Digital Omnibus tracker

ePrivacy Directive · Directive 2002/58/EC

Article 5

Compare the available Commission, Council and Parliament texts and amendments affecting this article.

Article total: 2 parts · 4 Council drafts · 12 Parliament amendments

Removed wording is struck through; added or replacement wording is highlighted.

Institutional text

The wording proposed by the Commission at the start of this legislative file.

Full article with Commission changes

Article with proposed changes

Official consolidated text dated 19 December 2009, with the Commission proposal change affecting this article applied.

Article 5

Confidentiality of the communications

  1. 1.

    Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.

  2. 2.

    Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.

  3. 3.

    Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.

    This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.

Commission source wording and instructions

Article 5(3), additional subparagraph

Commission proposal

This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.

Institutional text

Council Presidency texts

Successive Presidency compromise texts. Their inclusion does not imply agreement or adoption.

Article 5(3), additional subparagraph

May Presidency compromise

Council wording reconstructed for this provision from the official operation

3. Member States shall ensure that the storing of information, or gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed when that person has given his or her consent, in accordance with Regulation (EU) 2016/679. Storing of information, or gaining of access to information already stored, in the terminal equipment of a natural person without consent, and subsequent processing for the same purpose, shall be lawful to the extent it is strictly necessary for any of the following purposes: a) carrying out the transmission of an electronic communication over an electronic communications network; b) providing a service explicitly requested by the user; c) creating anonymous aggregated information about the usage of an online service requested by the user to measure the audience of such a service, where it is carried out by the provider of that online service, or by a third party acting together with or on behalf of this provider, solely for their own use, including where the third party is performing audience measurement in accordance with Article 24 of Regulation (EU) 2024/1083; d) maintaining or restoring the security of the interface strictly necessary for the provision of an information society service requested by the user or the security of the terminal equipment used for the provision of such service, including in particular cybersecurity, the protection of personal data and privacy of the user and prevention of fraud; The user shall be able to refuse requests for consent in an easy and intelligible manner with a single-click button or equivalent means. If the user gives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the data subject. If the data subject refuses a request for consent, the controller shall not make a new request for consent for the same purpose for a period of at least six months. Member States shall designate the competent supervisory authority under Regulation (EU) 2016/679 for the supervision and enforcement of the rules under this paragraph. 2a In Article 17, the following paragraph is added:

Competing proposals

European Parliament amendments

These are alternative tabled amendments. An amendment affecting several tracked parts appears once here, with each target identified.

More filters

Alternative wording Amendment 499 · Piotr Müller IMCO
ThisStoring paragraphof personal data, or gaining of access to personal data already stored, in the terminal equipment of a natural person without consent, and subsequent processing, shall be lawful to the extent it is necessary for any of the following: (a) carrying out the transmission of an electronic communication over an electronic communications network; (b) providing a service explicitly requested by the user and improving functionality of the requested service; (c) measuring and displaying advertising which is not selected on the basis of any user profiling; (d) measuring the audience of an online service in order to create anonymous aggregated information about the usage of that online service, where it is carried out by the controller of that online service, or by a third party acting together with or on behalf of this provider, or by an entitled and independent third party performing audience measurement in accordance with Article 24(1) of Regulation (EU) 2024/1083; (e) maintaining, or restoring, or ensuring the security of the interface strictly necessary for the provision of an information society service requested by the user or the security of the terminal equipment used for the provision of such service, including in particular cybersecurity, the protection of personal data and privacy of the user and prevention of fraud and unauthorised access; Paragraph (3) letters (b), (c) and (d) shall not apply ifto data controllers designated as gatekeepers under Regulation (EU) 2022/1925 (the subscriberDigital orMarkets user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal dataAct).
Preview
against:
Source identification

Header printed in the source: Article 5 – paragraph 1 – point 2 / Directive 2002/58/EC / Article 5 – paragraph 3

Alternative wording Amendment 500 · David Cormand on behalf of the Verts/ALE Group IMCO
3. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for sole the purposes set out in Article 88a(3) of Regulation (EU) 2016/679. of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service. This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data. .’
Justification

Adaptation necessary to cater to changes under GDPR in new Articles 88a and b and to ensure consistency between both legal acts.

Preview
against:
Source identification

Header printed in the source: Article 5 – paragraph 1 – point 2 / Directive 2002/58/EC (ePrivacy Directive) / Article 5, paragraph 3

Alternative wording Amendment 1712 · Ondřej Krutílek ITRE · LIBE
1a. In Article 5(3), the last sentence is replaced by the following:
3. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service, or storage of or access to anonymous and necessary information in terminal equipment for the purposes of road safety, transport safety, and accident prevention, including the operation and maintenance of connected vehicles and mobility systems."
Justification

The narrow exemptions of Article 5 have led to interpretations that effectively reduce the regime to a “consent-first” model, making even low-risk or anonymous data uses unnecessarily complex. It creates significant difficulties for vehicle manufacturers; any time the onboard telematics unit or sensors send data externally, it may qualify as “accessing/storing information” under Article 5(3). A vehicle is rarely used by a single individual; it may be driven by the owner, a family member, an employee, or a short-term renter, with passengers also potentially implicated.

