TABLE OF CONTENT
Search inside this publication
Criminal investigations involve the large-scale processing of highly sensitive personal data, such as witness statements, biometric information and digital evidence. Effectively using such data for law enforcement purposes without violating the rights of people is notably regulated through EU data protection law. While the need for establishing a comprehensive evidence base for law enforcement is clear, any processing of personal data of natural persons in this context has to comply with the right to the protection of personal data.
The Law Enforcement Directive (LED) [1] Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, p. 89, ELI: http://data.europa.eu/eli/dir/2016/680/oj).
establishes rules for processing personal data by competent authorities in order to protect fundamental rights and freedoms, in particular the protection of personal data. Competent authorities include any public body that is responsible for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, including in relation to threats to public security. Competent authorities include, in particular, law enforcement authorities, prosecutor’s offices and judicial authorities (e.g. courts).
This report examines how competent authorities apply data protection in practice, focusing on the implementation of the LED.
Although closely related to the General Data Protection Regulation (GDPR) [2] Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1, ELI: http://data.europa.eu/eli/reg/2016/679/oj).
, the LED is less well known. As a directive, the LED sets minimum standards but allows EU Member States to have flexibility in terms of its implementation, leading to differences across national systems.
Drawing on 132 interviews across all Member States, this report provides practical insights into how law enforcement and judicial authorities apply the LED. The interviews cover both operational officers and data protection officers (DPOs) working in law enforcement, as well as judicial authorities (i.e. prosecutors and investigating judges). Interviews were also conducted with national supervisory authorities (i.e. the national data protection authorities (DPAs) that are in charge of monitoring the application of the LED). The results contribute to an EU-level assessment of how the LED is applied and to providing suggestions for future improvements for the practical implementation of the LED.
Article 4 of the LED establishes the principles for the legal framework applicable to competent authorities when processing personal data for the purposes of the prevention, investigation, detection or prosecution of criminal offences. These include the principles of data minimisation, purpose limitation and data security. The first two, although closely linked, relate to different concepts and have different objectives: purpose limitation means that personal data must be collected for specified, explicit and legitimate purposes and that its processing must remain tied to those specified purposes, while data minimisation signifies that, for a given purpose, only data that are adequate, relevant and not excessive should be collected and used. Data security involves the implementation of technical and organisational measures to ensure the confidentiality and integrity of personal data. In addition, the LED requires that Member States verify the appropriateness of data storage, either by specifying time limits in their national legislation or by conducting regular inspections.
Most interviewees working in competent authorities, including police and judicial authorities, are aware of these concepts and, from the perspective of the DPOs interviewed by the European Union Agency for Fundamental Rights (FRA), these concepts represent a positive evolution towards data protection within these authorities. However, the interviews also show that the data protection principles set out in the LED are not always fully understood by staff working within competent authorities. Data minimisation and purpose limitation are often confused and are not seen as separate principles. Data security measures are seen as a means to ensure both data minimisation and purpose limitation. While data security measures may indeed support the authorities’ obligations to collect (and store) the necessary data for a specified purpose, the practical means of implementing data security measures need to be clarified.
In addition, some shortcomings were identified when it comes to knowledge of the applicable legal framework regulating data storage. Several interviewees among operational staff in competent authorities were unaware of the applicable rules concerning time limits and regular inspections.
Interviews with staff working in competent authorities show, in some cases, an over-reliance on data management information technology (IT) systems used by competent authorities to ensure data protection requirements (including features such as the automatic deletion of data, obligated motivation fields or loggings). However, very few DPOs working at competent authorities referred to regular inspections or audits of the data management system to ensure that data protection principles were appropriately secured in practice.
The interviews with staff working in competent authorities also point to structural challenges regarding the accuracy of personal data (Article 4(1)(d) of the LED). When asked about measures to ensure the accuracy of data, several of these interviewees were unable to describe specific safeguards, and some explicitly stated that there was no continuous or proactive monitoring in place to ensure data quality. While data may be updated in the course of day-to-day operational work, regular checks were described as not feasible. In some cases, the same data are stored separately in different databases, meaning that updates made in one system do not automatically apply to others, potentially resulting in outdated or duplicate records. A few of these interviewees noted that police and judicial authorities use separate, non-interoperable systems. In addition, some representatives from the judiciary indicated that their role in ensuring data accuracy is limited, as they rely on information collected during pretrial investigations by other actors, notably the police.
