ePrivacy Directive · Directive 2002/58/EC
Article 5
Compare the available Commission, Council and Parliament texts and amendments affecting this article.
Article total: 2 parts · 4 Council drafts · 12 Parliament amendments
Removed wording is struck through; added or replacement wording is highlighted.
Institutional text
European Commission proposal
All Commission’s changes to ePrivacy DirectiveThe wording proposed by the Commission at the start of this legislative file.
Full article with Commission changes
Article with proposed changes
Official consolidated text dated 19 December 2009, with the Commission proposal change affecting this article applied.
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.
No standalone Commission wording is mapped to this tracked part. A newly proposed provision may have no earlier text of its own.
Commission source wording and instructions
Article 5(3), additional subparagraph
Commission proposal
This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.
Institutional text
Council Presidency texts
Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.
No Council wording is mapped to this tracked part.
Article in May Presidency compromise Council text
Comparison basis: Existing law (19 December 2009) compared with May Presidency compromise (21 May 2026)
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or
thegaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowedon conditionwhen thatthe subscriber or user concernedperson has given his or her consent,having been provided with clear and comprehensive information,in accordance withDirectiveRegulation95(EU) 2016/46/EC679. Storing of information,interoraliagaining of access to information already stored,aboutin thepurposesterminal equipment of a natural person without consent, and subsequent processing for the same purpose, shall be lawful to the extent it is strictly necessary for any of theprocessing.followingThispurposes:shall not prevent any technical storage or access for the sole purpose ofa) carrying out the transmission ofaan electronic communication over an electronic communications network; b) providing a service explicitly requested by the user; c) creating anonymous aggregated information about the usage of an online service requested by the user to measure the audience of such a service, where it is carried out by the provider of that online service, orasby a third party acting together with or on behalf of this provider, solely for their own use, including where the third party is performing audience measurement in accordance with Article 24 of Regulation (EU) 2024/1083; d) maintaining or restoring the security of the interface strictly necessaryin orderfor theproviderprovision of an information society serviceexplicitlyrequested by thesubscriberuser or the security of the terminal equipment used for the provision of such service, including in particular cybersecurity, the protection of personal data and privacy of the user and prevention of fraud; The user shall be able toproviderefuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means. If theserviceuser gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the data subject. If the data subject refuses a request for consent, the controller shall not make a new request for consent for the same purpose for a period of at least six months. Member States shall designate the competent supervisory authority under Regulation (EU) 2016/679 for the supervision and enforcement of the rules under this paragraph. 2a In Article 17, the following paragraph is added: 3. Member States shall adopt and publish, by [24 months after the adoption of this Regulation] the laws, regulations and administrative provisions necessary to comply with Article 5(3). They shall immediately communicate the text of those measures to the Commission. They should apply those measures from [24 months after the adoption of this Regulation].
Article 5(3), additional subparagraph
May Presidency compromise
Council wording reconstructed for this provision from the official operation
3. Member States shall ensure that the storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed when that person has given his or her consent, in accordance with Regulation (EU) 2016/679. Storing of information, or gaining of access to information already stored, in the terminal equipment of a natural person without consent, and subsequent processing for the same purpose, shall be lawful to the extent it is strictly necessary for any of the following purposes: a) carrying out the transmission of an electronic communication over an electronic communications network; b) providing a service explicitly requested by the user; c) creating anonymous aggregated information about the usage of an online service requested by the user to measure the audience of such a service, where it is carried out by the provider of that online service, or by a third party acting together with or on behalf of this provider, solely for their own use, including where the third party is performing audience measurement in accordance with Article 24 of Regulation (EU) 2024/1083; d) maintaining or restoring the security of the interface strictly necessary for the provision of an information society service requested by the user or the security of the terminal equipment used for the provision of such service, including in particular cybersecurity, the protection of personal data and privacy of the user and prevention of fraud; The user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means. If the user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the data subject. If the data subject refuses a request for consent, the controller shall not make a new request for consent for the same purpose for a period of at least six months. Member States shall designate the competent supervisory authority under Regulation (EU) 2016/679 for the supervision and enforcement of the rules under this paragraph. 2a In Article 17, the following paragraph is added:
Member States shall adopt and publish, by [24 months after the adoption of this Regulation] the laws, regulations and administrative provisions necessary to comply with Article 5(3). They shall immediately communicate the text of those measures to the Commission. They should apply those measures from [24 months after the adoption of this Regulation].
Article in June Presidency compromise · 10 June Council text
Comparison basis: Existing law (19 December 2009) compared with June Presidency compromise · 10 June (10 June 2026)
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or
thegaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowedon conditionwhen thatthe subscriber or user concernedperson has given his or her consent,having been provided with clear and comprehensive information,in accordance withDirectiveRegulation95(EU) 2016/46/EC679. Storing of information,interoraliagaining of access to information already stored,aboutin thepurposesterminal equipment of a natural person without consent, and subsequent processing of personal data for the same purpose, shall be lawful to the extent it is strictly necessary for any of theprocessing.followingThispurposes:shall not prevent any technical storage or access for the sole purpose ofa) carrying out the transmission ofaan electronic communication over an electronic communications network,;orb)asprovidingstrictly necessary in order for the provider of an information societya service explicitly requested by the subscriber or usertoandprovideensuring the functionality of the service requested; c) Measuring the audience of an online service in order to create anonymous aggregated information about the usage of that online service, where it is carried out by the provider of that online service, or by a third party acting together with or on behalf of this provider, including where the third party is an entitled and independent third party performing audience measurement in accordance with Article 24 of Regulation (EU) 2024/1083; d) maintaining or restoring the security of the interface strictly necessary for the provision of an information society service requested by the subscriber or user or the security of the terminal equipment used for the provision of such service; e) preventing or detecting fraud provided that such measures do not override the fundamental rights and interests of the subscriber or user. The subscriber or user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means. If the subscriber or user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the data subject. If the subscriber or user refuses a request for consent, the provider shall not make a new request for consent for the same purpose for a period of at least six months. Member States shall designate the competent supervisory authority under Regulation (EU) 2016/679 for the supervision and enforcement of the rules under this paragraph.
