Wednesday

18th Oct 2017

Focus

EU proposes tougher privacy rules for online messaging

  • Messaging services are facing tougher privacy rules (Photo: Nicolas Nova)

The EU commission is tightening privacy rules on messaging services like WhatsApp, Skype and web-based email.

On Tuesday (10 January), it proposed to overhaul the e-privacy directive to bridge the gap between traditional telephone operators and the broadly US-based instant messaging services.

Thank you for reading EUobserver!

Subscribe now for a 30 day free trial.

  1. €150 per year
  2. or €15 per month
  3. Cancel anytime

EUobserver is an independent, not-for-profit news organization that publishes daily news reports, analysis, and investigations from Brussels and the EU member states. We are an indispensable news source for anyone who wants to know what is going on in the EU.

We are mainly funded by advertising and subscription revenues. As advertising revenues are falling fast, we depend on subscription revenues to support our journalism.

For group, corporate or student subscriptions, please contact us. See also our full Terms of Use.

If you already have an account click here to login.

The current directive, last reformed in 2009, only covers telecom operators. The reform expands the rules to online services, gives people more control over intrusive cookies, and evolves the directive into a much more powerful regulation.

The EU commission says the reforms are also needed because over 90 percent of people in an EU survey want their emails and online messaging to remain confidential.

The proposal involves giving people the choice to opt in or out of services provided by so-called Over-The-Top (OTT) applications such as WhatsApp or Facebook Messenger. But it also claims to open up new business opportunities for more traditional telecom operators by allowing them to commercialise data that was previously off limits.

"Consent of the user is paramount," EU digital economy commissioner Andrus Ansip told reporters.

Ansip said the new rules would not only apply to traditional services like voice calls or SMS, but also to internet based communication services "or future based services that allow any type of communication".

Consent will be required for anything from so-called metadata - the details of when and where a call was placed - to the content of communications.

Email providers like Gmail regularly scan people's emails to help target adverts. Cookies are also required to provide Google's translation services of those emails.

The Commission says the same services will now have to provide "effective consent", giving people a more readily available option of saying no instead of having to read through the small print in the terms and conditions.

Gmail will also only be able to process the bare minimum of data needed to provide the email service for free.

It means today's email scanning will be banned unless the user agrees. But saying no to email scans only prevents adverts from being personalised or relevant to the user. It does not stop adverts.

Consent won't be needed for everything. Things like remembering shopping histories and filling in online forms will be exempted.

One Finnish web developer recently discovered a "phishing" attack that specifically targets auto-fill, reported the Guardian.

The developer found that some browsers like Google Chrome's auto-fill can be tricked into giving away personal information like email addresses through an auto-fill function that is not disabled by default.

Brussels-based consumer lobby group Beuc argues that the Commission's proposal should have blocked cookies by default.

“Consumers must have an alternative to being under 24/7 commercial surveillance when using digital services," said Beuc director Monique Goyens.

Some are not happy, fearing it will cut into their advertising revenues.

"The approach to extend historic telephony rules to new services does not reflect today’s market realities," said the Brussels-based American Chamber of Commerce to the EU.

Firms that break the rules could end up paying fines of up to 4 percent of their global turnover.

The Brussels-executive is hoping to have the new rules up and running by the time the EU's data protection regulation, agreed last year, is fully operational by May 2018.

Data protection regulation and e-privacy

EU commission officials say their is no overlap between e-privacy and the general data protection regulation.

They note that the regulation deals with processing of personal data, while e-privacy covers communication between people.

OTTs under the old data protection rules were also able use a "legitimate interest" clause to process data without people's consent. The new rules remove that clause.

The EU's digital economy in 2015 was worth €272 billion.

EU trying to salvage US deal on data privacy

Privacy safeguards for EU citizens' personal data that is sent to the United States remains exposed to abuse, due to the lack of oversight and the shift towards increased surveillance under president Trump.

EU leaders impatient with digital rules, leak says

'Despite considerable progress, work in this area needs to be accelerated in order to meet this deadline' of finishing the digital single market by the end of 2018, leaked draft conclusions of next week's summit said.

Germany tells EU to slow down on new cyber rules

'First comes first', said a German government agency official, meaning that previously agreed rules on cybersecurity should be implemented before discussing the EU commission's new proposal.

Germany tells EU to slow down on new cyber rules

'First comes first', said a German government agency official, meaning that previously agreed rules on cybersecurity should be implemented before discussing the EU commission's new proposal.

Interview

EU 'underestimated' cyber-crime

"Cybercrime is growing much, much faster than I think we anticipated," the EU commissioner for security, Julian King, told EUobserver.

News in Brief

  1. Catalonia will 'not back down'
  2. New toxic incident in EU building ahead of summit
  3. Murdered Malta journalist's family invited to Parliament
  4. EU food safety chief denies keeping studies 'secret'
  5. EU states pledge 24,000 resettlement places so far
  6. US ready for arms sale to update Greece's F-16 fleet
  7. Austria's Green leaders step down following election failure
  8. Icelandic journalists protest ban on reporting PM's finances

Stakeholders' Highlights

  1. EU2017EENorth Korea Leaves Europe No Choice, Says Estonian Foreign Minister Sven Mikser
  2. Mission of China to the EUZhang Ming Appointed New Ambassador of the Mission of China to the EU
  3. International Partnership for Human RightsEU Should Seek Concrete Commitments From Azerbaijan at Human Rights Dialogue
  4. European Jewish CongressEJC Calls for New Austrian Government to Exclude Extremist Freedom Party
  5. CES - Silicones EuropeIn Healthcare, Silicones Are the Frontrunner. And That's a Good Thing!
  6. EU2017EEEuropean Space Week 2017 in Tallinn from November 3-9. Register Now!
  7. European Entrepreneurs CEA-PMEMobiliseSME Exchange Programme Open Doors for 400 Companies Across Europe
  8. CECEE-Privacy Regulation – Hands off M2M Communication!
  9. ILGA-EuropeHealth4LGBTI: Reducing Health Inequalities Experienced by LGBTI People
  10. EU2017EEEHealth: A Tool for More Equal Health
  11. Mission of China to the EUChina-EU Tourism a Key Driver for Job Creation and Enhanced Competitiveness
  12. CECENon-Harmonised Homologation of Mobile Machinery Costs € 90 Million per Year