# Reply to the civil society open letter in response on recent spyware abuse cases in the EU

- Type: Guidance
- Source: EDPB
- Identifier: reply-civil-society-open-letter-response-recent-spyware-abuse-en
- Date: 2026-02-16
- Original: https://www.edpb.europa.eu/documents/reports-statements-and-letters/reply-to-the-civil-society-open-letter-in-response-on_en
- Canonical: https://overview.legal/posts/53741
- Topics: Monitoring, Telecommunications, Direct Marketing, Cookies, Supervision, Personal Data, Law Enforcement, Processing, Consent, Information Provision Modalities and Communication Methods

## Summary

EDPB, Reply to the civil society open letter in response on recent spyware abuse cases in the EU

## Full text

European Data Protection Board R ue Wiertz, 60 1047 Brussels Anu Talus Chair of the European Data Protection Board Silvia Lorenzo Perez Centre for Democracy and Technology Europe (CDT Europe) sperez@cdt.org Brussels, 11 February 2026 by e - mail only Dear Ms. Silvia Lorenzo Perez, Thank you for your letter of 26 June 2025 regarding your concerns on s pyware abuse cases in the European Union (‘EU’). Please be assured that the European Data Protection Board (‘EDPB’) is also vigilant as to the effects of the u se of such spyware on civil society and fundamental rights and follows reports on the abuse of such products closely, in particular where this use is directed against NGOs or journalists. The protection of journalists and their sources is of utmost importa nce for the freedom of the press and thus for the protection of fundamental rights, the rule of law and democracy as such. The European Media Freedom Act 1 includes a general prohibition of such intrusive surveillance software in devices, materials and digital tools used by media service providers, including journalists, with narrowly defined exceptions for the investigation of certain offences listed in the European Arrest Warrant 2 or other serious crimes, and subject to strict substantive and procedural conditions. The EDPB is the independent European body, which contributes to the consistent application of data protection rules throughout the EU by issui ng guidance on data protection law and promoting cooperation between the EU data protection authorities (‘DPAs’). Under the General Data Protection Regulation (‘GDPR’), the investigation and enforcement of data protection rules in individual cases, includi ng regarding the alleged use of spyware by private entities, falls under the competence of the DPAs. In matters relating to any processing operations carried out by competent authorities for the purposes of the prevention, investigation, detection or pro secution of criminal offences or the execution of criminal penalties, including the safeguarding against and the prevention of threats to public security, the competence of the DPAs would be based on the Law Enforcement Directive (‘LED’). 3 Furthermore, 1 Regulation (EU) 2024/1083 of the European Parliament and of the Council of 11 April 2024 establishing a common framework for media services in the internal market and amending Directive 2010/13/EU (European Media Freedom Act) (hereinafter referred to as ‘European Media Freedom Act’) (OJ L , 2024/1083, 17.4.2024). 2 See Article 2(2) Council Framework Decision of 13 June 2002 on the European arrest warrant and the surrender procedures between Member States (2002/584/JHA) (OJ L 190 18.7.2002, p. 1). 3 Directive (EU) 2016/680 of the European P arliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or t he execution of criminal penalties, European Data Protection Board R ue Wiertz, 60 1047 Brussels th e ePrivacy Directive 4 also provides rules for the protection of the users’ right to privacy and confidentiality of their electronic communications, as well as the integrity of their terminal equipment. 5 In this regard, the EDPB has issued guidelines on t he applicability of Article 5(3) of the ePrivacy Directive. 6 The EDPB notes that while some data processing operations, mainly related to the deployment of such software, might fall within the scope of Union law, any processing activities relating to nati onal security fall outside of the scope of Union law. 7 Yet, it is important to stress that Member States cannot abusively invoke national security to escape from the application of EU law 8 . It should also be noted that whenever spyware is used to process personal data in the context of activities falling within the scope of the EU data protection law, both national authorities and private entities are obliged to comply with the obligations se t out therein. This includes inter alia identifying a valid legal basis for the processing of personal data, complying with the data protection principles and respecting the data subjects’ rights. The CJEU case law states that access, retention and further use of personal data by public authorities for surveillance purposes must not exceed the limits of what is strictly necessary. 9 While the EDPB’s competences are limited where the use of such spyware is related to national security aspects, the EDPB is m ainly competent insofar spyware is deployed for processing purposes falling under the scope of the GDPR and the LED. At the same time, the EDPB does not have the same competences, tasks and powers as national data protection authorities. Indeed, at nationa l level, the assessment of alleged infringements of the EU data protection framework, including regarding the use of spyware by private entities, falls first and foremost within the competence of the responsible and independent national supervisory authori ties. In addition, the principle of transparency may be of particular relevance in this regard, as it requires data subjects to be made aware of the risks, safeguards and rights in relation to the processing of their personal data in a concise, intelligi ble and easily accessible form, using clear and plain language. While in certain limited circumstances, Member States may restrict the information obligations under Articles 12 to 14 GDPR pursuant to Article 23 GDPR, such restrictions must be laid down in law, be and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, pp. 89 – 131) . 4 Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerni ng the processing of personal data and the protection of privacy in the electronic communications sector (OJ L 201, 31.7.2002, pp. 37 – 47 ). 5 In particular, Article 5(1) and 5(3) of the ePrivacy Directive provide that, as a rule, the users’ prior consent is required for the storing of information, or the gaining of access to information already stored, in their terminal equipment. 6 EDPB Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive, adopted on 7 October 2024. 7 Please note that reg arding the ePrivacy Directive, the CJEU has ruled that its Articles 1(3), 3 and 15(1), read in the light of Article 4(2)TEU , must be interpreted as meaning that national legislation enabling a State authority to require providers of electronic communicatio ns services to forward traffic data and location data to the security and intelligence agencies for the purpose of safeguarding national security falls within the scope of that Directive (CJEU, Judgment of 6 October 2020, C - 623/17, Privacy International , p aragraph 49). It should also be noted that, in any event, as regards national security considerations, Member States are still bound by the guarantees of the European Convention of Human Rights. 8 Judgment of the CJEU of 4 June 2013, ZZ v Secretary of Stat e for the Home Department, C - 300/11, ECLI:EU:C:2013:363, paragraph 38 . 9 CJEU Case C - 623/17, Privacy International, paragraph 81. European Data Protection Board R ue Wiertz, 60 1047 Brussels necessary and proportionate in a democratic society, and respect the essence of the fundamental rights concerned. 10 The EDPB will continue to pay attention to the use of such spyware for surveillance purposes including when necessary, by analysing the use of these and other similar technologies. The EDPB will also continue to support cooperation among DPAs in order to e nsure the fundamental rights of EU citizens, in particular their right to privacy and data protection. Yours sincerely Anu Talus 10 More information on this principle can be found in Article 29 Working Party’s Guidelines on transparency under Regulation 2016/679, as endorsed by the EDPB, available at: https://www.edpb.europa.eu/our - work - tools/general - guidance/endorsed - wp29 - guidelines_ en

