Archive-Opsec

Search

/ to open · ↑↓ to move · Enter to open

Indexes guides, archive entries, news, resources and sources. Nothing is sent to a third party.

Archive categories

Surveillance

Bulk interception of communications in the European Union

The legal instruments that permit large-scale interception of electronic communications in the European Union, and the limits the Court of Justice placed on them.

Event date 12 June 2000 Status In force Review UNCHECKED Jurisdiction European Union Council of Europe

EU law on interception has always been split across two instruments, and the split is the first thing to understand:

  1. The ePrivacy Directive (2002/58/EC) provides that the confidentiality of communications may not be interfered with without a legislative basis.
  2. Directive 2000/584/EC is that legislative basis. It sets the conditions under which member states may authorise interception.

So a lawful interception in the EU is not a matter of national practice alone. It is national practice measured against a directive that was itself adopted under the Treaty.

The conditions the Directive imposes

Article 5 of Directive 2000/584/EC is the operative provision. It requires that:

  • interception be authorised in advance by a legislative instrument;
  • the authorisation be granted only for the categories of serious crime defined by national law;
  • the authorisation be subject to the opinion of a competent supervisory body and to control by a competent national authority;
  • the authorisation be necessary and proportionate for the purpose for which it was requested.

The two-stage structure — a legislative basis for the offence category, then an individual authorisation for a specific target — is what separates a targeted interception power from a bulk one. The wording of Article 5 does not obviously require a target.

Digital Rights Ireland

In Case C-362/08, the Court of Justice held that EU law could not, as such, require a Member State to adopt legislation mandating indiscriminate interception. The judgment is why the phrase “indiscriminate interception” appears in almost every subsequent debate on the subject: it is the standard the Court applied to a directive that purported to require domestic legislation.

Whether a given national measure satisfies that standard is decided nationally and is frequently litigated, so the answers differ between member states and over time.

The 2023 recast

Directive (EU) 2023/2773 recast the 2000 framework. The material change is scope: the recast brings within the framework not only interception in transit but also data stored by a provider in one member state and accessible from another. That is the provision which raises the cross-border question directly, and its relationship with Digital Rights Ireland is actively contested.

Sources

Claim labels

FACT

Article 5 of the Telecommunications Interceptions Directive 2000/584/EC requires that interception on a national territory of the communication by means of telecommunications networks may take place only if authorised in advance by a legislative instrument.

FACT

The same Article requires authorisation to be subject to the opinion of a competent supervisory body and to control by a competent national authority.

FACT

The Directive defines categories of serious crime for which interception may be authorised, and requires that the authorisation be necessary for those categories as defined by national law.

FACT

In Case C-362/08, Digital Rights Ireland, the Court of Justice held that a legislative act of the European Union may not, as such, impose on a Member State the obligation to adopt legislation requiring indiscriminate interception of electronic communications.

FACT

The 2000/584/EC framework was recast by Directive (EU) 2023/2773, adopted in December 2023, which extended the scope of the interception framework to cover inter-provider communications, including data generated in one member state and stored in another.

SOURCE CLAIM

The Recast Directive extends interception to data in transit and data stored by providers. That is what the instrument says; whether it is consistent with the Digital Rights Ireland judgment is a contested question, not a settled finding.

Sources

Last link check: 2026-09-29. A link check confirms reachability, not that every claim has been independently reviewed.

  1. Directive 2000/584/EC on the protection of individuals with regard to the interception of communications Publications Office of the European Union regulator Accessed
  2. Digital Rights Ireland v. Minister for Communications (C-362/08) Court of Justice of the European Union court Accessed
  3. Directive (EU) 2023/2773 recasting Directive 2000/584/EC Publications Office of the European Union regulator Accessed
  4. Article 8, European Convention on Human Rights Council of Europe court Accessed

Was this entry useful?

One vote per reader per entry. No comments are accepted on this site. Votes are counted server-side; changing a vote is possible a few times, and the stored data contains no name, address or link between a reader and their choice.