CHAPTER XIFINAL PROVISIONS

Article 95Relationship with Directive 2002/58/EC

Official text

This Regulation shall not impose additional obligations on natural or legal persons in relation to processing in connection with the provision of publicly available electronic communications services in public communication networks in the Union in relation to matters for which they are subject to specific obligations with the same objective set out in Directive 2002/58/EC.

Commentary

Article 95 GDPR is one of the most important conflict-of-laws provisions in the GDPR. It regulates the relationship between the GDPR and Directive 2002/58/EC (theePrivacy Directive orEPD), which governs the privacy and confidentiality of electronic communications.

The provision embodies the principle of lex specialis derogat legi generali: where the ePrivacy Directive lays down specific obligations addressing a particular matter, those specific rules take precedence over the more general provisions of the GDPR.

Article 95 must be read together with:

  • Recital 173 GDPR;

  • Directive 2002/58/EC (ePrivacy Directive);

  • Article 7 Charter of Fundamental Rights of the EU (privacy and confidentiality of communications);

  • Article 8 Charter (protection of personal data);

  • relevant CJEU case law, particularly C-654/23 Inteligo Media SA.

1. Purpose of Article 95

The GDPR applies broadly to the processing of personal data across all sectors of the economy.

The ePrivacy Directive, by contrast, focuses on a narrower field:

  • confidentiality of communications;

  • communications metadata;

  • traffic and location data;

  • electronic marketing communications;

  • cookies and similar technologies;

  • telecommunications and electronic communications services.

Without Article 95, organizations operating electronic communications services could potentially face overlapping requirements from both legal instruments.

Article 95 seeks to prevent duplication.

It provides that the GDPR does not impose additional obligations where:

  1. the processing occurs in connection with publicly available electronic communications services in public communications networks; and

  2. the ePrivacy Directive already contains specific obligations pursuing the same objective.


2. Recital 173

Recital 173 explains the rationale of Article 95.

The GDPR applies to all matters concerning the protection of individuals' rights and freedoms unless the matter is already governed by specific obligations with the same objective under the ePrivacy Directive.

Thus:

Where the ePrivacy Directive regulates a matter

➡ The specific ePrivacy rule takes precedence.

Where the ePrivacy Directive does not regulate a matter

➡ The GDPR applies normally.


3. Historical Background

Before the GDPR existed, the predecessor framework consisted of:

  • Directive 95/46/EC (Data Protection Directive);

  • Directive 2002/58/EC (ePrivacy Directive).

The ePrivacy Directive expressly stated that it:

"particularises and complements"

the general data protection framework.

When the GDPR replaced Directive 95/46/EC via Article 94 GDPR, the relationship remained substantially the same.

The ePrivacy Directive continued operating as a sector-specific instrument while the GDPR became the general data protection framework.


4. Lex Specialis Principle

Article 95 is fundamentally an application of the doctrine:

Lex specialis derogat legi generali

Meaning:

A specific law prevails over a general law when both regulate the same matter.

The GDPR is the general framework for personal data processing.

The ePrivacy Directive is the specialized framework for electronic communications privacy.

Therefore, where the ePrivacy Directive comprehensively regulates a particular electronic communications activity, organizations are assessed primarily under the ePrivacy rules rather than the GDPR.


5. Scope of Article 95

For Article 95 to apply, several conditions must be satisfied.

The processing must:

  1. occur in connection with electronic communications services;

  2. involve publicly available services;

  3. use public communications networks;

  4. concern a matter regulated by the ePrivacy Directive;

  5. be subject to obligations having the same objective as the GDPR provision in question.

Each element is important.


Unlike many GDPR provisions, Article 95 refers to both:

  • natural persons;

  • legal persons.

This reflects the broader scope of the ePrivacy Directive.

The GDPR protects personal data of natural persons.

The ePrivacy Directive additionally protects certain interests of legal entities, particularly in relation to communications confidentiality.


7. Publicly Available Electronic Communications Services

Article 95 only applies where processing occurs in connection with the provision of publicly available electronic communications services.

Historically this covered:

  • mobile telephone operators;

  • internet service providers;

  • telecommunications providers.


8. Traditional Examples

Covered services typically include:

  • Vodafone;

  • Orange;

  • Deutsche Telekom;

  • Airtel;

  • internet broadband services.

These providers transmit communications using public networks.


9. Internet-Based Services

The position became more complex following developments in EU telecommunications law.

Under the original framework, a service generally needed responsibility for signal transmission.

The European Electronic Communications Code (EECC) broadened the concept to include many online communication services.

Examples

may include:

  • WhatsApp;
  • Skype;
  • Signal;
  • Messenger-type services. These services fall within the category of interpersonal communications services.

10. Ancillary Communication Functions

Services are generally not electronic communications services where communication is merely ancillary.

Example

A retailer's website that happens to contain a contact form is not transformed into an electronic communications service. Communication is merely incidental to the primary commercial activity. In such situations, Article 95 will usually not apply. The GDPR remains fully applicable.


11. Public Communications Networks

Article 95 also requires use of a public communications network.

A public network is generally one made available to the public to transmit communications.

