Telecoms Package Council Common Position

Telecoms Package: Council of European Union Common Position − 2009-02-09

Proposal for a Directive of the European Parliament and of the Council amending Directives 2002/21/EC on a common regulatory framework for electronic communications networks and services, 2002/19/EC on access to, and interconnection of, electronic communications networks and services, and 2002/20/EC on the authorisation of electronic communications networks and services (COD/2007/0247)

Article 9
Article 9 − Obligation of transparency

1. National regulatory authorities may, in accordance with the provisions of Article 8, impose obligations for transparency in relation to interconnection and/or access, requiring operators to make public specified information, such as accounting information, technical specifications, network characteristics, terms and conditions for supply and use, including traffic management policies, and prices.

2. In particular where an operator has obligations of non-discrimination, national regulatory authorities may require that operator to publish a reference offer, which shall be sufficiently unbundled to ensure that undertakings are not required to pay for facilities which are not necessary for the service requested, giving a description of the relevant offerings broken down into components according to market needs, and the associated terms and conditions including prices. The national regulatory authority shall, inter alia, be able to impose changes to reference offers to give effect to obligations imposed under this Directive.

3. National regulatory authorities may specify the precise information to be made available, the level of detail required and the manner of publication.

4. Notwithstanding paragraph 3, where an operator has obligations under Article 12 concerning wholesale network infrastructure access, including unbundled access to the local loop at a fixed location, national regulatory authorities shall ensure the publication of a reference offer containing at least the elements set out in Annex II.

5. The Commission may adopt the necessary amendments to Annex II in order to adapt it to technological and market developments. The measures, designed to amend non-essential elements of this Directive, shall be adopted in accordance with the regulatory procedure with scrutiny referred to in Article 14(3). In implementing the provisions of this paragraph, the Commission may be assisted by GERT.

Article 12
Article 12 − Obligations of access to, and use of, specific network facilities

1. A national regulatory authority may, in accordance with the provisions of Article 8, impose obligations on operators to meet reasonable requests for access to, and use of, specific network elements and associated facilities, inter alia in situations where the national regulatory authority considers that denial of access or unreasonable terms and conditions having a similar effect would hinder the emergence of a sustainable competitive market at the retail level, or would not be in the end-user's interest.

Operators may be required inter alia:

(a) to give third parties access to specified network elements and/or facilities, including access to network elements which are not active and/or unbundled access to the local loop, to inter alia allow carrier selection and/or pre-selection and/or subscriber line resale offer;

(b) to negotiate in good faith with undertakings requesting access;

(c) not to withdraw access to facilities already granted;

(d) to provide specified services on a wholesale basis for resale by third parties;

(e) to grant open access to technical interfaces, protocols or other key technologies that are indispensable for the interoperability of services or virtual network services;

(f) to provide co-location or other forms of associated facility sharing, including the sharing of ducts, buildings or entry to buildings, antennae, towers and other supporting constructions, conduits, masts, manholes and cabinets;

(g) to provide specified services needed to ensure interoperability of end-to-end services to users, including facilities for intelligent network services or roaming on mobile networks;

(h) to provide access to operational support systems or similar software systems necessary to ensure fair competition in the provision of services;

(i) to interconnect networks or network facilities;

(j) to provide access to associated services such as identity, location and presence service.

National regulatory authorities may attach to those obligations conditions covering fairness, reasonableness and timeliness.

2. When national regulatory authorities are considering the obligations referred in paragraph 1, and in particular when assessing how such obligations would be imposed proportionate to the objectives set out in Article 8 of Directive 2002/21/EC (Framework Directive), they shall take account in particular of the following factors:

(a) the technical and economic viability of using or installing competing facilities, in the light of the rate of market development, taking into account the nature and type of interconnection and/or access involved, including the viability of other upstream access products such as access to ducts;

(b) the feasibility of providing the access proposed, in relation to the capacity available;

(c) the initial investment by the facility owner, bearing in mind the risks involved in making the investment;

(d) the need to safeguard competition in the long term, including through economically efficient infrastructure-based competition;

(e) where appropriate, any relevant intellectual property rights;

(f) the provision of pan-European services.

3. When imposing obligations on an operator to provide access in accordance with the provisions of this Article, national regulatory authorities may lay down technical or operational conditions to be met by the provider and/or beneficiaries of such access where necessary to ensure normal operation of the network. Obligations to follow specific technical standards or specifications shall be in compliance with the standards and specifications laid down in accordance with Article 17 of Directive 2002/21/EC (Framework Directive).

