Notes

← Back to home

A collection of fragments of understanding in the pursuit of deeper questions.

The e-Privacy Framework Cybersecurity - Legal Issues

What is e-Privacy? The exchange of information through public electronic communication services, such as the internet and mobile and landline telephony and via their accompanying networks, requires specific rules and safeguards to ensure the service and that network users' right to privacy and confidentiality are respected.

The e-Privacy Directive The Electronic Privacy Directive (2002/58) was drafted specifically to address the requirements of new digital technologies, ease the advance of electronic communications services and create favourable market conditions for the digital economy. The subject of the directive is the «right to privacy in the electronic communications sector» and «free movement of data, communication equipment and services». It was designed to complement the data protection rules and other rules on telecoms.

Scope of application of the e-Privacy Directive

  • Unlike the GDPR, the e-privacy Directive also protects the interests of legal persons.
  • It applies to processing of personal data in connection with provision of publicly available electronic communications services in public communications networks.
  • Does not apply to activities outside the scope of EU law, or concerning public security, defense and State security and the areas of the State in criminal law. Note: e-privacy rules under the Directive only cover traditional telecoms providers; not other services such as Skype, WhatsApp, Facebook Messenger, Gmail, iMessage, Viber, etc. There is a convergence due to the variety of usage of the new technologies, new services competing with the traditional operators, and the rules were crafted having in mind the traditional operators.

The e-Privacy Directive The Directive sets out rules to:

  • Ensure security in the processing of personal data (including the notice for data breaches).
  • Ensure confidentiality of communications.
  • Introducing safeguards in the processing of traffic data.
  • Ban unsolicited communications where the user has not given consent.

Key Provisions of the e-Privacy Directive Providers of electronic communication services must secure their services by at least:

  • Ensuring personal data are accessed only by authorized persons;
  • Protecting personal data from being destroyed, lost or accidentally altered and from other unlawful or unauthorized forms of processing;
  • Ensuring the implementation of security policy on the processing of personal data. The service provider must inform the national authority of any personal data breach within 24 hours. Individual users must also be informed if the personal data is likely to harm their privacy, unless specifically identified technological measures have been taken to protect the data. EU Member States must ensure the confidentiality of communications made over public networks, in particular they must:
  • Prohibit the listening, tapping, storage or any type of surveillance or interception of communications and traffic data without the consent of users, except where there is a legal authorization and in compliance with specific requirements;
  • Guarantee that the storing of information or the access to stored information on users' personal equipment is permitted only if the user has been clearly and fully informed, inter alia, of the purpose of that access and has been given the right of refusal:
  • When traffic data are no longer required for communication or billing, they must be erased or anonymized.
    • Service providers may process these data form marketing purposes for as long as the user gives his or her consent (consent may be withdrawn at any time).

Prior User Consent is required in a number of situations, including:

  • To send unsolicited communications (SPAM). This also applies to short message services (SMSs) and other electronic messaging systems;
  • To store information (Cookies) on users' computers or devices or to obtain access to that information.
    • The user must be given clear and full information, among others, on the purpose of the storage or access;
  • For the appereance of telephone numbers, e-mail addresses or postal addresses in public directories.

EU Member States are required to have a system of penalties including legal sanctions for infringements of the Directive.

The scope of the rights and obligations can only be restricted by national legislative measures when such restrictions are necessary and proportionate to safeguard specific public interests, such as to allow criminal investigations or to safeguard national security, defense or public security.

Relationship with GDPR GDPR gives effect to art. 8 of the EU Charter (right to data protection) v. e-Privacy Regulation gives effect to art. 7 of the Charter (right to privacy and respect of private life). E-Privacy Regulation is intended to complement and enhance the GDPR rules. E-Privacy constitutes lex specialis to GDPR. (meaning that this is a law which regulates a specific domain, electronic communication service, while the GDPR is still applicable, however the privacy framework will contain some more specific rules to apply in these situations), (lex specialis derogate generali). Recital 175: This regulation should apply to all matters [...] which are not subject to specific obligations with the same objective set out in Directive 2002/58/EC [...] In order to clarify the relationship between this regulation and Directive 2002/58/EC, that Directive should be amended accordingly. Once this regulation is adopted, Directive 2002/58/EC should be reviewed in particular in order to ensure consistency with this regulation. Art. 95: This regulation shall not impose additional obligations on natural or legal persons in relation to processing in connection with the provision of publicly available electronic communications services in public communication networks in the Union in relation to matters for which they are subject to specific obligations with the same objective set out in Directive 2002/58/EC.

Proposed e-Privacy Regulation: where are we?

