Elektrine lite

← Feed

@aristot73@infosec.exchange

Post #3981250

2026-07-21 08:26 UTC

Renewed debate on a future EU data retention framework EPRS | European Parliamentary Research Service - Hendrik Mildebrath and Silvia González Vidal Published: 7 July 2026 "Although the Court of Justice of the European Union (CJEU) continued developing EU data retention standards after invalidating the former EU Data Retention Directive in 2014, national interpretations diverge and efforts towards alignment have stalled. Law enforcement and judicial authorities report operational challenges arising from this fragmentation, sometimes precluding timely access to communications-related data necessary for identifying suspects and victims, reconstructing criminal activity, and generating investigative leads. In response to these issues and to calls from the Council, the European Commission is assessing the need for a new EU framework. Any legislative action would require a series of politically and legally sensitive design choices. Controversy may arise in relation to the legitimacy and appropriate scope of renewed EU legislative intervention; the operationalisation of the CJEU's system of graduated objectives and safeguards; the adequacy of retention periods; the design of access conditions and safeguards; and, possibly, the need to regulate automated processing of retained datasets. This briefing builds on the overviews provided in the EPRS briefings 'Towards new EU data retention rules' and 'Mapping CJEU limits on data retention framework'." https://www.europarl.europa.eu/thinktank/en/document/EPRS_BRI(2026)789334

Replies (1)

  • @aristot73@infosec.exchange 2026-07-21 08:28

    Mapping CJEU limits on data retention frameworks: A basic introduction EPRS Briefing 16-07-2025 "Since the 2014 invalidation of the Data Retention Directive, the EU legal landscape has become fragmented, causing uncertainty for providers and challenges for law enforcement. With a Commission proposal likely and growing Member State support for a more permissive EU regime, a solid understanding of relevant CJEU case law may help inform Parliament's assessment. Over the past decade, CJEU case law has set detailed requirements for data retention. Laws must respect proportionality and necessity, with a clear hierarchy of objectives: general and indiscriminate retention of traffic and location data is only permissible for safeguarding national security, while targeted retention of such data may be justified by public security or other important public interest goals. Any such framework must also include robust safeguards. Similarly, access to retained data must be limited to the purpose for which it was collected or a more important objective. The ECtHR ruled that such retention and access require safeguards similar to those for secret surveillance. Stakeholders are divided on a new EU data retention regime. Law enforcement agencies favour EU-level harmonisation but warn against restrictive retention rules that would limit their operational effectiveness. Providers of electronic communications services support a CJEU-compliant EU framework and seek cost compensation. Civil society organisations oppose new EU rules and urge the Commission to focus on enforcing existing case law through infringement procedures." https://www.europarl.europa.eu/thinktank/en/document/EPRS_BRI(2025)775878

    Open ##3981271