03/02/2020
CURIA - Documents
3.
For the purpose of marketing electronic communications services or for the provision of value added services,
the provider of a publicly available electronic communications service may process the data referred to in
paragraph 1 to the extent and for the duration necessary for such services or marketing, if the subscriber or user to
whom the data relate has given his or her prior consent. Users or subscribers shall be given the possibility to
withdraw their consent for the processing of traffic data at any time.
...
5.
Processing of traffic data, in accordance with paragraphs 1, 2, 3 and 4, must be restricted to persons acting
under the authority of providers of the public communications networks and publicly available electronic
communications services handling billing or traffic management, customer enquiries, fraud detection, marketing
electronic communications services or providing a value added service, and must be restricted to what is necessary
for the purposes of such activities.’
Article 9(1) of that directive, that article being headed ‘Location data other than traffic data’, provides:
‘Where location data other than traffic data, relating to users or subscribers of public communications networks or
publicly available electronic communications services, can be processed, such data may only be processed when
they are made anonymous, or with the consent of the users or subscribers to the extent and for the duration
necessary for the provision of a value added service. The service provider must inform the users or subscribers,
prior to obtaining their consent, of the type of location data other than traffic data which will be processed, of the
purposes and duration of the processing and whether the data will be transmitted to a third party for the purpose of
providing the value added service. …’
Article 15 of that directive, headed ‘Application of certain provisions of Directive [95/46]’, states:
‘1.
Member States may adopt legislative measures to restrict the scope of the rights and obligations provided
for in Article 5, Article 6, Article 8(1), (2), (3) and (4), and Article 9 of this Directive when such restriction
constitutes a necessary, appropriate and proportionate measure within a democratic society to safeguard national
security (i.e. State security), defence, public security, and the prevention, investigation, detection and prosecution
of criminal offences or of unauthorised use of the electronic communication system, as referred to in Article 13(1)
of Directive [95/46]. To this end, Member States may, inter alia, adopt legislative measures providing for the
retention of data for a limited period justified on the grounds laid down in this paragraph. All the measures referred
to in this paragraph shall be in accordance with the general principles of Community law, including those referred to
in Article 6(1) and (2) of the Treaty on European Union.
...
1b.
Providers shall establish internal procedures for responding to requests for access to users’ personal data
based on national provisions adopted pursuant to paragraph 1. They shall provide the competent national authority,
on demand, with information about those procedures, the number of requests received, the legal justification
invoked and their response.
2.
The provisions of Chapter III on judicial remedies, liability and sanctions of Directive [95/46] shall apply with
regard to national provisions adopted pursuant to this Directive and with regard to the individual rights derived
from this Directive.
...’
Directive 95/46
Article 22 of Directive 95/46, which is in Chapter III of that directive, is worded as follows:
‘Without prejudice to any administrative remedy for which provision may be made, inter alia before the supervisory
authority referred to in Article 28, prior to referral to the judicial authority, Member States shall provide for the
right of every person to a judicial remedy for any breach of the rights guaranteed him by the national law
applicable to the processing in question.’
Directive 2006/24/EC
Article 1(2) of Directive 2006/24/EC of the European Parliament and of the Council of 15 March 2006 on the
retention of data generated or processed in connection with the provision of publicly available electronic
communications services or of public communications networks and amending Directive 2002/58/EC (OJ 2006
L 105, p. 54), that article being headed ‘Subject matter and scope’, provided:
‘This Directive shall apply to traffic and location data on both legal entities and natural persons and to the related
data necessary to identify the subscriber or registered user. It shall not apply to the content of electronic
communications, including information consulted using an electronic communications network.’
Article 3 of that directive, headed ‘Obligation to retain data’, provided:
‘1.
By way of derogation from Articles 5, 6 and 9 of [Directive 2002/58], Member States shall adopt measures
to ensure that the data specified in Article 5 of this Directive are retained in accordance with the provisions thereof,
to the extent that those data are generated or processed by providers of publicly available electronic
communications services or of a public communications network within their jurisdiction in the process of supplying
the communications services concerned.
2.
The obligation to retain data provided for in paragraph 1 shall include the retention of the data specified in
Article 5 relating to unsuccessful call attempts where those data are generated or processed, and stored (as
regards telephony data) or logged (as regards Internet data), by providers of publicly available electronic
communications services or of a public communications network within the jurisdiction of the Member State
concerned in the process of supplying the communication services concerned. This Directive shall not require data
relating to unconnected calls to be retained.’
Swedish law
It is apparent from the order for reference in Case C‑203/15 that the Swedish legislature, in order to transpose
Directive 2006/24 into national law, amended the lagen (2003:389) om elektronisk kommunikation [Law
(2003:389) on electronic communications; ‘the LEK’] and the förordningen (2003:396) om elektronisk
kommunikation [Regulation (2003:396) on electronic communications]. Both of those texts, in the versions
curia.europa.eu/juris/document/document.jsf?text=&docid=186492&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=1088733
4/16