Quo Vadis, EU Data Retention Policy? - An Outlook on Digital Privacy and Cyber Prosecution in the European Union



Ein Beitrag von Jan-Willem Prügel1


“Nothing was your own except the few cubic centimetres inside your skull.”2

I. Introduction

This dystopic quote from George Orwell’s famous novel 1984 illustrates the sentiment of people living in a society where government surveillance is omnipresent and any attempt at individualism causes instant prosecution. While life in Europe today is still not quite as dreary as in the fictional world envisioned by Orwell, there have in fact been recent developments hinting at eerie similarities.
With the proliferation of cellular phones and the internet, people disclose increasingly more information about themselves and those who they are in contact with, often unknowingly so. Whenever a call is made, a text message sent or a website visited, there remains, at least for some time, a digital footprint in form of a record in the service provider’s database. If the government was to look not even at the content, but only at this so-called meta or traffic data3, it could effectively deduce an individual’s movement, contacts, daily habits and much more. Just as frequent calls to the doctor’s office during business hours may indicate health issues, so could an e-mail sent from a smartphone in a red light district indicate unfaithfulness or even ties to the underworld. Needless to say, the collection and analysis of traffic data presents not only a sharp intrusion into one’s most private spheres, but could also be used to blackmail politicians and other influential figures, if fallen into the wrong hands.4 Nonetheless, the European Parliament passed the highly controversial5 Data Retention Directive6 (Directive) to stipulate an EU-wide obligation for all telecommunication traffic data to be stored by the service providers for up to 24 months, while bestowing upon government agencies the power to use that data for “the investigation, detection, and prosecution of criminal offences”7. The Directive aimed at harmonizing the Union-wide data retention policies and, thus, ultimately at facilitating the prosecution of “serious crimes”8. Recently, roughly eight years after its ratification, the European Court of Justice (Court) has struck down the Directive, declaring it incompatible with the EU Charter of Fundamental Rights9 (Charter) and invalid ab initio.10
This article will briefly analyze the decision, point out its implications and suggest a few possible solutions for an improved data retention policy compatible with the Charter.

II. The Judgment

The Court agreed with the claims submitted by the Irish and Austrian courts that the stipulated data retention granting national authorities access to their citizen’s traffic data was indeed an interference with the fundamental rights to privacy (Art. 7) and data protection (Art. 8). When applying the Directive to the Charter’s proportionality principle laid out in Art. 52(1) and established by the Court’s case law11 in order to determine whether the interference was justified, an improved combat of “serious crimes” was found to be a satisfactory objective of general interest as it safeguarded public security within the Union.12 Nonetheless the Court is of the opinion that the EU legislature has exceeded its discretion under the proportionality principle for various reasons. It analogously applied the reasoning developed in the European Court of Human Rights’ (ECtHR) Marper13 decision that the broad and thus serious interference with data privacy severely restricts the legislature’s discretion.14 Taking this legislative restriction into consideration it found, inter alia, the undifferentiated collection of data, the unclear term of “serious crimes”16, the seemingly arbitrary storage time frame as well as the lackadaisical approach to protecting the stored data18 to be disproportionate and hence incompatible with Art. 7 and 8 of the Charter.

III. Analysis of the Decision

While the Court’s reasoning is sound for the most part and the decision rendered an important signal for the data protection policies across all Member States, there remain some fundamental flaws in the judgment.
First, the Court holds that
“[the Directive’s appropriateness as a legitimate objective] cannot be called into question by the fact […] that there are several methods of electronic communication which do not fall within the scope of Directive 2006/24 or which allow anonymous communication. Whilst, admittedly, that fact is such as to limit the ability of the data retention measure to attain the objective pursued, it is not, however, such as to make that measure inappropriate […].19
This statement hints at a profound misconception of both data retention’s viability to prevent crime in general as well as being useful against professional criminals in particular.
The Court acknowledges the existence of alternative collectible telecommunication methods, but deems them to be of such low relevance that they allegedly do not interfere sufficiently with the recording measures stipulated by the Directive to render the collection inappropriate. This argument cannot be accepted. There is a plethora of ways for individuals to avoid having their digital activities recorded or even noticed.20 Even the tracking of cell phones might prove to be useless, if the phone is registered under a different person or bought in a country without registration requirements.21 Granted, such behavior and technical savvy may indeed not be expected from the average European citizen and thereby lending a prima facie credibility to the Court's findings. Data collection is, however, specifically aimed at combating “serious matters such as organized crime and terrorism”.22 Individuals involved in structures specifically assembled to commit crimes are in most cases either professional criminals themselves or have access to trained experts. Since these persons are the target group and the data collection is unlikely to detect most of their disguised activities, the Directive would at this point already have to be considered inappropriate to accomplish the objective of crime prevention.
Furthermore, research shows that additional data retention as envisioned by the Directive only plays a minuscule role in preventing and solving criminal cases and thus represents a very small benefit that is heavily outbalanced by the severe privacy violations.23 Unfortunately, the Court fails to discuss the general usefulness of data retention which could have been an important source of strong arguments for the ongoing political debates all over the EU and beyond, especially so in the absence of a guiding directive.
Second, the Court mistakenly examines the Directive’s proportionality in the face of prevention and prosecution of crime, the eventual goal, rather than its actually stated objective, i.e., the harmonization of the EU market and retention policies.24 This is particularly problematic since it thereby conveniently circumvents its findings in Ireland v Council stating that the Directive predominantly relates to the functioning of the internal market.25

IV. Outlook and Conclusion

Considering the strong lobbyism of both international as well as national police and security agencies26 and numerous politicians, there will likely be an ongoing debate and possibly a new version of a data retention directive. The Court has made clear, however, that blanket data retention is unacceptable in the light of the proportionality requirements. A new directive would therefore have to offer a sophisticated system of differentiations between the persons targeted, the type of information collected and the length of time data would be stored for.
A potential solution to two currently problematic aspects could be the creation of a database for individuals suspected of being involved in either terrorism or other forms of organized crime. This would firstly clarify the opaque phrasing of “serious crimes” and secondly offer a way of targeting only a small group of viable suspects based on probable cause, while excluding a vast number of people from having their privacy unnecessarily intruded. Germany’s “anti terror file” (ATDG)27 could provide a valuable point of reference. According to § 2 ATDG, only individuals who have a reported history of participating in or actively endorsing terrorist organizations may be added to the file. EU Member States could adopt a similar approach to narrow the new directive’s ambit and use such a database to further differentiate in terms of data types collected and duration of information stored, thereby complying with some of the Court’s proportionality desiderata.
Another possible implication concerning the future of governmental cooperation is the proscription of storing data outside of the EU. While the Court’s reasoning has a sound foundation considering the enforceability of security standards, it also hints at distrust to non-EU data privacy legislations. Regardless of this conjecture’s veracity, it is nonetheless indicative of the fact, that future police collaboration in the form of data transfer might face another set of challenges.
To conclude, the decision has for many human rights groups been a long-awaited deliverance from a purportedly Orwellian effort of EU governments to implement a strict surveillance measure. It has also helped to shed some light on the future of the complex rules and implications that are created by the increased digitalization of our times. The interaction between policy, human rights and the (cyber) prosecution of serious crimes will continue to shape the way we live in and prove to be one of the greatest legal challenges of the 21st century.