Finally, in relation to international data transfers, interviewees pointed out that some uncertainties remain. Specifically, the lack of adequacy decisions adopted with non-EU countries creates both legal and technical difficulties for competent authorities transferring data to non-EU countries, as the assessment of what would constitute ‘appropriate safeguards with regard to the protection of personal data’ is difficult and requires competent authorities to invest time and human resources. From a practical perspective, some interviewees also mentioned a lack of legal clarity when it comes to accessing specific foreign-based data, either because of these data being saved in clouds or because the types of data (e.g. genetic data) are regulated differently across the EU.
As demonstrated by a few promising practices identified in this report, any concrete measures aimed at reinforcing the implementation of data protection principles largely depend on evidence-based analysis of the situation within each Member State. National evaluations of data protection awareness within law enforcement and judicial authorities allow evidence-based initiatives to be undertaken to reinforce the application of the LED in practice.
Member States should consider undertaking a systematic assessment of the level of awareness and understanding of the applicable national data protection framework for law enforcement purposes among those responsible for applying it. The objective of such an assessment would be to propose evidence-based measures for tackling a lack of awareness or understanding of the legal requirements stemming from this legal framework. Such an assessment should describe how competent authorities handle personal data, in particular sensitive categories, and whether they respect core principles of data protection law.
Member States and relevant EU agencies (e.g. the European Union Agency for Law Enforcement Training (CEPOL), the European Union Agency for Criminal Justice Cooperation (Eurojust) or the European Union Agency for Law Enforcement Cooperation (Europol)) should develop further guidance and training that clearly explains the objectives of each data protection principle in the context of law enforcement work and the measures that should be consistently implemented to ensure the practical implementation of these principles. Such guidance and training should be specific to the LED, adapted to the work of the competent authority and tailored to each professional group (criminal investigators, cybercrime experts, IT professionals, etc.) that, within the authority, may process personal data.
Member States should regularly evaluate whether their technical and organisational measures (e.g. the automatic deletion of data, obligated motivation fields and loggings to handle data subjects ) that have been put in place to comply with some of the LED requirements (notably data minimisation, purpose limitation, data accuracy, data erasure and data storage) are sufficient and effective.
The European Commission and the European Data Protection Board (EDPB) should provide further guidance on the rules applicable to international data transfers to non-EU countries when no adequacy decisions have been adopted. The guidance should explain the criteria based on which competent authorities should evaluate appropriate safeguards. In addition, EU institutions and Member States should take measures to identify specific challenges faced by competent authorities when it comes to cross-border access to personal data (e.g. evidence stored in clouds based in non-EU countries or access to DNA databases), to develop targeted, clear and practical guidelines for competent authorities.
Article 32 of the LED requires controllers to designate a DPO, although Member States may exempt courts and other independent judicial authorities from this obligation when acting in their judicial capacity. Article 33 introduces a broad mandate for the DPO, requiring their involvement ‘in all issues which relate to the protection of personal data’.
Despite the gaps in knowledge reported earlier, most of the DPOs interviewed have observed improvements in staff awareness of data protection requirements. At the same time, many DPOs stated that fulfilling their role remains challenging for several reasons.
First, a lack of resources is a recurring concern. Most of the interviewees among the DPOs reported facing a heavy workload, and many indicated that they have no or only very small teams and support. More than half of the DPOs interviewed reported that they cannot focus exclusively on tasks related to data protection and are required to perform additional duties, such as tasks that they used to perform in their previous law enforcement position before being appointed as a DPO. In addition, the large volume of requests related to the Schengen information system was mentioned during several interviews. Several interviewees indicated that both their teams and other staff within their organisations lack sufficient technical expertise. This includes expertise on the way data are processed and the use of AI systems. The absence of dedicated IT specialists constrains DPOs’ ability to engage meaningfully with technologically complex processing operations. Overall, many DPOs described being largely dissatisfied or only moderately satisfied with their working conditions, noting that resource constraints confine their role to day-to-day operational tasks rather than enabling proactive or in-depth work.
