03/02/2020
CURIA - Documents
Directive 2006/24 affects, in a comprehensive manner, all persons using electronic communications services, but
without the persons whose data are retained being, even indirectly, in a situation which is liable to give rise to
criminal prosecutions. It therefore applies even to persons for whom there is no evidence capable of suggesting
that their conduct might have a link, even an indirect or remote one, with serious crime. Furthermore, it does not
provide for any exception, with the result that it applies even to persons whose communications are subject,
according to rules of national law, to the obligation of professional secrecy.
Moreover, whilst seeking to contribute to the fight against serious crime, Directive 2006/24 does not require any
relationship between the data whose retention is provided for and a threat to public security and, in particular, it is
not restricted to a retention in relation (i) to data pertaining to a particular time period and/or a particular
geographical zone and/or to a circle of particular persons likely to be involved, in one way or another, in a serious
crime, or (ii) to persons who could, for other reasons, contribute, by the retention of their data, to the prevention,
detection or prosecution of serious offences.
Secondly, not only is there a general absence of limits in Directive 2006/24 but Directive 2006/24 also fails to lay
down any objective criterion by which to determine the limits of the access of the competent national authorities to
the data and their subsequent use for the purposes of prevention, detection or criminal prosecutions concerning
offences that, in view of the extent and seriousness of the interference with the fundamental rights enshrined in
Articles 7 and 8 of the Charter, may be considered to be sufficiently serious to justify such an interference. On the
contrary, Directive 2006/24 simply refers, in Article 1(1), in a general manner to serious crime, as defined by each
Member State in its national law.
Furthermore, Directive 2006/24 does not contain substantive and procedural conditions relating to the access of
the competent national authorities to the data and to their subsequent use. Article 4 of the directive, which governs
the access of those authorities to the data retained, does not expressly provide that that access and the
subsequent use of the data in question must be strictly restricted to the purpose of preventing and detecting
precisely defined serious offences or of conducting criminal prosecutions relating thereto; it merely provides that
each Member State is to define the procedures to be followed and the conditions to be fulfilled in order to gain
access to the retained data in accordance with necessity and proportionality requirements.
In particular, Directive 2006/24 does not lay down any objective criterion by which the number of persons
authorised to access and subsequently use the data retained is limited to what is strictly necessary in the light of
the objective pursued. Above all, the access by the competent national authorities to the data retained is not made
dependent on a prior review carried out by a court or by an independent administrative body whose decision seeks
to limit access to the data and their use to what is strictly necessary for the purpose of attaining the objective
pursued and which intervenes following a reasoned request of those authorities submitted within the framework of
procedures of prevention, detection or criminal prosecutions. Nor does it lay down a specific obligation on Member
States designed to establish such limits.
Thirdly, so far as concerns the data retention period, Article 6 of Directive 2006/24 requires that those data be
retained for a period of at least six months, without any distinction being made between the categories of data set
out in Article 5 of that directive on the basis of their possible usefulness for the purposes of the objective pursued
or according to the persons concerned.
Furthermore, that period is set at between a minimum of 6 months and a maximum of 24 months, but it is not
stated that the determination of the period of retention must be based on objective criteria in order to ensure that
it is limited to what is strictly necessary.
It follows from the above that Directive 2006/24 does not lay down clear and precise rules governing the extent of
the interference with the fundamental rights enshrined in Articles 7 and 8 of the Charter. It must therefore be held
that Directive 2006/24 entails a wide-ranging and particularly serious interference with those fundamental rights in
the legal order of the EU, without such an interference being precisely circumscribed by provisions to ensure that it
is actually limited to what is strictly necessary.
Moreover, as far as concerns the rules relating to the security and protection of data retained by providers of
publicly available electronic communications services or of public communications networks, it must be held that
Directive 2006/24 does not provide for sufficient safeguards, as required by Article 8 of the Charter, to ensure
effective protection of the data retained against the risk of abuse and against any unlawful access and use of that
data. In the first place, Article 7 of Directive 2006/24 does not lay down rules which are specific and adapted to (i)
the vast quantity of data whose retention is required by that directive, (ii) the sensitive nature of that data and (iii)
the risk of unlawful access to that data, rules which would serve, in particular, to govern the protection and security
of the data in question in a clear and strict manner in order to ensure their full integrity and confidentiality.
Furthermore, a specific obligation on Member States to establish such rules has also not been laid down.
Article 7 of Directive 2006/24, read in conjunction with Article 4(1) of Directive 2002/58 and the second
subparagraph of Article 17(1) of Directive 95/46, does not ensure that a particularly high level of protection and
security is applied by those providers by means of technical and organisational measures, but permits those
providers in particular to have regard to economic considerations when determining the level of security which they
apply, as regards the costs of implementing security measures. In particular, Directive 2006/24 does not ensure
the irreversible destruction of the data at the end of the data retention period.
In the second place, it should be added that that directive does not require the data in question to be retained
within the European Union, with the result that it cannot be held that the control, explicitly required by Article 8(3)
of the Charter, by an independent authority of compliance with the requirements of protection and security, as
referred to in the two previous paragraphs, is fully ensured. Such a control, carried out on the basis of EU law, is an
essential component of the protection of individuals with regard to the processing of personal data (see, to that
effect, Case C‑614/10 Commission v Austria EU:C:2012:631, paragraph 37).
Having regard to all the foregoing considerations, it must be held that, by adopting Directive 2006/24, the EU
legislature has exceeded the limits imposed by compliance with the principle of proportionality in the light of
curia.europa.eu/juris/document/document.jsf?doclang=EN&text=&pageIndex=0&part=1&mode=DOC&docid=150642&occ=first&dir=&cid=99319 (judgme…
10/11