Annex I
A. Conditions which may be attached to a general authorisation

19. Transparency obligations on undertakings providing electronic communications services available to the public to ensure end-to-end connectivity, in conformity with the objectives and principles set out in Article 8 of Directive 2002/21/EC (Framework Directive), disclosure regarding traffic management policies and, where necessary and proportionate, access by national regulatory authorities to such information needed to verify the accuracy of such disclosure.

Article 8
Article 8 − Policy objectives and regulatory principles

1. Member States shall ensure that in carrying out the regulatory tasks specified in this Directive and the Specific Directives, the national regulatory authorities take all reasonable measures which are aimed at achieving the objectives set out in paragraphs 2, 3 and 4. Such measures shall be proportionate to those objectives.

Unless otherwise provided for in Article 9 regarding radio frequencies, Member States shall take the utmost account of the desirability of making regulations technologically neutral and shall ensure that, in carrying out the regulatory tasks specified in this Directive and the Specific Directives, in particular those designed to ensure effective competition, national regulatory authorities do likewise.

National regulatory authorities may contribute within their competencies to ensuring the implementation of policies aimed at the promotion of cultural and linguistic diversity, as well as media pluralism.

2. The national regulatory authorities shall promote competition in the provision of electronic communications networks, electronic communications services and associated facilities and services by inter alia:

(a) ensuring that users, including disabled users, elderly users, and users with special social needs derive maximum benefit in terms of choice, price, and quality;

(b) ensuring that there is no distortion or restriction of competition in the electronic communications sector;

(d) encouraging efficient use and ensuring the effective management of radio frequencies and numbering resources.

3. The national regulatory authorities shall contribute to the development of the internal market by inter alia:

(a) removing remaining obstacles to the provision of electronic communications networks, associated facilities and services and electronic communications services at European level;

(b) encouraging the establishment and development of trans-European networks and the interoperability of pan-European services, and end-to-end connectivity;

(d) cooperating with each other, with the Commission and GERT so as to ensure the development of consistent regulatory practice and the consistent application of this Directive and the Specific Directives.

4. The national regulatory authorities shall promote the interests of the citizens of the European Union by inter alia:

(a) ensuring all citizens have access to a universal service specified in Directive 2002/22/EC (Universal Service Directive);

(b) ensuring a high level of protection for consumers in their dealings with suppliers, in particular by ensuring the availability of simple and inexpensive dispute resolution procedures carried out by a body that is independent of the parties involved;

(c) contributing to ensuring a high level of protection of personal data and privacy;

(d) promoting the provision of clear information, in particular requiring transparency of tariffs and conditions for using publicly available electronic communications services;

(e) addressing the needs of specific social groups, in particular disabled users, elderly users and users with special social needs;

(f) ensuring that the integrity and security of public communications networks are maintained;

5. The national regulatory authorities shall, in pursuit of the policy objectives referred to in paragraphs 2, 3 and 4, apply objective, transparent, non-discriminatory and proportionate regulatory principles by, inter alia:

(a) promoting regulatory predictability;

(b) ensuring that, in similar circumstances, there is no discrimination in the treatment of undertakings providing electronic communications networks and services;

(c) safeguarding competition to the benefit of consumers and promoting, where appropriate, infrastructure-based competition;

(d) promoting efficient investment and innovation in new and enhanced infrastructures, including by taking into account investment risks;

(e) taking due account of the variety of conditions relating to competition and consumers that exist in the various geographic areas within a Member State;

(f) imposing ex-ante regulatory obligations only where there is no effective and sustainable competition and relaxing or lifting such obligations as soon as such competition exists.

Article 9
Article 9 − Management of radio frequencies for electronic communications services

1. Taking due account of the fact that radio frequencies are a public good that has an important social, cultural and economic value, Member States shall ensure the effective management of radio frequencies for electronic communication services in their territory in accordance with Article 8. They shall ensure that spectrum allocation used for electronic communications services and issuing general authorisations or individual rights of use of such radio frequencies by competent national authorities are based on objective, transparent, non-discriminatory and proportionate criteria. In doing so, they shall respect relevant international agreements and may take public policy considerations into account.

2. Member States shall promote the harmonisation of the use of radio frequencies across the Community, consistent with the need to ensure effective and efficient use thereof and in pursuit of benefits for the consumer such as economies of scale and interoperability of services. In so doing, they shall act in accordance with Decision No 676/2002/EC (Radio Spectrum Decision).

3. Unless otherwise provided in the second subparagraph, Member States shall ensure that all types of technology used for electronic communications services may be used in the radio frequency bands, available for electronic communications services in accordance with their National Frequency Allocation Plan and the ITU Radio Regulations.

