- ECJ examines whether national data retention is compatible with the ePrivacy Directive and Charter, taking into account the Digital Rights Ireland ruling.
- Advocate General supports possible storage, but demands strict legal basis, access protection, retention period and security guarantees.
- Six proportionality requirements: Legal basis, preservation of essence, legitimate aim, suitability, necessity and proportionality.
The ECJ will rule on referrals from Sweden and the United Kingdom (united Rs. C‑203/15 and C‑698/15) to decide whether national data retention rights are compatible with European law, in particular with the ePrivacy Directive and the Charter. The Advocate General has today presented his submissions on this (Media release and Applications).
Background: “Digital Rights Ireland
The ECJ had already on April 8, 2014 in the Digital Rights Ireland judgment (Joined Cases C‑293/12 and C‑594/12). to decide on data retention issues (for this purpose, the Article 29 Working Party has Opinion authored).
At that time, it declared Directive 2006/24/EC (retention of data generated or processed in connection with the provision of publicly available electronic communications services or of public communications networks) invalid. The retention of traffic data provided for in the Directive seriously interferes with the fundamental right to respect for private life and the other rights under Article 7 of the Charter, and is disproportionate: It is true that data retention is suitable for achieving the goal of solving serious crimes. However, it is not sufficiently limited in the Directive because it neither requires a concrete suspicion nor is it limited to data of a certain period of time or a certain area or group of persons (i.e. it can be carried out “without cause”).
The “Digital Rights Ireland” judgment concerned the Data Retention Directive. Subsequently, the Swedish and English laws on data retention were submitted to the ECJ as a preliminary question (for more information, see e‑comm). The ECJ must therefore assess data retention in the national context against the background of the ePrivacy Directive, whereby the framework determined in Digital Rights Ireland will be decisive.
Requests of the Advocate General
The Advocate General proposes the following answer to the questions referred:
Article 15(1) of Directive 2002/58/EC […], and Articles 7, 8 and 52(1) of the Charter […] are to be interpreted as not precluding Member States from imposing on providers of electronic communications services an obligation to retain all data relating to communications effected by the users of their services where all of the following conditions are satisfiedwhich it is for the referring courts to determine in the light of all the relevant characteristics of the national regimes at issue in the main proceedings:
- the obligation and the safeguards which accompany it must be provided for in legislative or regulatory measures possessing the characteristics of accessibility, foreseeability and adequate protection against arbitrary interference;
- the obligation and the safeguards which accompany it must observe the essence of the rights recognised by Articles 7 and 8 of the Charter of Fundamental Rights;
- the obligation must be strictly necessary in the fight against serious crime, which means that no other measure or combination of measures could be as effective in the fight against serious crime while at the same time interfering to a lesser extent with the rights enshrined in Directive 2002/58 and Articles 7 and 8 of the Charter of Fundamental Rights;
- the obligation must be accompanied by all the safeguards described by the Court in paragraphs 60 to 68 of its judgment of 8 April 2014 in Digital Rights Ireland and Others (C‑293/12 and C‑594/12, EU:C:2014:238) concerning access to the data, the period of retention and the protection and security of the data, in order to limit the interference with the rights enshrined in Directive 2002/58 and Articles 7 and 8 of the Charter of Fundamental Rights to what is strictly necessary; and
- the obligation must be proportionate, within a democratic society, to the objective of fighting serious crime, which means that the serious risks engendered by the obligation, in a democratic society, must not be disproportionate to the advantages which it offers in the fight against serious crime.
The following considerations were decisive:
- The ePrivacy Policy is applicable to data retention.
- Data retention does not fundamentally violate the ePrivacy Directive:
In light of the foregoing, I consider that general data retention obligations are consistent with the regime established by Directive 2002/58 and that Member States are therefore entitled to avail themselves of the possibility offered by Article 15(1) of that directive in order to impose a general data retention obligation. (20) Recourse to that option is, however, subject to compliance with strict requirements which flow not only from Article 15(1) but also from the relevant provisions of the Charter, read in the light of Digital Rights Ireland, which I shall examine later on. (21)
- The Charter is applicable to data retention.
- This results in general requirements for data retention:
- 132. Together, those two provisions establish six requirements that must be satisfied in order for the interference caused by a general data retention obligation to be justified:
- the retention obligation must have a legal basis;
- it must observe the essence of the rights enshrined in the Charter;
- it must pursue an objective of general interest;
- it must be appropriate for achieving that objective;
- it must be necessary in order to achieve that objective;
- it must be proportionate, within a democratic society, to the pursuit of that same objective.