In a nonbinding opinion at the European Court of Justice, an advocate general said that under the 2002 Privacy and Electronic Communications Directive, EU member states cannot require telecommunications companies to hand over bulk data to national security agencies.

If nations want to collect data on individuals, they must have permission from an independent authority, inform the person, and keep the data within the EU, the court adviser said.

The opinion, written by advocate general Manuel Campos Sánchez-Bordona, was delivered ahead of forthcoming judgments on a number of cases in which national security measures have been challenged on grounds that they failed to protect citizens' data privacy: one is from the United Kingdom, two are from France, and one is from Belgium.

Opinions from the EU Court of Justice's 11 advocates general are not binding but are followed by the court in the vast majority of cases. If its ruling is consistent with the opinion, it would invalidate a U.K. law that requires telecommunications companies to hand over bulk data to the British security agency MI6 and others. It would also nullify Belgian and French laws requiring technology companies like Facebook to retain location data on their users in case that data is needed in an investigation.

The French government established its law requiring telecommunications companies and internet service providers to store all traffic and data location after the 2015 terrorist attacks in Paris at the Bataclan music venue, which resulted in the deaths of 90 people. Similar measures were adopted in Belgium following attacks there in 2016.

The U.K. is scheduled to leave the EU on Jan. 31, but it would still be subject to EU regulations until the end of the year while it transitions out of the political and economic union.

Sánchez-Bordona wrote in his opinion that EU data privacy rules do not interfere with security and intelligence services' ability to act to protect public safety, despite fears expressed by governments.

The Court of Justice has resisted arguments made by the U.K. and others in the past. In 2014, it invalidated the European Union Data Retention Directive, which required companies to maintain personal data in case it was needed by security authorities. The judges found it didn't offer sufficient privacy protections for users.

And in a 2016 ruling, the court held that indiscriminate location data collection is also illegal in the European Union.

A final ruling in all four cases is expected later this year.

|

Read More:

Privacy Concerns Continue to Get Increased Attention in UK