Second, interviewees from competent authorities pointed to gaps in training and guidance, despite the clear requirement in Article 33 of the LED that controllers should support the DPO by maintaining their expert knowledge. Most DPOs indicated that they were already employed within the authority before being appointed to the DPO function, and many of them had not received specific training on the LED. Available training opportunities, including external training courses and conferences, were described as predominantly focused on the GDPR and insufficiently tailored to the specificities of data processing by law enforcement or judicial authorities.
While data protection impact assessments (DPIAs) were generally considered useful, for instance for early risk detection, DPOs reported experiencing a lack of concrete guidance in conducting them. Several interviewees explained that they largely develop DPIA templates on their own and would welcome more detailed and case-specific guidance at the EU or national level.In this area, the lack of IT expertise was again highlighted as a compounding factor that can sometimes prevent DPOs from developing exhaustive, detailed DPIAs.
Finally, the DPOs interviewed described challenges related to the organisational positioning of DPOs, despite Article 33 of the LED, which requires Member States to support controllers in ensuring that ‘the data protection officer is involved, properly and in a timely manner, in all issues which relate to the protection of personal data’. DPOs who are not positioned at the managerial level reported experiencing resistance from colleagues when recalling applicable data protection procedures. Some of the DPOs interviewed indicated that they do not always receive the information necessary to adequately review and assess impact assessments. Several DPOs reported being asked to perform tasks that fell outside their mandate, such as providing general legal advice (beyond Article 34 of the LED, which requires DPOs to advise controllers on the correct implementation of the LED’s requirements). Others explained that, in order to foster goodwill and cooperation, they often adopt a service-oriented approach, accompanying operational staff rather than exercising a control function. Several DPOs reported that operational staff sometimes expect them to carry out assessments or take decisions on their behalf. The DPOs interviewed by FRA highlighted instances of role confusion, in which advisory input is perceived as instruction and operational responsibilities are informally shifted to the DPO.
Experts working in DPAs emphasised the importance of DPOs’ independence. In this regard, several DPOs working in competent authorities highlighted that both their independence and the recognition and effectiveness of their mandate are strongly related to their position in the organigram of the authority and are reinforced when they are not in a subordinate position.
Member States should make sure that each competent authority has a data protection office with sufficient staff and expertise to enable them to carry out their tasks effectively, as required by Articles 32 and 33 of the LED. To give practical effect to this obligation, Member States should ensure that each competent authority has access to an adequately staffed data protection function covering both technological and legal expertise. This includes allocating adequate time for in-depth and proactive assessments and for providing targeted guidance to operational staff.
The European Commission, in cooperation with Member States and the EDPB, should support the development of further guidance aimed at DPOs working within the scope of the LED to ensure the consistent application of the directive. This could include a train-the-trainer approach to strengthen DPO expertise, clearer guidance on when a DPIA is required and consideration of a DPIA template tailored to law enforcement processing, taking into account the specific features of the LED framework and common high-risk processing activities, with a view to enhancing efficiency and reducing fragmentation.
Member States should ensure that the organisational positioning of DPOs safeguards their independence and provides access to the necessary expertise within the authority. As required in Articles 32 to 34 of the LED, the scope of the DPO’s role should be clearly defined in order to enhance the awareness about their exact tasks and responsibilities among the authority’s staff, ensuring that advisory functions are not conflated with operational decision-making or general legal, IT or cybersecurity tasks beyond the DPO’s mandate.
Under the LED, DPAs are tasked with investigating compliance, handling and making decisions on complaints from individuals and promoting public awareness of data protection rights. They have the power to access premises, systems and information to conduct their inspections and investigations effectively. DPAs also have corrective powers: they can issue warnings, reprimands and binding orders to bring processing operations into compliance, including ordering the rectification, erasure or restriction of unlawful data processing. They also advise national institutions on legislative and administrative measures, cooperate with other EU supervisory authorities and the EDPB, where relevant, and have the authority to engage in legal proceedings to ensure the effective enforcement of the national provisions transposing the LED.
