03/02/2020
CURIA - Documents
applicable to the dispute in the main proceedings, contain rules on the retention of electronic communications data
and on access to that data by the national authorities.
Access to that data is, in addition, regulated by the lagen (2012:278) om inhämtning av uppgifter om elektronisk
kommunikation i de brottsbekämpande myndigheternas underrättelseverksamhet (Law (2012:278) on gathering of
data relating to electronic communications as part of intelligence gathering by law enforcement authorities: ‘Law
2012:278’) and by the rättegångsbalken (Code of Judicial Procedure; ‘the RB’).
The obligation to retain electronic communications data
According to the information provided by the referring court in Case C‑203/15, the provisions of Paragraph 16a of
Chapter 6 of the LEK, read together with Paragraph 1 of Chapter 2 of that law, impose an obligation on providers of
electronic communications services to retain data the retention of which was required by Directive 2006/24. The
data concerned is that relating to subscriptions and all electronic communications necessary to trace and identify
the source and destination of a communication; to determine its date, time, and type; to identify the
communications equipment used and to establish the location of mobile communication equipment used at the start
and end of each communication. The data which there is an obligation to retain is data generated or processed in
the context of telephony services, telephony services which use a mobile connection, electronic messaging systems,
internet access services and internet access capacity (connection mode) provision services. The obligation extends
to data relating to unsuccessful communications. The obligation does not however extend to the content of
communications.
Articles 38 to 43 of Regulation (2003:396) on electronic communications specify the categories of data that must
be retained. As regards telephony services, there is the obligation to retain data relating to calls and numbers
called and the identifiable dates and times of the start and end of the communication. As regards telephony
services which use a mobile connection, additional obligations are imposed, covering, for example, the retention of
location data at the start and end of the communication. As regards telephony services using an IP packet, data to
be retained includes, in addition to data mentioned above, data relating to the IP addresses of the caller and the
person called. As regards electronic messaging systems, data to be retained includes data relating to the numbers
of senders and recipients, IP addresses or other messaging addresses. As regards internet access services, data to
be retained includes, for example, data relating to the IP addresses of users and the traceable dates and times of
logging into and out of the internet access service.
Data retention period
In accordance with Paragraph 16d of Chapter 6 of the LEK, the data covered by Paragraph 16a of that Chapter
must be retained by the providers of electronic communications services for six months from the date of the end of
communication. The data must then be immediately erased, unless otherwise provided in the second subparagraph
of Paragraph 16d of that Chapter.
Access to retained data
Access to retained data by the national authorities is governed by the provisions of Law 2012:278, the LEK and the
RB.
–
Law 2012:278
In the context of intelligence gathering, the national police, the Säkerhetspolisen (the Swedish Security Service),
and the Tullverket (the Swedish Customs Authority) may, on the basis of Paragraph 1 of Law 2012:278, on the
conditions prescribed by that law and without informing the provider of an electronic communications network or a
provider of an electronic communications service authorised under the LEK, undertake the collection of data
relating to messages transmitted by an electronic communications network, the electronic communications
equipment located in a specified geographical area and the geographical areas(s) where electronic communications
equipment is or was located.
In accordance with Paragraphs 2 and 3 of Law 2012:278, data may, as a general rule, be collected if, depending
on the circumstances, the measure is particularly necessary in order to avert, prevent or detect criminal activity
involving one or more offences punishable by a term of imprisonment of at least two years, or one of the acts listed
in Paragraph 3 of that law, referring to offences punishable by a term of imprisonment of less than two years. Any
grounds supporting that measure must outweigh considerations relating to the harm or prejudice that may be
caused to the person affected by that measure or to an interest opposing that measure. In accordance with
Paragraph 5 of that law, the duration of the measure must not exceed one month.
The decision to implement such a measure is to be taken by the director of the authority concerned or by a person
to whom that responsibility is delegated. The decision is not subject to prior review by a judicial authority or an
independent administrative authority.
Under Paragraph 6 of Law 2012:278, the Säkerhets och integritetsskyddsnämnden (the Swedish Commission on
Security and Integrity Protection) must be informed of any decision authorising the collection of data. In
accordance with Paragraph 1 of Lagen (2007:980) om tillsyn över viss brottsbekämpande verksamhet (Law
(2007:980) on the supervision of certain law enforcement activities), that authority is to oversee the application of
the legislation by the law enforcement authorities.
–
The LEK
Under Paragraph 22, first subparagraph, point 2, of Chapter 6 of the LEK, all providers of electronic
communications services must disclose data relating to a subscription at the request of the prosecution authority,
the national police, the Security Service or any other public law enforcement authority, if that data is connected
with a presumed criminal offence. On the information provided by the referring court in Case C‑203/15, it is not
necessary that the offence be a serious crime.
–
The RB
The RB governs the disclosure of retained data to the national authorities within the framework of preliminary
investigations. In accordance with Paragraph 19 of Chapter 27 of the RB, ‘placing electronic communications under
surveillance’ without the knowledge of third parties is, as a general rule, permitted within the framework of
curia.europa.eu/juris/document/document.jsf?text=&docid=186492&pageIndex=0&doclang=EN&mode=lst&dir=&occ=first&part=1&cid=1088733
5/16