Brussels, 16/01/2009 (Agence Europe) - The European Data Protection Supervisor (EDPS) is unhappy with a number of points on the protection of private data, in the common position adopted by the Council of Ministers of 27 November on the Telecoms Package. In a second opinion adopted on 9 January, the EDPS repeats observations made in the first opinion, expressing the view that the Council had failed to endorse some of the data protection safeguards proposed by the European Parliament and the European Commission. The opinion focuses particularly on the provisions setting up a compulsory security breach notification system. In this, the EDPS supports the approach put forward by the EP, which, in first reading, wanted to extend the scope of the directive to include publicly accessible private networks, such as banks and pharmacies, while the Commission and Council prefer to limit it to internet access providers. “Citizens will expect such a system to apply not only to their internet access providers, but also to their on-line banks and on-line pharmacies. … The Parliament and the Council will need to meet the challenge of determining the proper standard setting forth the conditions for notification and ensuring that the appropriate processes are put into effect,” says EDPS Peter Hustinx. However, he does not support the new article brought in by the Parliament, and retained in the Council and Commission common position, permitting the collection of traffic data for security purposes. According to the EDPS, such a provision is unnecessary and could give rise to abuses, particularly if it is adopted in a form that does not include the necessary data protection safeguards. Lastly, the EDPS calls on the Commission and Council to adopt the provision introduced by the Parliament which allows the possibility of legal entities, such as consumer associations, bringing legal action against infringements of any provisions of the directive. (I.L./transl.rt)