requirement means that the information provided in a durable medium must include
the mandatory privacy policy terms.
Furthermore, the Directive provides that service providers that send unsolicited
commercial communications by electronic mail should consult regularly and respect
the existing opt-out registers, containing the identification of data subjects that did
not give their consent to receive those communications. The legislation of EU
Member States reflects the transposition of these provisions.
62
The legal framework for unsolicited commercial communications and for managing personal databases for that specific purpose is further detailed in the Directive
on privacy and electronic communications. Although primarily designed to regulate
privacy in the electronic communications sector, notably the processing of personal
data in connection with the provision of publicly available electronic communications services and public communications networks, including public communications networks supporting data collection and identification devices, this Directive
includes several provisions applicable to the processing of personal data by electronic means, in general, whether by a provider of a publicly available electronic
communications service or networks or by any other entity. This Directive establishes, as a rule, an opt-in system for unsolicited commercial communications,
requiring the prior consent of the data subject, except for certain specific scenarios,
such as in the context of the sale of a product or a service. Moreover, this Directive
addresses the storing of information, or the gaining of access to information already
stored, in the terminal equipment of a subscriber or user of an electronic service.
According to the Directive, this specific data processing, such as the one that takes
place with the use of cookies in certain websites, shall only be permitted on the
condition that the subscriber or user concerned has given his or her consent, which
must be preceded by clear and comprehensive information on the conditions of the
corresponding processing of personal data.
63
The abovementioned legal framework, contained in the European Union’s directives, has been transposed to the Member States’ domestic laws.
64 In certain
circumstances, though, the conformity of national legislation with the European
62 See, for example, Spanish National Report, Sects. 2.1.1 and 2.1.2.
63 The Directive on privacy and electronic communications also covers obligations to protect
personal data conveyed and stored through electronic means, as well as obligations to inform
third parties about data breaches. Nevertheless, and contrarily to the previous provisions, these
obligations are set out only for providers of publicly available electronic communications services
and or for providers of public communications networks and, consequently, should be addressed in
the following topic, regarding data protection in the electronic communications sector.
64 See, for instance, the opt-in system referred to in the German National Report, Sect. 2.1.4, the
Portuguese National Report, Sect. 2, the Greek National Report, Sect. 2.1.1, the French National
Report, Sect. 2, and the Spanish National Report, Sects. 2.1.1 and 2.1.2. The national provisions on
the storing of information, and access to information already stored, in the terminal equipment, are
also included, for example, in the Czech Republic National Report, Sect. 2.1, the Portuguese
National Report, Sect. 2, the Greek National Report, Sect. 2.1.1, the French National Report,
Sect. 2, and the Spanish National Report, Sect. 2.1.2.
14
D. Moura Vicente and S. de Vasconcelos Casimiro
Précédent

- 23/540

Suivant