Article 5(3), additional subparagraph
June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
3. Member States shall ensure that the storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed when that person has given his or her consent, in accordance with Regulation (EU) 2016/679. Storing of information, or gaining of access to information already stored, in the terminal equipment of a natural person without consent, and subsequent processing of personal data for the same purpose, shall be lawful to the extent it is strictly necessary for any of the following purposes:
carrying out the transmission of an electronic communication over an electronic communications network;
providing a service explicitly requested by the subscriber or user and ensuring the functionality of the service requested;
Measuring the audience of an online service in order to create anonymous aggregated information about the usage of that online service, where it is carried out by the provider of that online service, or by a third party acting together with or on behalf of this provider, including where the third party is an entitled and independent third party performing audience measurement in accordance with Article 24 of Regulation (EU) 2024/1083;
maintaining or restoring the security of the interface strictly necessary for the provision of an information society service requested by the subscriber or user or the security of the terminal equipment used for the provision of such service;
preventing or detecting fraud provided that such measures do not override the fundamental rights and interests of the subscriber or user. The subscriber or user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means. If the subscriber or user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the data subject. If the subscriber or user refuses a request for consent, the provider shall not make a new request for consent for the same purpose for a period of at least six months. Member States shall designate the competent supervisory authority under Regulation (EU) 2016/679 for the supervision and enforcement of the rules under this paragraph.
Article in June Presidency compromise · 18 June Council text
Comparison basis: Existing law (19 December 2009) compared with June Presidency compromise · 18 June (18 June 2026)
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or
thegaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowedon conditionwhen thatthe subscriber or user concernedperson has given his or her consent,having been provided with clear and comprehensive information,in accordance withDirectiveRegulation95(EU) 2016/46/EC679. Storing of information,interoraliagaining of access to information already stored,aboutin thepurposesterminal equipment oftheaprocessing. This shall not prevent any technical storagesubscriber oraccessuser without consent, and subsequent processing of personal data for thesolesame purpose,ofshall be lawful to the extent it is solely related to and strictly necessary for the following purposes: a) carrying out the transmission ofaan electronic communication over an electronic communications network; b) providing a service,orincludingasitsstrictly necessary in order for the provider of an information society servicefunctionality, explicitly requested by the subscriber or user; c) Measuring the audience of an online service by creating anonymous aggregated information about the usage of that online service, where it is carried out by the provider of that online service, including jointly with others, or on behalf of that provider, or by an entitled and independent third party performing audience measurement in accordance with Article 24 of Regulation (EU) 2024/1083; c) maintaining or restoring the technical security of the means strictly necessary for the provision of an information society service requested by the subscriber or user or the technical security of the terminal equipment used for the provision of such service; The subscriber or user shall be able toproviderefuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means. If theservicesubscriber or user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the subscriber or user. If the subscriber or user refuses a request for consent, the provider shall not make a new request for consent for the same purpose for a period of at least six months. Member States shall designate the competent supervisory authority under Regulation (EU) 2016/679 for the supervision and enforcement of the rules under this paragraph. 2a In Article 17, the following paragraph is added: 3. Member States shall adopt and publish, by [24 months after the adoption of this Regulation] the laws, regulations and administrative provisions necessary to comply with Article 5(3). They shall immediately communicate the text of those measures to the Commission. They should apply those measures from [24 months after the adoption of this Regulation].
Article 5(3), additional subparagraph
June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
3. Member States shall ensure that the storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed when that person has given his or her consent, in accordance with Regulation (EU) 2016/679. Storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user without consent, and subsequent processing of personal data for the same purpose, shall be lawful to the extent it is solely related to and strictly necessary for the following purposes: a) carrying out the transmission of an electronic communication over an electronic communications network; b) providing a service, including its functionality, explicitly requested by the subscriber or user; c) Measuring the audience of an online service by creating anonymous aggregated information about the usage of that online service, where it is carried out by the provider of that online service, including jointly with others, or on behalf of that provider, or by an entitled and independent third party performing audience measurement in accordance with Article 24 of Regulation (EU) 2024/1083; c) maintaining or restoring the technical security of the means strictly necessary for the provision of an information society service requested by the subscriber or user or the technical security of the terminal equipment used for the provision of such service; The subscriber or user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means. If the subscriber or user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the subscriber or user. If the subscriber or user refuses a request for consent, the provider shall not make a new request for consent for the same purpose for a period of at least six months. Member States shall designate the competent supervisory authority under Regulation (EU) 2016/679 for the supervision and enforcement of the rules under this paragraph. 2a In Article 17, the following paragraph is added:
Member States shall adopt and publish, by [24 months after the adoption of this Regulation] the laws, regulations and administrative provisions necessary to comply with Article 5(3). They shall immediately communicate the text of those measures to the Commission. They should apply those measures from [24 months after the adoption of this Regulation].
