# Telecommunications — legal context bundle

> Curated from overview.legal on 2026-08-22. Canonical page: https://overview.legal/topics/telecommunications
> Sources are cited per item. Verify against the official texts before relying on them.

Processing by telecom providers and eprivacy

## Overview

## Legal Framework

The ePrivacy Directive (Directive 2002/58/EC) governs the processing of personal data in the electronic communications sector, operating as a lex specialis to the GDPR. Article 5 of the ePrivacy Directive establishes the confidentiality of communications, prohibiting interception, monitoring, or storage of communications content and related traffic data without consent or another specified legal basis. Article 5(3) extends this confidentiality principle to information stored on or retrieved from users' terminal equipment — the legal foundation requiring consent for cookies and similar tracking technologies. Article 2 defines the directive's scope, covering the processing of personal data in connection with the provision of publicly available electronic communications services over public communications networks. Article 13 addresses unsolicited communications, requiring prior consent for marketing via electronic mail unless an existing customer relationship exists under narrowly defined conditions.

The interplay between the ePrivacy Directive and the GDPR is critical: where the ePrivacy Directive provides specific rules on confidentiality, consent for storage/access on devices, and marketing, those rules prevail. The GDPR fills the gaps on matters such as security obligations, data subject rights, and lawful bases not specifically addressed by ePrivacy provisions.

## Key Developments

The CJEU's ruling in *Digital Rights Ireland Ltd v. Ireland* established fundamental parameters for data retention obligations imposed on telecom providers. The Court held that mandatory retention of traffic and location data constitutes a serious interference with Article 7 (private life) and Article 8 (data protection) of the Charter of Fundamental Rights. While blanket retention does not necessarily impair the essence of those rights — because content is not accessed — the Court insisted on robust safeguards: retention must be limited to what is strictly necessary, targeted, and subject to judicial or independent administrative oversight. Generalized access to communication content, by contrast, compromises the very essence of Article 7, as reaffirmed in *Data Protection Commissioner v. Schrems and Facebook*.

In *Valsts policijas Rīgas reģiona pārvaldes Kārtības policijas pārvalde v. Rīgas satiksme*, the CJEU addressed Article 7(f) of Directive 95/46 (now Article 6(1)(f) GDPR), clarifying that legitimate interests provides a possibility for processing — not an obligation — and that public authorities disclosing data to third parties may additionally require a specific legal obligation to do so. This narrows the legitimate interests basis for telecom-related disclosures involving public bodies.

The EDPB's Guidelines 2/2023 on the technical scope of Article 5(3) clarify that the consent requirement extends beyond cookies to encompass fingerprinting, tracking pixels, and any technology that stores or accesses information on terminal equipment, regardless of the technical method employed.

Enforcement remains aggressive: NAIH fined Mediaworks Hungary Zrt. €140,500 and Blikk Kft. €70,300 for insufficient legal bases underlying data processing in the communications and media sector.

## Practical Guidance

- **Obtain specific, informed consent before placing or accessing any information on users' terminal equipment**, including not only cookies but fingerprinting and similar technologies, per Article 5(3) ePrivacy Directive as interpreted in EDPB Guidelines 2/2023.
- **Avoid blanket data retention regimes**; retention of traffic and location data must be targeted, time-limited, and subject to independent oversight, following the *Digital Rights Ireland* requirements.
- **Do not rely on legitimate interests alone for disclosures to or from public authorities** without confirming an underlying legal obligation, per the *Rīgas satiksme* ruling.
- **Implement technical and organizational security measures** for retained communications data equivalent to protections applied on the live network, as required by the data security provisions referenced in *Digital Rights Ireland*.
- **Verify that any unsolicited electronic marketing relies on valid prior consent** or a qualifying existing customer relationship under Article 13 ePrivacy Directive, given the enforcement trajectory demonstrated by NAIH penalties.

## Legislation (full text of key provisions)

### EPRIVACY-ART-13

*Source: ePrivacy Directive, eprivacy-art-13, 2025-10-08 — https://overview.legal/posts/3181*

### EPRIVACY-ART-6

*Source: ePrivacy Directive, eprivacy-art-6, 2025-10-08 — https://overview.legal/posts/3180*

### EPRIVACY-ART-5

*Source: ePrivacy Directive, eprivacy-art-5, 2025-10-08 — https://overview.legal/posts/3179*

### EPRIVACY-ART-2

*Source: ePrivacy Directive, eprivacy-art-2, 2025-10-08 — https://overview.legal/posts/3178*

### EPRIVACY-ART-1

*Source: ePrivacy Directive, eprivacy-art-1, 2025-10-08 — https://overview.legal/posts/3177*

### Definitions

*Source: ePrivacy, eprivacy-art-2-en, 2002-07-12 — https://overview.legal/posts/132169*

DefinitionsSave as otherwise provided, the definitions in Directive 95/46/EC and in Directive 2002/21/EC of the European Parliament and of the Council of 7 March 2002 on a common regulatory framework for electronic communications networks and services (Framework Directive) ( 8 ) shall apply.The following definitions shall also apply:‘user’ means any natural person using a publicly available electronic communications service, for private or business purposes, without necessarily having subscribed to this service;‘traffic data’ means any data processed for the purpose of the conveyance of a communication on an electronic communications network or for the billing thereof; ▼M2 ‘location data’ means any data processed in an electronic communications network or by an electronic communications service, indicating the geographic position of the terminal equipment of a user of a publicly available electronic communications service; ▼B ‘communication’ means any information exchanged or conveyed between a finite number of parties by means of a publicly available electronic communications service. This does not include any information conveyed as part of a broadcasting service to the public over an electronic communications network except to the extent that the information can be related to the identifiable subscriber or user receiving the information; ▼M2 ————— ▼B ‘consent’ by a user or subscriber corresponds to the data subject's consent in Directive 95/46/EC;‘value added service’ means any service which requires the processing of traffic data or location data other than traffic data beyond what is necessary for the transmission of a communication or the billing thereof;‘electronic mail’ means any text, voice, sound or image message sent over a public communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient; ▼M2 ‘personal data breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed in connection with the provision of a publicly available electronic communications service in the Community.

### Relationship with Directive 2002/58/EC

*Source: GDPR, gdpr-art-95-en, 2016-04-27 — https://overview.legal/posts/91491*

This Regulation shall not impose additional obligations on natural or legal persons in relation to processing in connection with the provision of publicly available electronic communications services in public communication networks in the Union in relation to matters for which they are subject to specific obligations with the same objective set out in Directive 2002/58/EC.

### Services concerned

*Source: ePrivacy, eprivacy-art-3-en, 2002-07-12 — https://overview.legal/posts/132170*

Services concernedThis Directive shall apply to the processing of personal data in connection with the provision of publicly available electronic communications services in public communications networks in the Community, including public communications networks supporting data collection and identification devices.

### Exceptions

*Source: ePrivacy, eprivacy-art-10-en, 2002-07-12 — https://overview.legal/posts/132202*

ExceptionsMember States shall ensure that there are transparent procedures governing the way in which a provider of a public communications network and/or a publicly available electronic communications service may override:the elimination of the presentation of calling line identification, on a temporary basis, upon application of a subscriber requesting the tracing of malicious or nuisance calls. In this case, in accordance with national law, the data containing the identification of the calling subscriber will be stored and be made available by the provider of a public communications network and/or publicly available electronic communications service;the elimination of the presentation of calling line identification and the temporary denial or absence of consent of a subscriber or user for the processing of location data, on a per-line basis for organisations dealing with emergency calls and recognised as such by a Member State, including law enforcement agencies, ambulance services and fire brigades, for the purpose of responding to such calls.

