"The providers of electronic
communications services shall ensure that
there is sufficient protection in place
against unauthorised access or alterations
to the electronic communications data,
and that the confidentiality and safety of
the transmission are also guaranteed by
the nature of the means of transmission
used or by state-of-the-art end-to-end
encryption of the electronic
communications data. Furthermore, when
encryption of electronic communications
data is used, decryption, reverse
engineering or monitoring of such
communications shall be prohibited.
Member States shall not impose any
obligations on electronic communications
service providers that would result in the
weakening of the security and encryption
of their networks and services"
I interpret this as the following clauses:
* "sufficient protection in place against unauthorised access or alterations" [through]
* "guaranteed by the nature of the means of transmission used "
* "OR"
* "state-of-the-art end-to-end encryption of the electronic communications data"
aka:
- HTTPS, non-ETE: fine
- HTTP, non-ETE: not fine
- HTTP, ETE: fine