Europol Poised for More Data Access in Cybercrime Fight: Privacy Advocates Raise Objections

Tactical flowchart detailing Europol's proposed expansion of data processing powers, contrasting cybercrime enforcement with GDPR privacy safeguards by Adv. Shoeb Hakim

The European Commission has proposed significant reforms for Europol to strengthen its ability to fight cybercrime—but civil liberties campaigners are warning that the agency is becoming a “data black hole” swallowing fundamental rights.


Introduction

“If cybercrime were a country, it would have the third-largest economy in the world.” — Henna Virkkunen, European Commission Executive Vice President.

The European Commission has proposed significant reforms for Europol intended to strengthen the law enforcement cooperation agency’s ability to fight crime, including digital extortion. But civil liberties campaigners are not happy about the privacy implications.

This article analyzes the proposed reforms, the privacy concerns raised, and the broader implications for fundamental rights in the EU.


The Proposed Reforms

Key elements of the proposal:

AspectDetails
Cooperation with ENISABoost cooperation between Europol’s European Cybercrime Centre and ENISA on ransomware incidents
Expanded R&DNew remit for digital forensics, lawful access, and encrypted data analysis
Police shared data spaceSecure cloud infrastructure for transnational investigations
Data sharingMoving beyond bilateral, ad hoc data exchanges to structured sharing

The Commission’s justification:

The proposal aims to correct “a growing structural imbalance between the scale and technological sophistication of criminal networks and the collective capabilities available to EU law enforcement authorities.” Europol would “fully act as the EU-level capability hub needed to reduce fragmentation, pool resources and provide member states with the advanced operational and technological support needed to respond to the evolving threat environment.”

Virkkunen’s warning:

“Cybercrime costs our economy trillions of euros every year.”


The Privacy Concerns

The current limitation:

As things stand, Europol is only supposed to process the personal data of suspected criminals, victims, witnesses, and other relevant people. This requires categorizing the data before processing.

The proposed change:

Europol would be able to process personal data of anyone—not just suspects, victims, and witnesses—as long as doing so is “necessary and proportionate for the performance of Europol’s tasks.”

Why this matters:

Reform backers argue the current limitation is disconnected from “the operational reality of modern law enforcement where the extraction of information from large and unstructured datasets constitutes a core operational task of law enforcement authorities.”

The safeguards (proposed):

  • Data of non-relevant people must be deleted “once the purpose of processing it is fulfilled”
  • Europol must inform its in-house data protection officer
  • Such data must be kept “functionally separate from ‘categorized’ data”

The Critics’ Response

Protect Not Surveil coalition:

“The new mandate grants the rogue agency all its wildest wishes and continues its transformation into a data black hole—swallowing our fundamental rights, and undermining justice, safety and accountability.” — Chloé Berthélémy, senior policy adviser, European Digital Rights

The coalition’s concerns:

  • The proposal would “surely increase the number of people whose personal data is unlawfully accessed by Europol”
  • EDPS oversight would be weakened
  • Europol would gain the ability to process sensitive data without EDPS’s prior approval in some cases
  • Much of EDPS’s oversight role would be transferred to Europol’s data protection officer

The Pattern: A Troubling Precedent

The 2022 confrontation:

In 2022, the European Data Protection Supervisor (EDPS) tried to crack down on Europol over its retention of vast unstructured datasets that naturally included the personal data of many people who had nothing to do with criminal investigations.

The Commission’s response:

The European Commission approved Europol reforms that effectively retroactively legalized what Europol was doing, to an extent.

The legal challenge:

The EDPS challenged the new rules, but the General Court ruled for the Commission.

The pattern:

  • Agency exceeds its legal mandate
  • Commission expands mandate to cover what agency was doing
  • Courts uphold the expansion
  • Agency’s powers expand further

The Operational Context: Operation Endgame

With excellent timing, Europol also hailed its role in the latest Operation Endgame takedown of cybercriminal infrastructure. It played a coordinating role in the targeting of the “assembly lines” that were being used to launch ransomware and critical infrastructure attacks, as well as malware such as SocGholish.

Why this matters:

Europol’s operational successes are cited as justification for expanded powers. The pattern is consistent: a crisis is used to justify expanded surveillance, and safeguards are weakened in the name of security.


The Data Protection Implications

AspectCurrentProposed
Data processingLimited to suspects, victims, witnessesAnyone, if “necessary and proportionate”
EDPS oversightStrongWeakened
Data Protection OfficerAdvisory roleExpanded oversight role
Sensitive data processingRequires EDPS approvalCan be done without prior approval in some cases
Data retentionLimitedExpanded
Unstructured dataNot processedWill be processed

The Broader Context: EU Digital Sovereignty vs. Fundamental Rights

The tension:

The EU is pursuing digital sovereignty while simultaneously expanding surveillance capabilities. The two goals are not inherently incompatible, but the current trajectory suggests that surveillance is being prioritized over privacy.

The legal framework:

The proposed reforms must be consistent with the EU’s data protection framework, including the GDPR and the Charter of Fundamental Rights. The question is whether they are.


