valid consent and that the protection extends broadly to any device accessing user terminal equipment:

"Terminal equipment of users of electronic communications networks and any information stored on such equipment are part of the private sphere of the users requiring protection under the European Convention for the Protection of Human Rights and Fundamental Freedoms"
— Planet49 ¶7

Beyond ePrivacy, telecom providers fall within the scope of NIS2 Art. 2, which applies regardless of entity size where the provider is essential for critical societal or economic activities. The AI Act also reaches telecom-adjacent AI systems through its broad scope under AI Act Art. 2, and the European Telecommunications Standards Institute (ETSI) holds a permanent seat on the AI Act's advisory forum under AI Act Art. 67(5).

Key Developments

The CJEU's Planet49 ruling remains the cornerstone precedent for consent requirements in electronic communications. The case clarified that consent under the ePrivacy Directive must meet the same standard as GDPR consent — freely given, specific, informed, and unambiguous. Pre-ticked boxes fail this test.

Belgian DPA enforcement illustrates the practical interplay between ePrivacy and GDPR supervisory powers. The authority confirmed that data protection authorities apply the GDPR even where other regulators (such as telecom regulators) are competent to monitor specific ePrivacy obligations:

"are to apply the AVG to data processing, including in the context where other public authorities would be competent to monitor certain parts of the processing of personal data under national implementation of the ePrivacy Directive"
— Belgian DPA §29

Breach notification obligations for telecom providers predate the GDPR. The EDPB has noted the continuity:

"Obligations to notify in cases of breaches existed for certain organisations, such as providers of publicly-available electronic communications services (as specified in Directive 2009/136/EC and Regulation (EU) No 611/2013)"
— EDPB Guidelines 9/2022 §4

Dutch courts have addressed the lawfulness of intercepted communications data from encrypted platforms (EncroChat, SkyECC), focusing on whether cross-border evidence gathering complied with Directive 2014/41/EU notification requirements — though these rulings concern criminal procedure rather than telecom data protection per se.

Status of the Debate

This topic is actively contested. The ePrivacy Regulation — intended to replace the 2002 Directive — has been stalled in the legislative process for years, creating regulatory uncertainty about how cookie consent, metadata processing, and machine-to-machine communications should be handled going forward. The EDPB has repeatedly called for swift adoption. Meanwhile, courts and DPAs apply the existing Directive alongside the GDPR, producing a patchwork of interpretations on jurisdictional boundaries between telecom regulators and data protection authorities. A finalized ePrivacy Regulation would resolve the most pressing open questions, particularly around consent thresholds for non-cookie tracking technologies and the scope of "electronic communications services" in an OTT-dominated market.

Practical Guidance

  • Consent mechanisms: Implement opt-in consent for all storage or access to terminal equipment. Pre-ticked boxes, implied consent, or continue-browsing banners do not satisfy the standard set by Planet49.
  • Regulatory mapping: Identify which national authority supervises ePrivacy compliance (often the telecom regulator) versus GDPR compliance (the DPA), and coordinate reporting obligations across both. The Belgian DPA decision confirms DPAs retain competence over GDPR aspects even where ePrivacy is separately supervised.
  • Breach notification: Telecom providers must notify breaches under both the ePrivacy framework (Article 4 of Regulation 611/2013) and GDPR Article 33. Align internal incident response to satisfy the stricter of the two timelines.
  • Security obligations under NIS2: Assess whether your telecom entity qualifies as essential or important under NIS2 Art. 2, triggering enhanced risk-management and incident-reporting duties.
  • AI systems in telecom infrastructure: Where AI is deployed in network management, customer service, or fraud detection, evaluate applicability of the AI Act and whether the system qualifies as high-risk under Article 6.
Everything on this topic ranked by relevance · links go to the exact provision / paragraph / section
Guidelines 2/2023 Technical Scope of Art. 5(3) of ePrivacy Directive Guidelines ·EDPB Guidance EDPB Oct 2024 interpretation of ePrivacy Directive
why this is here
Article 5(3) ePD applies if: a. CRITERION A: the operations carried out relate to information...

Directly interprets Article 5(3) of the ePD applicable to telecommunications.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 05/2020 consent under Regulation 2016/679 Guidelines on consent Guidelines ·EDPB Guidance EDPB May 2020 ePrivacy and consent
why this is here
The notion of consent in the draft ePrivacy Regulation remains linked to the notion of consent in the GDPR.

Mentions ePrivacy in context of consent but does not focus on telecommunications providers.

assessed by deepseek/deepseek-v4-flash-0731 · 7 Sept 2026

Guidelines 1/2020 processing personal data in the context of connected vehicles and mobility related applications Guidelines on processing of personal data through video devices Guidelines ·EDPB Guidance EDPB Jan 2020 Electronic communication networks
why this is here
connected via electronic communication networks

The document mentions connectivity via electronic communication networks, which relates to telecommunications, but does not address eprivacy rules.

assessed by deepseek/deepseek-v4-flash-0731 · 28 Aug 2026

This is the top of each pile — all 78 Case Law · all 59 Guidance · all 26 Laws · all 482 Enforcement · all 50 Literature · all 52 News