  • 10 Jan 2017, proposal for a regulation on the respect for private life and the protection of personal data in electronic communications.
  • 19 Oct 2017, Adoption of the draft in EU Parliament
  • 2018, Trilogue negotiations.
  • 2019, Romanian Presidency did not adopt a Common Council Position.
  • End of 2019, Finnsih Presidency + new EU Parliament: negotiations are likely to start and adopt "general approach".

Proposed e-Privacy Regulation: key provisions

  • Set out to replace the e-Privacy Directive and specify GDPR.
  • "New" providers are covered to ensure they guarantee the same level of confidentiality of communications as traditional telecoms operators Over-the-Top communications services ("OTTs").
  • The same rules and level of protection will directly apply across the EU (Regulation v. Directive).

    Applies to communication content and metadata (e.g. time of a call, location), which have a high privacy component and must be anonymized or deleted if users did not give their consent, unless the data is needed for billing. Main contentious issues:

  • Location tracking.
  • Browser and defaults settings.
  • Tracking walls (something that tracks usage of websites).
  • Confidentiality of communications.

Cookie Law

  • Prior Consent
  • Clear and Simple language
  • Browser fingerprinting techniques should be subject to requirements.
  • Cookies for purely analytical purposes should be exempted from the rule.
  • New requirements for browsers: browsers must contain controls on cookies and users must choose these settings as part of the installation process.
  • Settings must provide easy ways to allow or refuse cookies.
  • Default settings for cookies are set in most current browsers to "accept all cookies" are not acceptable -> more intermediate solutions are needed (provide different degrees of acceptance, e.g., "refuse all", "reject third party cookies", "accept all").
  • No consent is needed for no-privacy intrusive cookies improving internet experience (e.g. to remember shopping cart history) or cookies used by a website to count the number of visitors.

Rules guaranteeing privacy for content and metadata on electronic communications

  • Prohibition to interfere with electronic communications (listen to, store, monitor, scan, etc.)
  • Obligation to delete or anonymize content and metadata after the transmission
  • Permitted uses
    • Users' consent
    • Processing of the data is required for billing or security purposes.

Rules Protecting against SPAM

  • Unsolicited electronic communications by emails, SMS and automated calling machines are banned.
  • Direct marketing allowed where users give their consent.
  • For voice-to-voice marketing calls, individuals may be protected "by default" or can be included in a "do-not-call" list depends on national law implementation (opt in/out).
  • Marketing callers will need to display their telephone number or use a special prefix.

Stronger and more effective enforcement

  • Responsibility to monitor and enforce e-privacy rules is shifted to national data protection authorities.
  • Competence to ensure the consistent application of the e-privacy regulation is awarded to the European Data Protection Board (i.e. GDPR body).

The European Electronic Communications Code

  • Established by Directive (EU) 2018/1972
  • Provides a set of rules to regulate electronic communications (telecoms) networks, telecoms services, and associated facilities and services;
  • Sets out tasks for national regulatory authorities and establishes a set of procedures to ensure that the regulatory framework is harmonized throughout the EU;
  • Aims to stimulate competition and increased investment in 5G and very high capacity networks, to achieve high quality connectivity, a high level of consumer protection and an increased choice of innovative digital services.

Focus: Cookies Planet49 case: ECJ Judgment of 1 October 2019. Case concerned the placing of cookies with the purpose of online tracking for behavioral advertising as a condition to access an online service (online lottery). The Directive has led to disparate approaches from national transposition laws and supervisory authorities.

  • Pre-ticked boxes do not amount to valid consent.
  • Expiration date of cookies and third-party sharing should be disclosed to users when obtaining consent.
  • Different purposes should not be bundled under the same consent ask.
  • In order for consent to be valid "an active behaviour with a clear view" ('intention') of consenting should be obtained.
  • These rules apply to cookies regardless of whether the data accessed is personal or not.
  • Still open question: what does "freely given" consent mean?

The Cybersecurity Framework Cybersecurity ensures the security of network and information systems. It consists of the protection of internet-connected systems, including hardware, software and data, from different types of cyberattacks.

The challenges of cybersecurity

  • Fundamental rights and freedoms
  • Internet and Network Integrity
  • Control by multiple entities
  • Shared responsibility

EU's strategic priorities on cybersecurity

  • Cyber Resilience
  • Drastic reduction of cybercrime
  • Develop cyber defense policy and capabilities
  • Develop the industrial and technological resources for cyber security
  • Establish a coherent international cyberspace policy.

Cyber Resilience EU's approach:

  • Economic logic, develop a secure information society for all.
  • Security logic, protecting critical infrastructure against terrorist attacks. Note: the e-Privacy and data protection frameworks provide relevant requirements to manage risks, security requirements, reporting obligations for security or data breaches.