### Recital 92 — telecom and trust service providers scope

*Source: NIS2, nis2-rec-92-en, 2022-12-14 — https://overview.legal/posts/96712*

In order to streamline the obligations imposed on providers of public electronic communications networks or of publicly available electronic communications services, and trust service providers, related to the security of their network and information systems, as well as to enable those entities and the competent authorities under Directive (EU) 2018/1972 of the European Parliament and of the Council (20) and Regulation (EU) No 910/2014 respectively to benefit from the legal framework established by this Directive, including the designation of a CSIRT responsible for incident handling, the participation of the competent authorities concerned in the activities of the Cooperation Group and the CSIRTs network, those entities should fall within the scope of this Directive. The corresponding provisions laid down in Regulation (EU) No 910/2014 and Directive (EU) 2018/1972 related to the imposition of security and notification requirements on those types of entity should therefore be deleted. The rules on reporting obligations laid down in this Directive should be without prejudice to Regulation (EU) 2016/679 and Directive 2002/58/EC.

## Case law

### Judgment of the Court (First Chamber) of 13 November 2025.#Inteligo Media SA v Autoritatea Naţională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP).#Request for a preliminary ruling from the Curtea de Apel Bucureşti.#Reference for a preliminary ruling – Processing of personal data and the protection of privacy in the electronic communications sector – Directive 2002/58/EC – Article 13(1) and (2) – Unsolicited communications – Concept of communication ‘for the purposes of di

*Source: Court of Justice of the European Union, C-654/23, 2025-11-13 — https://overview.legal/posts/132132 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0654*

The Court of Justice of the European Union ruled on a preliminary reference from the Romanian Curtea de Apel Bucureşti in proceedings between Inteligo Media SA and the Romanian DPA (ANSPDCP) concerning the scope of "direct marketing" and the customer-relationship exception under Article 13 of the ePrivacy Directive (Directive 2002/58/EC) in relation to GDPR Article 6. The case addressed whether a daily newsletter sent to users who registered on an online platform to access additional content qualifies as a communication "for the purposes of direct marketing" and whether the platform registration constitutes obtaining contact details "in the context of the sale of a product or a service" under Article 13(2). The Court's ruling clarifies the interplay between the ePrivacy Directive's specific consent regime for unsolicited communications and the GDPR's general lawfulness requirements, with the underlying national proceedings involving an administrative penalty imposed by ANSPDCP for processing customers' personal data without consent.

### Judgment of the Court (Fourth Chamber) of 27 October 2022.#Proximus NV v Gegevensbeschermingsautoriteit.#Request for a preliminary ruling from the Hof van beroep te Brussel.#Reference for a preliminary ruling – Processing of personal data and protection of privacy in the electronic communications sector – Directive 2002/58/EC – Article 12 – Public telephone directories and directory enquiry services – Subscriber’s consent – Obligations of the provider of directories and of directory enquiry serv

*Source: Court of Justice of the European Union, C-129/21, 2022-10-27 — https://overview.legal/posts/132304 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62021CJ0129*

In a preliminary ruling requested by the Brussels Court of Appeal, the Court of Justice of the European Union addressed the interpretation of Article 12 of Directive 2002/58/EC (ePrivacy Directive) and several GDPR provisions in proceedings between Proximus NV and the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit). The core issue concerned the obligations of providers of public telephone directories regarding subscriber consent, information requirements, and the right to erasure under the GDPR, following the DPA's imposition of a EUR 20,000 fine and remedial orders against Proximus. The Court clarified the interplay between the ePrivacy Directive's consent regime for directory inclusion and the GDPR's broader data protection obligations, including the controller's responsibility to ensure erasure of subscriber data upon withdrawal of consent.

### CE - 451423

*Source: Supreme Administrative Court, 2022-06-27 — https://overview.legal/posts/108993 — original: https://gdprhub.eu/index.php?title=CE_-_451423*

Facts — The French DPA had received a complaint on 28 May 2018 regarding the lawfulness of processing by Amazon Europe Core ('Provider' or 'The company'). The French DPA had forwarded this complaint to the Luxembourg DPA under the 'one stop shop' mechanism of Article 56 GDPR. The luxembourg DPA started an investigation regarding Amazon's use of cookies and its compliance with the GDPR and the ePrivacy directive. However, the French DPA started its own investigation into Amazon's compliance with Article 82 of the French Data protection act, a national implementation of Article 5(3) of the ePrivacy directive. (directive 2002/58/EC). This investigation regarding Article 82 had resulted in decision SAN-2020-013. In this decision, the French DPA fined Amazon €35,000,000 for the failure to obtain prior consent and the failure to inform users of their rights with regards to the processing of their data, which was mandatory under Article 82 of the Data Protection Act. The DPA found that when a user visited the "Amazon.fr" site, a large number of cookies with advertising purposes were automatically placed on the data subjects computer. Because this type of cookie was not essential to the service provided by the controller, the DPA considered that the controller had not complied with the obligation to obtain the consent of Internet users before depositing the cookies. Amazon appealed this decision at the Conseil d'Etat, the French Supreme Administrative Court, and requested its annulment. Amazon also asked the Conseil to refer several questions to the CJEU for a preliminary ruling. Among other arguments, Amazon claimed that the French DPA had made an incorrect interpretation of the law regarding its competence and had disregarded its competence by imposing the contested sanction. The controller also stated that the involvement of the French DPA, when the Luxembourg DPA was already involved, constituted a violation of Article 50 of the Charter of Fundamental Rights. According to this article, the same person may not be prosecuted more than once for the same acts. Holding — With regard to the application of the "one-stop shop" mechanism and the CNIL's jurisdiction: The Conseil ruled that the application and enforcement of the ePrivacy directive was the responsibility of national DPAs according to Article 15a of the directive. The "one-stop shop" mechanism did not apply in this case, even when there was a form of a cross-border processing. The Conseil also stated that the absence of a 'one-stop shop' mechanism did not imply any infringement of Article 50 of the Charter of Fundamental Rights, because the DPA only ruled on breaches of national law transposing EU law in the contested decision, and not on GDPR related violations. The Conseil also assessed the compatibility of Article 3 of the French Data protection Act with the ePrivacy Directive. The Conseil determined that Directive 2002/58/EC did not prevent the French DPA to apply the French data protection Act (including Article 82). The Directive would therefore also not prevent the French DPA from penalising the controller for supposed violations of Article 82 of the French data protection Act. Therefore, the Conseil established that the French DPA could enforce the French data protection act against any person or legal entity responsible for the processing of data who had an establishment in France, irrespective of the location of the principal establishment of the responsible entity. This enforcement by the DPA would also not constitute violations of articles 49 (Freedom of establishment) or 56 (Freedom to provide services) of the TFEU. With regard to the sanction imposed by the CNIL: The Conseil deemed that the applicant was sufficiently informed regarding the scope of the DPA's investigations, the facts and the legal grounds on which the sanction was based. Moreover, the Conseil considered that the applicant was given sufficient time to present its defence. The Conseil also ruled that the involvement of the French DPA, while the Luxembourg DPA was the lead supervisory authority, was not enough to constitute a breach of the equality of arms principle. Amazon had argued that the involvement of the French DPA in the procedure had enabled the French DPA to gain access to privileged and confidential information and had used this information as a basis for its own decision. The Conseil determined that Amazon did not provide enough proof for this argument and stated that Amazon was not able to prove that was the procedure contrary to Article 15a(4) of Directive 2002/58/EC. On a possible violation of Article 50 of the Charter of Fundamental Rights: The Conseil explained, based on the CJEU's case law (Aklagaren v Akerberg Fransson C-617/10, Powszechny Zaklad Ubezpieczen na Zycie SA of C-617/17 and bpost SA v Belgian Competition Authority C-117/20), that the principle invoked by the applicant, that the same person may not be the subject of several proceeding in respect of the same facts, was not violated by the French DPA. The Conseil stated that the principle could only be enforced when criminal proceedings had been definitively terminated. This was in particular the case when a criminal penalty had become final. The Conseil held that Amazon was not found to be the subject of a final sanction issued by the Luxembourg DPA for the facts that had resulted in the €35,000,000 fine in the contested decision. The Conseil rejected the applicant's claim for a reference for a preliminary ruling on the matter. Regarding the application of French Data Protection Act by the French DPA, Amazon had argued that the legal framework regarding cookies was not stable and unclear at the time when proceedings against Amazon were started. The Conseil concluded that it had published guidelines detailing obligations for entities under the applicable law, and considered that the fact that other national supervisory authorities had taken divergent positions in interpreting the conditions and procedures applicable to the collection of user consent had no bearing on the application of the French Data Protection Act by the French DPA. On the proportionality of the sanction imposed: Taking into account the elements assessed by the French DPA to calculate the imposed fine, the Conseil ruled that the DPA had not imposed a disproportionate penalty on the controller. Consequently, the Conseil rejected the entirety of controller's claims.