Article in September Presidency compromise Council text
Comparison basis: Existing law (19 December 2009) compared with September Presidency compromise (3 September 2026)
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or
thegaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowedon conditionwhen thatthe subscriber or user concernedperson has given his or her consent,having been provided with clear and comprehensive information,in accordance withDirectiveRegulation95(EU) 2016/46/EC679. Storing of information,interoraliagaining of access to information already stored,aboutin thepurposesterminalof the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmissionequipment of acommunication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by thesubscriber or usertowithoutprovideconsent, and subsequent processing of personal data for theservice.same purpose, shall be lawful to the extent it is solely related to and strictly necessary for the following purposes:- (a)
carrying out the transmission of an electronic communication over an electronic communications network;
- (b)
providing a service, including its functionality, explicitly requested by the subscriber or user;
- (c)
creating anonymous aggregated information about the usage of an online service to measure the audience of that service, provided that it is carried out by the provider of the service requested by the subscriber or user, or by a third party on behalf of that provider, and the data collected for the purpose of aggregating the information is not shared with third parties nor combined with data from third parties;
- (d)
performing audience measurement in compliance with Article 24 of Regulation (EU) 2024/1083, provided that personal data are pseudonymised immediately after collection, and that any information shared with third parties other than those acting either on behalf of or jointly together with that provider does not contain personal data;
- (e)
maintaining or restoring the technical security of the means strictly necessary for the provision of an information society service requested by the subscriber or user or the technical security of the terminal equipment used for the provision of such service;
- (f)
measuring the display and performance of advertising that is based solely on the immediate content displayed during an individual visit to a single web page or on the basis of a single search query, provided that such measurement does not involve profiling, data retention or any link with the past or future activity of the subscriber or user, where such measurement is carried out by the provider of an online service, including jointly with others, or by a third party on behalf of that provider. The subscriber or user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means. If the subscriber or user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the subscriber or user. If the subscriber or user refuses a request for consent, the provider shall not make a new request for consent for the same purpose for a period of at least six months.
- (a)
Article 5(3), additional subparagraph
September Presidency compromise
Council wording reconstructed for this provision from the official operation
3. Member States shall ensure that the storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed when that person has given his or her consent, in accordance with Regulation (EU) 2016/679. Storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user without consent, and subsequent processing of personal data for the same purpose, shall be lawful to the extent it is solely related to and strictly necessary for the following purposes: (a) carrying out the transmission of an electronic communication over an electronic communications network; (b) providing a service, including its functionality, explicitly requested by the subscriber or user; (c) creating anonymous aggregated information about the usage of an online service to measure the audience of that service, provided that it is carried out by the provider of the service requested by the subscriber or user, or by a third party on behalf of that provider, and the data collected for the purpose of aggregating the information is not shared with third parties nor combined with data from third parties; (d) performing audience measurement in compliance with Article 24 of Regulation (EU) 2024/1083, provided that personal data are pseudonymised immediately after collection, and that any information shared with third parties other than those acting either on behalf of or jointly together with that provider does not contain personal data; (e) maintaining or restoring the technical security of the means strictly necessary for the provision of an information society service requested by the subscriber or user or the technical security of the terminal equipment used for the provision of such service; (f) measuring the display and performance of advertising that is based solely on the immediate content displayed during an individual visit to a single web page or on the basis of a single search query, provided that such measurement does not involve profiling, data retention or any link with the past or future activity of the subscriber or user, where such measurement is carried out by the provider of an online service, including jointly with others, or by a third party on behalf of that provider. The subscriber or user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means. If the subscriber or user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the subscriber or user. If the subscriber or user refuses a request for consent, the provider shall not make a new request for consent for the same purpose for a period of at least six months.
Official source passage and amending instruction
2. In Article 5, paragraph 3 is replaced by the following: ‘3. Member States shall ensure that the storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed when that person has given his or her consent, in accordance with Regulation (EU) 2016/679. Storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user without consent, and subsequent processing of personal data for the same purpose, shall be lawful to the extent it is solely related to and strictly necessary for the following purposes: (a) carrying out the transmission of an electronic communication over an electronic communications network; (b) providing a service, including its functionality, explicitly requested by the subscriber or user; (c) creating anonymous aggregated information about the usage of an online service to measure the audience of that service, provided that it is carried out by the provider of the service requested by the subscriber or user, or by a third party on behalf of that provider, and the data collected for the purpose of aggregating the information is not shared with third parties nor combined with data from third parties; (d) performing audience measurement in compliance with Article 24 of Regulation (EU) 2024/1083, provided that personal data are pseudonymised immediately after collection, and that any information shared with third parties other than those acting either on behalf of or jointly together with that provider does not contain personal data; (e) maintaining or restoring the technical security of the means strictly necessary for the provision of an information society service requested by the subscriber or user or the technical security of the terminal equipment used for the provision of such service; (f) measuring the display and performance of advertising that is based solely on the immediate content displayed during an individual visit to a single web page or on the basis of a single search query, provided that such measurement does not involve profiling, data retention or any link with the past or future activity of the subscriber or user, where such measurement is carried out by the provider of an online service, including jointly with others, or by a third party on behalf of that provider. The subscriber or user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means. If the subscriber or user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the subscriber or user. If the subscriber or user refuses a request for consent, the provider shall not make a new request for consent for the same purpose for a period of at least six months.’
