The European Commission plans to significantly expand the data processing powers of the EU law enforcement agency Europol while scaling back existing privacy safeguards for citizens. A draft regulation presented in June classifies current requirements—which mandate that stored data must be proportionate and directly linked to a specific crime—as administrative burdens. For European Union citizens, the initiative means that data belonging to innocent individuals could routinely end up in police analysis systems in the future.
Dropping the Distinction Between Suspects and Non-Suspects
Until now, Europol has generally only been permitted to store personal data if a concrete link to an investigation is demonstrated to the European Data Protection Supervisor, Wojciech Wiewiórowski. Furthermore, data had to be strictly segmented into categories such as suspects or victims. Under the proposals by Brussels officials, Europol would be granted permission to conduct non-targeted, suspicionless data searches.
In its impact assessment, the Commission justifies this move directly by pointing to the use of modern algorithms: strictly differentiating between suspects and non-suspects hinders the effective feeding of training data into machine learning tools and advanced analytics. Civil rights organization Statewatch warns that this step paves the way for the widespread deployment of experimental AI systems in routine police work.
Cloud Data Space and Tighter Ties with Tech Corporations
The draft also outlines the creation of a cloud-based European police data space. Member state security agencies would be able to automatically ingest investigative data via direct uploads. Additionally, plans include access to the Prüm II network for exchanging biometric data and resuming systematic bulk data transfers from border agency Frontex, which were previously halted by the European Data Protection Supervisor due to legal violations.
At the same time, Europol is set to establish closer ties with the private sector. Private tech companies would gain access to the agency’s testing environments. Furthermore, Europol would act as a central hub for private actors to exchange information and secure funding to develop digital surveillance tools targeting capabilities like automated profiling or circumventing encryption. Europol would also gain access to funding pools such as the EU research framework program Horizon Europe—slated for 175 billion euros from 2028 to 2034—for which the agency previously could not apply on its own.
Criticism Over Lack of Transparency and Loss of Control
Civil liberties advocates and privacy campaigners view the plans as a concerning erosion of fundamental rights. According to Statewatch, lowering these safeguards increases the risk of misinformation and discrimination caused by faulty algorithms. Furthermore, it would become virtually impossible for affected individuals to challenge unauthorized data storage in court. Europol had already previously secured exemptions from transparency requirements under the European AI Act for high-risk applications.
The proposal is further compounded by recent disclosures from former employees alleging that Europol previously operated unauthorized shadow systems to bypass data retention limits. Additionally, the agency’s practice of scraping online data using automated scripts and logging changes only “where possible” is said to violate European Court of Justice case law, which mandates full audit trails and traceability for automated data modifications.
Implications in Practice
The proposal fits into broader so-called relief packages: through legislative initiatives like the AI Omnibus and the planned Digital Omnibus, critics argue that the Commission and Council are systematically seeking to water down baseline data privacy standards.
Sources: Heise – News, Heise – Netzpolitik














