Lohan, Alén-Savikko, Chen, Järvinen, Leppäkoski, Kuusniemi, and Korpisaari
308
location data [38,40]. With the reform of the ePrivacy Directive, communications metadata, such as location data, would be made more available for provision of additional
services also by traditional telecoms operators, provided that end‐user consent is
secured [124,125]. According to the Regulation proposal, “[l]ocation data that is generated other than in the context of providing electronic communications services should
not be considered as metadata” (preamble, 17) [124,125].
Users must also be informed of transfers to third parties for value‐added service provision, while subcontracting must be in compliance with data protection law (art 9(1);
preamble, 32 ePrivacyD). Alongside consent withdrawal, users must have the possibility
of “temporarily refusing the processing of such data for each connection to the network
or for each transmission of a communication” (art 9(2); preamble, 35 ePrivacyD).
Information on the processing and a possibility for revisiting it must be provided to
those whose location data is being collected by those who collect it; this might be the
provider of a value‐added service or the operator [38,40]. In addition, the ePrivacy
Directive includes in its article 5(3) requirements for storing information or accessing
information stored on a device (so‐called “cookie rule”): consenting in the meaning of
data protection law is required, unless it is for transmission or imperative for providing
a demanded service. In addition, article 4 of the Directive regulates security of processing in order to safeguard confidentiality and integrity of personal data in authorized use.
However, as Minch notes [100], “[with] multiple sensors, device location tracking can
reveal much more than a simple cookie […]. ”
The abundance of tracking techniques is acknowledged in the reform of the ePrivacy
Directive. Moreover, the reform aims at simplifying the “cookie rule”, while also obliging
adoption of tailored privacy settings following the principles of data protection by
design and default [124,125].
13.11.6 Summary of EU Legal Instruments
A summary of EU legal instruments is shown in Table 13.3.
13.11.7 International Issues
5G development has strong international linkages. International organizations such as
the International Telecommunication Union (ITU) are actively pursuing global
approaches. Moreover, Public Private Partnerships (PPP) are encouraged in the area
[107]. For its part, the EU is actively promoting 5G technology, as noted above. The EU
is also cooperating closely with countries such as Japan and Brazil [37].
In addition to EU law already discussed, there are international instruments, such as
the Council of Europe Convention on Data Protection and OECD Privacy Guidelines.
However, these are out of the scope of this chapter.
As a comparison, the US system differs from the EU approach in that there is no general
data protection law comparable to the GDPR and its predecessor, the Directive. Targeted
laws, exist in silos and both on state and federal levels, alongside consumer protection
patrolled by the Federal Trade Commission [71]. As a constitutional right, privacy is
enshrined under the 4th amendment (US v. Katz), which protects people against unreasonable searches, among others. Privacy also operates on the so‐called “reasonable expectations” doctrine, whereby public places and voluntary third‐party disclosure imply that
no such expectations of privacy exist [56,84]. However, the 4th amendment is being
308
location data [38,40]. With the reform of the ePrivacy Directive, communications metadata, such as location data, would be made more available for provision of additional
services also by traditional telecoms operators, provided that end‐user consent is
secured [124,125]. According to the Regulation proposal, “[l]ocation data that is generated other than in the context of providing electronic communications services should
not be considered as metadata” (preamble, 17) [124,125].
Users must also be informed of transfers to third parties for value‐added service provision, while subcontracting must be in compliance with data protection law (art 9(1);
preamble, 32 ePrivacyD). Alongside consent withdrawal, users must have the possibility
of “temporarily refusing the processing of such data for each connection to the network
or for each transmission of a communication” (art 9(2); preamble, 35 ePrivacyD).
Information on the processing and a possibility for revisiting it must be provided to
those whose location data is being collected by those who collect it; this might be the
provider of a value‐added service or the operator [38,40]. In addition, the ePrivacy
Directive includes in its article 5(3) requirements for storing information or accessing
information stored on a device (so‐called “cookie rule”): consenting in the meaning of
data protection law is required, unless it is for transmission or imperative for providing
a demanded service. In addition, article 4 of the Directive regulates security of processing in order to safeguard confidentiality and integrity of personal data in authorized use.
However, as Minch notes [100], “[with] multiple sensors, device location tracking can
reveal much more than a simple cookie […]. ”
The abundance of tracking techniques is acknowledged in the reform of the ePrivacy
Directive. Moreover, the reform aims at simplifying the “cookie rule”, while also obliging
adoption of tailored privacy settings following the principles of data protection by
design and default [124,125].
13.11.6 Summary of EU Legal Instruments
A summary of EU legal instruments is shown in Table 13.3.
13.11.7 International Issues
5G development has strong international linkages. International organizations such as
the International Telecommunication Union (ITU) are actively pursuing global
approaches. Moreover, Public Private Partnerships (PPP) are encouraged in the area
[107]. For its part, the EU is actively promoting 5G technology, as noted above. The EU
is also cooperating closely with countries such as Japan and Brazil [37].
In addition to EU law already discussed, there are international instruments, such as
the Council of Europe Convention on Data Protection and OECD Privacy Guidelines.
However, these are out of the scope of this chapter.
As a comparison, the US system differs from the EU approach in that there is no general
data protection law comparable to the GDPR and its predecessor, the Directive. Targeted
laws, exist in silos and both on state and federal levels, alongside consumer protection
patrolled by the Federal Trade Commission [71]. As a constitutional right, privacy is
enshrined under the 4th amendment (US v. Katz), which protects people against unreasonable searches, among others. Privacy also operates on the so‐called “reasonable expectations” doctrine, whereby public places and voluntary third‐party disclosure imply that
no such expectations of privacy exist [56,84]. However, the 4th amendment is being