Article 5(3), additional subparagraph 4 Council drafts
Article 5(3), additional subparagraph
21 May 2026 · May Presidency compromise
Council wording reconstructed for this provision from the official operation
3. Member States shall ensure that the storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed when that person has given his or her consent, in accordance with Regulation (EU) 2016/679. Storing of information, or gaining of access to information already stored, in the terminal equipment of a natural person without consent, and subsequent processing for the same purpose, shall be lawful to the extent it is strictly necessary for any of the following purposes: a) carrying out the transmission of an electronic communication over an electronic communications network; b) providing a service explicitly requested by the user; c) creating anonymous aggregated information about the usage of an online service requested by the user to measure the audience of such a service, where it is carried out by the provider of that online service, or by a third party acting together with or on behalf of this provider, solely for their own use, including where the third party is performing audience measurement in accordance with Article 24 of Regulation (EU) 2024/1083; d) maintaining or restoring the security of the interface strictly necessary for the provision of an information society service requested by the user or the security of the terminal equipment used for the provision of such service, including in particular cybersecurity, the protection of personal data and privacy of the user and prevention of fraud; The user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means. If the user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the data subject. If the data subject refuses a request for consent, the controller shall not make a new request for consent for the same purpose for a period of at least six months. Member States shall designate the competent supervisory authority under Regulation (EU) 2016/679 for the supervision and enforcement of the rules under this paragraph. 2a In Article 17, the following paragraph is added:
Member States shall adopt and publish, by [24 months after the adoption of this Regulation] the laws, regulations and administrative provisions necessary to comply with Article 5(3). They shall immediately communicate the text of those measures to the Commission. They should apply those measures from [24 months after the adoption of this Regulation].
Article 5(3), additional subparagraph
10 June 2026 · June Presidency compromise · 10 June
Council wording reconstructed for this provision from the official operation
3. Member States shall ensure that the storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed when that person has given his or her consent, in accordance with Regulation (EU) 2016/679. Storing of information, or gaining of access to information already stored, in the terminal equipment of a natural person without consent, and subsequent processing of personal data for the same purpose, shall be lawful to the extent it is strictly necessary for any of the following purposes:
carrying out the transmission of an electronic communication over an electronic communications network;
providing a service explicitly requested by the subscriber or user and ensuring the functionality of the service requested;
Measuring the audience of an online service in order to create anonymous aggregated information about the usage of that online service, where it is carried out by the provider of that online service, or by a third party acting together with or on behalf of this provider, including where the third party is an entitled and independent third party performing audience measurement in accordance with Article 24 of Regulation (EU) 2024/1083;
maintaining or restoring the security of the interface strictly necessary for the provision of an information society service requested by the subscriber or user or the security of the terminal equipment used for the provision of such service;
preventing or detecting fraud provided that such measures do not override the fundamental rights and interests of the subscriber or user. The subscriber or user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means. If the subscriber or user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the data subject. If the subscriber or user refuses a request for consent, the provider shall not make a new request for consent for the same purpose for a period of at least six months. Member States shall designate the competent supervisory authority under Regulation (EU) 2016/679 for the supervision and enforcement of the rules under this paragraph.
Article 5(3), additional subparagraph
18 June 2026 · June Presidency compromise · 18 June
Council wording reconstructed for this provision from the official operation
3. Member States shall ensure that the storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed when that person has given his or her consent, in accordance with Regulation (EU) 2016/679. Storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user without consent, and subsequent processing of personal data for the same purpose, shall be lawful to the extent it is solely related to and strictly necessary for the following purposes: a) carrying out the transmission of an electronic communication over an electronic communications network; b) providing a service, including its functionality, explicitly requested by the subscriber or user; c) Measuring the audience of an online service by creating anonymous aggregated information about the usage of that online service, where it is carried out by the provider of that online service, including jointly with others, or on behalf of that provider, or by an entitled and independent third party performing audience measurement in accordance with Article 24 of Regulation (EU) 2024/1083; c) maintaining or restoring the technical security of the means strictly necessary for the provision of an information society service requested by the subscriber or user or the technical security of the terminal equipment used for the provision of such service; The subscriber or user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means. If the subscriber or user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the subscriber or user. If the subscriber or user refuses a request for consent, the provider shall not make a new request for consent for the same purpose for a period of at least six months. Member States shall designate the competent supervisory authority under Regulation (EU) 2016/679 for the supervision and enforcement of the rules under this paragraph. 2a In Article 17, the following paragraph is added:
Member States shall adopt and publish, by [24 months after the adoption of this Regulation] the laws, regulations and administrative provisions necessary to comply with Article 5(3). They shall immediately communicate the text of those measures to the Commission. They should apply those measures from [24 months after the adoption of this Regulation].
