data protection framework, subsidiary to the more specific rules of the ePR. Any data
processing in context to electronic communications not being within the scope of the
ePR, would be subject to the rules laid down in the GDPR.
33 There would be no
room left for specific national legislation. We will answer the following questions
assuming this scenario. The processing of personal data in context of services
provided at a distance, by electronic means, at the individual request of a recipient
of services, would then be regulated by the ePR and subsidiarily by the GDPR. None
of those regulations provides for any specific legislation concerning services provided at a distance.
2.1.2 Particular Rules Applicable
Specific Protection for the Data Subject
The proposed ePR protects data subjects by regulating the use of tracking and third
party cookies in Art. 8 and 9 ePR. The (amending) rules of the GDPR do not contain
specific protection for the data subject in the context of services provided at a
distance. The GDPR establishes general information duties, Art. 12–14 GDPR.
The information has to be given in a transparent easily accessible form, using clear
language. The information can be provided in writing, or by other means, including
electronic means, where appropriate, Art. 12 GDPR. Besides the principles of data
protection laid down in Art. 5 para. 1 GDPR apply.
34
An additional point to be noted is the existence of specific consumer protection by
contract law
35 in the situation at hand, introduced in transposition of the Consumer
Rights Directive.
36 On the one hand, such rules are without direct effect on the
legality of data processing. On the other hand, they might produce significant
consequences as to the legitimation of the responsible person.
The Role of Previous Consent of the Data Subject
Electronic processing of personal data is subject to general data processing rules on
consent.
37 A general principle of data protection both on EU and national level is the
prohibition of processing of personal data without permission. The processing of
33 Pohle (2017), p. 05452.
34 The principles of data protection include the principle of lawfulness, fairness and transparency,
the principle of purpose limitation, the principle of data minimization, the principle of accuracy, the
principle of storage limitation, the principle of integrity and confidentiality and the principle of
accountability, Art. 5 para. 1 GDPR.
35 Especially sec. 312 et seq. of the German Civil Code deal with consumer protection in context
with services provided by distance.
36 Directive 2011/83/EU.
37 These rules do not differentiate between electronic or non-electronic processing of personal data.
Data Protection in the Internet: National Report Germany
189
Précédent

- 197/540

Suivant