What This Means for Citizens

The risk:

  • Your personal data could be processed by Europol even if you are not a suspect, victim, or witness
  • You may not be informed that your data has been processed
  • The safeguards for protecting your data are being weakened
  • Oversight of Europol’s data processing is being reduced

What you can do:

  • Follow the legislative process
  • Support civil liberties organizations
  • Demand stronger safeguards
  • Hold your MEPs accountable

What This Means for Law Enforcement

The opportunity:

  • Faster access to data
  • More effective cross-border investigations
  • Better coordination with member states
  • Enhanced technical capabilities

The responsibility:

  • Ensure safeguards are effective
  • Delete data of non-relevant people promptly
  • Maintain transparency
  • Respect fundamental rights

What This Means for Policymakers

The challenge:

  • Balance security and fundamental rights
  • Ensure effective oversight
  • Maintain public trust
  • Comply with EU data protection law

The solution:

  • Stronger safeguards
  • Independent oversight
  • Transparency
  • Accountability

Conclusion

The European Commission has proposed significant reforms for Europol intended to strengthen the law enforcement cooperation agency’s ability to fight crime, including digital extortion. But civil liberties campaigners are not happy about the privacy implications.

The proposal:

  • Boost cooperation between the European Cybercrime Centre and ENISA on ransomware incidents
  • Expanded R&D for digital forensics, lawful access, and encrypted data analysis
  • New “police shared data space” with secure cloud infrastructure

The privacy concern:

Europol would be allowed to process personal data of anyone—not just suspects, victims, and witnesses—as long as it is “necessary and proportionate.” Oversight by the EDPS would be weakened.

The critics:

“The new mandate grants the rogue agency all its wildest wishes and continues its transformation into a data black hole—swallowing our fundamental rights, and undermining justice, safety and accountability.”

The pattern:

Agency exceeds mandate → Commission expands mandate → Courts uphold expansion → Agency’s powers expand further.

The bottom line:

The fight against cybercrime and the protection of fundamental rights are not mutually exclusive. But the current proposal appears to prioritize one at the expense of the other. Citizens, civil liberties organizations, and policymakers must work together to ensure that the balance is restored.

KNOWLEDGE CHECK QUIZ

Q: Under the current legal framework, whose personal data is Europol specifically restricted to processing? Ans: Europol is currently only permitted to process the personal data of categorized individuals directly related to a crime: specifically, suspected criminals, victims, and witnesses.

Q: How does the European Commission’s new proposal change this data processing limitation? Ans: The proposal allows Europol to process the personal data of anyone (including innocent third parties found in unstructured datasets), as long as the agency determines that doing so is “necessary and proportionate.”

Q: Which independent oversight body is being significantly weakened under these proposed reforms? Ans: The European Data Protection Supervisor (EDPS). Much of its oversight authority, including prior approvals for processing sensitive data, is being transferred to Europol’s own in-house Data Protection Officer.

Q: What highly controversial precedent occurred in 2022 regarding Europol and the EDPS? Ans: The EDPS ordered Europol to delete vast amounts of unlawfully retained unstructured data. In response, the European Commission passed reforms that retroactively legalized Europol’s data retention practices, a move later upheld by the General Court.

───

FREQUENTLY ASKED QUESTIONS (FAQ)

Q: Why does Europol want access to “unstructured data”? Ans: When law enforcement seizes servers from a cybercrime syndicate (like a ransomware gang), the data is massive and unorganized (unstructured). Europol argues that to find the actual criminals, they need the legal authority to use advanced digital forensics and AI to sift through the entire dataset, even if it contains the private data of millions of innocent people.

Q: What is the “Protect Not Surveil” coalition’s main argument against this expansion? Ans: The coalition, including European Digital Rights, argues that giving Europol the power to process anyone’s data without strict external EDPS oversight turns the agency into a “data black hole.” They believe it will inevitably lead to the unlawful access of innocent citizens’ data, sacrificing fundamental human rights under the guise of security.

Q: If Europol collects my data accidentally, are they required to delete it? Ans: The proposed safeguards state that data of non-relevant people must be kept “functionally separate” and deleted “once the purpose of processing it is fulfilled.” However, privacy advocates argue this phrasing is a massive loophole, allowing Europol to retain the data indefinitely by claiming the investigation or analysis is ongoing.


Adv. Shoeb Hakim
Data Protection & Cybercrime Policy Advisor

📌 Follow me on LinkedIn for daily data protection and cybercrime policy insights: https://www.linkedin.com/in/shoebhakim

📌 Visit my website for more articles: https://www.shoebhakim.com
📌 Visit my website for legal knowledge: https://www.vakilverse.com
📌 Visit my website for research fellowship: https://www.legalcomplaince.in

♻️ Share this article with your network.


Disclaimer: This article is for informational purposes only and does not constitute legal advice.


Hashtags: #AdvShoebHakim #Europol #Cybercrime #DataProtection #Privacy #ENISA #Ransomware #DigitalForensics #LawfulAccess #Encryption #EuropeanCommission #DataBlackHole #EDPS #CivilLiberties #FundamentalRights #ECHR #GDPR #EUDataProtection #PoliceCooperation #LawEnforcement #TransnationalCrime #DigitalExtortion #CyberSecurity #InfoSec #PrivacyMatters #DataRetention #Surveillance #HumanRights #EuropeanCybercrimeCentre #OperationEndgame #SocGholish #CloudInfrastructure #PoliceSharedDataSpace #BilateralDataExchanges #DataProcessing #UnstructuredData #DataProtectionOfficer #EDPSOversight #CourtOfJustice #GeneralCourt #ProtectNotSurveil #EuropeanDigitalRights #SecurityVsPrivacy #FundamentalRightsAgency #EUCharterOfFundamentalRights #DataProtectionRegulation #EUDataProtectionSupervisor #PrivacyAdvocates #CivilLibertiesCampaigners #CybercrimeCosts #DigitalEconomy #CriticalInfrastructure #RansomwareAttacks #LawfulInterception

Find