Data Privacy
,
Data Security
,
General Data Protection Regulation (GDPR)

CJEU Advocate-General Maciej Szpunar Says Oversight Could Mitigate Rights Harms

David Meyer
September 4, 2026    

Europe Tiptoes to Legalizing Bulk Collection of ISP Metadata
Image: Shutterstock

The most senior adviser at the European Union’s highest court recommended striking down a Belgian data retention law that is largely intended to fight cybercrime, because it violates people’s fundamental privacy rights.

See Also: How Enterprise Browsers Enhance Security and Efficiency

In doing so, Advocate-General Maciej Szpunar also suggested that it may be time for the EU to move past its old conception of mass surveillance – partly because of the growing realities of cybercrime.

The law the Court of Justice of the EU is scrutinizing was passed in 2022. It forces online service providers to store identification, traffic and location metadata, with the aim of fighting cybercrime, network security breaches and online fraud. It is the third in a series of Belgian data retention laws that have, so far, all been scuppered by major decisions from the same court.

The first such ruling came in 2014, when the court killed the EU-wide Data Retention Directive. Under that law, member states were meant to require that communications service providers store customers’ telecommunications metadata – who calls or messages whom and when or when people use the internet – for between six and 24 months, for the benefit of law enforcement.

The court called the directive essentially a mass surveillance measure. It required the storage of too much data without justification and with insufficient controls on access. Importantly, the ruling reflected the European view that the violation was taking place at the start of the process, when the data was first collected and stored – rather than at the point of access.

With its first attempt in ruins, Belgium formulated a second data retention law that it hoped would clear hurdles established by the court. But re-do also tripped up when the Court of Justice of the EU published another ruling in 2020, in a case brought by French digital rights group La Quadrature du Net. The court wrote that a national data retention law could pass muster only if it was targeted and had good access safeguards. It also said it might be acceptable to indefinitely store IP addresses for the purposes of fighting serious crime or defending national security.

Either way, Belgium’s law didn’t pass the standards set by the court, and the government had to try again. The replacement it produced in 2022 was nothing if not expansive, demanding the retention of origin and destination identifiers and timestamps for each communication, terminal location and port information, phone numbers, IP addresses and more.

Meanwhile, in 2024 the Court of Justice of the EU made a ruling in another case brought by La Quadrature du Net. That lawsuit challenged the legality of France’s copyright infringement regime, which hinges on the retention of IP addresses and customer identity information. Copyright violations are routinely prosecuted following the combination of these types of metadata.

In that ruling, the court said it was fine to indiscriminately collect and store this information, even for the purposes of fighting crime that is less than serious – as long as the separate types of metadata are kept separate until someone provides a legal basis for combining them.

In his Thursday opinion, Szpunar recommended that the court follow the same logic to its conclusion, allowing for the general and indiscriminate retention of further traffic and location data types – not just IP addresses – so long as the controls placed on recombination are “effectively watertight.” He argued that strong separation rules and oversight could mitigate serious interference with fundamental rights and therefore make it proportionate.

“Such a solution would, first of all, in my opinion, mitigate the risk of systemic impunity for offenses committed exclusively online or whose commission or preparation is facilitated by the specific characteristics of the internet,” Szpunar wrote. “It guarantees, in effect, the existence of the data necessary for their prosecution, even as the development and ever-increasing importance of the internet simultaneously lead to an increase in cybercriminal behavior.”

“This could well be a very important opinion as the AG essentially appears to invite the CJEU to reconsider the basis of its data retention case law by focusing on storage and access controls,” wrote TJ McIntyre, a University of Dublin law professor who is also the longstanding chair of Digital Rights Ireland, in a Monday Bluesky post.

But Szpunar also said the Belgian law in question was definitely illegal under EU law, because it covered a “particularly broad set of data” and lacked the necessary controls. “It does not impose any storage methods for this data that would guarantee a truly watertight separation of the different categories of data, preventing, at the storage stage, any combined use of these different categories of data,” he wrote.

As a result, Szpunar said, the Belgian law results in disproportionate interference with privacy rights. He also pointed out that the legislation was imprecise, in some circumstances leaving it up to communications providers to figure out which data to retain and for how long.

Of course, the Court of Justice may choose not to follow the advice of its advocate-general, as sometimes happens – but it usually does. And, if so, Europe would move further away from its old principle that indiscriminate data collection and storage necessarily equates to illegal mass surveillance.

Although it is yet to formally produce a proposal, the European Commission has been quietly working on new, pan-EU rules to replace the long-dead Data Retention Directive. It conducted an impact assessment and public consultation last year, and promised to “explore measures to improve cross-border cooperation for lawful interception of data by 2027, both among authorities, and between authorities and services providers.”

Rights groups indicated that they are ready to fight again, arguing that taking up following the course laid out by Spuznar would mark a return to illegal mass surveillance that “creates inadmissible data security risks, considering that the vast amounts of personal data retained for law enforcement are vulnerable to cyberattacks.”

“We also stress in our submission that there is still no scientifically proven link between indiscriminate data retention and impact on crime or crime clearance,” the groups, writing under the banner of the European Digital Rights coalition, added at the time.