‘National security’ can’t be used as an excuse to bypass privacy laws

A preliminary ECJ ruling would limit the power of member states to sidestep privacy and data protection laws

EU member states might no longer be able to cite national security concerns as the basis for flouting data protection and privacy laws in the bulk collection of personal data, according to a preliminary legal judgement.

Security services should not have a blanket power to demand the personal and communications data of citizens from telecoms and tech companies, according to the European Court of Justice (ECJ) advocate general Campos Sanchez-Bordona.

Activities aimed at safeguarding national security - and that don’t rely on the co-operation of third parties - are exempt from the Directive on privacy and electronic communications, the advocate general has said. There are, however, complications that arise when private companies and other organisations are imposed upon by member states to hand over personal and private data.

“When the cooperation of private parties, on whom certain obligations are imposed, is required, even when that is on grounds of national security, that brings those activities into an area governed by EU law: the protection of privacy enforceable against those private actors,” his opinion states.

Related Resource

Testing for compliance just became easier

How you can use technology to ensure compliance in your organisation

Download now

“Accordingly, the Directive is applicable, in principle, where providers of electronic services are required by law to retain data belonging to their subscribers and to activities that are aimed at safeguarding national security and are carried out by the public authorities on their own account, without requiring the cooperation of private parties and not, therefore, imposing obligations on the latter in relation to the management of their businesses.”

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

The advocate general, moreover, has suggested the indiscriminate retention of all traffic and location data of subscribers and registered users to any particular third-party service is entirely disproportionate.

He has recommended that data retention is targeted and limited to certain categories, with access to this data also limited and subject to approval by a court or independent authority. 

There are a handful of circumstances, however, where Sanchez-Bordona sees no reason why data can’t be retained and accessed on a general basis, for example in the event of intelligence pointing to an immediate threat.

Generally, however, such data collection is not compatible with the general EU privacy rules, and should not be exempted from them over national security grounds.

The preliminary ruling is directly antagonistic to the wishes of various EU governments, including and especially the UK, having argued that legislation such as the Investigatory Powers Act 2016 is necessary to keep citizens safe. 

Advertisement - Article continues below

The act, nicknamed the ‘Snooper’s Charter’, contains provisions for bulk data collection and has been subject to various legal challenges through European courts. The UK has argued that the provisions outlined in the legislation should be exempt from privacy laws.

While the advocate general does not speak for the ECJ, their opinion carries great weight in the process by which decisions are reached. Deliberations have begun, and a judgement will be delivered at a later indeterminate date.

Featured Resources

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Three keys to maximise application migration and modernisation success

Harness the benefits that modernised applications can offer

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

The 3 approaches of Breach and Attack Simulation technologies

A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals

Download now
Advertisement

Recommended

Visit/data-insights/data-management/354423/eu-us-data-transfer-tools-used-by-facebook-ruled-legal
data management

EU-US data transfer tools used by Facebook ruled legal

19 Dec 2019
Visit/backup/33385/arcserve-udp-9240dr-review-beef-up-your-backups
backup

Arcserve UDP 9240DR review: Beef up your backups

4 Apr 2019

Most Popular

Visit/operating-systems/25802/17-windows-10-problems-and-how-to-fix-them
operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020
Visit/microsoft-windows/32066/what-to-do-if-youre-still-running-windows-7
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
Visit/web-browser/30394/what-is-http-error-503-and-how-do-you-fix-it
web browser

What is HTTP error 503 and how do you fix it?

7 Jan 2020
Visit/policy-legislation/general-data-protection-regulation-gdpr/354577/data-protection-fines-hit-ps100m
General Data Protection Regulation (GDPR)

Data protection fines hit £100m during first 18 months of GDPR

20 Jan 2020