Cyber Crime Cybercrime is one of the fastest growing types of crime: it is high-profit and low-risk. Criminals often exploit anonymity of website domains. It can severely hamper the economy and national/regional plans of economic growth. Crimes specific to the Internet, such as attacks against information systems or phishing (e.g. fake bank websites to solicit passwords enabling access to victims' bank accounts). Online fraud and forgery. Large-scale fraud can be committed online through instruments such as identity theft, phishing, spam and malicious code. Illegal online content, including child sexual abuse material, incitement to racial hatred, incitement to terrorist acts and glorification of violence, terrorism, racism and xenophobia.

Cyber Defense Policy and Capabilities Related to the Common Security and Defense Policy (CSDP). EU Agency for Network and Information Security (ENISA)

  • Established by EU regulations 460/2004 and 526/2013, repealed by the Cybersecurity Act.
  • Provides practical advice for the public and private sector in EU countries and for the EU institutions, including:
    • Organizing cross-Europe cyber crisis exercises
    • Assist in the development of National Cyber Security Strategies.
    • Promoting cooperation between computer emergency response teams and capacity building.
  • Supports drafting of EU policy and law on network and information security.
  • Maintains a network of private and public stakeholders, works closely on joint research and communication activities, supports other EU Agencies

The NIS Directive In this directive, the EU, for the first time, tried to create a cooperation among European countries in facing cybersecurity attacks and emergencies. Key Definitions:

  • Cybersecurity, the ability of network and information systems to resist action that compromises the availability, authenticity, integrity or confidentiality of digital data or the services those systems provide.
  • Network and Information System, an electronic communications network, or any device or group of interconnected devices which process digital data, the digital data stored, processed, retrieved or transmitted.
  • Essential Services, private or public entities with an important role for the society and economy, e.g. water supply, electricity services, etc. Broad set of measures to boost the level of security of network and information systems to secure services vital to the EU economy and society. Aims to ensure that EU Member States are well prepared and ready to handle and respond to cyberattacks through:
  • The designation of competent authorities,
  • The set-up of computer-security incident response teams (CSIRTs),
  • The adoption of national cybersecurity strategies. Establish EU-level cooperation at strategic and technical level. Introduces the obligation on essential service providers and digital providers to take appropriate security measures and to notify the relevant national authorities about serious incidents.

Improve National Cybersecurity Capabilities EU Member States must:

  • Designate 1+ national competent authorities and CSIRT and identify a single point of contact (The point of contact is the authority which will cooperate with the point of contact of other states in order to develop a strategy and advise other countries of a possible threat).
  • Identify providers of essential services in critical sectors and digital infrastructure where a cyberattack could disrupt an essential service.
  • Put in place a national cybersecurity strategy for network and information systems, covering:
    • Preparedness to handle and respond to cyberattacks.
    • Roles, responsibilities, cooperation of governments and other parties.
    • Education, awareness-raising and training programs.
    • Research and development planning.
    • Plan to identify risks.

National competent authorities monitoring obligations

  • Assess the cybersecurity and security policies of providers of essential services;
  • Supervise digital service providers;
  • Participate in the work of the cooperation group (formed by national NIS competent authorities + EU Commission + ENISA);
  • Inform the public where necessary to prevent an incident or to deal with an ongoing incident, while respecting confidentiality;
  • Issuing binding instructions to remedy cybersecurity deficiencies

Computer-security incident response teams (CSIRTs) Responsibilities:

  • Monitor and respond to cybersecurity incidents;
  • Provide risk analysis and incident analysis and situational awareness;
  • Participate in the CSIRTs network;
  • Cooperate with the private sector;
  • Promote the use of standardized practices for incident and risk-handling and information classification.

Security and Notification Requirements

  • Promote a culture of risk management businesses operating in key sectors must evaluate the risks they run and adopt relevant measures.
  • These companies must notify the competent authorities or CSIRTs of any relevant incident (e.g. hacking, theft of data) that seriously compromises cybersecurity and has a significant disruptive effect on the continuity of critical services and supply of goods.
  • Take into account an incident's duration and geographical spread and other factors (e.g. number of users).
  • Key digital service providers will also have to comply with the security and notification requirements.

Improving EU-level Cooperation

  • Cooperation group between national authorities
  • CSIRT network comprising representatives of Member States' CSIRTS + Computer Emergency Response Team (CERT-EU)

Penalties

  • EU Member States must apply effective, proportionate and dissuasive penalties to ensure that the terms of the NIS Directive are applied The main question is that the Directive does not include public administration but rather only the private sector.

The Cybersecurity Act (2017) It introduces a new approach mainly focused on the certification sector.

European cybersecurity certification framework:

  • EU certification framework for ICT digital products, services and processes comprehensive set of rules, technical requirements, standards and procedures.