Notes

← Back to home

A collection of fragments of understanding in the pursuit of deeper questions.

The European Right to Digital Privacy - The Digital Rights Ireland case

Steps Forward by the CJEU

  • Data Retention (Digital Rights Ireland)
  • Google Spain
  • Schrems
  • Tele 2 Sverige The two cases were adopted by European Court of Justice, to define laws.

Data Retention Directive (2006) Data retention means the ways according to which the data is stocked and processed and for how long. The duration of Data retention is important because Data could be very important to carry on investigations, institutions can arrive to the identification of the possible criminals. Also, to prevent terrorism attacks (London 2005).

  • Created in reaction to the terrorism' attacks, then it can be shifted to Pandemic seasons
  • It was not against the DNA of the rights, but against the principle of proportionality.
  • The proportionality principle was broken for 3 reasons:
    • No definition of Serious Crime.
    • No Procedural Rights.
    • 2 Years was too long.
  • The directive was annulled because was a piece of secondary legislation of European Union, which was against the Primary Legislation. Mandatory retention of traffic and location data (Article 5) for ISP and ECS, identifying:
  • Source and Destination
  • Location
  • Users' Device
  • Date and Time
  • Type of Communication
  • Duration Therefore, they can't retain the content of the conversation, so the essence of the right is not affected. Retention period between 6 months and 2 years, it means that the Data could be retained from 6 months to 2 years, for specific reasons otherwise they should be deleted earlier. One of these reasons is the prevention of terrorism attacks, or: "for the purpose of the investigation, detection and prosecution of serious crime, as defined by each Member State in its national law" (Art. 1).

The Ruling

  • Art. 52 Charter (of fundamentals right of EU) Any limitation on the exercise of the rights and freedoms recognized by this Charter must be provided for by law and respect the essence of those rights (DNA of the rights) and freedoms. Subject to the principle of proportionality, limitations may be made only if they are necessary and genuinely meet objectives of general interest recognized by the Union or the need to protect the rights and freedoms of others. Guideline for dealing with crimes, but also for modern problems like Pandemics. If the Member States want to restrict one of the rights provided by the Charter, for example privacy, they should respect such conditions: not affecting the DNA of the rights and should be proportionate, it means that has to be necessary and should not restrict more than the necessary.
  • The Essence of the Rights "[I]t must be held that, even though the retention of data required by Directive 2006/24 constitutes a particularly serious interference with those rights, it is not such as to adversely affect the essence of those rights given that, as follows from Article 1(2) of the directive, the directive does not permit the acquisition of knowledge of the content of the electronic communications as such". "[T]he use of electronic communications are particularly important and therefore a valuable tool in the prevention of offences and the fight against crime, in particular organized crime." Data retention "genuinely satisfies an objective of general interest."
  • Principle of Proportionality
    • The Directive has exceeded the limits imposed by compliance with the principle of proportionality. (According to the Court of Justice this directive of 2006 affects the principle of proportionality, because...)
    • There is no definition of "serious crime" and "competent authorities". (During emergencies, Governments have more power to restrict rights, in authoritarian countries they will far more than the necessary to strength the regime, so the interpretation of "serious crime" cannot be left to the single state , because then it will change by state and state according to the ideas of the governments)

      There are no objective and procedural criteria to establish limits of access to the metadata by the authorities. (According to the Court of Justice there aren't clear procedures, how are they treated, to establish the limits of access to the metadata)

      Excessive length of the retention period. (The time is too long, two years, even if the goal to prevents crime is reasonable, it's not proportionated).

  • The Court refuses the idea of mass surveillance of "the entire European population". (Freedom and privacy are fundamental rights)

The metadata (Art. 5), taken as a whole, allow specific and precise deductions concerning private lives, habits, relationships, movements of the users. Absence of any relationship between the retained data and the serious crimes.

  • The Directive does not ensure a high level of protection since it does not guarantee the "destruction of the data at the end of the data retention period". (It's important because the Data that it isn't destructed can be aggregated, anonymized and used to do Big Data previsions)

    The Directive does not require that the data in question is to be retained within the European Union. On those grounds, the Court rules that the Directive 2006/24/EC is invalid.

Data Retention Saga Continues

  • Principle of Proportionality
  • Importance of Security Measures
  • Role of the Nizza Charter to interpret EU Law, the role of the Nizza Charter is a sort of "bill of rights" of the European Institutions, but it binds also the institutions of the Member States.
  • Data shall be retained within the EU. Over every institution in EU Area there is the ECHR, but, for example, Russia is neglecting the obligations dictated. Quoted the Article 8.