Criminal investigations increasingly rely on large volumes of sensitive personal data, from witness statements and biometric information to digital evidence. The EU’s Law Enforcement Directive (LED) aims to ensure that authorities can use such data when fighting crime while respecting the fundamental right to data protection.
The report ‘The Law Enforcement Directive – data protection challenges in practice’ looks into the experiences, practices and challenges of law enforcement and supervisory authorities when protecting personal data under the Directive. It calls for:
- Greater awareness and understanding: despite greater awareness of data protection principles, staff in law enforcement and the judiciary often lack a clear understanding of the Directive’s core principles and requirements, including when it comes to international data transfers. This risks unlawful data processing and can undermine trust in and the effectiveness of criminal investigations. Member States should offer specific practical guidance and training on the Directive and how to apply it. The European Commission and the European Data Protection Board (EDPB) should provide further guidance on the rules on international data transfers to non-EU countries.
- More resources: data protection officers in law enforcement and the judiciary often face heavy workloads and limited resources. Data protection authorities face similar constraints, which can limit proactive inspections and monitoring. Member States should ensure authorities have sufficient human, financial and technical resources to effectively fulfil their tasks under the Directive.
- Technological expertise and support: Rapid technological advances have left some data protection experts without access to specialised technical knowledge and expertise for preparing for the application in practice of new regulations that intersect with the Law Enforcement Directive, including the AI Act. Modern technologies can raise concerns about bias, transparency, accountability, and the adequacy of data protection safeguards, particularly when data is transferred outside the EU. Member States should regularly review the use of such technologies and ensure access to specialised technical expertise to support compliance with the Directive.
FRA's report comes as the European Commission reviews how the Directive works in practice.
The report draws on over 130 interviews with experts across all EU Member States. Interviewees include staff from data protection authorities, as well as law enforcement and the judiciary, including their data protection officers, across all EU Member States. It provides first-hand evidence from these interviewees about where implementation can be strengthened to ensure the Directive’s data protection legal safeguards are not viewed as an obstacle to effective policing rather than an integral part of it.