Policing by design: the latest EU surveillance plan

Topic
Country/Region
EU

The EU should reintroduce mass telecommunications surveillance and create backdoors to encrypted data, a new plan drafted in secret by police and security officials says. To do so, close coordination between the state and industry would be required, to ensure what the plan calls “lawful access by design.” The plan repeats demands made many times over the years by officials, and may find a warm reception from the incoming European Commission.

Support our work: become a Friend of Statewatch from as little as £1/€1 per month.


Image: Maxwell Ingham on Unsplash


Secret surveillance plan

The plan (pdf), first published by Netzpolitik and now also made public by the European Commission, was drafted by the “High-Level Group (HLG) on access to data for effective law enforcement," which was convened following a proposal by the Swedish Presidency of the Council last spring.

The HLG was composed (pdf) of senior officials from member states and the Commission, representatives of EU justice and home affairs agencies, and the EU Counter-Terrorism Coordinator, and was chaired by the Council Presidency and the Commission.

Building upon previous proposals drafted by police and security officials from Europe and North America, the plan contains 42 separate recommendations, amongst which are calls for the re-introduction of mass telecommunications surveillance (“data retention”) and the undermining of encrypted communication systems.

Data retention

The paper calls for “a harmonised EU regime on data retention” that is “technology neutral and future-proof,” covers all types of telecommunications service providers, includes measures ensuring both retention of and access to data, and is “in full compliance with privacy and data protection rules.”

The EU’s previous data retention legislation was struck down by the Court of Justice in 2014, which found that the law allowed for “a wide-ranging and particularly serious interference” with the fundamental rights to privacy and data protection. The court has confirmed this interpretation in several cases about national data retention measures.

At the same time, the Court ruled that the legislation did not undermine the essence of those rights, and that retaining telecommunications data for criminal investigations “satisfies an objective of general interest” – the problem with the law was that it was seriously disproportionate.

The plans outlined by the HLG, however, would cover even more forms of communication than the previous legislation – the paper calls for retention of data from “service providers of any kind that could provide access to electronic evidence.”

This may raise questions about the proportionality of any future legislation based on the group’s proposals – not to mention the more fundamental objection raised by opponents of data retention that it automatically treats everyone as a potential suspect.

Encryption

Encrypted communications are also in the crosshairs of the HLG, which “agreed upon the need for law enforcement to have access to data en clair” and bemoans “the pace of technological developments related to encryption of information” that apparently make existing decryption technologies “ineffective”.

The document insists that “future technical solutions or tools that are developed must not result in the weakening or undermining of encryption technologies for the communication of other users that is not subject to the lawful access measure,” though makes no mention of the fact technical experts have repeatedly pointed out the impossibility of doing so.

Instead, the group is pinning its hopes on new technology being developed:

“...technological solutions can be implemented where they exist or should be developed to preserve privacy and data protection, guarantee cybersecurity, and enable the implementation of targeted lawful access measures at the same time.”

State-industry collaboration

To achieve these goals – along with many of the others outlined in the plan – the HLG proposes close coordination and collaboration between state authorities and private industry.

In particular, the plan calls for requirements to be placed on hardware and software developers for new devices and applications to allow “access by design” for law enforcement authorities, whether through legislation, memoranda of understanding, or through the participation of policing agencies in technical standardisation committees.

The plan also calls for legal obligations to be placed on telecoms service providers to cooperate with requests for access to data, and for penalties to be imposed where they fail to do so without good reason.

In this regard, the plan is an attempt by the state to coordinate and guide the activities of private companies so that their products meet the requirements of the police – a direction of travel that sits uneasily with the EU’s commitment to “an open market economy with free competition.”

What lies ahead?

So far no formal proposals have been published to carry forward the work of the High-Level Expert Group – although the majority of the recommendations would not require legislation to be enacted, and the plan refers to other means such as recommendations, “agreed common principles”, technical standards and “soft law” to reach its goals.

What exactly will become of the plan is likely to depend on the composition of the next European Commission, following the European Parliament elections, as well as the will of the member states in the Council.

Outgoing MEP Patrick Breyer from the German Pirate Party has suggested that “this secret wish list of EU governments stands an excellent chance of being hastily implemented by the next EU Commission under the auspices of ‘Big Sister’ von der Leyen, right after the European elections.”

If that is the case, then privacy advocates will have much to do to halt what Breyer’s colleague and Pirate Party lead candidate for the elections, Anja Hirschel, has called an “excessive leap directly into a fully monitored society.”

Our work is only possible with your support.
Become a Friend of Statewatch from as little as £1/€1 per month.

Further reading

13 September 2023

Statement to EU countries: Do not agree to mass surveillance proposal, warn NGOs

Over 80 organisations, including Statewatch, are calling on EU member states to block the proposed Child Sexual Abuse Regulation, which would fatally undermine encryption and thus the safety and privacy of all internet users. In the UK, the government has recently conceded that similar clauses in the Online Safety Bill will not be enforced until it is technologically possible to do so - which is likely to be never.

20 July 2023

EU: Law enforcement data access demands could encompass any connected device

Law enforcement officials are meeting today and tomorrow in Logroño, Spain, to discuss "access to electronic communications and digital data as a premise for law enforcement." The Spanish Council Presidency published a discussion paper prior to the meeting, but a document obtained by Statewatch offers far more information on current plans.

19 April 2023

"Going dark": will the next assault on privacy take place behind closed doors?

The Swedish Presidency of the Council proposed to create a High-Level Expert group on data retention to strike a new "balance" between the right to privacy and the right to security, according to two documents published by Statewatch. Member state feedback has been enthusiastic. The aim is to change the rhetoric on surveillance to facilitate the adoption of new rules. The expert group format of discussion and the participation of civil society are still to be decided, with the Commission and the Council likely to co-chair.

 

Spotted an error? If you've spotted a problem with this page, just click once to let us know.

Report error