Article 5(3), additional subparagraph
3 September 2026 · September Presidency compromise
Council wording reconstructed for this provision from the official operation
3. Member States shall ensure that the storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed when that person has given his or her consent, in accordance with Regulation (EU) 2016/679. Storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user without consent, and subsequent processing of personal data for the same purpose, shall be lawful to the extent it is solely related to and strictly necessary for the following purposes: (a) carrying out the transmission of an electronic communication over an electronic communications network; (b) providing a service, including its functionality, explicitly requested by the subscriber or user; (c) creating anonymous aggregated information about the usage of an online service to measure the audience of that service, provided that it is carried out by the provider of the service requested by the subscriber or user, or by a third party on behalf of that provider, and the data collected for the purpose of aggregating the information is not shared with third parties nor combined with data from third parties; (d) performing audience measurement in compliance with Article 24 of Regulation (EU) 2024/1083, provided that personal data are pseudonymised immediately after collection, and that any information shared with third parties other than those acting either on behalf of or jointly together with that provider does not contain personal data; (e) maintaining or restoring the technical security of the means strictly necessary for the provision of an information society service requested by the subscriber or user or the technical security of the terminal equipment used for the provision of such service; (f) measuring the display and performance of advertising that is based solely on the immediate content displayed during an individual visit to a single web page or on the basis of a single search query, provided that such measurement does not involve profiling, data retention or any link with the past or future activity of the subscriber or user, where such measurement is carried out by the provider of an online service, including jointly with others, or by a third party on behalf of that provider. The subscriber or user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means. If the subscriber or user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the subscriber or user. If the subscriber or user refuses a request for consent, the provider shall not make a new request for consent for the same purpose for a period of at least six months.
Official source passage and amending instruction
2. In Article 5, paragraph 3 is replaced by the following: ‘3. Member States shall ensure that the storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed when that person has given his or her consent, in accordance with Regulation (EU) 2016/679. Storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user without consent, and subsequent processing of personal data for the same purpose, shall be lawful to the extent it is solely related to and strictly necessary for the following purposes: (a) carrying out the transmission of an electronic communication over an electronic communications network; (b) providing a service, including its functionality, explicitly requested by the subscriber or user; (c) creating anonymous aggregated information about the usage of an online service to measure the audience of that service, provided that it is carried out by the provider of the service requested by the subscriber or user, or by a third party on behalf of that provider, and the data collected for the purpose of aggregating the information is not shared with third parties nor combined with data from third parties; (d) performing audience measurement in compliance with Article 24 of Regulation (EU) 2024/1083, provided that personal data are pseudonymised immediately after collection, and that any information shared with third parties other than those acting either on behalf of or jointly together with that provider does not contain personal data; (e) maintaining or restoring the technical security of the means strictly necessary for the provision of an information society service requested by the subscriber or user or the technical security of the terminal equipment used for the provision of such service; (f) measuring the display and performance of advertising that is based solely on the immediate content displayed during an individual visit to a single web page or on the basis of a single search query, provided that such measurement does not involve profiling, data retention or any link with the past or future activity of the subscriber or user, where such measurement is carried out by the provider of an online service, including jointly with others, or by a third party on behalf of that provider. The subscriber or user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means. If the subscriber or user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the subscriber or user. If the subscriber or user refuses a request for consent, the provider shall not make a new request for consent for the same purpose for a period of at least six months.’
Competing proposals
European Parliament amendments
These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.
More filters
Alternative wording Amendment 499 · Piotr Müller IMCO
against:
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
ThisStoringparagraphofshallpersonalnotdata,applyorifgaining of access to personal data already stored, in thesubscriberterminalorequipmentuser isof a natural person without consent, andthesubsequentinformationprocessing,storedshallorbeaccessed constitutes or leadslawful to theprocessingextent it is necessary for any ofpersonalthedata.following:- (a)
carrying out the transmission of an electronic communication over an electronic communications network;
- (b)
providing a service explicitly requested by the user and improving functionality of the requested service;
- (c)
measuring and displaying advertising which is not selected on the basis of any user profiling;
- (d)
measuring the audience of an online service in order to create anonymous aggregated information about the usage of that online service, where it is carried out by the controller of that online service, or by a third party acting together with or on behalf of this provider, or by an entitled and independent third party performing audience measurement in accordance with Article 24(1) of Regulation (EU) 2024/1083;
- (e)
maintaining, or restoring, or ensuring the security of the interface strictly necessary for the provision of an information society service requested by the user or the security of the terminal equipment used for the provision of such service, including in particular cybersecurity, the protection of personal data and privacy of the user and prevention of fraud and unauthorised access;
-
Paragraph (3) letters (b), (c) and (d) shall not apply to data controllers designated as gatekeepers under Regulation (EU) 2022/1925 (the Digital Markets Act).
- (a)
Alternative wording Amendment 500 · David Cormand on behalf of the Verts/ALE Group IMCO
Justification
Adaptation necessary to cater to changes under GDPR in new Articles 88a and b and to ensure consistency between both legal acts.
against:
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
ThisMemberparagraphStates shallnotensureapplythatifthe storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or userisconcernedahasnaturalgivenpersonhis or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about theinformationpurposesstored or accessed constitutes or leads toof the processing. This shall not prevent any technical storage or access for sole the purposes set out in Article 88a(3) ofpersonalRegulationdata(EU) 2016/679. of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.This paragraph shall not apply if the information constitutes processing of personal data. .’