Preview
against:
Source identification

Header printed in the source: Article 5 – paragraph 1 – point 1 a (new) / Directive 2002/58/EC / Article 5 – paragraph 3

Remove proposed wording Amendment 1714 · Sibylle Berg, Martin Sonneborn ITRE · LIBE
2. After Article 5(3), the following subparagraph is added: ‘This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.’
Preview
against:
Source identification

Header printed in the source: Article 5 – paragraph 1 – point 2 / Directive 2002/58/EC / Article 5 – paragraph 3

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 1715 · Julie Rechagneux, Mélanie Disdier, Aleksandar Nikolic, Pierre-Romain Thionnet, Alexandre Varaut, Fabrice Leggeri, Marion Maréchal, Christophe Bay ITRE · LIBE
2. After Article 5(3), the following subparagraph is added: ‘This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.’
Preview
against:
Source identification

Header printed in the source: Article 5 – paragraph 1 – point 2 / Directive 2002/58/EC / Article 5 – paragraph 3

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 1716 · Krzysztof Hetman, Adam Jarubas ITRE · LIBE
2. After Article 5(3), the following subparagraph is added: ‘This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.’
Preview
against:
Source identification

Header printed in the source: Article 5 – paragraph 1 – point 2 / Directive 2002/58/EC / Article 5 – paragraph 3

Deletion marker printed in the source: deleted

Remove proposed wording Amendment 1724 · Marina Kaljurand, Elena Sancho Murillo, Brando Benifei, Birgit Sippel, Alex Agius Saliba, Francisco Assis, Elisabeth Grossmann, Kristian Vigenin, Matjaž Nemec ITRE · LIBE
This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.
Justification

This change is proposed due to other amendments tabled moving e-privacy provisions under Regulation (EU) 2016/679.

Preview
against:
Source identification

Header printed in the source: Article 5 – paragraph 1 – point 2 / Directive 2002/58/EC / Article 5 – paragraph 3 – subparagraph 2 (new)

Deletion marker printed in the source: deleted

Additional proposed wording Amendment 1725 · Markéta Gregorová, Damian Boeselager on behalf of the Verts/ALE Group ITRE · LIBE

In Article 5, the following paragraph is added:

Member States shall ensure that the storing of information, or gaining of access to information already stored, in the terminal equipment of a natural person without specific consent, shall be lawful to the extent it is strictly technically and solely necessary for any of the following purpose:

Context reproduced in the official amendment

The amendment reproduces a wider legal passage. It is shown as context because it does not cover the same legal unit as the proposed wording.

This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.

Justification

Article 88a moved back to ePrivacy, in order to avoid that non-personal data is protected better than personal data stored in the terminal equipment.

Preview
against:
Source identification

Header printed in the source: Article 5 – paragraph 1 – point 2 / Directive 2002/58/EC / Article 5 – paragraph 3a (new)

