5G Positioning: Security and Privacy Aspects 305
Communications Code [26]. The Code aims at regulating the leeway for national regulators and providing for legal certainty in the telecommunications sector of the internet
era. It covers networks and services and includes, among others, provisions on planning
and coordination of spectrum policy.
The Data Protection Directive and the GDPR both apply to processing of personal
data by (partly) automated means, as well as by other means where filing systems are
formed (3(1) DPD; 2(1) GDPR). On the one hand, the territorial scope of application
also overlaps when it comes to the establishment of the controller in the EU. A notable
difference is that the GDPR as a legal instrument is a Regulation with direct applicability across the Member States, while the Directive relied on national implementation,
and differing national laws came to exist. On the other hand, whereas the Directive
refers additionally to making use of “equipment, automated or otherwise, situated on
the territory of the said Member State, unless such equipment is used only for purposes of transit” (art 4(1)(c)), the GDPR speaks of offering goods and services to data
subjects in the EU as well as monitoring their behavior where this behavior is taking
place in the EU (art 3(2)) [35]. The latter approach more clearly applies to various
tracking methods. However, already at present, technologies such as cookies fall under
EU Regulation [71,117].
The GDPR does not apply to anonymous data whereby an individual is no longer
identifiable; however, in assessing identifiability, all means “reasonably likely to be used”
should be accounted for, which means considering the resources required and technology available (GDPR preamble, 26 [35]). Pseudonymous data in turn is covered.
Pseudonymization means that attribution to a specific individual requires additional
information, which is kept separately and secured (art 4(5)).
While the Data Protection Directive does not explicitly tackle “location data”, the
GDPR does. Indeed, “personal data” is defined as “any information relating to an identified or identifiable natural person”, while:
…an identifiable natural person is one who can be identified, directly or indirectly [24,40], in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors
specific to the physical, physiological, genetic, mental, economic, cultural or
social identity of that natural person” (art 4(1) GDPR).
This means that singling out a user of a specific device is sufficient [39]. The Regulation
also refers to location in the context of profiling (GDRP preamble, 71, 75; art 4(4)) [35].
Nonetheless, already under the Directive, geo-location data from smart mobile devices
as well as, for instance, the calculated location of a Wi‐Fi access point combined with a
unique identifier, are personal data [38].
In addition, as a specific instrument regulating data protection and privacy in electronic communications sector, the ePrivacy Directive (2002/58/EC [41], as amended by
2009/136 EC), is applicable with regard to base station data processed by operators – but
operations on the application level only (i.e. independent from the telecom network) are
out of the scope. Nonetheless, providers of other type of infrastructure, such as those
relying on WiFi access points, remain within the scope of general data protection law,
and the same applies to application providers and developers of operating systems
[32,40]. The ePrivacy Directive is currently being reformed in the context of the
Communications Code [26]. The Code aims at regulating the leeway for national regulators and providing for legal certainty in the telecommunications sector of the internet
era. It covers networks and services and includes, among others, provisions on planning
and coordination of spectrum policy.
The Data Protection Directive and the GDPR both apply to processing of personal
data by (partly) automated means, as well as by other means where filing systems are
formed (3(1) DPD; 2(1) GDPR). On the one hand, the territorial scope of application
also overlaps when it comes to the establishment of the controller in the EU. A notable
difference is that the GDPR as a legal instrument is a Regulation with direct applicability across the Member States, while the Directive relied on national implementation,
and differing national laws came to exist. On the other hand, whereas the Directive
refers additionally to making use of “equipment, automated or otherwise, situated on
the territory of the said Member State, unless such equipment is used only for purposes of transit” (art 4(1)(c)), the GDPR speaks of offering goods and services to data
subjects in the EU as well as monitoring their behavior where this behavior is taking
place in the EU (art 3(2)) [35]. The latter approach more clearly applies to various
tracking methods. However, already at present, technologies such as cookies fall under
EU Regulation [71,117].
The GDPR does not apply to anonymous data whereby an individual is no longer
identifiable; however, in assessing identifiability, all means “reasonably likely to be used”
should be accounted for, which means considering the resources required and technology available (GDPR preamble, 26 [35]). Pseudonymous data in turn is covered.
Pseudonymization means that attribution to a specific individual requires additional
information, which is kept separately and secured (art 4(5)).
While the Data Protection Directive does not explicitly tackle “location data”, the
GDPR does. Indeed, “personal data” is defined as “any information relating to an identified or identifiable natural person”, while:
…an identifiable natural person is one who can be identified, directly or indirectly [24,40], in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors
specific to the physical, physiological, genetic, mental, economic, cultural or
social identity of that natural person” (art 4(1) GDPR).
This means that singling out a user of a specific device is sufficient [39]. The Regulation
also refers to location in the context of profiling (GDRP preamble, 71, 75; art 4(4)) [35].
Nonetheless, already under the Directive, geo-location data from smart mobile devices
as well as, for instance, the calculated location of a Wi‐Fi access point combined with a
unique identifier, are personal data [38].
In addition, as a specific instrument regulating data protection and privacy in electronic communications sector, the ePrivacy Directive (2002/58/EC [41], as amended by
2009/136 EC), is applicable with regard to base station data processed by operators – but
operations on the application level only (i.e. independent from the telecom network) are
out of the scope. Nonetheless, providers of other type of infrastructure, such as those
relying on WiFi access points, remain within the scope of general data protection law,
and the same applies to application providers and developers of operating systems
[32,40]. The ePrivacy Directive is currently being reformed in the context of the
