Judgment of the Court (Grand Chamber) of 2 October 2018.

Delivered 2018-10-02 · ECLI:EU:C:2018:788 · Court of Justice · Languages: LT · EN · IT · SV · PL · LV · ET · SL · FR · DE

Case
C-207/16
Court
Court of Justice
Date
2018-10-02
Parties
Proceedings brought by Ministerio Fiscal
ECLI
ECLI:EU:C:2018:788
Original
EUR-Lex ↗
PresidentK. LenaertsPresidentA. TizzanoJudgeR. Silva de LapuertaJudge · rapporteurT. von DanwitzJudgeJ.L. da Cruz VilaçaJudgeC.G. FernlundJudgeC. VajdaJudgeE. JuhászJudgeA. Borg BarthetJudgeC. ToaderJudgeM. SafjanJudgeD. ŠvábyJudgeM. BergerJudgeE. JarašiūnasJudgeE. ReganAdvocate GeneralH. Saugmandsgaard ØeRegistrarL. Carrasco Marco
Summary
Preparing…

JUDGMENT OF THE COURT (Grand Chamber)

2 October 2018 (*1)

(Reference for a preliminary ruling — Electronic communications — Processing of personal data — Directive 2002/58/EC — Articles 1 and 3 — Scope — Confidentiality of electronic communications — Protection — Article 5 and Article 15(1) — Charter of Fundamental Rights of the European Union — Articles 7 and 8 — Data processed in connection with the provision of electronic communications services — Access of national authorities to the data for the purposes of an investigation — Threshold of seriousness of an offence capable of justifying access to the data)

In Case C‑207/16,

REQUEST for a preliminary ruling under Article 267 TFEU from the Audiencia Provincial de Tarragona (Provincial Court, Tarragona, Spain), made by decision of 6 April 2016, received at the Court on 14 April 2016, in the proceedings brought by

Ministerio Fiscal,

THE COURT (Grand Chamber),

composed of K. Lenaerts, President, A. Tizzano, Vice-President, R. Silva de Lapuerta, T. von Danwitz (Rapporteur), J.L. da Cruz Vilaça, C.G. Fernlund and C. Vajda, Presidents of Chambers, E. Juhász, A. Borg Barthet, C. Toader, M. Safjan, D. Šváby, M. Berger, E. Jarašiūnas and E. Regan, Judges,

Advocate General: H. Saugmandsgaard Øe,

Registrar: L. Carrasco Marco, Administrator,

having regard to the written procedure and further to the hearing on 29 January 2018,

after considering the observations submitted on behalf of

after hearing the Opinion of the Advocate General at the sitting on 3 May 2018,

gives the following

Judgment

Legal context

EU law

Directive 95/46

‘1. This Directive shall apply to the processing of personal data wholly or partly by automatic means, and to the processing otherwise than by automatic means of personal data which form part of a filing system or are intended to form part of a filing system.

Directive 2002/58

‘(2)

This Directive seeks to respect the fundamental rights and observes the principles recognised in particular by the [Charter]. In particular, this Directive seeks to ensure full respect for the rights set out in Articles 7 and 8 of that Charter.

…

…

…

‘1. This Directive provides for the harmonisation of the national provisions required to ensure an equivalent level of protection of fundamental rights and freedoms, and in particular the right to privacy and confidentiality, with respect to the processing of personal data in the electronic communication sector and to ensure the free movement of such data and of electronic communication equipment and services in the Community.
‘Save as otherwise provided, the definitions in Directive [95/46] and in Directive 2002/21/EC of the European Parliament and of the Council of 7 March 2002 on a common regulatory framework for electronic communications networks and services (Framework Directive) [( OJ 2002 L 108, p. 33 )] shall apply.

The following definitions shall also apply:

…

…’

‘This Directive shall apply to the processing of personal data in connection with the provision of publicly available electronic communications services in public communications networks in the Community, including public communications networks supporting data collection and identification devices.’
‘1. Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). …

…

‘1. Traffic data relating to subscribers and users processed and stored by the provider of a public communications network or publicly available electronic communications service must be erased or made anonymous when it is no longer needed for the purpose of the transmission of a communication without prejudice to paragraphs 2, 3 and 5 of this Article and Article 15(1).

…’

‘Member States may adopt legislative measures to restrict the scope of the rights and obligations provided for in Article 5, Article 6, Article 8(1), (2), (3) and (4), and Article 9 of this Directive when such restriction constitutes a necessary, appropriate and proportionate measure within a democratic society to safeguard national security (i.e. State security), defence, public security, and the prevention, investigation, detection and prosecution of criminal offences or of unauthorised use of the electronic communication system, as referred to in Article 13(1) of Directive [95/46]. To this end, Member States may, inter alia, adopt legislative measures providing for the retention of data for a limited period justified on the grounds laid down in this paragraph. All the measures referred to in this paragraph shall be in accordance with the general principles of Community law, including those referred to in Article 6(1) and (2) of the Treaty on European Union.’

Spanish law

Law 25/2007

‘1. The purpose of this law is to regulate the obligation of operators to retain the data generated or processed in the context of the supply of electronic communications services or public communication networks, and the obligation to communicate those data to authorised agents whenever they are requested to do so by the necessary judicial authorisation, for the purposes of the detection, investigation and prosecution of serious offences provided for in the Criminal Code or in special criminal laws.

…’

The Criminal Code

‘Serious offences are those which the law punishes with a serious penalty.’
‘1. Depending on their nature and duration, penalties shall be classified as serious, less serious and light.

…’

Code of Criminal Procedure

‘1. The court may authorise the interception of private postal and telegraphic correspondence, including fax, Burofax and international money orders, which the suspect sends or receives, and also the opening and analysis of such correspondence where there are grounds for thinking that that will permit the discovery or verification of a fact or a factor of relevance for the case, provided that the investigation relates to one of the following offences:

…’

‘1. Electronic data retained by service providers or by persons who supply the communication pursuant to the legislation on the retention of electronic communications data, or on their own initiative for commercial or other reasons, and who are connected with communications processes, shall be communicated in order to be taken into account in the context of the proceedings only when authorised by the court.

The main proceedings and the questions referred for a preliminary ruling

‘(1)

Can the sufficient seriousness of offences, as a criterion which justifies interference with the fundamental rights recognised by Articles 7 and 8 of the [Charter], be determined taking into account only the sentence which may be imposed in respect of the offence investigated, or is it also necessary to identify in the criminal conduct particular levels of harm to individual and/or collective legally protected interests?

Procedure before the Court

Consideration of the questions referred

The jurisdiction of the Court

Admissibility

Substance

Costs

On those grounds, the Court (Grand Chamber) hereby rules:

Article 15(1) of Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications), as amended by Directive 2009/136/EC of the European Parliament and of the Council of 25 November 2009, read in the light of Articles 7 and 8 of the Charter of Fundamental Rights of the European Union, must be interpreted as meaning that the access of public authorities to data for the purpose of identifying the owners of SIM cards activated with a stolen mobile telephone, such as the surnames, forenames and, if need be, addresses of the owners, entails interference with their fundamental rights, enshrined in those articles of the Charter of Fundamental Rights, which is not sufficiently serious to entail that access being limited, in the area of prevention, investigation, detection and prosecution of criminal offences, to the objective of fighting serious crime.

[Signatures]

(*1) Language of the case: Spanish.

Text from our archive (Publications Office of the EU, Cellar). Commission Decision 2011/833/EU — free reuse incl. commercial; attribution to EUR-Lex / Court of Justice of the European Union required; EUR-Lex is not the authentic record of the Court.