
Europe's data protection supervisor has raised the alarm over European Commission plans to dramatically expand Europol's surveillance capabilities, warning the reforms could allow the EU policing agency to retain personal data on vast numbers of innocent people for indefinite periods.
The European Data Protection Supervisor Wojciech Wiewiórowski said Thursday the proposal "creates serious risks, particularly regarding the processing of the personal data of individuals with no established criminal links." His intervention comes about two months after the Commission unveiled a plan to make Europol the central hub for police forces across the EU to trade and analyse data using the latest technologies.
A Fundamental Shift in Data Processing
The reforms represent a significant departure from current rules. They'd relax requirements that data be sorted into different categories before Europol can determine whether it's legally allowed to use it. The Commission has defended this change as necessary to remove a "key operational bottleneck," arguing that Europol deals with high volumes of unstructured data that can't be efficiently processed under existing regulations.
But Wiewiórowski warned that the proposal would allow Europol to retain data on a "vast" number of people with no links to criminal activity "for an extensive and unspecified period of time." That's a profound shift in how EU agencies handle personal information — and one that raises fundamental questions about the balance between security and civil liberties.
The Security Argument
The Commission's proposal is part of a wider strategy to give EU justice agencies more firepower to tackle cross-border crime and terrorism. In an era of encrypted communications, darknet marketplaces, and transnational criminal networks, the argument goes, police agencies need the technological capacity to match the threats they face.
The EDPS acknowledged that Europe's security architecture needs to be developed to protect against increasingly complex criminal threats. But the privacy watchdog underlined that the proposed Europol reform "must provide robust safeguards and real oversight." That's the tension at the heart of this debate: no one disputes that cross-border crime requires cross-border policing. The question is whether the Commission's proposal includes sufficient protections against mission creep and abuse.
What's Missing: Oversight and Limits
The EDPS opinion doesn't reject the need for reform outright. It calls for stronger safeguards. That means clear limits on how long data can be retained, strict criteria for what counts as legitimate use, and genuine independent oversight — not just bureaucratic box-ticking. Without those protections, Europol could become a sprawling surveillance apparatus with minimal accountability, processing the personal data of millions of Europeans who've never been suspected of any crime.
This isn't just a technical question about database architecture. It's about what kind of Europe we're building — and whether the institutions designed to protect us end up threatening the freedoms they're supposed to defend.
Why This Matters:
The Europol reform proposal crystallizes a fundamental dilemma facing European democracies: how to build effective security infrastructure without eroding civil liberties. The Commission is right that cross-border crime requires cross-border policing — individual nations can't tackle terrorism, trafficking, and cybercrime alone. But the EDPS warning shows that the current proposal tilts too far toward surveillance without adequate safeguards. If Europol can indefinitely retain data on people with no criminal links, that's not targeted policing — it's mass surveillance. The European Parliament must strengthen oversight provisions and impose strict time limits on data retention. Europe needs effective law enforcement, but it also needs to remain a union of laws, not a surveillance state. The balance hasn't been struck yet.