Categories of “Communication Data”
Electronic communications data is classified in two categories, electronic communications content and electronic communications metadata. Electronic communications content means the content exchanged by means of electronic communications
services, such as text, voice, videos, images, and sound, Art. 4 para. 3 lit. b) ePR.
Electronic communications metadata means data processed in an electronic communications network for the purposes of transmitting, distributing or exchanging
electronic communications content; including data used to trace and identify the
source and destination of a communication, data on the location of the device
generated in the context of providing electronic communications services, and the
date, time, duration and the type of communication, Art. 4 para. 3 lit. c) ePR.
Confidentiality of Communication Data
The confidentiality of communication data is nominated in Art. 5 ePR and derives
from the fundamental right to secrecy of communications.
57 Confidentiality of
electronic communications data means that any interference with electronic communications data by persons other than the end-users shall be prohibited, except
when permitted by the ePR.
58 Permissions are provided in Art. 6 ePR. Para.
1 contains general permissions of the processing of electronic communications
data. Para. 2 then nominates permissions only regarding the processing of electronic
communications metadata, whereas para. 3 names permissions to process electronic
communications content.
Security Measures by the Electronic Communications Providers
There are no specific legal rules about the implementation of security measures by
the electronic communications providers in order to protect personal data. Recital
37 ePR refers to Art. 32 GDPR.
59 A direct reference on that provision can be found
in Art. 8 para. 2 lit. b) ePR.
In the case of risk of a breach of the security, the provider shall inform end-users
concerning such risk and, where the risk lies outside the scope of the measures to be
taken by the service provider, inform end-users of any possible remedies, including
an indication of the likely costs involved, Art. 17 ePR.
57 See Sect. 2.2.1.
58 Art. 5 ePR.
59 Directive on security of network and information systems (EU) 2016/1148.
Data Protection in the Internet: National Report Germany
197
Précédent

- 205/540

Suivant