Alternative wording Amendment 1712 · Ondřej Krutílek ITRE · LIBE
Justification
The narrow exemptions of Article 5 have led to interpretations that effectively reduce the regime to a “consent-first” model, making even low-risk or anonymous data uses unnecessarily complex. It creates significant difficulties for vehicle manufacturers; any time the onboard telematics unit or sensors send data externally, it may qualify as “accessing/storing information” under Article 5(3). A vehicle is rarely used by a single individual; it may be driven by the owner, a family member, an employee, or a short-term renter, with passengers also potentially implicated.
against:
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service, or storage of or access to anonymous and necessary information in terminal equipment for the purposes of road safety, transport safety, and accident prevention, including the operation and maintenance of connected vehicles and mobility systems."
This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.
Remove proposed wording Amendment 1714 · Sibylle Berg, Martin Sonneborn ITRE · LIBE
against:
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.
Remove proposed wording Amendment 1715 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
against:
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.
Remove proposed wording Amendment 1716 · Krzysztof Hetman, Adam Jarubas ITRE · LIBE
against:
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.
Remove proposed wording Amendment 1724 · Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec ITRE · LIBE
Justification
This change is proposed due to other amendments tabled moving e-privacy provisions under Regulation (EU) 2016/679.
against:
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.
Additional proposed wording Amendment 1725 · Markéta Gregorová, Damian Boeselager on behalf of the Verts/ALE Group ITRE · LIBE
In Article 5, the following paragraph is added:
Member States shall ensure that the storing of information, or gaining of access to information already stored, in the terminal equipment of a natural person without specific consent, shall be lawful to the extent it is strictly technically and solely necessary for any of the following purpose:
carrying out or facilitating the transmission of an electronic communication over an electronic communications network;
providing an information society service specifically requested by the natural person;
measuring the audience of an information society service explicitly requested by the data subject by creating instantly anonymous aggregated information about the usage of that service, where
it is carried out by the provider of that service, or by a processor acting on behalf of this provider, or by an entitled and independent third party performing audience measurement in accordance with Article 24 of Regulation (EU) 2024/1083. This provision does not apply to gatekeepers within the meaning of Regulation (EU) 2022/1925;
it is carried out solely for the provider’s own use and not processed for other purposes;
the data is not combined with data from other services from the provider service, or from a third party, nor shared with a third party except for third parties referred to in point (i);
such measurement does not adversely affect the fundamental rights of the natural person; and
the natural person is given a possibility to object;
maintaining or restoring the security, confidentiality, integrity, availability and authenticity of the terminal equipment of the user, by means of updates, for the duration necessary for that purpose of a service provided by the controller and explicitly requested by the user or the terminal equipment used for the provision of such service given that
such interest is not overridden by the interests or fundamental rights and freedoms of the data subject;
the user is informed about the storing or gaining access and their purpose;
a genuine choice is given to the user to postpone and decide on the automatic nature of such updates, except in the case of a vulnerability presenting a significant cybersecurity risk; and
this does not in any way change the functionality of the hardware or software or the privacy settings chosen by the user;
complying with paragraph 4 point c of this Article, without storing personal data including unique identifiers;
Member States shall ensure that where storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person is based on consent, the following shall apply:
the data subject shall be able to refuse requests for consent in an easy and intelligible manner with a prominently displayed single-click button;
if the data subject gives consent, the controller shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the data subject;
if the data subject declines a request for consent, the controller shall not make a new request for consent for the same purpose;
the interface used to request consent shall be presented in a machine-readable format.
Member States shall ensure that no user shall be denied access to any information society service or functionality, regardless of whether this service is remunerated or not, on grounds that he or she has not given his or her consent to the processing of personal information and/or the use of processing or storage capabilities of his or her terminal equipment that is not necessary for the provision of that service or functionality.
Member States shall ensure that the conditions for giving, refusing or withdrawing consent using automated and machine-readable signals pursuant to Article 88b of Regulation (EU) 2016/679 shall also apply to this Article.
This Article shall apply from [OP: please insert the date = 6 months following the date of entry into force of this Regulation].
Context reproduced in the official amendment
The amendment reproduces a wider legal passage. It is shown as context because it does not cover the same legal unit as the proposed wording.
This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.
Justification
Article 88a moved back to ePrivacy, in order to avoid that non-personal data is protected better than personal data stored in the terminal equipment.
against:
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.
- 3a.
Member States shall ensure that the storing of information, or gaining of access to information already stored, in the terminal equipment of a natural person without specific consent, shall be lawful to the extent it is strictly technically and solely necessary for any of the following purpose:
- (a)
carrying out or facilitating the transmission of an electronic communication over an electronic communications network;
- (b)
providing an information society service specifically requested by the natural person;
- (c)
measuring the audience of an information society service explicitly requested by the data subject by creating instantly anonymous aggregated information about the usage of that service, where
- (i)
it is carried out by the provider of that service, or by a processor acting on behalf of this provider, or by an entitled and independent third party performing audience measurement in accordance with Article 24 of Regulation (EU) 2024/1083. This provision does not apply to gatekeepers within the meaning of Regulation (EU) 2022/1925;
- (ii)
it is carried out solely for the provider’s own use and not processed for other purposes;
- (iii)
the data is not combined with data from other services from the provider service, or from a third party, nor shared with a third party except for third parties referred to in point (i);
- (iv)
such measurement does not adversely affect the fundamental rights of the natural person; and
- (v)
the natural person is given a possibility to object;
- (d)
maintaining or restoring the security, confidentiality, integrity, availability and authenticity of the terminal equipment of the user, by means of updates, for the duration necessary for that purpose of a service provided by the controller and explicitly requested by the user or the terminal equipment used for the provision of such service given that
- (i)
such interest is not overridden by the interests or fundamental rights and freedoms of the data subject;
- (ii)
the user is informed about the storing or gaining access and their purpose;
- (iii)
a genuine choice is given to the user to postpone and decide on the automatic nature of such updates, except in the case of a vulnerability presenting a significant cybersecurity risk; and
- (iv)
this does not in any way change the functionality of the hardware or software or the privacy settings chosen by the user;
- (e)
complying with paragraph 4 point c of this Article, without storing personal data including unique identifiers;
- 5.