Covered

  • mobile networks;

  • public telephone networks;

  • public internet access networks.

Not Covered

  • closed internal corporate networks;

  • private intranets;

  • purely internal employee communication systems.


12. Example

A company's internal staff messaging platform is not normally a public communications network.

Therefore:

✅ GDPR applies.

❌ Article 95 generally does not displace GDPR obligations.


13. "Specific Obligations with the Same Objective"

This is the most important element of Article 95.

The mere existence of an ePrivacy provision does not automatically displace the GDPR.

The ePrivacy rule must pursue the same objective as the GDPR obligation being considered.


14. Example: Confidentiality of Communications

The ePrivacy Directive contains specific confidentiality obligations relating to communications content and metadata.

Where those provisions apply, Article 95 prevents the GDPR from imposing overlapping requirements with the same objective.


15. Inteligo Media (C‑654/23)

The CJEU gave important guidance in Inteligo Media SA (C‑654/23).

The Court held that where Article 13(2) of the ePrivacy Directive comprehensively regulates a communication-related processing activity, the legality of that processing should be assessed under the ePrivacy Directive rather than separately under GDPR Article 6 legal bases.

The Court explained that Article 95 avoids the duplication of legal requirements where the ePrivacy Directive already establishes a complete regulatory framework for the relevant processing activity.

This is one of the clearest judicial confirmations of Article 95's lex specialis function.


16. Does the GDPR Still Apply?

Yes.

A common misconception is that Article 95 excludes the GDPR entirely.

It does not.

Article 95 excludes only additional GDPR obligations concerning matters already regulated by equivalent ePrivacy provisions.

Everything else remains governed by the GDPR.


17. Examples Where GDPR Continues to Apply

Data Subject Rights

The ePrivacy Directive does not contain a complete rights framework comparable to:

  • Article 15 (access);

  • Article 16 (rectification);

  • Article 17 (erasure);

  • Article 18 (restriction);

  • Article 20 (portability).

Therefore GDPR rights generally continue to apply.


18. Transparency

The ePrivacy Directive does not provide a complete transparency regime equivalent to:

  • Articles 12-14 GDPR.

Accordingly, GDPR transparency obligations remain relevant.


19. Accountability

The ePrivacy Directive does not contain the GDPR's accountability structure, including:

  • records of processing;

  • DPIAs;

  • DPO requirements;

  • governance obligations.

These GDPR obligations continue to apply where relevant.


20. Cookies and Tracking Technologies

One of the most debated areas concerns cookies.

Article 5(3) ePrivacy Directive regulates:

  • cookies;

  • tracking technologies;

  • device storage access.

Importantly, this provision applies far beyond traditional telecom providers.

Any website operator placing non-essential cookies may fall within its scope.


21. Example

A news website installs advertising cookies on a user's device.

The act of placing or reading the cookie is regulated by Article 5(3) ePrivacy Directive.

However:

  • subsequent processing of personal data derived from those cookies;

  • profiling;

  • retention;

  • security;

  • data subject rights;

may still be subject to the GDPR.

Thus both frameworks frequently operate together.


22. Practical Examples

Example

1: Telecom Provider Metadata A telecommunications company processes traffic data to route calls. The ePrivacy Directive contains specific rules governing this activity. Article 95 prevents overlapping GDPR obligations with the same objective.


23. Example 2: Marketing Emails

A telecom provider sends direct marketing emails.

The dispatch of marketing communications may be governed by ePrivacy rules.

However, related GDPR obligations concerning transparency, records, security, and rights may still apply where the Directive does not regulate those aspects.


24. Example 3: WhatsApp-Type Service

A messaging platform processes communications metadata.

Specific ePrivacy requirements concerning communications confidentiality may prevail.

At the same time:

  • GDPR rights;

  • security obligations;

  • accountability requirements;

  • international transfer obligations;

may still apply unless specifically displaced.


25. The Failed ePrivacy Regulation Proposal

Recital 173 anticipated that the ePrivacy Directive would be revised following the GDPR.

Consequently, the European Commission proposed an ePrivacy Regulation in 2017.

The intention was to replace the old Directive and align communications privacy law with the GDPR framework.

However, after years of negotiations, the proposal was eventually withdrawn in 2025.

As a result, the ePrivacy Directive of 2002 remains in force today, alongside the GDPR.


26. Key Takeaways

  • Article 95 governs the relationship between the GDPR and the ePrivacy Directive.

  • It applies the lex specialis principle: specific ePrivacy rules override general GDPR rules where both pursue the same objective.

  • It primarily affects processing connected to publicly available electronic communications services operating through public communications networks.

  • The GDPR is not excluded entirely; it continues to apply wherever the ePrivacy Directive does not provide equivalent regulation.

  • The CJEU confirmed in Inteligo Media (C‑654/23) that processing comprehensively regulated by the ePrivacy Directive does not need a separate GDPR Article 6 assessment.

  • Common areas where both instruments interact include:

  • telecommunications services;

  • messaging platforms;

  • cookies and tracking technologies;

  • direct marketing communications.

  • The proposed ePrivacy Regulation was withdrawn in 2025, meaning the GDPR continues to coexist with Directive 2002/58/EC.