internet communication, including social media (Id.). Contrarily, the employer can
access email and, arguably, other social media that it creates for an employee, with
his consent, with the aim of pursuing the company’s activities (article 50).
3.2 Data Protection in the Electronic Communications Sector
There is specific legislation that regulates some aspects of the matter approved in
2001: the already mentioned Protection of Personal Data in the Telecommunication
Sector Act. In some aspects it resembles the European E-Privacy Directive,
116 but it
was enacted prior to this, which can be explained by the fact that its promoter
probably took the draft directive into account. It focuses globally on all kinds of
telecommunications.
Nonetheless, according to article 4, the “law is applicable to data treatment of
personal data in connection with the offer of telecommunications service available to
the public in public telecommunications networks”, which means that any entity that
offers services of telecommunications falls under the obligations inserted in that Act.
Furthermore, the law does not include a concept of communication data, though it
mentions that it is applicable to all services provided through the digital web with
services integration. Regrettably, there is no relevant case law that has tried to deal
with the concept, especially designed to define its scope with regard to possible
application to internet-provided services in the sense that the Act only contains a
general framework regarding all forms of telecommunications, without a classification in different categories.
117
There is a general norm in the Act—article 6—that guarantees confidentiality and
secrecy of communication through any means of telecommunication accessible to
the public and public webs of telecommunication, forbidding eavesdropping, interception or surveillance of communication and storage of data without the consent of
users. In addition, the Act, under article 7, applies to all forms of telecommunication,
traffic data, which must be erased or anonymised. Article 5 establishes, generally,
that the service provider is obliged to adopt all necessary measures to guarantee
security of telecommunications services—which must be, according to it,
‘adequate’—to cover existent risks, though subject to the principle of proportionality, considering costs of adopting such measures and the state of technological
development of the country. In the case of special risk of security breaches,
according to article 5, paragraph 3, the service provider has a duty to inform
subscribers of that situation, as well as of the possible solutions to avoid its
materialisation and respective costs.
116 As stressed by Traça and Embry (2011), p. 255.
117 For this reason, the National Authority on Data Protection (2017), p. 16, has recommended its
amendment.
98
J. Pina-Delgado
access email and, arguably, other social media that it creates for an employee, with
his consent, with the aim of pursuing the company’s activities (article 50).
3.2 Data Protection in the Electronic Communications Sector
There is specific legislation that regulates some aspects of the matter approved in
2001: the already mentioned Protection of Personal Data in the Telecommunication
Sector Act. In some aspects it resembles the European E-Privacy Directive,
116 but it
was enacted prior to this, which can be explained by the fact that its promoter
probably took the draft directive into account. It focuses globally on all kinds of
telecommunications.
Nonetheless, according to article 4, the “law is applicable to data treatment of
personal data in connection with the offer of telecommunications service available to
the public in public telecommunications networks”, which means that any entity that
offers services of telecommunications falls under the obligations inserted in that Act.
Furthermore, the law does not include a concept of communication data, though it
mentions that it is applicable to all services provided through the digital web with
services integration. Regrettably, there is no relevant case law that has tried to deal
with the concept, especially designed to define its scope with regard to possible
application to internet-provided services in the sense that the Act only contains a
general framework regarding all forms of telecommunications, without a classification in different categories.
117
There is a general norm in the Act—article 6—that guarantees confidentiality and
secrecy of communication through any means of telecommunication accessible to
the public and public webs of telecommunication, forbidding eavesdropping, interception or surveillance of communication and storage of data without the consent of
users. In addition, the Act, under article 7, applies to all forms of telecommunication,
traffic data, which must be erased or anonymised. Article 5 establishes, generally,
that the service provider is obliged to adopt all necessary measures to guarantee
security of telecommunications services—which must be, according to it,
‘adequate’—to cover existent risks, though subject to the principle of proportionality, considering costs of adopting such measures and the state of technological
development of the country. In the case of special risk of security breaches,
according to article 5, paragraph 3, the service provider has a duty to inform
subscribers of that situation, as well as of the possible solutions to avoid its
materialisation and respective costs.
116 As stressed by Traça and Embry (2011), p. 255.
117 For this reason, the National Authority on Data Protection (2017), p. 16, has recommended its
amendment.
98
J. Pina-Delgado