Member States may, however, provide for proportionate and non-discriminatory restrictions to the types of radio network or wireless access technology used for electronic communications services where this is necessary to:

(a) avoid harmful interference,

(b) protect public health against electromagnetic fields,

(c) ensure technical quality of service,

(d) ensure maximisation of radio frequency sharing,

(e) safeguard efficient use of spectrum, or

(f) ensure the fulfilment of a general interest objective in accordance with paragraph 4.

4. Unless otherwise provided for in the second subparagraph, Member States shall ensure that all types of electronic communications services may be provided in the radio frequency bands, available for electronic communications services in accordance with their National Frequency Allocation Plan and the ITU Radio Regulations.

Member States may, however, provide for proportionate and non-discriminatory restrictions to the types of electronic communications services to be provided.

Measures that require an electronic communications service to be provided in a specific band available for electronic communications services shall be justified in order to ensure the fulfilment of a general interest objective as defined by Member States in conformity with Community law, such as, and not limited to:

(a) safety of life,

(b) the promotion of social, regional or territorial cohesion,

(c) the avoidance of inefficient use of radio frequencies, or

(d) the promotion of cultural and linguistic diversity and media pluralism, for example by the provision of radio and television broadcasting services.

A measure which prohibits the provision of any other electronic communications service in a specific band may only be provided for where justified by the need to protect safety of life services. Member States may also extend such a measure in order to fulfil other general interest objectives.

5. Member States shall regularly review the necessity of the restrictions referred to in paragraphs 3 and 4, and shall make the results of these reviews public.

6. Paragraphs 3 and 4 shall apply to spectrum allocated to be used for electronic communications services, general authorisations issued and individual rights of use of radio frequencies granted after ...(The date of transposition of Directive 2009/.../EC [amending Directive 2002/21/EC].).

Spectrum allocations, general authorisations and individual rights of use which existed by ...(The date of transposition of Directive 2009/.../EC [amending Directive 2002/21/EC].) shall be subject to Article 9a.

7. Without prejudice to the provisions of the Specific Directives and taking into account the relevant national circumstances, Member States may lay down rules in order to prevent spectrum hoarding, in particular by setting out strict deadlines for the effective exploitation of the rights of use by the holder of the rights and by applying penalties, including financial penalties or the withdrawal of the rights of use in case of non-compliance with the deadlines. These rules shall be established and applied in a proportionate, non-discriminatory and transparent manner.

Proposal for a Directive of the European Parliament and of the Council amending Directive 2002/22/EC on universal service and users' rights relating to electronic communications networks, Directive 2002/58/EC concerning the processing of personal data and the protection of privacy in the electronic communications sector and Regulation (EC) No 2006/2004 on consumer protection cooperation (COD/2007/0248)

Article 20
Article 20 − Contracts

1. Member States shall ensure that, when subscribing to services providing connection to a public communications network and/or publicly available electronic communications services, consumers, and other end-users so requesting, have a right to a contract with an undertaking or undertakings providing such connection and/or services. The contract shall specify in a clear, comprehensive and easily accessible form at least:

(a) the identity and address of the supplier;

(b) the services provided, including in particular,

- information on the provider's traffic management policies,

- the minimum service quality levels offered, namely the time for the initial connection and, where appropriate, other quality of service parameters, as defined by the national regulatory authorities,

- the types of maintenance service offered and customer support services provided, as well as the means of contacting these services,

- any restrictions imposed by the provider on the use of terminal equipment supplied;

(c) where an obligation exists under Article 25, the subscriber's options as to whether or not to include his or her personal data in a directory, and the data concerned;

(d) details of prices and tariffs, the means by which up-to-date information on all applicable tariffs and maintenance charges may be obtained, payment methods offered and any differences in costs due to payment method;

(e) the duration of the contract and the conditions for renewal and termination of services and of the contract, including:

- conditions regarding minimum contract duration related to promotions,

- any charges related to portability of numbers and other identifiers,

- any charges due on termination of the contract, including cost recovery with respect to terminal equipment;

(f) any compensation and the refund arrangements which apply if contracted service quality levels are not met;

(g) the means of initiating procedures for the settlement of disputes in accordance with Article 34;

(h) the type of action that might be taken by the undertaking in reaction to security or integrity incidents or threats and vulnerabilities.

Member States may also require that the contract include any information which may be provided by the relevant public authorities for this purpose on the use of electronic communications networks and services to engage in unlawful activities or to disseminate harmful content, and on the means of protection against risks to personal security, privacy and personal data, referred to in Article 21(4)(a) and relevant to the service provided.