### Judgment of the Court (Fifth Chamber) of 17 June 2021.#Mircom International Content Management & Consulting (M.I.C.M.) Limited v Telenet BVBA.#Request for a preliminary ruling from the Ondernemingsrechtbank Antwerpen.#Reference for a preliminary ruling – Intellectual property – Copyright and related rights – Directive 2001/29/EC – Article 3(1) and (2) – Concept of ‘making available to the public’ – Downloading of a file containing a protected work via a peer-to-peer network and the simultaneous

*Source: Court of Justice of the European Union, C-597/19, 2021-06-17 — https://overview.legal/posts/132322 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62019CJ0597*

The Court of Justice of the European Union ruled on a preliminary reference from the Ondernemingsrechtbank Antwerpen (Belgium) in proceedings between Mircom International Content Management & Consulting Limited and Telenet BVBA concerning whether downloading a copyrighted file via a peer-to-peer network while simultaneously uploading portions constitutes "making available to the public" under Directive 2001/29/EC, and whether ISPs can be compelled to disclose subscriber identities linked to collected IP addresses. The CJEU held that peer-to-peer file sharing involving simultaneous uploading qualifies as communication to the public, and that the processing of IP addresses for copyright enforcement purposes is lawful under Article 6(1)(f) GDPR read with Article 15(1) of Directive 2002/58/EC, provided that national legislative measures imposing such obligations are proportionate and respect the fundamental rights balance between intellectual property protection, privacy, and personal data protection. No fine was imposed as this was a preliminary ruling.

### LG Rostock - 3 O 762/19

*Source: LG Rostock, 2020-09-15 — https://overview.legal/posts/122848 — original: https://gdprhub.eu/index.php?title=LG_Rostock_-_3_O_762/19*

Facts — The German consumer organisation Bundesverband der Verbraucherzentralen und Verbraucherverbände - Verbraucherzentrale Bundesverband e.V. (vzbv, the claimant) filed a lawsuit against advocado GmbH (advocado, the defendant), a German-based company that runs an online platform where attorneys can offer their services. The defendant's website had used a cookie banner with pre-ticked boxes for the use of marketing and analytics cookies. This included the use of tools such as Google Analytics that entail a data transfer to third countries. The claimant argued that the data processing in connection with the placed cookies was unlawful under Article 6(1) GDPR: A user's consent under Article 6(1)(a) GDPR could not be considered valid under Articles 4(11) and 7 GDPR, especially since the boxes were pre-ticked. Moreover, the claimant claimed that the defendant had violated Articles 5(1)(a), 13/14, 26 and 44 et seqq. GDPR as it had failed to properly inform users of the scope of intended processing activities, joint controllers and international data transfers in connection with the use of cookies. The defendant stated that it had based the use of cookies on legitimate interests under Article 6(1)(f) GDPR until the CJEU issued its decision C-673/17 on 01.10.2019 ("Planet 49"). Afterwards, the defandent argued that they changed the legal basis for processing to consent under Article 6(1)(a) GDPR, which it considered valid under Articles 4(11) and 7 GDPR. The defendant also stated that it was the sole controller for the processing activities - there were no joint controllers involved, only processors. (Furthermore, the claimant had also argued that some provisions in the defendant's general terms and conditions were unlawful from a civil law / consumer protection law perspective. This will not be discussed further in this summary.) Dispute — Was it necessary to ask for the users' consent under Article 6(1)(a) GDPR or could the processing activities in connection with the use of marketing and analytics cookies be based on legitimate interest under Artilce 6(1)(f)? Was the consent given by users' when interacting with the defendant's cookie banner valid under Articles 6(1)(a), 4(11) and 7 GDPR? Did the defendant violate GDPR provisions on transparency? Was the defendant the sole controller regarding the processing activities in connection with the use of marketing and analytics cookies or were there any joint controllers? Holding — Legal basis and validity of consent — The court held that the marketing and analytics cookies used by the defendant c an only be placed with the users' consent under Article 6(1)(a) GDPR : § 15(3) Telemediengesetz that deals with such cookies must be interpreted in light of Article 5(3) e-Privacy Directive, which requires consent for cookies not strictly necessary for technical reasons. Taking into consideration the design of the cookie banner and the lack of information provided to a website user, the court held that consent given could not be considered valid under Articles 6(1)(a), 4(11) and 7 GDPR. The banner featured pre-ticked boxes and a big "OK" button. The option "use only necessary cookies" was designed to not look like an interactive button but rather a link. Consent could therefore not be considered "freely given" and was invalid. Transparency — The court further held that the defendant violated Article 13 GDPR by mentioning an incorrect transfer mechanism under Articles 44 et seqq. GDPR for data transfers in connection with the use of cookies. Sole or joint controllership when using Google Analytics? — Lastly, the court held that the use of Google Analytics results in joint controllership of the website provider using this tool and Google . Google does not qualify as the website provider's processor under Article 4(7). This is because Google does not process the data solely for the purpose of use by the website provider. Rather, Google, like other third-party providers, expressly reserves the right to process the data for its own purposes as well. The fact that the defendant and Google entered into a data processing agreement under Article 28 GDPR does not change this assessment. The court's legal view is in line with the official opinion of the "Datenschutzkonferenz", a gathering of all German DPAs.

### Supreme Court - III CZP 78/19

*Source: Supreme Court, 2020-08-06 — https://overview.legal/posts/158451 — original: https://gdprhub.eu/index.php?title=Supreme_Court_-_III_CZP_78/19*

Facts — The parties were involved in social initiatives aimed at supporting or questioning the need for certain investments in the vicinity of the housing estate where they live. The defendants accused the claimant that, as a result of her interventions in the housing estate, the city carried out no investments. The defendants publicly criticised the claimant's attitude and they also expressed their opinions in social media. The applicant claimed that the defendants had thereby infringed her personal rights. The Regional Court held that there was no infringement, as the defendants exercised their right to freedom of expression. In the Regional Court's opinion the defendants cannot be held responsible for the form of statements made by other people, including Internet users. The claimant has appealed against the judgment. The claimant complained that the court omitted her request for evidence to oblige the domain registrar and the Internet access service provider to disclose the names and addresses of subscribers to the service using pseudonyms (nicknames), who published entries about the claimant on an Internet forum. The Court of Appeal identified the subscriber of the domain and obtained from him information about e-mail addresses to the accounts with logins indicated by the claimant and lists of posts written from those addresses. Next, it called the Internet provider for the established IP addresses to indicate the subscribers of the Internet access service. The Internet provider refused to provide information, citing telecommunication secrecy. Additionally, it indicated that the deadline within which it is obliged to store, among others, the data requested by the Court, has already passed. The Court of Appeal has addressed the Supreme Court with a legal issue. Dispute — Is an entity providing Internet access services, i.e. an entity bound by telecommunication secrecy, entitled to refuse to provide personal data of the subscriber of this service in a case of infringement of personal rights, if it is the content presented via the Internet that may constitute the basis for this infringement and in this case is the basis for providing this data at the request of a civil court? Holding — The Supreme Court held that a court is entitled to demand from an entity bound by telecommunications secrecy information that allows to verify the claimant's claim that an act infringing her personal rights was committed by the defendant in the case.

