03/02/2020
CURIA - Documents
Equality and Law Reform, the Commissioner of the Garda Síochána, Ireland and the Attorney General, regarding
the legality of national legislative and administrative measures concerning the retention of data relating to
electronic communications.
The request made by the Verfassungsgerichtshof (Constitutional Court) (Case C‑594/12) concerns constitutional
actions brought before that court by the Kärntner Landesregierung (Government of the Province of Carinthia) and
by Mr Seitlinger, Mr Tschohl and 11 128 other applicants regarding the compatibility with the Federal Constitutional
Law (Bundes-Verfassungsgesetz) of the law transposing Directive 2006/24 into Austrian national law.
Legal context
Directive 95/46/EC
The object of Directive 95/46/EC of the European Parliament and of the Council of 24 October 1995 on the
protection of individuals with regard to the processing of personal data and on the free movement of such data (OJ
1995 L 281, p. 31), according to Article 1(1) thereof, is to protect the fundamental rights and freedoms of natural
persons, and in particular their right to privacy with regard to the processing of personal data.
As regards the security of processing such data, Article 17(1) of that directive provides:
‘Member States shall provide that the controller must implement appropriate technical and organi[s]ational
measures to protect personal data against accidental or unlawful destruction or accidental loss, alteration,
unauthorised disclosure or access, in particular where the processing involves the transmission of data over a
network, and against all other unlawful forms of processing.
Having regard to the state of the art and the cost of their implementation, such measures shall ensure a level of
security appropriate to the risks represented by the processing and the nature of the data to be protected.’
Directive 2002/58/EC
The aim of Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the
processing of personal data and the protection of privacy in the electronic communications sector (Directive on
privacy and electronic communications), as amended by Directive 2009/136/EC of the European Parliament and of
the Council of 25 November 2009 (OJ 2009 L 337, p. 11, ‘Directive 2002/58), according to Article 1(1) thereof, is to
harmonise the provisions of the Member States required to ensure an equivalent level of protection of fundamental
rights and freedoms, and in particular the right to privacy and to confidentiality, with respect to the processing of
personal data in the electronic communication sector and to ensure the free movement of such data and of
electronic communication equipment and services in the European Union. According to Article 1(2), the provisions
of that directive particularise and complement Directive 95/46 for the purposes mentioned in Article 1(1).
As regards the security of data processing, Article 4 of Directive 2002/58 provides:
‘1.
The provider of a publicly available electronic communications service must take appropriate technical and
organisational measures to safeguard security of its services, if necessary in conjunction with the provider of the
public communications network with respect to network security. Having regard to the state of the art and the cost
of their implementation, these measures shall ensure a level of security appropriate to the risk presented.
1a. Without prejudice to Directive 95/46/EC, the measures referred to in paragraph 1 shall at least:
ensure that personal data can be accessed only by authorised personnel for legally authorised purposes,
protect personal data stored or transmitted against accidental or unlawful destruction, accidental loss or alteration,
and unauthorised or unlawful storage, processing, access or disclosure, and,
ensure the implementation of a security policy with respect to the processing of personal data,
Relevant national authorities shall be able to audit the measures taken by providers of publicly available electronic
communication services and to issue recommendations about best practices concerning the level of security which
those measures should achieve.
2.
In case of a particular risk of a breach of the security of the network, the provider of a publicly available
electronic communications service must inform the subscribers concerning such risk and, where the risk lies outside
the scope of the measures to be taken by the service provider, of any possible remedies, including an indication of
the likely costs involved.’
As regards the confidentiality of the communications and of the traffic data, Article 5(1) and (3) of that directive
provide:
‘1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a
public communications network and publicly available electronic communications services, through national
legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance
of communications and the related traffic data by persons other than users, without the consent of the users
concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not
prevent technical storage which is necessary for the conveyance of a communication without prejudice to the
principle of confidentiality.
…
3.
Member States shall ensure that the storing of information, or the gaining of access to information already
stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user
concerned has given his or her consent, having been provided with clear and comprehensive information, in
accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any
technical storage or access for the sole purpose of carrying out the transmission of a communication over an
electronic communications network, or as strictly necessary in order for the provider of an information society
service explicitly requested by the subscriber or user to provide the service.’
Article 6(1) of Directive 2002/58 states:
‘Traffic data relating to subscribers and users processed and stored by the provider of a public communications
network or publicly available electronic communications service must be erased or made anonymous when it is no
longer needed for the purpose of the transmission of a communication without prejudice to paragraphs 2, 3 and 5
of this Article and Article 15(1).’
curia.europa.eu/juris/document/document.jsf?doclang=EN&text=&pageIndex=0&part=1&mode=DOC&docid=150642&occ=first&dir=&cid=99319 (judgment… 2/11