2. Member States shall ensure that where contracts are concluded between subscribers and undertakings providing electronic communications services that allow voice communication, subscribers are clearly informed as to whether or not access to emergency services and caller location information is provided. Providers of electronic communications services shall ensure that customers are clearly informed in advance of the conclusion of a contract of any limitation on access to emergency services, and of any change to access to emergency services.

3. Member States shall ensure that subscribers have a right to withdraw from their contract without penalty upon notice of modification to the contractual conditions proposed by the undertakings providing electronic communications networks and/or services. Subscribers shall be given adequate notice, not shorter than one month, of any such modification, and shall be informed at the same time of their right to withdraw, without penalty, from their contract if they do not accept the new conditions. Member States shall ensure that national regulatory authorities are able to specify the format of such notifications.

''(20) In order to address public interest issues with respect to the use of communications services and to encourage protection of the rights and freedoms of others, the relevant national authorities should be able to produce and have disseminated, with the aid of providers, public interest information related to the use of communications services. This information could include public interest information regarding copyright infringement, other unlawful uses and the dissemination of harmful content, and advice and means of protection against risks to personal security, which may for example arise from disclosure of personal information in certain circumstances, as well as risks to privacy and personal data. The information could be coordinated by way of the cooperation procedure established in Article 33(3) of Directive 2002/22/EC (Universal Service Directive). Such public interest information should be updated whenever necessary and should be presented in easily comprehensible printed and electronic formats, as determined by each Member State, and on national public authority websites. National regulatory authorities should be able to oblige providers to disseminate this standardised information to all their customers in a manner deemed appropriate by the national regulatory authorities. When required by Member States, the information should also be included in contracts.''

''(22) Given the increasing importance of electronic communications for consumers and businesses, users should be fully informed of the traffic management policies of the service and/or network provider with which they conclude the contract. Where there is a lack of effective competition, national regulatory authorities should use the remedies available to them under Directive 2002/19/EC (Access Directive) to ensure that users' access to particular types of content or application is not unreasonably restricted.''

''(23) In the absence of relevant rules of Community law, content, applications and services are deemed lawful or harmful in accordance with national substantive and procedural law. It is a task for the Member States, not for providers of electronic communications networks or services, to decide, in accordance with due process, whether content, applications or services are lawful or harmful. The Framework Directive and the Specific Directives are without prejudice to Directive 2000/31/EC of the European Parliament and of the Council of 8 June 2000 on certain legal aspects of information society services, in particular electronic commerce, in the Internal Market (Directive on electronic commerce)(OJ L 178, 17.7.2000, p. 1.), which, inter alia, contains a "mere conduit" rule for intermediary service providers, as defined therein.''

Article 21
Article 21 − Transparency and publication of information

1. Member States shall ensure that national regulatory authorities are able to oblige undertakings providing electronic communications networks and/or services to publish transparent, comparable, adequate and up-to-date information, as set out in Annex II, on applicable prices and tariffs and standard terms and conditions in respect of access to, and use of, services provided by them to end-users and consumers. National regulatory authorities may specify additional requirements regarding the form in which such information is published to ensure transparency, comparability, clarity and accessibility for the benefit of consumers.

2. National regulatory authorities shall encourage the provision of comparable information to enable end-users and consumers to make an independent evaluation of the cost of alternative usage patterns, for instance by means of interactive guides or similar techniques. Member States shall ensure that national regulatory authorities may make such guides or techniques available, in particular where they are not available, on the market free of charge or at a reasonable price. Third parties shall have a right to use, free of charge, the information published by undertakings providing electronic communications networks and/or services for the purposes of selling or making available such guides or techniques.

3. Member States shall ensure that national regulatory authorities are able to oblige undertakings providing electronic communications services to inter alia:

(a) provide applicable tariff information to subscribers regarding any number or service subject to particular pricing conditions; with respect to individual categories of services, national regulatory authorities may require such information to be provided immediately prior to connecting the call;

(b) inform subscribers of any change to the provider's traffic management policies;

(c) inform subscribers of their right to determine whether or not to include their personal data in a directory, and of the types of data concerned, in accordance with Article 12 of Directive 2002/58/EC (Directive on privacy and electronic communications); and

(d) regularly inform disabled subscribers of details of products and services designed for them.

If deemed appropriate, national regulatory authorities may promote self- or co-regulatory measures prior to imposing any obligation.