## Cited law provisions (7)

### GDPR — gdpr-art-2-par-2-nl

Deze verordening is niet van toepassing op de verwerking van persoonsgegevens:

### GDPR — gdpr-art-5-par-1-nl

Persoonsgegevens moeten:

### GDPR — gdpr-art-4-nl

Voor de toepassing van deze verordening wordt verstaan onder:

### GDPR — gdpr-art-5-nl

Beginselen inzake verwerking van persoonsgegevens

### GDPR — gdpr-art-23-nl

Beperkingen

### GDPR — gdpr-art-29-nl

De verwerker en eenieder die onder het gezag van de verwerkingsverantwoordelijke of van de verwerker handelt en toegang heeft tot persoonsgegevens, verwerkt deze uitsluitend in opdracht van de verwerkingsverantwoordelijke, tenzij hij Unierechtelijk of lidstaatrechtelijk tot de verwerking gehouden is.

### GDPR — gdpr-art-4-par-2-nl

„verwerking”: een bewerking of een geheel van bewerkingen met betrekking tot persoonsgegevens of een geheel van persoonsgegevens, al dan niet uitgevoerd via geautomatiseerde procedés, zoals het verzamelen, vastleggen, ordenen, structureren, opslaan, bijwerken of wijzigen, opvragen, raadplegen, gebruiken, verstrekken door middel van doorzending, verspreiden of op andere wijze ter beschikking stellen, aligneren of combineren, afschermen, wissen of vernietigen van gegevens;

---
Generated by overview.legal · https://overview.legal/posts/53741 · 2026-08-22