In practice, as the findings confirm, most DPAs suffer from a shortage of staff, time and expertise when it comes to overseeing the application of national provisions transposing the LED. The lack of resources affecting DPAs with respect to GDPR-related tasks was highlighted by FRA as a recurring problem in previous reports in 2014, 2019 and 2024. Several interviewees working in DPAs highlighted that, as a result of this resource shortage, their DPA prioritises the GDPR over the LED and concentrates resources on the most pressing (and mandatory) part of their work: addressing complaints. Although the volume of LED-related complaints to the supervisory authorities may not be high, the range of tasks described earlier is broad. The interviews with DPAs also show that the lack of resources has direct and concrete implications for a number of tasks that are not, or not often enough, conducted by DPAs. The main impact lies in the inability of some DPAs to conduct more regular audits and monitoring on their own initiatives. Several DPAs also struggle to develop expertise on technologies that may be used by competent authorities and expertise on preparing for new regulations that intersect with the scope the LED, such as the AI Act [3] Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167/2013, (EU) No 168/2013, (EU) 2018/858, (EU) 2018/1139 and (EU) 2019/2144 and Directives 2014/90/EU, (EU) 2016/797 and (EU) 2020/1828 (Artificial Intelligence Act) (OJ L, 2024/1689, 12.7.2024, ELI: http://data.europa.eu/eli/reg/2024/1689/oj).
.
The interviews with DPAs show that the overall scope of and importance given to tasks performed by competent authorities that may have LED-related implications clearly indicate a need for increased (and specialised) human resources in DPAs across Member States, to support them in supervising these authorities more frequently and more effectively. In addition, DPAs in which a sector or unit was created to deal exclusively with LED-related cases have declared that they are under less resource pressure than other DPAs.
Finally, while some respondents from DPAs emphasised that the investigations benefited from good cooperation with competent authorities, several of them identified what they considered to be a serious lack of expertise and understanding of LED requirements within law enforcement and judicial authorities. When it comes to cooperation during investigations or inspections, while most interviewees indicated that they did not face any issue in accessing documents, even when these were classified, some interviewees reported that, in some cases, police authorities have been reluctant to hand over documents. Interviewees working in DPAs with no or limited access to classified information indicated that this does prevent them from effectively investigating competent authorities. In addition, some interviewees working in law enforcement authorities indicated that they believe that the DPA has no authority to investigate them. Finally, a challenging point raised by some interviewees concerns the fact that supervisory and competent authorities do not always agree on what constitutes ‘necessary information’ for the purpose of an investigation, in the sense of Article 47(1) of the LED, which requires that DPAs should have the power to ‘obtain from the controller … all information necessary for the performance of its tasks’.
Member States should provide national DPAs with sufficient resources to ensure that DPAs have sufficient human, financial and technical resources to fulfil each of their tasks as provided by the LED. This includes conducting ad hoc inspections, providing advice and ensuring in-house expert knowledge and understanding. The European Commission should ensure that its periodical report on the implementation of the LED covers the appropriateness of resources allocated to DPAs. Expert knowledge of DPAs should cover potential data protection interferences stemming from the use of AI systems or other advanced technologies, as well as the intersection between data protection legislation and other legislation, such as the AI Act. Where it is not the case, national DPAs should consider creating separate, dedicated units for dealing exclusively with matters of data protection falling under the scope of the LED.
Member States and EU institutions should develop specific guidelines clarifying the processes under which DPAs’ inspections and investigations should be conducted under the LED, to ensure access to effective remedies. Guidance should, in particular, clarify what ‘necessary information’ means and should provide practical explanations of cases in which the exemptions to data subjects’ rights may be applied. Guidelines should provide DPAs with clear and practical examples that support them in their assessment.
Member States should consider implementing rules and safeguards to ensure the mandatory and efficient cooperation of competent authorities during DPAs’ inspections and investigations, while safeguarding the effectiveness of criminal investigations. In Member States where DPAs do not have access to classified information, Member States should consider providing DPAs with such investigatory power.