4. Member States may require that undertakings referred to in paragraph 3 distribute public interest information free of charge to existing and new subscribers, where appropriate. In such a case, that information shall be provided by the relevant public authorities in a standardised format and shall, inter alia, cover the following topics:

(a) the most common uses of electronic communications services to engage in unlawful activities or to disseminate harmful content, particularly where it may prejudice respect for the rights and freedoms of others, including infringements of copyright and related rights, and their legal consequences; and

(b) the means of protection against risks to personal security, privacy and personal data when using electronic communications services.

Article 22
Article 22 − Quality of service

1. Member States shall ensure that national regulatory authorities are, after taking account of the views of interested parties, able to require undertakings that provide publicly available electronic communications networks and/or services to publish comparable, adequate and up-to-date information for end-users on the quality of their services and measures taken to ensure comparable access for disabled end-users. That information shall, on request, be supplied to the national regulatory authority in advance of its publication.

2. National regulatory authorities may specify, inter alia, the quality of service parameters to be measured and the content, form and manner of the information to be published, including possible quality certification mechanisms, in order to ensure that end-users have access to comprehensive, comparable, reliable and user-friendly information. Where appropriate, the parameters, definitions and measurement methods set out in Annex III may be used.

3. In order to prevent the degradation of service and the hindering or slowing down of traffic over networks, Member States shall ensure that national regulatory authorities are able to set minimum quality of service requirements on an undertaking or undertakings providing public communications networks.

(26) A competitive market should ensure that users enjoy the quality of service they require, but in particular cases it may be necessary to ensure that public communications networks attain minimum quality levels so as to prevent degradation of service, the blocking of access and the slowing of traffic over networks.

Article 28
Article 28 − Access to numbers and services

1. Member States shall ensure that, where technically and economically feasible, and except where a called subscriber has chosen for commercial reasons to limit access by calling parties located in specific geographical areas, relevant national authorities take all necessary steps to ensure that end-users are able to:

(a) access and use services using non-geographic numbers within the Community; and

(b) access all numbers provided in the Community, including those in the national numbering plans of Member States, those from the ETNS and Universal International Freephone Numbers (UIFN).

2. Member States shall ensure that the relevant authorities are able to require undertakings providing public communications networks and/or publicly available electronic communications services to block, on a case-by-case basis, access to numbers or services where this is justified by reasons of fraud or misuse and to require that in such cases providers of electronic communications services withhold relevant interconnection or other service revenues.

''(36) A single market implies that end-users are able to access all numbers included in the national numbering plans of other Member States and to access services using non-geographic numbers within the Community, including, among others, freephone and premium rate numbers. End-users should also be able to access numbers from the European Telephone Numbering Space (ETNS) and Universal International Freephone Numbers (UIFN). Cross-border access to numbering resources and associated services should not be prevented, except in objectively justified cases, for example to combat fraud or abuse (e.g. in connection with certain premium-rate services), when the number is defined as having a national scope only (e.g. a national short code) or when it is technically or economically unfeasible. Users should be fully informed in advance and in a clear manner of any charges applicable to freephone numbers, such as international call charges for numbers accessible through standard international dialling codes.''

Article 33
Article 33 − Consultation with interested parties

1. Member States shall ensure as far as appropriate that national regulatory authorities take account of the views of end-users, consumers (including, in particular, disabled end-users), manufacturers and undertakings that provide electronic communications networks and/or services on issues related to all end-user and consumer rights concerning publicly available electronic communications services, in particular where they have a significant impact on the market.

In particular, Member States shall ensure that national regulatory authorities establish a consultation mechanism ensuring that in their decisions on issues related to end-user and consumer rights concerning publicly available electronic communications services, due consideration is given to consumer interests in electronic communications.

2. Where appropriate, interested parties may develop, with the guidance of national regulatory authorities, mechanisms, involving consumers, user groups and service providers, to improve the general quality of service provision by, inter alia, developing and monitoring codes of conduct and operating standards.

3. Without prejudice to national rules in conformity with Community law promoting cultural and media policy objectives, such as cultural and linguistic diversity and media pluralism, national regulatory authorities and other relevant authorities may promote cooperation between undertakings providing electronic communications networks and/or services and sectors interested in the promotion of lawful content in electronic communication networks and services. That cooperation may also include coordination of the public interest information to be provided pursuant to Article 21(4)(a) and Article 20(1).

''(39) In order to overcome existing shortcomings in terms of consumer consultation and to appropriately address the interests of citizens, Member States should put in place an appropriate consultation mechanism. Such a mechanism could take the form of a body which would, independently of the national regulatory authority and service providers, carry out research into consumer-related issues, such as consumer behaviour and mechanisms for changing suppliers, and which would operate in a transparent manner and contribute to the existing mechanisms for stakeholder consultation. Furthermore, a mechanism could be established for the purpose of enabling appropriate cooperation on issues relating to the promotion of lawful content. Any cooperation procedures agreed pursuant to such a mechanism should, however, not allow for the systematic surveillance of internet usage.''

