Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Privacy

EU Court Rules Against German Data Collection Law

A German law requiring telecoms companies to retain customer data is a breach of EU legislation, a European court ruled Tuesday, prompting the justice minister to vow an overhaul of the rules. 

A German law requiring telecoms companies to retain customer data is a breach of EU legislation, a European court ruled Tuesday, prompting the justice minister to vow an overhaul of the rules. 

Firms Telekom Deutschland and SpaceNet took action in the German courts challenging the law that obliged telecoms companies to retain customers’ traffic and location data for several weeks. 

The case headed to the European Court of Justice (ECJ) in Luxembourg, which ruled against the German legislation.

“EU law precludes the general and indiscriminate retention of traffic and location data,” the court said in a statement, confirming its previous judgements on the issue.

The Federal Administrative Court, one of Germany’s top courts, had argued there was a limited possibility of conclusions being drawn about people’s private lives from the data, and sufficient safeguards were in place. 

But the ECJ said the German legislation — which required traffic data to be retained for 10 weeks, and location for four — applies to a “very broad set” of information. 

It “may allow very precise conclusions to be drawn concerning the private lives of the persons whose data are retained… and, in particular, enable a profile of those persons to be established.”

The stated aim of the law was to prosecute serious criminal offences or prevent specific risks to national security, but the court said that such measures were not permitted on a “preventative basis”.

Advertisement. Scroll to continue reading.

However, it said that in cases where an EU state faces a “serious threat to national security” that is “genuine and present”, telecoms providers can be ordered to retain data. 

Such an instruction must be subject to review and can only be in place for a period deemed necessary. 

Following the announcement, Justice Minister Marco Buschmann hailed a “good day for civil rights”.

“We will now, swiftly and definitively, remove data retention without cause from the law,” the minister wrote on Twitter.

Data privacy is a sensitive issue in Germany, and its courts have in the past issued rulings aiming to limit security services access to people’s data.

Buschmann is from the liberal FDP party, which has made data protection a key plank of its policies.

Written By

AFP 2023

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Artificial Intelligence

Two of humanity’s greatest drivers, greed and curiosity, will push AI development forward. Our only hope is that we can control it.

Cybersecurity Funding

Los Gatos, Calif-based data protection and privacy firm Titaniam has raised $6 million seed funding from Refinery Ventures, with participation from Fusion Fund, Shasta...

Privacy

Many in the United States see TikTok, the highly popular video-sharing app owned by Beijing-based ByteDance, as a threat to national security.The following is...

Privacy

Employees of Chinese tech giant ByteDance improperly accessed data from social media platform TikTok to track journalists in a bid to identify the source...

Application Security

Open banking can be described as a perfect storm for cybersecurity. At one end, small startups with financial acumen but little or no security...

Government

The proposed UK Online Safety Bill is the enactment of two long held government desires: the removal of harmful internet content, and visibility into...

Mobile & Wireless

As smartphone manufacturers are improving the ear speakers in their devices, it can become easier for malicious actors to leverage a particular side-channel for...