Member States shall ensure that where storing of personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person is based on consent, the following shall apply:
- (a)
the data subject shall be able to refuse requests for consent in an easy and intelligible manner with a prominently displayed single-click button;
- (b)
if the data subject gives consent, the controller shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the data subject;
- (c)
if the data subject declines a request for consent, the controller shall not make a new request for consent for the same purpose;
- (d)
the interface used to request consent shall be presented in a machine-readable format.
- 6.
Member States shall ensure that no user shall be denied access to any information society service or functionality, regardless of whether this service is remunerated or not, on grounds that he or she has not given his or her consent to the processing of personal information and/or the use of processing or storage capabilities of his or her terminal equipment that is not necessary for the provision of that service or functionality.
- 7.
Member States shall ensure that the conditions for giving, refusing or withdrawing consent using automated and machine-readable signals pursuant to Article 88b of Regulation (EU) 2016/679 shall also apply to this Article.
- 8.
This Article shall apply from [OP: please insert the date = 6 months following the date of entry into force of this Regulation].
- (a)
Alternative wording Amendment 1727 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
against:
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.- 1.
Member States shall ensure that the storing of information, or gaining access to information already stored, in the terminal equipment of a user of a service or a subscriber of a service can only be done based on consent of said user or subscriber, in accordance with Regulation 2016/679.
- 2.
The storing of information, or gaining access to information already stored, in the terminal equipment of a subscriber or user of a specific service and the subsequent processing of personal data for the same purpose shall only be lawful without obtaining consent to the extent that is strictly necessary and solely related for the following purposes:
- (a)
carrying out the transmission of an electronic communication over an electronic communications network;
- (b)
providing a service requested by the user or subscriber, as well as its full functionality and personalisation; including the storing of or access to data strictly necessary for the provision of content such as personalisation or recommendation of content, the management of a digital subscription, or the maintenance of a user session;
- (c)
measuring the audience of an online service by creating aggregated information about the usage of that online service, also by a third party, provided that the measuring does not involve repurposing of said data for profiling, advertising, or other privacy intrusive purposes and is subject to relevant safeguards;
- (d)
measuring the audience of an online service by a trade association or its mandated measurement entity on behalf of one or more media service providers for joint audience measurement purposes in accordance with Article 24 of Regulation (EU) 2024/1083, subject to appropriate technical and organisational safeguards; or by a third party acting on behalf of the controller of that online service pursuant to a contractual arrangement with that controller, solely for the purpose of measuring the audience of that online service; or by an entity belonging to the same digital ecosystem as the controller of that online service, for the purpose of measuring the audience of services within that digital ecosystem;
- (e)
ensuring the security of the information society service or of the electronic communications network, provided that it is strictly necessary, proportionate, subject to appropriate safeguards, and only limited to information strictly necessary for this purpose and does not involve any general scanning or monitoring of information stored in the terminal equipment of a user or subscriber;
- (f)
preventing fraud directly related to the use of the specific service requested by the user, provided that such processing is strictly necessary, proportionate, subject to appropriate safeguards, limited to the smallest amount of data required for the purpose, and does not involve any general scanning or monitoring of information stored in the terminal equipment of a user or subscriber;
- (g)
provision, displaying and measurement of such advertising that is solely based on the content immediately displayed to the subscriber or user while using said service, no form of profiling or other privacy intrusive technologies shall be used.
- 3.
The subscriber or user shall be able to refuse requests for consent in an easy
-
and intelligible manner with a single-click button or equivalent means. If the subscriber or user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the subscriber or user.
- 4.
Nothing in this Article shall prevent a media service provider from conditioning access to its service upon the data subject’s consent to the processing of personal data for one or more specified purposes, or upon the payment of a reasonable fee for an equivalent version of the service that does not involve such processing. The specified purposes may include, but are not limited to, advertising, service improvement, product development, and analytics. Where such a choice is offered, both options must be presented to the data subject with equal prominence, in clear and plain language, and without the use of dark patterns.
- 1.
Alternative wording Amendment 1728 · Pernando Barrena Arza ITRE · LIBE
against:
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
ThisMemberparagraphStates shallnotensureapply ifthat the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user isaonlynaturalallowed when that person,andhasthegiveninformation storedhis oraccessedherconstitutesconsent,orinleadsaccordancetowiththeRegulationprocessing(EU)of personal data2016/679.This shall not prevent any technical storage or access and the corresponding processing of personal data if it is exclusively related to and strictly necessary for:
- a)
carrying out the transmission of an electronic communication over an electronic communications network;
- b)
providing a service explicitly requested by the subscriber or user;
- c)
measuring the general audience of an online service requested by a subscriber or user in an immediately anonymised and aggregated form;
- d)
maintaining or restoring the technical security of a service explicitly requested by the subscriber or user through strictly proportionate means;
-
If the subscriber or user refuses a request for consent, the provider shall not make a new request for consent for the same purpose for a period of at least six months. Refusing to give consent should not be more difficult than giving consent. Consent shall by default not be considered to be given in an informed and specific manner when the request for consent involves the disclosure of data to more than 10 controllers in a single action.