Article 34
Article 34 − Out-of-court dispute resolution

1. Member States shall ensure that transparent, simple and inexpensive out-of-court procedures are available for dealing with unresolved disputes between consumers and undertakings providing electronic communications networks and/or services arising under this Directive and relating to the contractual conditions and/or performance of contracts concerning the supply of those networks and/or services. Member States shall adopt measures to ensure that such procedures enable disputes to be settled fairly and promptly and may, where warranted, adopt a system of reimbursement and/or compensation. Member States may extend these obligations to cover disputes involving other end-users.

2. Member States shall ensure that their legislation does not hamper the establishment of complaints offices and the provision of on-line services at the appropriate territorial level to facilitate access to dispute resolution by consumers and end-users.

3. Where such disputes involve parties in different Member States, Member States shall coordinate their efforts with a view to bringing about a resolution of the dispute.

4. This Article is without prejudice to national court procedures.

Article 2
Article 2 − Definitions

Save as otherwise provided, the definitions in Directive 95/46/EC and in Directive 2002/21/EC on a common regulatory framework for electronic communications networks and services (Framework Directive) shall apply.

The following definitions shall also apply:

(a) “user” means any natural person using a publicly available electronic communications service, for private or business purposes, without necessarily having subscribed to this service;

(b) “traffic data” means any data processed for the purpose of the conveyance of a communication on an electronic communications network or for the billing thereof;

(c) “location data” means any data processed in an electronic communications network or by an electronic communications service, indicating the geographic position of the terminal equipment of a user of a publicly available electronic communications service;

(d) “communication” means any information exchanged or conveyed between a finite number of parties by means of a publicly available electronic communications service. This does not include any information conveyed as part of a broadcasting service to the public over an electronic communications network except to the extent that the information can be related to the identifiable subscriber or user receiving the information;

(e) “consent” by a user or subscriber corresponds to the data subject's consent in Directive 95/46/EC;

(f) “value added service” means any service which requires the processing of traffic data or location data other than traffic data beyond what is necessary for the transmission of a communication or the billing thereof;

(g) “electronic mail” means any text, voice, sound or image message sent over a public communications network which can be stored in the network or in the recipient's terminal equipment until it is collected by the recipient;

(h) “personal data breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed in connection with the provision of a publicly available electronic communications service in the Community.

Article 3
''(44) Technological progress allows the development of new applications based on devices for data collection and identification, which could be contactless devices using radio frequencies. For example, Radio Frequency Identification Devices (RFID) use radio frequencies to capture data from uniquely identified tags which can then be transferred over existing communications networks. The wide use of such technologies can bring considerable economic and social benefit and thus make a powerful contribution to the internal market, if their use is acceptable to citizens. To achieve this aim, it is necessary to ensure that all fundamental rights of individuals, including the right to privacy and data protection, are safeguarded. When such devices are connected to publicly available electronic communications networks or make use of electronic communications services as a basic infrastructure, the relevant provisions of Directive 2002/58/EC (Directive on privacy and electronic communications), including those on security, traffic and location data and on confidentiality, should apply.''

Article 4
Article 4 − Security of processing

1. The provider of a publicly available electronic communications service must take appropriate technical and organisational measures to safeguard security of its services, if necessary in conjunction with the provider of the public communications network with respect to network security. Having regard to the state of the art and the cost of their implementation, these measures shall ensure a level of security appropriate to the risk presented.

2. In case of a particular risk of a breach of the security of the network, the provider of a publicly available electronic communications service must inform the subscribers concerning such risk and, where the risk lies outside the scope of the measures to be taken by the service provider, of any possible remedies, including an indication of the likely costs involved.

3. In the case of a personal data breach, the provider of publicly available electronic communications services shall assess the scope of the personal data breach, evaluate its seriousness and consider whether it is necessary to notify the personal data breach to the competent national authority and subscriber concerned, taking into account the relevant rules set by the competent national authority in accordance with paragraph 4.

When the personal data breach represents a serious risk for the subscriber's privacy, the provider of publicly available electronic communications services shall notify the competent national authority and the subscriber of the breach without undue delay.

The notification to the subscriber shall at least describe the nature of the personal data breach and the contact points where more information can be obtained, and shall recommend measures to mitigate the possible negative effects of the personal data breach. The notification to the competent national authority shall, in addition, describe the consequences of, and the measures proposed or taken by the provider to address, the personal data breach.