### Digital Rights Ireland Ltd v Minister for Communications

*Source: CJEU, C-293/12, 2014-04-08 — https://overview.legal/posts/51474 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62012CJ0293&ref=51474*

Invalidated Data Retention Directive as incompatible with fundamental rights.

### BGH - I ZR 7/16

*Source: BGH, 2020-05-28 — https://overview.legal/posts/122851 — original: https://gdprhub.eu/index.php?title=BGH_-_I_ZR_7/16*

Facts — See facts at the GDPRhub entry to the "Planet 49 case" (C-637/1/). The second checkbox containing a preselected tick used by the defendant (Planet 49) read as follows: {| class="wikitable" !English translation !German original |- |‘I agree to the web analytics service Remintrex being used for me. This has the consequence that, following registration for the lottery, the lottery organiser, [Planet49], sets cookies, which enables Planet49 to evaluate my surfing and use behaviour on websites of advertising partners and thus enables advertising by Remintrex that is based on my interests. I can delete the cookies at any time. You can read more about this here.’ |"Ich bin einverstanden, dass der Webanalysedienst Remintrex bei mir eingesetzt wird. Das hat zur Folge, dass der Gewinnspielveranstalter, [Planet49], nach Registrierung für das Gewinnspiel Cookies setzt, welches Planet49 eine Auswertung meines Surf- und Nutzungsverhaltens auf Websites von Werbepartnern und damit interessengerichtete Werbung durch Remintrex ermöglicht. Die Cookies kann ich jederzeit wieder löschen. Lesen Sie Näheres hier." |} In the explanation linked to the word "here", it was pointed out that the cookies would receive a specific, randomly generated number (ID) associated with the registration data of the user who entered his/her name and address in the web form provided. If the user with the stored ID would visit the website of an advertising partner registered for Remintrex, this visit should be recorded, as well as which product the user is interested in and whether a contract is concluded. Holding — Following the CJEU's reasoning in its preliminary ruling, the BGH dismissed the defendants' appeal and, on the plaintiff's appeal, overturned the appellate judgment regarding cookie consent and restored the first instance conviction of the defendant: The declaration of consent by the preselected tick box does not constitute an "informed indication of the data subject's wishes" within the meaning of Article 2(h) Directive 95/46/EC or an "informed and unambiguous indication of the data subject's wishes" within the meaning of Article 2(h) GDPR. Therefore there is no legally valid consent for the data processing. The plaintiff is entitled to injunctive relief against the storage of cookies on his device under § 1 UKlaG in connection with § 307 BGB because the request for consent by a preselected tick box constitutes an "unreasonable disadvantage to the user". The request for consent by a preselected tick box further violates § 15 TMG. An interpretation of § 15 TMG in light of Article 5(3) Directive 2002/58/EC leads to the conclusion that there is no effective consent within the meaning of these provision if the storage of cookies is permitted by a present checkbox which the user must uncheck to refuse consent. Pursuant to Article 94 and 95 GDPR the above said fully applies also after 25.05.2018.

### Judgment of the Court (Grand Chamber) of 20 September 2022.#Bundesrepublik Deutschland v SpaceNet AG and Telekom Deutschland GmbH.#Requests for a preliminary ruling from the Bundesverwaltungsgericht.#Reference for a preliminary ruling – Processing of personal data in the electronic communications sector – Confidentiality of communications – Providers of electronic communications services – General and indiscriminate retention of traffic and location data – Directive 2002/58/EC – Article 15(1) –

*Source: Court of Justice of the European Union, C-793/19, 2022-10-27 — https://overview.legal/posts/132305 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62019CJ0793*

In Joined Cases C-793/19 and C-794/19, the Court of Justice of the European Union (Grand Chamber) addressed preliminary references from the German Federal Administrative Court concerning the interpretation of Article 15(1) of Directive 2002/58/EC (the ePrivacy Directive) in proceedings between the Federal Republic of Germany and telecommunications providers SpaceNet AG and Telekom Deutschland GmbH. The core issue was whether EU law permits Member States to impose general and indiscriminate data retention obligations on electronic communications service providers. The Court ruled that EU law, read in light of the Charter of Fundamental Rights, precludes such general and indiscriminate retention of traffic and location data, while permitting limited, targeted retention regimes and other narrowly tailored measures subject to strict safeguards and prior review by a court or independent administrative body. No fine was imposed.

### Judgment of the Court (Grand Chamber) of 20 September 2022.#Criminal proceedings against VD bd]&#xd; &#xd; Criminal proceedings against VD and SR.#Requests for a preliminary ruling from the Cour de cassation.#References for a preliminary ruling – Single market for financial services – Market abuse – Insider dealing – Directive 2003/6/EC – Article 12(2)(a) and (d) – Regulation (EU) No 596/2014 – Article 23(2)(g) and (h) – Supervisory and investigatory powers of the Autorité des marchés financiers

*Source: Court of Justice of the European Union, C-339/20, 2022-09-20 — https://overview.legal/posts/132308 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62020CJ0339*

In Joined Cases C-339/20 and C-397/20, the Court of Justice of the European Union (Grand Chamber) addressed preliminary ruling requests from the French Cour de cassation in criminal proceedings against VD and SR, concerning whether the French financial markets authority (AMF) could require electronic communications service providers to retain and disclose traffic data for insider dealing investigations. The Court examined the interplay between the market abuse regulatory framework and the ePrivacy Directive (2002/58/EC), assessing whether national legislation authorizing general and indiscriminate retention of traffic data complies with Articles 7, 8, and 11 of the EU Charter of Fundamental Rights. The Court held that such general and indiscriminate retention is precluded and that national courts may not restrict the temporal effects of a declaration of invalidity with respect to incompatible national provisions.

### Judgment of the Court (Second Chamber) of 15 March 2017.#Tele2 (Netherlands) BV and Others v Autoriteit Consument en Markt (ACM).#Request for a preliminary ruling from the College van Beroep voor het Bedrijfsleven.#Reference for a preliminary ruling — Electronic communications networks and services — Directive 2002/22/EC — Article 25(2) — Directory enquiry services and directories — Directive 2002/58/EC — Article 12 — Directories of subscribers — Making available personal data concerning subscri

*Source: Court of Justice of the European Union, C-536/15, 2017-03-15 — https://overview.legal/posts/132349 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62015CJ0536*

In a preliminary ruling raised by the Dutch College van Beroep voor het Bedrijfsleven, the Court of Justice of the European Union interpreted Article 25(2) of the Universal Service Directive (2002/22/EC) and Article 12 of the ePrivacy Directive (2002/58/EC) in a dispute between Dutch telecom providers (Tele2, Ziggo, Vodafone Libertel) and the Autoriteit Consument en Markt (ACM) regarding the obligation to share subscriber data with directory services. The core issue was whether telecom operators must provide subscriber personal data to foreign directory enquiry services without additional subscriber consent, and whether applying different consent requirements based on the Member State where the directory service operates violates the principle of non-discrimination. The Court held that Article 25(2) requires undertakings to make subscriber data available for all directory services across the EU, subject to data protection rules, and that while prior informed consent for inclusion in directories is required, Member States cannot impose different consent conditions depending on whether the directory service is domestic or foreign. No fine was imposed in this ruling.

