lexiara

§1.6.2 Contracts where the consumer provides personal data

The Directive applies to contracts for online digital content and contracts for digital services under which the consumer provides personal data to the trader (27). In this respect, the CRD follows the same approach as the Digital Content Directive (‘DCD’). — For example, the CRD will apply to contracts providing free access to online digital content or digital services and the consumer consents to personal data processing also for marketing purposes. However, like the DCD, the CRD does not cover contracts for online digital content and contracts for digital services where the personal data are only processed for the purpose of performing the contract and complying with legal requirements. Recital 34 of Directive (EU) 2019/2161 clarifies that such legal requirements can include, for instance, registration of the consumer for security and identification purposes where specifically laid down by applicable law. Furthermore, as explained in Recital 35 of Directive (EU) 2019/2161, the Directive does not apply to situations where the consumer, without having concluded a contract with the trader, is exposed to advertisements exclusively in order to gain access to digital content or a digital service (28). It also clarifies that the Directive does not apply to situations where the trader only collects metadata, such as information concerning the consumer’s device or browser (‘device fingerprinting’ or ‘browser fingerprinting’) or browsing history, except where this situation is considered to be a contract under national law (29). Where the contract involves the processing of personal data, the trader must comply with its obligations under consumer law and – in its capacity of controller – also with the obligations under the General Data Protection Regulation (EU) 2016/679 of the European Parliament and of the Council (30) (‘GDPR’). Both legal frameworks apply to the business-to-consumer relationship simultaneously and in a complementary manner. For all contracts where the consumer provides personal data (irrespective of whether payment is involved or not), the trader must inform the consumer about the purposes of processing at the time when the personal data are obtained. Furthermore, the controller has to demonstrate that the processing of the personal data can be based on one of the legal grounds laid down in Article 6(1) GDPR. ‘Contract’ (Article 6(1)(b) GDPR) is one of the authorised legal bases thereunder. However, it is valid only for the processing ‘necessary for the performance of the contract’ which is strictly interpreted (31). Accordingly, for the processing operations that are not necessary for the performance of the contract, the trader must additionally rely on another authorised legal basis for processing under the GDPR, for example, the consumer’s free and informed consent (Article 6(1)(a)) (32). In accordance with the GDPR, consumers’ consent is only valid if it is freely given, specific, informed and unambiguous. In the context of a contractual relationship, consent can only be freely given if it is not conditional to the performance of contract (Article 7(4) GDPR). Being able to withdraw consent without detriment is therefore an essential requirement for the validity of consent (Recital 42 GDPR). After the consent is withdrawn, the trader can no longer lawfully process the personal data whose processing was based on that consent. Accordingly, for the processing operations that are not necessary for the performance of the contract, the trader-controller must ensure that there is another legal basis for processing under the GDPR. In contrast, the ‘contract’ in the meaning of the CRD encompasses all the rights and obligations of the parties, regardless of the distinction in the legal basis for personal data processing under the GDPR. Identifying the processing activities in the context of contracts with consumers and the correct legal basis under the GDPR can help the trader to understand if the ‘contract’ that it concludes with the consumer is subject to the CRD. In practice, when the trader has to rely on a separate consumer consent or other legal basis under the GDPR (except legal obligation) for processing of personal data of consumers, the contract in the context of which this processing is taking place will be subject to the requirements of the CRD.

· All articles ·

Source: EUR-Lex (Cellar) · retrieved 2026-09-07