lexiara

§1.2.10 Interplay with the General Data Protection Regulation and the e-Privacy Directive

The respect for private and family life and the protection of personal data are fundamental rights under Articles 7 and 8 of the EU Charter of Fundamental Rights. Under Article 7, everyone has the right to respect for his or her private and family life, home and communications. As regards the protection of personal data, Article 8(2) of the Charter contains key data protection principles (fair processing, consent or legitimate aim prescribed by law, right to access and rectification). Article 8(3) of the Charter requires that compliance with data protection rules be subject to control by an independent authority (84). The General Data Protection Regulation (85) (GDPR) regulates the protection of personal data and the free movement of such data. Data protection rules are enforced by national supervisory authorities and national courts. The GDPR applies to the processing of ‘personal data’. Personal data means any information relating to an identified or identifiable natural person (‘data subject’). An identifiable person is someone who can be identified, directly or indirectly, in particular by reference to an identification number or to one or more factors specific to his or her physical, physiological, genetic, mental, economic, cultural or social identity. The processing of personal data, which includes collecting and storing personal data, must be fair and lawful. One aspect of fair processing is that the data subject is given relevant information, including on the purposes of that processing, having regard to the specific circumstances in which the data are collected. Fair and lawful processing of personal data requires that data protection principles are complied with and that at least one of the six grounds for legitimate processing applies to any processing activity (see Article 6(1) GDPR). Consent by the individual is one of these grounds. Another is where a controller is under a legal obligation imposed by Union or Member State law to process the data (e.g. know-your-customer obligation). The e-Privacy Directive (86) particularises and complements the GDPR regarding the processing of personal data in the electronic communication sector, as it facilitates the free movement of such data and of electronic communication equipment and services. In particular, Article 5(3) of the e-Privacy Directive requires the user’s consent when ‘cookies’ or other forms of accessing and storing information on an individual’s device (e.g. tablet or smartphone) are used, except where such storage or access is necessary for carrying out the transmission of a communication or for the provision of an information society service explicitly requested by a user. Data-driven business structures are becoming predominant in the online world. In particular, online platforms analyse, process and sell data related to consumer preferences and other user-generated content. This, together with advertising, often constitutes their main source of revenues. The collection and processing of personal data in these types of situations must comply with the legal requirements under the ePrivacy Directive and GDPR mentioned above. A trader’s violation of the GDPR or of the ePrivacy Directive will not, in itself, always mean that the practice is also in breach of the UCPD. However, such privacy and data protection violations should be considered when assessing the overall unfairness of commercial practices under the UCPD, particularly in the situation where the trader processes consumer data in violation of privacy and data protection requirements, i.e. for direct marketing purposes or any other commercial purposes like profiling, personal pricing or big data applications. From a UCPD perspective, the first issue to be considered concerns the transparency of the commercial practice. Under Articles 6 and 7 of the UCPD, traders should not mislead consumers on aspects that are likely to have an impact on their transactional decisions. More specifically, Article 7(2) and No 22 of Annex I prevent traders from hiding the commercial intent behind the commercial practice. See also section 3.4 on the use of the claim ‘free’ to describe digital products, which could be in breach of No 20 of Annex I. Furthermore, the information requirements from the GDPR and e-Privacy Directive may be considered as material information under the UCPD Article 7(5). Personal data, consumer preferences and other user-generated content have economic value and are often being made available to third parties. Consequently, under Article 7(2) and No 22 of Annex I UCPD, if the trader does not inform a consumer that the data provided will be used for commercial purposes, this could be considered a misleading omission of material information, as well as a breach of transparency and other requirements under Articles 12 to 14 of the GDPR.

· All articles ·

Source: EUR-Lex (Cellar) · retrieved 2026-09-07