CIPP/E Study Guide
IAPP Training · Module 8 - BoK V.B

Module 8 · Surveillance framework - Article 23, content vs metadata

Surveillance is observation of individuals - covert or overt, real-time or stored. Article 23 lets EU/Member State law restrict data-subject rights, but only if it respects the essence of fundamental rights and is a necessary and proportionate measure in a democratic society. State surveillance must respect Charter Article 7 (private life) and Article 8 (data protection); the Law Enforcement Directive governs law-enforcement processing. In ePrivacy terms, content (the message itself) is distinguished from metadata (data about data).

Surveillance is observation of individuals, whether covert or overt, in real time or from stored records. Article 23 allows EU/Member State law to restrict data-subject rights, but the restriction must respect the essence of fundamental rights and be a necessary and proportionate measure in a democratic society (see EDPB Guidelines 10/2020 on Article 23 restrictions).

Public/state surveillance for national security or law enforcement must respect Charter Article 7 (respect for private life) and Article 8 (protection of personal data). The Law Enforcement Directive governs law-enforcement processing (lawful, fair, necessary, proportionate), while private surveillance must comply with the GDPR.

Communications data: content vs metadata
CategoryExamples
ContentThe conversation itself - email body and subject, attachments, the spoken words.
Metadata - traffic dataCalling/called numbers, time and duration of a call.
Metadata - location dataLatitude/longitude, cell location.
Metadata - subscriber dataAccount holder details tied to the service.
Why content vs metadata matters

The content / metadata distinction drives which ePrivacy rules apply - metadata is not 'harmless', it is still regulated communications data.

Key terms - quick answers

What is “Surveillance”?
Observation of individuals - covert or overt, real-time or stored from records.
What is “Article 23”?
GDPR provision allowing EU/Member State law to restrict data-subject rights, subject to respecting the essence of fundamental rights and being necessary and proportionate.
What is “Law Enforcement Directive”?
EU directive governing processing by competent authorities for law-enforcement purposes - lawful, fair, necessary and proportionate.
What is “Metadata”?
Data about data - e.g. traffic data (calling numbers), location data and subscriber data - as opposed to the content of a communication.