Article 5(1) requires Member States to ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, including the prohibition of listening, tapping, storage or other kinds of interception or surveillance of communications, except when legally authorised in accordance with Article 15(1). Article 5(2) allows the recording of communications and traffic data for the purposes of providing evidence of a commercial transaction. Article 5(3) imposes the famous prior-consent rule: the storing of information or the gaining of access to information already stored, in the terminal equipment of a subscriber or user, is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information in accordance with Directive 95/46/EC (now the GDPR), inter alia about the purposes of the processing. This is the rule operationalised for cookies, web beacons, tracking pixels, browser fingerprinting and on-device app SDKs. The strictly-necessary exception (Article 5(3) carve-out) permits storage / access where necessary to provide an information-society service explicitly requested by the subscriber.
This control maps to 3 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.
Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.
The graph holds this control, the 3 it maps to, and the evidence behind each claim, over MCP and REST.