''(47) A breach of security resulting in the loss or compromising of personal data of an individual subscriber may, if not addressed in an adequate and timely manner, result in substantial economic loss and social harm, including identity fraud. Therefore, as soon as the provider of publicly available electronic communications service becomes aware that such a breach has occurred, it should assess the risks associated with it, e.g. by establishing the type of data affected by the breach (including their sensitivity, context and the security measures in place), the cause and extent of the breach, the number of subscribers affected and the possible harm for subscribers as a result of the breach (e.g. identity theft, financial loss, loss of business or employment opportunities or physical harm). The subscribers concerned by security incidents that could result in a serious risk to their privacy (e.g. identity theft or fraud, physical harm, significant humiliation or damage to reputation) should be notified without delay in order to allow them to take the necessary precautions. The notification should include information about measures taken by the provider to address the breach, as well as recommendations for the users affected. Notification of a security breach to a subscriber should not be required if the provider has demonstrated to the competent authority that it has implemented appropriate technological protection measures, and that those measures were applied to the data concerned by the security breach. Such technological protection measures should render the data unintelligible to any person who is not authorised to access it.''

4. Member States shall ensure that the competent national authority is able to set detailed rules and, where necessary, issue instructions concerning the circumstances in which notification of personal data breaches by providers of a publicly available electronic communications service is necessary, the format applicable to such notification and the manner in which the notification is to be made.

5. In order to ensure consistency in implementation of the measures referred to in paragraphs 1 to 4 the Commission may, following consultation with the European Network and Information Security Agency (ENISA), the Article 29 Working Party and the European Data Protection Supervisor, adopt recommendations concerning, inter alia, the circumstances, format and procedures applicable to the information and notification requirements referred to in this Article.

Article 5
Article 5 − Confidentiality of the communications

1. Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality.

2. Paragraph 1 shall not affect any legally authorised recording of communications and the related traffic data when carried out in the course of lawful business practice for the purpose of providing evidence of a commercial transaction or of any other business communication.

3. Member States shall ensure that the storing of information, or access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned is provided with clear and comprehensive information, in accordance with Directive 95/46/EC, inter alia about the purposes of the processing, and is offered the right to refuse such processing by the data controller. This shall not prevent any technical storage or access for the sole purpose of carrying out or facilitating the transmission of a communication over an electronic communications network, or as strictly necessary in order to provide an information society service explicitly requested by the subscriber or user.

Article 6
Article 6 − Traffic data

1. Traffic data relating to subscribers and users processed and stored by the provider of a public communications network or publicly available electronic communications service shall be erased or made anonymous when it is no longer needed for the purpose of the transmission of a communication. This shall be without prejudice to paragraphs 2, 3, 5 and 7 of this Article and Article 15(1).

2. Traffic data necessary for the purposes of subscriber billing and interconnection payments may be processed. Such processing is permissible only up to the end of the period during which the bill may lawfully be challenged or payment pursued.

3. For the purpose of marketing electronic communications services or for the provision of value added services, the provider of a publicly available electronic communications service may process the data referred to in paragraph 1 to the extent and for the duration necessary for such services or marketing, if the subscriber or user to whom the data relate has given his or her prior consent. Users or subscribers shall be given the possibility to withdraw their consent for the processing of traffic data at any time.

4. The service provider must inform the subscriber or user of the types of traffic data which are processed and of the duration of such processing for the purposes mentioned in paragraph 2 and, prior to obtaining consent, for the purposes mentioned in paragraph 3.

5. Processing of traffic data, in accordance with paragraphs 1, 2, 3 and 4, must be restricted to persons acting under the authority of providers of the public communications networks and publicly available electronic communications services handling billing or traffic management, customer enquiries, fraud detection, marketing electronic communications services or providing a value added service, and must be restricted to what is necessary for the purposes of such activities.

6. Paragraphs 1, 2, 3 and 5 shall apply without prejudice to the possibility for competent bodies to be informed of traffic data in conformity with applicable legislation with a view to settling disputes, in particular interconnection or billing disputes.

7. Traffic data may be processed to the extent strictly necessary to ensure network and information security, as defined by Article 4(c) of Regulation (EC) No 460/2004 of the European Parliament and of the Council of 10 March 2004 establishing the European Network and Information Security Agency (OJ L 77, 13.3.2004, p. 1.).

(41) The processing of traffic data to the extent strictly necessary for the purposes of the detection, location and elimination of faults and malfunctions of network and information security, ensuring the availability, authenticity, integrity and confidentiality of stored or transmitted data, will help prevent unauthorised access and malicious code distribution, "denial of service" attacks and damage to computer and electronic communication systems.