Alternative wording Amendment 1727 · Sebastian Tynkkynen, Diego Solier ITRE · LIBE
ThisArticle paragraph5 is replaced by the following:
1. Member States shall ensure that the storing of information, or gaining access to information already stored, in the terminal equipment of a user of a service or a subscriber of a service can only be done based on consent of said user or subscriber, in accordance with Regulation 2016/679. 2. The storing of information, or gaining access to information already stored, in the terminal equipment of a subscriber or user of a specific service and the subsequent processing of personal data for the same purpose shall only be lawful without obtaining consent to the extent that is strictly necessary and solely related for the following purposes: (a) carrying out the transmission of an electronic communication over an electronic communications network; (b) providing a service requested by the user or subscriber, as well as its full functionality and personalisation; including the storing of or access to data strictly necessary for the provision of content such as personalisation or recommendation of content, the management of a digital subscription, or the maintenance of a user session; (c) measuring the audience of an online service by creating aggregated information about the usage of that online service, also by a third party, provided that the measuring does not applyinvolve ifrepurposing of said data for profiling, advertising, or other privacy intrusive purposes and is subject to relevant safeguards; (d) measuring the audience of an online service by a trade association or its mandated measurement entity on behalf of one or more media service providers for joint audience measurement purposes in accordance with Article 24 of Regulation (EU) 2024/1083, subject to appropriate technical and organisational safeguards; or by a third party acting on behalf of the controller of that online service pursuant to a contractual arrangement with that controller, solely for the purpose of measuring the audience of that online service; or by an entity belonging to the same digital ecosystem as the controller of that online service, for the purpose of measuring the audience of services within that digital ecosystem; (e) ensuring the security of the information society service or of the electronic communications network, provided that it is strictly necessary, proportionate, subject to appropriate safeguards, and only limited to information strictly necessary for this purpose and does not involve any general scanning or monitoring of information stored in the terminal equipment of a user or subscriber; (f) preventing fraud directly related to the use of the specific service requested by the user, provided that such processing is strictly necessary, proportionate, subject to appropriate safeguards, limited to the smallest amount of data required for the purpose, and does not involve any general scanning or monitoring of information stored in the terminal equipment of a user or subscriber; (g) provision, displaying and measurement of such advertising that is solely based on the content immediately displayed to the subscriber or user iswhile using said service, no form of profiling or other privacy intrusive technologies shall be used. 3. The subscriber or user shall be able to refuse requests for consent in an easy and intelligible manner with a naturalsingle-click person,button andor equivalent means. If the information storedsubscriber or accesseduser constitutesgives consent, the provider shall not make a new request for consent for the same purpose for the period during which the controller can lawfully rely on the consent of the subscriber or leadsuser. 4. Nothing in this Article shall prevent a media service provider from conditioning access to its service upon the data subject’s consent to the processing of personal data for one or more specified purposes, or upon the payment of a reasonable fee for an equivalent version of the service that does not involve such processing. The specified purposes may include, but are not limited to, advertising, service improvement, product development, and analytics. Where such a choice is offered, both options must be presented to the data subject with equal prominence, in clear and plain language, and without the use of dark patterns.
Preview
against:
Source identification

Header printed in the source: Article 5 – paragraph 1 – point 2 / Regulation 2002/58/EC / Article 5

Alternative wording Amendment 1728 · Pernando Barrena Arza ITRE · LIBE
3. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed when that person has given his or her consent, in accordance with Regulation (EU) 2016/679. This paragraph shall not applyprevent any technical storage or access and the corresponding processing of personal data if it is exclusively related to and strictly necessary for: a) carrying out the transmission of an electronic communication over an electronic communications network; b) providing a service explicitly requested by the subscriber or user; c) measuring the general audience of an online service requested by a subscriber or user in an immediately anonymised and aggregated form; d) maintaining or restoring the technical security of a service explicitly requested by the subscriber or user isthrough strictly proportionate means; If the subscriber or user refuses a naturalrequest personfor consent, the provider shall not make a new request for consent for the same purpose for a period of at least six months. Refusing to give consent should not be more difficult than giving consent. Consent shall by default not be considered to be given in an informed and specific manner when the informationrequest storedfor orconsent accessedinvolves constitutesthe ordisclosure leadsof data to more than 10 controllers in a single action. Member States shall designate the processingcompetent supervisory authority under Regulation (EU) 2016/679 for the supervision and enforcement of personalthe datarules under this paragraph.
Preview
against:
Source identification

Header printed in the source: Article 5 – paragraph 1 – point 2 / Directive 2002/58/EC / Article 5 – paragraph 3

Alternative wording Amendment 1729 · Alex Agius Saliba ITRE · LIBE
Member States shall ensure that the storing of information, or gaining of access to information already stored in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given their consent, having been provided with clear and comprehensive information, in accordance with Regulation (EU) 2016/679, inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the purposes set out in Article 88a(3) of Regulation (EU) 2016/679 of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an online service explicitly requested by the subscriber or user to provide the service. This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to the processing of personal data.
Preview
against:
Source identification

Header printed in the source: Article 5 – paragraph 1 – point 2 / Directive 2002/58/EC / Article 5 – paragraph 3 – subparagraph 2 (new)

Alternative wording Amendment 1730 · Axel Voss, Oliver Schenk ITRE · LIBE
This paragraph shall not apply if the subscriber or user is a natural person, and the information stored or accessed constitutes or leads to theThe processing of personal data previously governed by these provisions shall be exclusively subject to Regulation (EU) 2016/679. (It applies to overall directive.)
Justification

The AM removes overlapping ePrivacy rules on security, terminal access, metadata, location data and direct marketing where personal-data processing is already governed by the GDPR. Keeping parallel regimes creates consent fatigue, divergent national transpositions and legal uncertainty, including stricter rules for some anonymous device data than for personal data. Consolidation under the GDPR’s risk-based framework simplifies compliance, strengthens coherent rights exercise, supports innovation and preserves sector-specific rules in dedicated instruments.

Preview
against:
Source identification

Header printed in the source: Article 5 – paragraph 1 – point 2 / Directive 2002/58/EC / Article 5 – paragraph 3 – subparagraph 2 (new)