Telecommunications
Follow topic LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this topic. Contains: the overview, key law text, case law, enforcement and guidance for this topic. Everything links back to its source on overview.legal — legal information, not advice.Processing by telecom providers and eprivacy
Overview
16 sources · Jul 15, 2026Legal Framework
The ePrivacy Directive (Directive 2002/58/EC) governs the processing of personal data in the electronic communications sector, operating as a lex specialis to the GDPR. Article 5 of the ePrivacy Directive establishes the confidentiality of communications, prohibiting interception, monitoring, or storage of communications content and related traffic data without consent or another specified legal basis. Article 5(3) extends this confidentiality principle to information stored on or retrieved from users' terminal equipment — the legal foundation requiring consent for cookies and similar tracking technologies. Article 2 defines the directive's scope, covering the processing of personal data in connection with the provision of publicly available electronic communications services over public communications networks. Article 13 addresses unsolicited communications, requiring prior consent for marketing via electronic mail unless an existing customer relationship exists under narrowly defined conditions.
The interplay between the ePrivacy Directive and the GDPR is critical: where the ePrivacy Directive provides specific rules on confidentiality, consent for storage/access on devices, and marketing, those rules prevail. The GDPR fills the gaps on matters such as security obligations, data subject rights, and lawful bases not specifically addressed by ePrivacy provisions.
Key Developments
The CJEU's ruling in Digital Rights Ireland Ltd v. Ireland established fundamental parameters for data retention obligations imposed on telecom providers. The Court held that mandatory retention of traffic and location data constitutes a serious interference with Article 7 (private life) and Article 8 (data protection) of the Charter of Fundamental Rights. While blanket retention does not necessarily impair the essence of those rights — because content is not accessed — the Court insisted on robust safeguards: retention must be limited to what is strictly necessary, targeted, and subject to judicial or independent administrative oversight. Generalized access to communication content, by contrast, compromises the very essence of Article 7, as reaffirmed in Data Protection Commissioner v. Schrems and Facebook.
In Valsts policijas Rīgas reģiona pārvaldes Kārtības policijas pārvalde v. Rīgas satiksme, the CJEU addressed Article 7(f) of Directive 95/46 (now Article 6(1)(f) GDPR), clarifying that legitimate interests provides a possibility for processing — not an obligation — and that public authorities disclosing data to third parties may additionally require a specific legal obligation to do so. This narrows the legitimate interests basis for telecom-related disclosures involving public bodies.
The EDPB's Guidelines 2/2023 on the technical scope of Article 5(3) clarify that the consent requirement extends beyond cookies to encompass fingerprinting, tracking pixels, and any technology that stores or accesses information on terminal equipment, regardless of the technical method employed.
Enforcement remains aggressive: NAIH fined Mediaworks Hungary Zrt. €140,500 and Blikk Kft. €70,300 for insufficient legal bases underlying data processing in the communications and media sector.
Practical Guidance
- Obtain specific, informed consent before placing or accessing any information on users' terminal equipment, including not only cookies but fingerprinting and similar technologies, per Article 5(3) ePrivacy Directive as interpreted in EDPB Guidelines 2/2023.
- Avoid blanket data retention regimes; retention of traffic and location data must be targeted, time-limited, and subject to independent oversight, following the Digital Rights Ireland requirements.
- Do not rely on legitimate interests alone for disclosures to or from public authorities without confirming an underlying legal obligation, per the Rīgas satiksme ruling.
- Implement technical and organizational security measures for retained communications data equivalent to protections applied on the live network, as required by the data security provisions referenced in Digital Rights Ireland.
- Verify that any unsolicited electronic marketing relies on valid prior consent or a qualifying existing customer relationship under Article 13 ePrivacy Directive, given the enforcement trajectory demonstrated by NAIH penalties.