### Judgment of the Court (Tenth Chamber) of 13 June 2024.#Criminal proceedings against HYA and Others.#Request for a preliminary ruling from the Sofiyski gradski sad.#Reference for a preliminary ruling – Telecommunications sector – Processing of personal data and the protection of privacy – Directive 2002/58/EC – Article 15(1) – Restriction of the confidentiality of electronic communications – Judicial decision authorising listening, tapping and storage in respect of telephone conversations of pers

*Source: Court of Justice of the European Union, C-229/23, 2024-06-13 — https://overview.legal/posts/132256 — original: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62023CJ0229*

In a preliminary ruling brought by the Sofia City Court in criminal proceedings against HYA and others, the Court of Justice of the European Union interpreted Article 15(1) of Directive 2002/58/EC (the ePrivacy Directive) in conjunction with Article 47 of the Charter of Fundamental Rights. The core issue was whether national legislation requiring judicial authorization for the interception of electronic communications to contain an express written statement of reasons—even where the criminal authorities had already submitted a reasoned application—complies with EU law. The Court ruled that the second paragraph of Article 47 of the Charter imposes an obligation on national courts to provide an express statement of reasons in their own decisions authorizing such interception measures, independent of any reasoned application by prosecuting authorities, to ensure adequate judicial safeguards for the fundamental right to privacy.

## Guidance

### Statement 3/2019 on an ePrivacy regulation

*Source: EDPB, statement-32019-on-an-eprivacy-regulation-en, 2019-03-13 — https://overview.legal/posts/126229 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-32019-on-an-eprivacy-regulation_en*

1 Statement 3 / 2019 on an ePrivacy r egulation Adopted on 13 March 2019 The European Data Protection Board has adopted the following statement: The EDPB calls on the EU legislators to intensify efforts towards the adoption of a n ePrivacy Regulation , which is necessary to complete the EU’s framework for data protection and confidentiality of communications. The EDPB wishes to reiterate the positions previously adopted by data protection authorities in the EU, including the Opinion 1/2017 of…

### Statement of the EDPB on the revision of the ePrivacy Regulation and its impact on the protection of individuals with regard to the privacy and confidentiality of their communications

*Source: EDPB, statement-of-the-edpb-on-the-revision-of-the-eprivacy-en, 2018-05-25 — https://overview.legal/posts/126329 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-of-the-edpb-on-the-revision-of-the-eprivacy_en*

Statement of the EDPB on the revision of the ePrivacy Regulation and its impact on the protection of individuals with regard to the privacy and confidentiality of their communications The Data Protection Authorities of the European Union, united in the European Data Protection Board, consider that the revision of the current ePrivacy Directive (2002/58/EC, amended by 2009/136/EC) is an important and necessary step that has to be concluded rapidly. The use of IP based communication services has…

### Statement 03/2021 on the ePrivacy Regulation

*Source: EDPB, statement-032021-on-the-eprivacy-regulation-en, 2021-03-09 — https://overview.legal/posts/126052 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-032021-on-the-eprivacy-regulation_en*

1 Statement 03/2021 on the ePrivacy Regulation Adopted on 9 March 2021 The European Data Protection Board has adopted the following statement: The EDPB welcomes the agreed negotiati on mandate adopted by the Council on the protection of privacy and confidentiality in the use of electronic communication services ( ’ the Council ’s position ’ ) , as a positive step towards a new ePrivacy Regulation . It is of utmost importance that the EU gen eral data protection framework is rapidly complemented…

### Statement on the ePrivacy Regulation and the future role of Supervisory Authorities and the EDPB

*Source: EDPB, statement-on-the-eprivacy-regulation-and-the-future-role-en, 2020-11-19 — https://overview.legal/posts/126113 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/statement-on-the-eprivacy-regulation-and-the-future-role_en*

1 Statement on the ePrivacy Regulation and the future role of Supervisory Authorities and the EDPB Adopted on 19 November 2020 The European Data Protection Board has adopted the following statement: Firstly, the EDPB wants to stress that this statement is without prejudice to its previous positions , including s tatement 3/2019 1 and its statement of 25 May 2018 2 . The ePrivacy Regulation must under no circumstances lower the level of protection offered by the curren t ePrivacy Directive…

### Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive

*Source: EDPB, edpb-guidelines-on-technical-scope-of-art-53-of-eprivacy-directive, 2024-10-16 — https://overview.legal/posts/38063 — original: https://www.edpb.europa.eu/documents/guideline/guidelines-22023-on-technical-scope-of-art-53-of-eprivacy-directive_en*

The European Data Protection Board (EDPB) issued Guidelines 2/2023 to clarify the technical scope of Article 5(3) of the ePrivacy Directive, focusing on its application to emerging tracking technologies that operate as alternatives to cookies. The guidelines establish three key elements—information, terminal equipment, and gaining access/storage—to determine whether specific technical operations require user consent. The document applies this framework to common use cases such as URL and pixel tracking, local processing, IP-based tracking, intermittent IoT reporting, and the use of unique identifiers.

### Report of the work undertaken by the Cookie Banner Taskforce

*Source: EDPB, report-of-the-work-undertaken-by-the-cookie-banner-taskforce-en, 2023-01-18 — https://overview.legal/posts/125875 — original: https://www.edpb.europa.eu/documents/task-force-report/report-of-the-work-undertaken-by-the-cookie-banner-taskforce_en*

Adopted 1 Report of the work undertaken by the Cookie Banner Taskforce Adopted on 17 January 2023 Adopted 2 Adopted 3 DISCLAIMER The positions presented in this document result from the coordination of the members of the TF with a view to handling the “cookies banner” complaints received from NOYB. They reflect the common denominator agreed by the SAs in their interpretation of the applicable provisions of the ePrivacy Directive, and of the applicable provisions of the GDPR, for the analysis to…

### EDPB Annual Report 2019

*Source: EDPB, edpb-annual-report-2019-en, 2020-05-18 — https://overview.legal/posts/126163 — original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/edpb-annual-report-2019_en*

EDPB Annual Report 2019 1 EDPB Annual Report 2019 1 European Data Protection Board 2019 Annual Report WORKING TOGETHER FOR STRONGER RIGHTS An Executive Summary of this report, which provides an overview of key EDPB activities in 2019, is also available. Further details about the EDPB can be found on our website at edpb.europa.eu. EDPB Annual Report 2019 EDPB Annual Report 2019 2 3 FOREWORD 1 4 MISSION STATEMENT, TASKS AND PRINCIPLES 2 5 Tasks and duties Guiding principles 5 6 2.1. 2.2 . ABOUT…

### Opinion 5/2019 on the interplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities

*Source: EDPB, opinion-52019-on-the-interplay-between-the-eprivacy-directive-en, 2019-03-12 — https://overview.legal/posts/126232 — original: https://www.edpb.europa.eu/documents/opinion-of-the-board-art-64/opinion-52019-on-the-interplay-between-the-eprivacy-directive_en*

adopted 1 Opinion 5 / 2019 on the i nterplay between the ePrivacy Directive and the GDPR, in particular regarding the competence, tasks and powers of data protection authorities Adopted on 12 March 2019 adopted 2 adopted 3 The European Data Protection Board Having regard to article 63 and article 64 (2) of the Regulation 2016/679/EU of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free…

## Enforcement decisions

### IP - 07121-1/2020/1570

*Source: IP (Slovenia), 2020-09-11 — https://overview.legal/posts/158458 — original: https://gdprhub.eu/index.php?title=IP_-_07121-1/2020/1570*