Article 14
Article 14 − Technical features and standardisation

1 In implementing the provisions of this Directive, Member States shall ensure, subject to paragraphs 2 and 3, that no mandatory requirements for specific technical features are imposed on terminal or other electronic communication equipment which could impede the placing of equipment on the market and the free circulation of such equipment in and between Member States.

2. Where provisions of this Directive can be implemented only by requiring specific technical features in electronic communications networks, Member States shall inform the Commission in accordance with the procedure provided for by Directive 98/34/EC of the European Parliament and of the Council of 22 June 1998 laying down a procedure for the provision of information in the field of technical standards and regulations and of rules on information society services.

3. Where required, measures may be adopted to ensure that terminal equipment is constructed in a way that is compatible with the right of users to protect and control the use of their personal data, in accordance with Directive 1999/5/EC and Council Decision 87/95/EEC of 22 December 1986 on standardisation in the field of information technology and communications.

Article 15
Article 15 − Application of certain provisions of Directive 95/46/EC

1. Member States may adopt legislative measures to restrict the scope of the rights and obligations provided for in Article 5, Article 6, Article 8(1), (2), (3) and (4), and Article 9 of this Directive when such restriction constitutes a necessary, appropriate and proportionate measure within a democratic society to safeguard national security (i.e. State security), defence, public security, and the prevention, investigation, detection and prosecution of criminal offences or of unauthorised use of the electronic communication system, as referred to in Article 13(1) of Directive 95/46/EC. To this end, Member States may, inter alia, adopt legislative measures providing for the retention of data for a limited period justified on the grounds laid down in this paragraph. All the measures referred to in this paragraph shall be in accordance with the general principles of Community law, including those referred to in Article 6(1) and (2) of the Treaty on European Union.

1a. Paragraph 1 shall not apply to data specifically required by Directive 2006/24/EC of the European Parliament and of the Council of 15 March 2006 on the retention of data generated or processed in connection with the provision of publicly available electronic communications services or of public communications networks to be retained for the purposes referred to in Article 1(1) of that Directive.

2. The provisions of Chapter III on judicial remedies, liability and sanctions of Directive 95/46/EC shall apply with regard to national provisions adopted pursuant to this Directive and with regard to the individual rights derived from this Directive.

3. The Working Party on the Protection of Individuals with regard to the Processing of Personal Data instituted by Article 29 of Directive 95/46/EC shall also carry out the tasks laid down in Article 30 of that Directive with regard to matters covered by this Directive, namely the protection of fundamental rights and freedoms and of legitimate interests in the electronic communications sector.

Article 15a
Article 15a − Implementation and enforcement

1. Member States shall lay down the rules on penalties applicable to infringements of the national provisions adopted pursuant to this Directive and shall take all measures necessary to ensure that they are implemented. The penalties provided for must be effective, proportionate and dissuasive and may be applied to cover the period of any breach, even where the breach has subsequently been rectified. The Member States shall notify those provisions to the Commission by ...(The date referred to in Article 4(1).), and shall notify it without delay of any subsequent amendment affecting them.

2. Member States shall ensure that the competent national authority and, where relevant, other national bodies have the power to order the cessation of the infringements referred to in paragraph 1.

3. Member States shall ensure that the competent national authority and, where relevant, other national bodies have all necessary investigative powers and resources, including the power to obtain any relevant information they might need to monitor and enforce national provisions adopted pursuant to this Directive.

4. In order to ensure effective cross-border cooperation in the enforcement of the national laws adopted pursuant to this Directive and to create harmonised conditions for the provision of services involving cross-border data flows, the Commission may adopt recommendations, following consultation with ENISA, the Article 29 Working Party and the relevant regulatory authorities.

''(54) The need to ensure an adequate level of protection of privacy and personal data transmitted and processed in connection with the use of electronic communications networks in the Community calls for effective implementation and enforcement powers in order to provide adequate incentives for compliance. Competent national authorities and, where appropriate, other relevant national bodies should have sufficient powers and resources to investigate cases of non-compliance effectively, including powers to obtain any relevant information they might need, to decide on complaints and to impose sanctions in cases of non-compliance.''

''(55) The implementation and enforcement of the provisions of this Directive often require cooperation between the national regulatory authorities of two or more Member States, for example in combating cross-border spam and spyware. In order to ensure smooth and rapid cooperation in such cases, procedures relating for example to the quantity and format of information exchanged between authorities, or deadlines to be complied with, should be defined in recommendations. Such procedures will also allow the resulting obligations of market actors to be harmonised, contributing to the creation of a level playing field in the Community.''