5G Positioning: Security and Privacy Aspects 307
or renewal of a minimum of once a year even where no changes are planned) and
sufficiently granular to enable precision of location data. Processing may only continue so far as necessary for the provision of a service. Service and app providers
are thus to ensure that geolocation data or derivative profiles are deleted following
justifiable storage periods – unless anonymized. In addition, third‐party access should
be logged [32,38,40].
13.11.4 Security Protection
Security of processing is regulated in article 32 GDPR [35]. Much like data protection
by design, appropriate security must thereby be ensured by implementing technological
and organizational measures, taking into account the state‐of‐the‐art, costs and type of
processing as well as the risks involved. Security measures include pseudonymization
and encryption, abilities safeguarding confidentiality, integrity and restoration, as well
as auditing processes.
13.11.5 A Closer Look at the e‐Privacy Directive
For its part, the ePrivacy Directive notes that privacy and data protection must be safeguarded in the development of new applications, which rely on devices connected to
publicly available networks or utilizing electronic communications services (Dir.
2009/136 preamble, 57). Restrictions on privacy in terms of identification may be
imposed in national law to combat nuisance calls and also with regard to location data
to enable emergency services (preamble, 36).
Definitions of “traffic data” and “location data” are included in article 2(2)(b)–(c) of
the ePrivacy Directive, whereby the former “means any data processed for the purpose
of the conveyance of a communication on an electronic communications network or for
the billing thereof ” and the latter “any data processed in [such a] network or by an
electronic communications service, indicating the geographic position of the terminal
equipment of a user of a publicly available electronic communications service. ” Traffic
data includes routing, duration, time, volume and format of a communication, the protocol in questions, the location of the device, the network in question, and duration of a
connection (ePrivacyD preamble, 15). Location data includes information such as latitude, longitude and altitude of the device, the direction of travel, the identification of
the network cell in question, and the time stamp of the location information (ePrivacyD
preamble, 14).
Traffic data may be processed by network and service providers for transmission and
billing purposes following the principle of necessity, among others – after which it must
be erased or anonymized (art 6 ePrivacyD). Users must be informed while prior consent
is needed for processing carried out for marketing and value‐added services by service
providers (art 6(3)‐(4)). Article 9 includes provisions on location data other than traffic
data, whereby the requirements for processing include anonymization or informed
consent. According to the Working Party, consent might concern a specific operation or
a more comprehensive type of service, and providing geolocation data to third parties
requires consent; the person consenting must also be the one whose data is concerned
(e.g. confirmation messages). Consenting must precede sharing of location data by
operators when they provide hybrid geolocation services using different types of
or renewal of a minimum of once a year even where no changes are planned) and
sufficiently granular to enable precision of location data. Processing may only continue so far as necessary for the provision of a service. Service and app providers
are thus to ensure that geolocation data or derivative profiles are deleted following
justifiable storage periods – unless anonymized. In addition, third‐party access should
be logged [32,38,40].
13.11.4 Security Protection
Security of processing is regulated in article 32 GDPR [35]. Much like data protection
by design, appropriate security must thereby be ensured by implementing technological
and organizational measures, taking into account the state‐of‐the‐art, costs and type of
processing as well as the risks involved. Security measures include pseudonymization
and encryption, abilities safeguarding confidentiality, integrity and restoration, as well
as auditing processes.
13.11.5 A Closer Look at the e‐Privacy Directive
For its part, the ePrivacy Directive notes that privacy and data protection must be safeguarded in the development of new applications, which rely on devices connected to
publicly available networks or utilizing electronic communications services (Dir.
2009/136 preamble, 57). Restrictions on privacy in terms of identification may be
imposed in national law to combat nuisance calls and also with regard to location data
to enable emergency services (preamble, 36).
Definitions of “traffic data” and “location data” are included in article 2(2)(b)–(c) of
the ePrivacy Directive, whereby the former “means any data processed for the purpose
of the conveyance of a communication on an electronic communications network or for
the billing thereof ” and the latter “any data processed in [such a] network or by an
electronic communications service, indicating the geographic position of the terminal
equipment of a user of a publicly available electronic communications service. ” Traffic
data includes routing, duration, time, volume and format of a communication, the protocol in questions, the location of the device, the network in question, and duration of a
connection (ePrivacyD preamble, 15). Location data includes information such as latitude, longitude and altitude of the device, the direction of travel, the identification of
the network cell in question, and the time stamp of the location information (ePrivacyD
preamble, 14).
Traffic data may be processed by network and service providers for transmission and
billing purposes following the principle of necessity, among others – after which it must
be erased or anonymized (art 6 ePrivacyD). Users must be informed while prior consent
is needed for processing carried out for marketing and value‐added services by service
providers (art 6(3)‐(4)). Article 9 includes provisions on location data other than traffic
data, whereby the requirements for processing include anonymization or informed
consent. According to the Working Party, consent might concern a specific operation or
a more comprehensive type of service, and providing geolocation data to third parties
requires consent; the person consenting must also be the one whose data is concerned
(e.g. confirmation messages). Consenting must precede sharing of location data by
operators when they provide hybrid geolocation services using different types of
