An endless but interesting debate: the interplay between the e-privacy directive and the GDPR for e-marketing communications

The European Data Protection Board (“EDPB”) recently published the first version of its Guidelines 1/2024 on processing of personal data based on legitimate interest. The Guidelines provide useful advice on how data controllers should assess whether the three cumulative conditions required to rely on legitimate interest as a legal basis for processing personal data are met: (i) the controller or a third party must pursue a legitimate interest; (ii) the processing must be necessary for the purposes of such legitimate interest; and (iii) the interests or fundamental rights of the concerned data subject should not take precedence over the legitimate interest of the controller.

While these Guidelines are currently open for public consultation and not yet final, they have sparked significant debate, particularly around the interplay between Directive 2002/58/EC (“ePrivacy Directive“) and the GDPR concerning the lawful sending of electronic marketing communications. This intersection raises the question as to whether the ePrivacy Directive’s specific rules on electronic commercial communications displace the need to rely on one of the legal bases outlined in Article 6 of the GDPR for personal data processing or, on the contrary, both sets of requirements must be satisfied simultaneously.

In this regard, the EDPB recalls that the ePrivacy Directive is considered a lex specialis in relation to the GDPR, meaning it provides specific rules that take precedence over the general provisions of data protection law when it comes to electronic communications. For instance, where the ePrivacy Directive imposes certain limitations on processing specific types of personal data (i.e. internet traffic data), a controller cannot bypass these restrictions by claiming GDPR compliance alone. Recital 10 of the ePrivacy Directive reinforces this by stating that the GDPR applies to “all matters concerning protection of fundamental rights and freedoms, which are not specifically covered by the provisions of this Directive.”

Additionally, the EDPB’s Opinion 5/2019 on the interplay between the ePrivacy Directive and the GDPR highlights that “where specific provisions exist which govern a particular processing operation or set of operations, the specific provisions should be applied (lex specialis), in all other cases (i.e. where no specific provisions govern a particular processing operation or set of operations), the general rule will apply (lex generalis)”.

In the context of direct electronic marketing, the ePrivacy Directive generally requires prior consent from the recipient to receive unsolicited communications from businesses via email, SMS, MMS, and similar channels. This consent must meet the requirements set out in Article 4(11) of the GDPR, which defines consent as a “freely given, specific, informed and unambiguous indication of the data subject’s wishes.”

However, an exception exists in the context of an existing customer relationship. Article 13(2) of the ePrivacy Directive allows companies to send marketing communications to existing customers without seeking their consent, provided that these communications relate to products or services similar to those previously purchased by the customer. It is precisely in these situations where it is not clear whether the processing of the customer’s personal data requires the application of one of the legal bases outlined in the GDPR, such as legitimate interest, or if the specific rule in Article 13(2) of the ePrivacy Directive is sufficient on its own to justify such processing.

Some scholars claim that, in the absence of explicit consent, a legitimate interest analysis should always be carried out when sending electronic marketing communications to existing customers, provided that the processing cannot be based on another legal basis under Art. 6 of GDPR. In this context, EDPB’s Guidelines 1/2024 provide a helpful framework to conduct such analysis, with a key factor being the recipient’s reasonable expectations, as outlined by the recent ruling of the Court of Justice of the European Union in case C-621/22, of 4 March 2024.

At national level, the Spanish Data Protection Authority (“AEPD”) had the opportunity to address this issue in several occasions, including in 2018 through a legal report issued in response to questions related to the possibility of relying on article 6(1)(f) of the GDPR (legitimate interest) to process customers personal data for the purposes of marketing communications. In its report, the AEPD emphasised that article 21 of Organic Law 34/2002 on Information Society Services and Electronic Commerce (“LSSI”), serves as a special regulation (lex specialis) concerning e-marketing activities, and that in the context of sending marketing communications through electronic means, the LSSI “constitutes a special rule […], so the provisions of the GDPR should not be applied to resolve the question posed, but rather the provisions of this special rule should be considered.”

Although the AEPD’s position on the intersection between the GDPR and the LSSI seems to be quite firm, it should not be viewed as absolute or irrefutable (let’s not forget that the AEPD is a supervisory authority without legislative power, and its interpretations have often been challenged and disregarded in court). Therefore, the debate remains ongoing and more intense than ever. Given that the EDPB’s Guidelines on legitimate interest are still in draft form, we believe it’s a good opportunity for the EDPB to provide further guidance on this topic.

 

Autores: Carlos García Berned, Gloria Zapata Pérez