Facts — The IP received a request for an opinion concerning sending of an SMS message to users about the new #StayHealthy app created by the National Institute of Public Health (NIJZ). The SMS message was to be carried out on a voluntary basis by operators at the initiative of NIJZ. The opinion relates to the legal basis for this SMS message. Dispute — Is there a legal basis under Slovenian national law for sending an SMS message to all users about a new application launched by the Slovenian National Institute of Public Health? Holding — The IP held that Article 6(3) GDPR applies in this context. As such the legal basis for processing is laid down by the Slovenian Electronic Communications Act (ZEKom-1). To come to this conclusion, the IP referred to the EDPB Opinion 5/2019 on the relationship between the ePrivacy Directive 2002/58/EC (transposed into Slovenian law by ZEKom-1) and the GDPR to establish that ZEKom-1 applies. The IP found that there are restrictions imposed by ZEKom-1 on electronic communications operators regarding lawful data processing. Article 148 ZEKom-1 provides a legal basis for processing subscribers' data, but limits the purposes for which such data is processed with the consent of the data subject. IP added that Article 158 ZEKom-1 restricts sending of unsolicited communications for the purpose of direct marketing through SMS messages. Such communications are only permitted on the basis of consent or certain exceptions. According to IP, the restriction in Article 158 applies to commercial and non-commercial communications, including for the promotion of ideas, political promotions and promotions by NGOs. Therefore, it is unlikely that unsolicited communications on ground relating to emergencies are exempt. Therefore, there was no legal basis for the SMS.

### BfDI: Legal uncertainty in German telecom data protection law (TKG/TMG) requires urgent

*Source: BfDI (Germany), 2026-07-17 — https://overview.legal/posts/125649 — original: https://gdprhub.eu/index.php?title=BfDI_(Germany)_-_4/2021*

Facts — Both of the TKG and TMG are fundamental for the electronic communication and there are many regulations still written in both laws that are only partially or not valid at all. Regarding cookies the TMG and the Directive on privacy and electronic communications (Directive 2002/58/EC) make different specifications. The legislature aims to pass a new Telecommunications Telemedia Data Protection Act (Telekommunikations-Telemedien-Datenschutzgesetz - TTDSG) with the provisions regarding data protection of the TMG and TKG and plans also an implementation of the Code electronic communication into the national law by passing a Telecommunications Modernization Act (Telekommunikationsmodernisierungsgesetzes - TKModG). Dispute — Holding — The DPA held that urgent clarifications are missing and that as a consequence there is legal uncertainty in practice regarding the consideration of the data protection law.

### Garante per la protezione dei dati personali (Italy) - 9788429

*Source: Garante per la protezione dei dati personali (Italy), 2022-07-07 — https://overview.legal/posts/122853 — original: https://gdprhub.eu/index.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_9788429*

Facts — Social media platform TikTok (the controller) provided personalized advertising to its users (the data subjects) on the legal basis of consent (Article 6(1)(a) GDPR). In June 2022, the controller announced that a new privacy policy would come into effect on 13 July 2022. Under the new policy, the controller would only serve personalize advertising to users over 18 years of age and on the legal basis of the legitimate interest of the controller (Article 6(1)(f) GDPR). The Italian DPA started an investigation and found that personalized advertisement would likely involve the use of cookies or other tracking mechanisms. Holding — Regarding the competence of the Italian DPA, it should be noted that the Irish DPA is the lead supervisory authority for the controller’s data processing activities under the GDPR's "one-stop-shop" mechanism. The Italian DPA acknowledged the Irish DPA’s position in its decision. However, the Italian DPA held the ePrivacy Directive to be applicable to the processing of cookies by the controller and held itself competent to enforce the Directive. The DPA referenced Recital 173 GDPR and EDPB Opinion 05/2020 on this point. The DPA held that the controller’s new privacy policy violated Article 5(3) ePrivacy Directive 2002/58/EC. The Article only allows the controller to process cookies and use similar tracking mechanisms with the user’s consent . For this reason, legitimate interest under Article 6(1)(f) GDPR is not a valid legal basis for the processing of cookies. The Italian DPA also held that the controller violated Article 122 of the Italian Privacy Code (d. lgs. 30 giugno 2003, n. 196). Article 122 is a direct transposition of Article 5(3) ePrivacy Directive. The violation of the Code constitutes a direct consequence of the violation of the Directive. The DPA issued a warning against the controller.

### BfDI (Germany) - 24-191 II

*Source: BfDI (Germany), 2022-01-27 — https://overview.legal/posts/125601 — original: https://gdprhub.eu/index.php?title=BfDI_(Germany)_-_24-191_II*

Facts — The data subject is a customer and user of services by the Deutsche Telekom AG (controller), the biggest telecommunications and internet provider in Europe. The data subject requested access from the controller to all of his data under Article 15 GDPR. He also requested to have his data transmitted in a portable format under Article 20 GDPR. The controller responded to both requests. The data subject, however, considered that both responses were not complete. He argued that information about his traffic data, his contracts with the controller and his requests to the controller's customer service were missing. Furthermore, the data subject criticised that the controller did not list all recipients in its answer, but only the "most important" ones, that the origin of the data was not specified and that the storage duration was not mentioned. He, therefore, lodged a complaint with the German Federal Data Protection Authority (Der Bundesbeauftragte für den Datenschutz und die Informationsfreiheit - BfDI). Holding — The BfDI partially upheld the complaint. It confirmed the data subject's view that the controller is obligated under Article 15 GDPR to name all recipients and not only the "most important" ones, to specify the origin of the data and to mention the deletion date. However, the DPA found it was not necessary to list each and every individual transfer to a recipient. With regard to the contract documents, the DPA found that it was sufficient that the controller referred the data subject to the online customer portal where the data subject could retrieve those documents. Regarding the data subject’s requests to the customer service of the controller, the DPA found that these requests are usually handled manually by phone or by paper and not automatically. Accordingly, the DPA concluded that Article 20(1)(b) GDPR was not met. Furthermore, the DPA held that the data collected in the course of service requests must be deleted immediately after the purpose has been achieved, that means after the request has been resolved, or, if the data is to be used for other purposes, it must be anonymised. Consequently, the DPA reasoned that the controller could not have provided this data in its answer to the request under Article 15 GDPR. Regarding the traffic data, the DPA reasoned that a data subject has no right to access traffic data under Article 15 GDPR because § 11 TTDSG (Telekommunikation-Telemedien-Datenschutz-Gesetz), which is an implementation of Article 7 ePrivacy Directive and lays down the right to receive itemized bills, takes precedence according to Article 95 GDPR. In the case at hand, the DPA concluded that the data subject did not invoke § 11 TTDSG since the data subject blackened this part of his submissions. Furthermore, the DPA held that by taking the principle of dataminimisation and Article 11 GDPR into account, the controller is only allowed to store IP addresses seven days. Since the IP addresses which were stored at the time of the request have already been deleted, the controller can no longer provide information about them. The DPA also determined that the controller was not obliged to give the data subject access to location data (Cell-ID) because the data subject did not sufficiently demonstrate that he was the sole user of the mobile phone in question. The DPA took the view that, since location data is very sensitive, the data subject must show that no one else was using the cellphone. Lastly, the DPA clarified that the controller is not allowed to record the content transmitted in an online session. Therefore, it found that it was impossible for the the controller to provide information on the visited websites under Articles 15 and 20 GDPR.

