Data Privacy,
Data Security,
General Data Protection Regulation (GDPR)
CJEU Advocate-General Maciej Szpunar Says Oversight Could Mitigate Rights Harms

In a significant legal development, the Advocate-General of the Court of Justice of the European Union (CJEU), Maciej Szpunar, has made a crucial recommendation regarding Belgian data retention law. This law, designed primarily to combat cybercrime, faces potential invalidation due to its violation of fundamental privacy rights. Szpunar’s stance emphasizes the ongoing tension between enacting laws to mitigate crime and protecting individual privacy rights, leading to a pivotal juncture in European legal discourse.
During his recommendation, Szpunar advocated for a rethinking of how mass surveillance is viewed in the context of a rising number of cybercrimes. He suggested that the European Union (EU) must evolve beyond its traditional perceptions of surveillance, particularly given the increasing sophistication and prevalence of online criminal activities.
The law under scrutiny, enacted in 2022, mandates that online service providers maintain extensive records of user data, including identification, traffic, and location metadata. The intention behind this requirement is to enhance efforts against cybercrime, online fraud, and network security breaches. However, this is not the first instance in Belgium’s attempts to legislate data retention; prior laws have been struck down by the CJEU, highlighting the contentious nature of balancing security and privacy.
The Court’s initial ruling on this matter occurred in 2014 when the EU-wide Data Retention Directive was deemed illegal. This directive required telecommunications service providers to store metadata about customer communications for a duration ranging from six to twenty-four months to assist law enforcement agencies. The court deemed such measures as constituting mass surveillance, as they involved the indiscriminate collection and retention of vast amounts of personal data without proper justification. Instead of focusing solely on how this data is accessed, the ruling emphasized the infringement on rights occurring from the moment data is collected.
Following the 2014 decision, Belgium attempted to create a more palatable data retention law, only to face further challenges and eventual rejection by the CJEU in 2020. In this ruling, the court stated that for a national data retention law to be deemed acceptable, it must be precise, targeted, and incorporate strong safeguards on data access. The idea of retaining IP addresses indefinitely was mentioned as permissible if it was deemed necessary for combating serious crimes or safeguarding national security. However, Belgium’s revised data retention law failed to meet these requirements.
The 2022 law was considerably expansive, leading to concerns about its legality. Szpunar stated that it covered a “particularly broad set of data” without requisite protections in place, making it vulnerable to misuse. Specifically, the law lacked strong mechanisms to ensure different categories of data remained protected from conflation or misuse, thereby infringing upon individuals’ rights to privacy.
On a related note, in a 2024 ruling against France’s copyright regime, CJEU reiterated its position on data rights by allowing the collection of IP addresses and identity data, emphasizing that they could be stored separately until justified for use. Szpunar’s opinion in the recent case suggests a shift toward permitting broader data retention, provided robust controls are implemented to separate and restrict access to this information. Such a pivot may imply a significant alteration in the court’s stance on data collection, nudging the EU toward a compromise between law enforcement needs and human rights protections.
Furthermore, Szpunar believes that introducing stringent oversight and separation conditions would mitigate substantial violations of privacy while retaining critical data necessary for prosecuting cyber offenses. His opinion underscores a growing recognition within legal circles that the nature of crime has evolved alongside technology, and thus the legal frameworks addressing these crimes must also adapt accordingly.
Legal experts like TJ McIntyre from University College Dublin have noted the importance of Szpunar’s recommendation. They observed that the Advocate-General’s guidance may prompt the CJEU to reassess its previous rulings and the broader implications of data retention laws in Europe.
However, it remains paramount to mention that while Szpunar’s recommendation is significant, it does not guarantee a particular outcome. The Court is not obligated to follow the Advocate-General’s counsel, even though it often does. Should the Court adopt Szpunar’s reasoning, it would signify a departure from its historical commitment to dismantling indiscriminate data collection practices, raising critical concerns among privacy advocates.
Across the EU, there is an ongoing discourse regarding data governance. The European Commission has been methodically working on new regulations aimed at replacing the defunct Data Retention Directive. These proposals reflect a balanced approach towards law enforcement’s needs and protecting citizens’ rights. Rights organizations, however, have voiced concerns that adopting Szpunar’s framework could usher in a return to illegal mass surveillance, jeopardizing the privacy of millions over unclear justifications.
Advocacy groups stress that significant evidence linking indiscriminate data retention to crime prevention remains absent, highlighting the precarious nature of policies that could infringe on fundamental rights in pursuit of enhanced security. As the legal landscape evolves, the ongoing battle between data privacy and security continues to provoke robust debate and scrutiny within European society.