Anamaria Corca, Director Policy Advisory, Considerati
Haritz Echarren, Consultant, Considerati
21/01/2025 - The landscape of law enforcement access to digital evidence is undergoing a significant transformation, marking 2025 as a pivotal year for EU digital policy. The evolution of law enforcement access to data since 9/11 reflects a journey from rapid expansion to careful balancing of competing interests. Starting with the 2001 Budapest Convention and US PATRIOT Act's expansive approach, that was initially shaped by counter-terrorism imperatives. The 2006 EU Data Retention Directive marked peak expansion, but the Snowden revelations in 2013 triggered a privacy backlash, leading to landmark decisions like Digital Rights Ireland invalidating the Directive. The field then entered a reform phase with the US CLOUD Act (2018) and EU e-Evidence regulation seeking to modernize frameworks, while the OECD worked to develop common principles for government access. Currently, multiple frameworks coexist: the Budapest Convention's Second Additional Protocol, the new but not yet ratified UN cybercrime treaty, and OECD principles, alongside regional approaches. This creates a complex web of obligations balancing security needs, privacy rights, and jurisdictional challenges, particularly around cloud data and encryption, while grappling with rapid technological change and competing international visions. While recent years have primarily focused on e-evidence frameworks within the EU and EU-US data access agreements, we're now witnessing an unexpected revival of intercept and data retention discussions – topics that had largely remained dormant in EU policy circles.
The EU thus stands at a critical juncture in the debate over law enforcement access to digital evidence, with recent developments and upcoming changes in 2025 reconciling security needs and fundamental rights. The Council's endorsement of recommendations from the High-Level Group (HLG) Concluding Report on law enforcement data access on 12 December 2024 is a precursor to that work.
A renewed focus on interception and data retention represents a shift in EU priorities. The mention of intercept rules in the recent DRAGOS report particularly stands out, signalling a broader reconsideration of law enforcement tools. This development marks a significant departure from the EU's previous trajectory, which had primarily concentrated on streamlining e-evidence procedures and international cooperation frameworks.
The Council's endorsement of recommendations from the High-Level Group (HLG) has prompted significant pushback from the European Data Protection Board (EDPB), highlighting the complex balancing act ahead. The EDPB's intervention particularly emphasizes the need for any new measures to be backed by empirical evidence of effectiveness, strictly limited in scope to prevent mass surveillance, technically feasible without compromising overall system security, and compliant with EU fundamental rights standards. This tension is further complicated by divergent judicial approaches to national security, with the ECHR traditionally granting member states broader discretion while the ECJ has taken a more restrictive approach in recent cases, emphasizing fundamental rights protections even in national security contexts.
Combined with the challenging geopolitical landscape and uncertainty surrounding key transatlantic data access frameworks - particularly the EU-US Law Enforcement Agreement and evolving international conventions - companies processing and retaining customer data face a complex regulatory horizon. Organizations will need to carefully assess how potential regulatory changes could impact their data handling practices, infrastructure decisions, and cross-border operations. The implications for privacy, security, and law enforcement effectiveness will continue to shape and constrain EU digital policy.
Beyond these political challenges, three key themes emerge that tech companies should watch closely: harmonization, technical solutions and public-private frameworks.
The fragmented landscape of data retention and access rules across EU Member States appears set to change.
Notably, the solutions proposed steers clear of requiring systematic weakening of encryption. Instead, it emphasizes finding technical solutions that enable targeted, lawful access while maintaining strong security.
Perhaps most significantly, both the Council conclusions and the HLG Concluding Recommendations emphasize the need for structured cooperation between law enforcement and service providers. Rather than an adversarial approach, the focus is on developing common standards, clear procedures, and mutual understanding of operational needs and technical constraints.
Tech companies should prepare for increased engagement with EU institutions in 2025 as these recommendations translate into concrete initiatives. While further mandatory requirements appear inevitable, the current emphasis on collaborative solution-finding reflects both technical complexities and policy uncertainties.
As the Commission develops its roadmap, the industry faces a critical opportunity to help shape technically sound solutions that balance security needs with privacy rights. Companies that proactively engage while maintaining clear focus on customer trust and data protection will be best positioned to navigate the evolving regulatory landscape.
Do you have any questions about the above or are you looking for EU Policy & Regulatory advice? Contact Considerati, we offer specialised advice and tailored support.
Our services ContactOur blogs
You may have noticed it in the annual search for the best policy at the most competitive premium; some health insurers operate business models where customers…