### CNIL fines Amazon Europe Core €35M for placing cookies without consent

*Source: CNIL (France), 2020-12-07 — https://overview.legal/posts/125659 — original: https://gdprhub.eu/index.php?title=CNIL_(France)_-_SAN-2020-013*

Facts — Between December 2019 and May 2020, the CNIL conducted three online and one on-site investigations on Amazon Europe Core (AEC), a subsidiary company of the Amazon group operating the shopping site amazon.fr. These investigations aimed at assessing the company's compliance with the French data protection law. The French DPA reported several infringements of the data protection law by AEC when placing cookies. The company responded by contesting the competence of the CNIL on this matter due to the fact that its main establishment is located in Luxembourg and by challenging the legality of the investigation procedure. Dispute — Is the French DPA competent to sanction a company whose main establishment is not located in France? Does the investigation procedure of the CNIL infringes with the right to a fair trial as guaranteed by Article 6 of the European Convention for the Protection of Human Rights and Fundamental Freedoms? Did AEC infringe on the French data protection law by placing cookies on the user's computer prior to any action on its part? Did AEC failed to properly inform the user of its use of cookies? Holding — The CNIL considered itself competent to investigate AEC and ruled that the company infringed on the French data protection law and on the Directive 2002/58/EC (ePrivacy) while placing cookies. As a consequence, the CNIL imposed a € 35000000 fine on AEC, coupled with an injunction to comply with the Law within three months with a € 100000 penalty per overdue day. Due to the seriousness of the wrongdoings and the high number of Amazon services' users, the CNIL decided to make this sanction publicly available for a two year period. On the territorial competence of the CNIL — AEC argued that the French DPA is not competent to investigate on its activity due to the one-stop-shop principle of GDPR. To support this claim, AEC higlights that the CNIL's investigation initial purpose was, among other things, to ensure that the company complied with GDPR, meaning that the sanction could only be given by the authority relevant to the main establishment of the company in the EU. Furthermore, AEC argued that even though the investigation dealt with cookies which are regulated by the Directive ePrivacy, cookies cannot be dissociated from personal data processing, meaning that the GDPR rules on national competence should prevail. The CNIL rejected this interpretation and deemed itself competent as it was not only investigating GDPR infringements but also breaches of the Directive ePrivacy, transcribed into French law. It reminded that GDPR and ePrivacy each had their own investigating procedure when dealing with their respective requirements. Also, it clarifies that ePrivacy applies as a specialia generalibus derogant rule, based on the interpretation of Article 95 GDPR in the line of the Rec (173) GDPR and Article 1(2) and 15a of the ePrivacy Directive. The CNIL added that the investigation focused on the amazon.fr website targeting french customers. On the legality of the investigation procedure — Regarding the legality of the procedure, AEC accuses the investigating party of submitting the company to questions without telling the purpose and legal basis of the controls carried out. This meant that the company could not exercise its right not to contribute to its own indictment . AEC also argued that the investigating party's method, involving reproducing a user's path was inaccurate as it did not allow to differentiate between Amazon's cookies and the ones placed by third parties when visiting other websites. The CNIL responded by quoting Article 18 of the French data protection law which states that the investigated body has to answer to the CNIL's questions without the CNIL having to justify them and that at the time of those questions no accusation was being made against AEC. Regarding the investigation method, the CNIL argued that it reproduced several user's path in order to determine which cookies were placed when visiting the Amazon website and that it excluded from the perimeter of the investigation those that originated from a third party website. As such, the CNIL considers its investigation procedure to be licit. On the placement of cookies prior to any action from the user — While investigating, the CNIL noticed that more than 40 cookies for commercial purposes were placed on the user's device prior to any act of consent from its part. AEC responded that its cookie practice is subject to the Luxembourg law and not the French law and that Luxembourg allowed to base the consent on the cookie parameters of the web browser. The company added that it changed its french cookie policy in September 2020, but affirmed that it never infringed on the Luxembourg law on cookies. The CNIL rejected this argumentation, considering that the website targeted french customers, and that cookies for commercial purposes always require consent from the data subject as they are not part of the exemptions listed in Article 5(3) of the Directive ePrivacy transcribed in Article 82 of the French data protection law. On the information of the user regarding cookies — The amazon.fr website displayed the following notice regarding cookies: "By using this site, you agree to os ar use of cookies to provide and improve our services. Further information" The DPA found that this wording is not sufficient in order to comply with the transparency principle as it did not provide the data subject with any information on how to exercise its rights or oppose cookies. It added that the expression "to provide and improve our services" does not inform the user of the commercial purposes of some cookies. Finally, the CNIL reminded Amazon that it had already pronounced several sanctions on insufficient information regarding cookies.

### Privacy Appeals Board: Datatilsynet may demand information from OpenX under GDPR Art.

*Source: Datatilsynet (Norway), 2020-09-07 — https://overview.legal/posts/122844 — original: https://gdprhub.eu/index.php?title=Datatilsynet_(Norway)-_20/02254*

Facts — The Norwegian Consumer Council (Forbrukerrådet) filed three complaints against the gay/bi dating app Grindr and five adtech companies that received personal data through the app. Subsequently, Datatilsynet sent a request for more information from one of the adtech companies; OpenX. OpenX refused to respond on the basis that Datatilsynet does not have legal grounds to impose such a request on them, because, in their opinion, the issue relates to the Electronic Communications Act § 2(7)(b) (cf. Article 5(3) ePrivacy Directive 2002/58/EC), where the Norwegian Communications Authority is the right supervisory authority (and not Datatilsynet), and filed a complaint to the Privacy Appeals Board. Dispute — Does the Datatilsynet have the legal grounds (as a supervisory authority) to impose a request for information on OpenX? Holding — The Privacy Appeals Board rejected OpenX's complaint as they concluded that Datatilsynet has legal grounds to impose such requests for information as per Article 58(1) GDPR.

### ANSPDCP (Romania) - Fine against There's an AI for that S.R.L

*Source: ANSPDCP (Romania), 2026-07-24 — https://overview.legal/posts/158433 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_Fine_against_There's_an_AI_for_that_S.R.L*

Facts — In October 2025, the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal – ANSPDCP) concluded an investigation into THERE’S AN AI FOR THAT S.R.L., a company operating a website that used cookies. The investigation began after a data subject submitted a complaint alleging a possible breach of data protection rules. Holding — The ANSPDCP found that the controller’s website stored cookies that were not technically necessary on users’ devices. The authority also found that users were not provided with clear and complete information about these cookies and that their explicit consent had not been obtained before such cookies were placed. The ANSPDCP held that the controller violated Article 4(5)(a) and Article 4(5)(b) of Law No. 506/2004 on the processing of personal data and the protection of privacy in the electronic communications sector (implementing ePrivacy Directive). As a result, the authority imposed an administrative fine of RON 30,000 (€6,000) on the controller for processing data through non-essential cookies without proper information or consent.

### AEPD: Digi Telecom violated Art 6(1) GDPR by issuing duplicate SIM to impersonator

*Source: AEPD (Spain), 2026-07-13 — https://overview.legal/posts/109001 — original: https://gdprhub.eu/index.php?title=AEPD_(Spain)_-_EXP202310345*

Facts — On December 28, 2022, DIGI Telecom, the controller, delivered a duplicate SIM card to an unauthorized third party without the consent of the original line holder (the data subject) The duplicate SIM card was delivered to an impersonator after they passed the established protocols for verifying the applicant's identity. The controller appealed the decision by the Spanish DPA to impose a fine because they claimed that they had appropriate security measures. The controller claims that, by focusing on the result, the Spanish DPA is acting under strict liability. The mere fact that identity theft occurred does not equal a lack of due diligence on the part of the controller. The controller also requested a reduction of the fine on the basis of Article 83(5)(a) GDPR because there were no aggravating circumstances and no special categories of data were processed Holding — The Spanish DPA found a violation of Article 6(1) GDPR because issuing a duplicate SIM card and delivering it to a person other than the telephone line holder constitutes the processing of personal data within the meaning of Article 4(1) GDPR without a legal basis because the data subject did not give consent. The DPA ruled that the controller violated their duty of care because the security measures lacked the dilligence required. According to Article 5(2) GDPR (principle of proactive responsibility) the controller must demonstrate compliance to the GDPR. Proactive responsibility means that the measures are compliant to the GDPR under normal circumstances. The controller must also demonstrate that the measures are compliant with the GDPR and that they are effective in the specific context and purposes of processing (Article 24 en 25 GDPR). The controller had a higher standard of care because of a documented risk to SIM swap attacks and the high scale of processing. Recital 74 GDPR states that the controller’s must implement effective and appropriate measures that take into account the nature, scope and context, and purposes of processing. The card allows an impersonator to access additional data through which they can carry out actions with grave consequences. The controller did not demonstrate that their security measures sufficiently protected the data subject. Factual circumstances should have alerted DIGI to the fraud: the SIM card replacement was processed at a physical store in a different province from where the data subject resided. The Spanish DPA flagged that the controller did not ask the reason for issuing the card and they did not verify whether the old SIM card was functioning. Therefore the security measures were not appropriate to prevent'SIM swap attacks' that are prevalent in the telecom context. With regard to to the height of the fine, the Spanish DPA found that no new legal arguments were made that would lead to the reduction of the fine.

