Europe's data protection supervisor has warned that a proposed expansion of data processing powers for the EU's policing agency, Europol, poses significant privacy risks. The European Commission unveiled a plan in June to make Europol a central hub for police forces to trade and analyze data using advanced technologies, aiming to bolster the fight against cross-border crime and terrorism.
The proposed reforms include a fundamental change to how Europol handles collected data, by relaxing current regulations that mandate data be sorted into specific categories before Europol can legally utilize it. The Commission has cited this categorization requirement as a "key operational bottleneck" given the high volume of unstructured data Europol manages.
In an opinion released on Thursday, European Data Protection Supervisor Wojciech Wiewiórowski stated that the proposal "creates serious risks, particularly regarding the processing of the personal data of individuals with no established criminal links." He cautioned that the plan would permit Europol to retain data on a "vast" number of individuals unconnected to criminal activity for an "extensive and unspecified period of time."
The EDPS, which acts as the data protection authority for EU institutions like Europol, acknowledged the need to develop Europe's security architecture to counter evolving criminal threats. However, the watchdog emphasized that any reform must incorporate "robust safeguards and real oversight" to protect privacy.