April 8, 2014
The Court of Justice of the European Union has declared the so-called Data Retention Directive to be invalid. Interestingly enough, in 2013 the same Court ordered Sweden to make a payment of 3 million Euro for its delay in transposing this law. Back then the CJEU ruled that a delay in the transposition is liable to have consequences for public and private interest.
In the current case, the requests for a preliminary ruling were filed with the Court of Justice of the European Union by Irish court and Austrian Constitutional Tribunal. The Irish case was initiated by the Digital Rights Ireland, an organisation defending digital fundamental rights. The Austrian case found support of, among other, 11 thousand Austrian citizens.
The Data Retention Directive was adopted in order to prevent serious crime, in particular organised crime and terrorism. The Court of Justice of the European Union has ruled today that the interference with fundamental rights connected with the implementation of European law is too far-reaching.
In the opinion on the case, advocate general Cruz Villalon also concluded that the application of the Data Retention Directive could not be reconciled with the provisions of the European Union Charter for Fundamental Rights and with the necessity to protect the right to privacy.
In its judgment, the Court of Justice noted that the data retained on the basis of retention regulations can provide precise information on the private lives of users, such as the habits of everyday life, place of residence, social relationships and social environments frequented.
Even though the Court of Justice states that retention itself can be justified by the need to combat serious crime and protect public safety, by adopting the Data Retention Directive the EU institutions crossed the boundary set by the principle of proportionality. The Court emphasized that the Directive does not guarantee that the interference in the privacy will be sufficiently circumscribed to ensure that that it is strictly necessary to achieve the above-mentioned goals.
Among others, the Directive does not guarantee that the data will indeed be used only to combat serious crime. Furthermore, access to data does not depend on any court control. The Directive does not provide guarantees which would prevent abuses, for example the use of data in an unauthorized manner. Finally, the Directive does not establish an obligation to retain the data in the territory of the European Union.
According to Dorota Głowacka, expert of the Warsaw based Helsinki Foundation for Human Rights, “All problems referred to by the Court are reflected in the provisions of Polish telecommunications law on data retention. Current rules allow fairly free access to these data by different agencies and may encourage abuse. HFHR has long emphasized the need to change the law in this regard. We postulated, among others, introduction of an effective mechanism for external oversight of the use of retained data, the need to create an exhaustive list of serious offenses for which the authorized entities will be able to use this tool, or the introduction of the obligation to notify the person whose data was accessed.”
In Poland, for quite some time now, the provisions of the Directive have raised concerns related, for example, to the wide array of situations in which the police and other agencies can request data administrators to make the telecommunications data available. In principle, this should be the case only in relation to the most serious crime. The practice, however, has diverged from this premise. There is no sufficient control over the requests formed by the police and other agencies, the matter of data destruction has not been properly regulated and it is often a problem to establish the exact number of requests.
However, it is not only the scale of telecommunications data use that is disquieting. The problem lies also in the lack of guarantees which would protect the citizen from possible abuses. This is visible on the example of Bogdan Wróblewski’s case. In 2013, Mr Wróblewski, then a journalist in one of the Polish dailies, won a precedential case for protection of personal interests against the Central Anti-corruption Bureau. The court decided that the CAB acquired the journalist’s phone records and other telecommunications data illegally. During the debate organized by the Helsinki Foundation for Human Rights, the director of CAB himself admitted that there had been abuses in Bogdan Wróblewski’s case.
“The judgement of the Court of Justice of the European Union will undoubtedly have influence on the judgement of the Polish Constitutional Tribunal. The Tribunal is currently assessing the compliance of the provisions of Telecommunications Law on data retention with the Constitution of the Republic of Poland. The interpretation based on the right to privacy and the principle of proportionality should definitely be reflected in the judgement of the Tribunal,” says Mr Adam Bodnar, the Vice president of the Helsinki Foundation for Human Rights.
So far the laws on data retention were declared unconstitutional in Germany, Romania and Czech Republic.
Zuzanna Warso, lawyer, Helsinki Foundation for Human Rights
firstname.lastname@example.org – contact the author
Author : Europe of Human Rights