## Recent developments

### ANSPDCP (Romania) - AMATO BESTSELLER S.R.L.

*Source: GDPRhub, 2026-08-18 — https://overview.legal/posts/291260 — original: https://gdprhub.eu/index.php?title=ANSPDCP_(Romania)_-_AMATO_BESTSELLER_S.R.L.*

The DPA imposed a 54,300 fine to a controller for violations of Article 32(4), Article 14 and Article 5(1)(c) in conjunction with Article 9 GDPR and ePrivacy Directive.The DPA imposed a RON 285,395 (€54,300) fine on a wholesale company for, amongst others, failing to implement appropriate security measures, allowing former employees to access personal data as well as for unlawfully using automated dialing and communication systems to call a significant number of data subjects. English Summary. E

### Digital Omnibus Report V3: Analysis of Select GDPR and ePrivacy Proposals by the Commission

*Source: noyb - European Center for Digital Rights, 2026-02-24 — https://overview.legal/posts/53132 — original: https://noyb.eu/en/digital-omnibus-report-v3-analysis-select-gdpr-and-eprivacy-proposals-commission*

GDPR Policy On 19 November 2025, the European Commission published its proposal for the "Digital Omnibus", subsequently sparking significant criticism and opposition. noyb conducted a thorough analysis of all the changes relevant to the GDPR and the ePrivacy Directive, which we firstly published a few days after the proposal was issued by the European Commission. The comprehensive report provides a comparison of the existing law with the Commission's proposal and compiles all our insights. The r

### Digital Omnibus: EU DPAs reject many proposed changes to the GDPR

*Source: noyb - European Center for Digital Rights, 2026-02-11 — https://overview.legal/posts/52485 — original: https://noyb.eu/en/digital-omnibus-eu-dpas-reject-many-proposed-changes-gdpr*

GDPR Policy The EDPB (combining all independent data protection authorities) and the European Data Protection Supervisor (EDPS) published a joint opinion expressing serious concerns about key elements of the proposed GDPR and ePrivacy changes in the so-called “Digital Omnibus” proposed by the European Commission. Specifically, the authorities strongly oppose the proposed narrowing of the definition of personal data. The opinion also question the need for various key proposals, such as the legal

### noyb WIN: French DPA fines Google €325 million for “Spam Emails” in Gmail

*Source: noyb - European Center for Digital Rights, 2025-09-04 — https://overview.legal/posts/53140 — original: https://noyb.eu/en/noyb-win-french-dpa-fines-google-eu325-million-spam-emails-gmail*

Forced Consent & Consent Bypass More than three years ago, noyb had filed a complaint against Google for sending unsolicited advertising emails directly to the inboxes of Gmail users. Contrary to EU law, the company never asked the people concerned for their consent. That's how the competent data protection authority sees it, too: Today, the CNIL has issued a decision siding with noyb – and fined Google €325 million. Press release by the CNILOriginal complaints from 2022Ads disguised as emails.

### Digital Omnibus Report V2: Analysis of Select GDPR and ePrivacy Proposals by the Commission

*Source: noyb - European Center for Digital Rights, 2026-01-20 — https://overview.legal/posts/52488 — original: https://noyb.eu/en/digital-omnibus-report-v2-analysis-select-gdpr-and-eprivacy-proposals-commission*

Version 2 of our report includes specific recommendations for the EU legislator on each of the most important articles, including on whether to reject or maintain proposed changes

## Literature

### European Union ∙ New EDPB Guidance Expands the Technical Scope of Article 5(3) ePrivacy Directive to Many Standard Tracking Technologies

*Source: European Data Protection Law Review, 2025-01-01 — https://overview.legal/posts/132452 — original: https://doi.org/10.21552/edpl/2024/4/8*

### La Quadrature du Net II and Data Retention under Article 15(1) ePrivacy Directive: CJEU Walks a Tightrope on IP Addresses Retention and Access for Public Authorities in Non-Serious Crime

*Source: European Data Protection Law Review, 2025-01-01 — https://overview.legal/posts/132457 — original: https://doi.org/10.21552/edpl/2025/2/17*

La Quadrature du Net II and Data Retention under Article 15(1) ePrivacy Directive Citation for published version (APA): Elisabeth Dekhuijzen, A. (2025). La Quadrature du Net II and Data Retention under Article 15(1) ePrivacy Directive: CJEU Walks a Tightrope on IP Addresses Retention and Access for Public Authorities in Non- Serious Crime. European Data Protection Law Review , 11 (2), 253-258. https://doi.org/10.21552/edpl/2025/2/17 Document status and date: Published: 01/01/2025 DOI: 10.21552/edpl/2025/2/17 Document Version: Publisher's PDF, also known as Version of record Document license: Taverne Please check the document version of this publication: • A submitted manuscript is the version of the article upon submission and before peer-review. There can be important differences between the submitted version and the official published version of record. People interested in the research are advised to contact the author for the final version of the publication, or visit the DOI to the publisher's website. • The final author version and the galley proof are versions of the publication after peer review. • The final published version features the final layout of the paper including

### Effective Regulation through Design – Aligning the ePrivacy Regulation with the EU General Data Protection Regulation (GDPR): Tracking Technologies in Personalised Internet Content and the Data Protection by Design Approach

*Source: SSRN Electronic Journal, 2021-01-01 — https://overview.legal/posts/132422 — original: https://doi.org/10.2139/ssrn.3945471*

### The Concept of Accountability in the Context of the Evolving Role of ENISA in Data Protection, ePrivacy and Cybersecurity

*Source: SSRN Electronic Journal, 2021-01-01 — https://overview.legal/posts/132453 — original: https://doi.org/10.2139/ssrn.4290558*

### European Union ∙ EDPB on the Interplay between the ePrivacy Directive and the GDPR

*Source: European Data Protection Law Review, 2019-01-01 — https://overview.legal/posts/132451 — original: https://doi.org/10.21552/edpl/2019/2/12*

## Related topics

- **Personal Data** — https://overview.legal/topics/persoonsgegevens
  Information relating to identified or identifiable natural persons
- **Processing** — https://overview.legal/topics/verwerking
  Any operation performed on personal data
- **Supervisory Authorities** — https://overview.legal/topics/supervisory-authorities
  National data protection authorities and their powers
- **Consent** — https://overview.legal/topics/toestemming
  Freely given, specific, informed indication of data subject wishes
- **Controllers** — https://overview.legal/topics/controllers
  Entities that determine purposes and means of processing
- **Law Enforcement** — https://overview.legal/topics/law-enforcement
  Processing for law enforcement purposes

---
Generated by overview.legal · https://overview.legal/topics/telecommunications · 2026-08-22
