CIPP/E Study Guide
IAPP Training · Module 8 - BoK V.B

Module 8 · ePrivacy Directive, location data & biometric data

The ePrivacy Directive (2002/58) governs data from terminal equipment over public electronic communications networks - its main basis is consent and it does NOT recognise legitimate interest. It is lex specialis over the GDPR. Article 5(1) protects confidentiality of communications; Article 15(1) allows limited exceptions. Location data usually needs opt-in consent. Biometric data (Article 4(14)) is special-category only when processed to uniquely identify a person.

The ePrivacy Directive (Directive 2002/58) governs data from terminal equipment over public electronic communications networks. Its main legal basis is consent (except where processing is part of a service the user expressly requested), and it does NOT recognise legitimate interest. It is lex specialis over the GDPR. If data passes only over a private network (e.g. a corporate intranet), ePrivacy does not apply - though monitoring rules still do.

  • Article 5(1) - confidentiality of communications; no interception without consent.
  • Article 15(1) - Member States may make limited exceptions (national security, law enforcement).
  • A lawful-business-purpose exemption allows interception over public networks where defined by Member State law.

Location data is an identifier under the GDPR (personal data if it can identify alone or combined). Under ePrivacy it usually requires opt-in consent given how intrusive it is.

Biometric data (Article 4(14)) is 'personal data resulting from specific technical processing... which allow or confirm the unique identification' (facial images, fingerprints, DNA, retina, voice, gait). Two uses: Identification ('who are you?') and Authentication ('are you who you claim to be?'). It is special-category only when processed for the purpose of uniquely identifying a person - a yearbook photo is not. See EDPB Guidelines 05/2022 on facial recognition in law enforcement.

Key terms - quick answers

What is “ePrivacy Directive”?
Directive 2002/58 governing communications over public electronic networks; main basis is consent, applies to public (not private) networks, and is lex specialis to the GDPR.
What is “lex specialis”?
A more specific law that prevails over a general one; the ePrivacy Directive is lex specialis over the GDPR for electronic communications.
What is “Location data”?
Data such as latitude/longitude; an identifier under the GDPR, and under ePrivacy usually requires opt-in consent given its intrusiveness.
What is “Biometric data (Article 4(14))”?
Data from specific technical processing of physical, physiological or behavioural traits that allows or confirms unique identification; special-category only when used to uniquely identify.