-
Member States shall designate the competent supervisory authority under Regulation (EU) 2016/679 for the supervision and enforcement of the rules under this paragraph.
- a)
Alternative wording Amendment 1729 · Alex Agius Saliba ITRE · LIBE
against:
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
Member States shall ensure that the storing of information, or gaining of access to information already stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given their consent, having been provided with clear and comprehensive information, in accordance with Regulation (EU) 2016/679, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the purposes set out in Article 88a(3) of Regulation (EU) 2016/679 of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an online service explicitly requested by the subscriber or user to provide the service. This paragraph shall not apply if the
subscriber or user is a natural person, and theinformationstored or accessedconstitutesor leads to theprocessing of personal data.
Alternative wording Amendment 1730 · Axel Voss, Oliver Schenk ITRE · LIBE
Justification
The AM removes overlapping ePrivacy rules on security, terminal access, metadata, location data and direct marketing where personal-data processing is already governed by the GDPR. Keeping parallel regimes creates consent fatigue, divergent national transpositions and legal uncertainty, including stricter rules for some anonymous device data than for personal data. Consolidation under the GDPR’s risk-based framework simplifies compliance, strengthens coherent rights exercise, supports innovation and preserves sector-specific rules in dedicated instruments.
against:
Article 5
Confidentiality of the communications
- 1.
Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.
- 2.
Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.
- 3.
Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.
This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to theThe processing of personal data previously governed by these provisions shall be exclusively subject to Regulation (EU) 2016/679.(It applies to overall directive.)
No amendments match these filters.
Selected texts
Compare wording
Choose a tracked part and a named pair of texts. Comparisons are offered only where both sides cover the same legal unit.
Select a specific tracked part above to compare wording.
No same-scope comparison is available for this tracked part. Its source wording remains available in the article text sections.
Article 5(3), additional subparagraph
European Commission proposal → Council Presidency text · ST 9547/26
Changes in context
RemovedAdded
Both texts in full
European Commission proposal
Council Presidency text · ST 9547/26
Article 5(3), additional subparagraph
Council Presidency text · ST 9547/26 → Council Presidency text · ST 10426/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 9547/26
Council Presidency text · ST 10426/26
Article 5(3), additional subparagraph
Council Presidency text · ST 10426/26 → Council Presidency text · ST 10677/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10426/26
Council Presidency text · ST 10677/26
Article 5(3), additional subparagraph
Council Presidency text · ST 10677/26 → Council Presidency text · ST 12535/26
Changes in context
RemovedAdded
Both texts in full
Council Presidency text · ST 10677/26
Council Presidency text · ST 12535/26
Article 5(3), additional subparagraph
Wording reproduced in the amendment → Amendment 1712 · ITRE–LIBE amendments 1565–1740 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1712 · ITRE–LIBE amendments 1565–1740 to the draft report
Article 5(3), additional subparagraph
Wording reproduced in the amendment → Amendment 1714 · ITRE–LIBE amendments 1565–1740 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1714 · ITRE–LIBE amendments 1565–1740 to the draft report: removal
This wording is removed.
Article 5(3), additional subparagraph
Wording reproduced in the amendment → Amendment 1715 · ITRE–LIBE amendments 1565–1740 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1715 · ITRE–LIBE amendments 1565–1740 to the draft report: removal
This wording is removed.
Article 5(3), additional subparagraph
Wording reproduced in the amendment → Amendment 1716 · ITRE–LIBE amendments 1565–1740 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1716 · ITRE–LIBE amendments 1565–1740 to the draft report: removal
This wording is removed.
Article 5(3), additional subparagraph
Wording reproduced in the amendment → Amendment 1724 · ITRE–LIBE amendments 1565–1740 to the draft report: removal
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1724 · ITRE–LIBE amendments 1565–1740 to the draft report: removal
This wording is removed.
Article 5(3), additional subparagraph
Wording reproduced in the amendment → Amendment 1727 · ITRE–LIBE amendments 1565–1740 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1727 · ITRE–LIBE amendments 1565–1740 to the draft report
Article 5(3), additional subparagraph
Wording reproduced in the amendment → Amendment 1728 · ITRE–LIBE amendments 1565–1740 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1728 · ITRE–LIBE amendments 1565–1740 to the draft report
Article 5(3), additional subparagraph
Wording reproduced in the amendment → Amendment 1729 · ITRE–LIBE amendments 1565–1740 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1729 · ITRE–LIBE amendments 1565–1740 to the draft report
Article 5(3), additional subparagraph
Wording reproduced in the amendment → Amendment 1730 · ITRE–LIBE amendments 1565–1740 to the draft report
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 1730 · ITRE–LIBE amendments 1565–1740 to the draft report
Article 5(3), additional subparagraph
Wording reproduced in the amendment → Amendment 499 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded
Both texts in full
Wording reproduced in the amendment
Amendment 499 · IMCO amendments 329–532 to the draft opinion
Article 5(3), additional subparagraph
Wording reproduced in the amendment → Amendment 500 · IMCO amendments 329–532 to the draft opinion
Changes in context
RemovedAdded