Collecting phone data is only legal in a few cases ECJ says
European Court of Justice said retaining bulk data only valid in the most serious circumstances


The European Court of Justice has ruled that bulk phone and email data can only be retained if it relates to serious crimes and should not be collected otherwise.
The findings come after ex-backbench Tory David Davis, and Tom Watson, Labour's deputy leader brought a claim to the court, saying it was unjust for the GCHQ, or any other organisation claiming to need access for legal issues to collect such sensitive information in bulk.
However, Davis withdrew his complaint after he was appointed to the cabinet, evidently not wanting to upset his peers.
"Solely the fight against serious crime is an objective in the general interest that is capable of justifying a general obligation to retain data, whereas combating ordinary offences and the smooth conduct of proceedings other than criminal proceedings are not," The ECJ's advocate general Henrik Saugmandsgaard said.
This opinion brings the European Union's stance closer to the regulations set out in the UK's Investigatory Powers Bill, which could come into question when the UK exits the EU.
"This legal opinion shows the prime minister was wrong to pass legislation when she was home secretary that allows the state to access huge amounts of personal data without evidence of criminality or wrongdoing," Tom Watson, Labour's deputy leader said.
"Labour has already secured important concessions, but I hope the government she leads will now revisit it. The opinion makes it clear that information including browsing history and phone data should not be made available to the security services and other state bodies without independent authorisation. The security services have an important job to do, but judicial oversight is vital if we are to maintain the right balance between civil liberties and state power."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The European Court of Justice will come to a final decision about a course of action in the next few months.

Clare is the founder of Blue Cactus Digital, a digital marketing company that helps ethical and sustainability-focused businesses grow their customer base.
Prior to becoming a marketer, Clare was a journalist, working at a range of mobile device-focused outlets including Know Your Mobile before moving into freelance life.
As a freelance writer, she drew on her expertise in mobility to write features and guides for ITPro, as well as regularly writing news stories on a wide range of topics.
-
Forcing Apple to allow alternative app stores might cause major security risks
Analysis Apple will be forced to allow third-party marketplaces on its devices, but some experts have raised serious security concerns
By Solomon Klappholz
-
Why bolstering your security capabilities is critical ahead of NIS2
NIS2 regulations will bolster cyber resilience in key industries as well as improving multi-agency responses to data breaches
By ITPro
-
New EU vulnerability disclosure rules deemed an "unnecessary risk"
News The vulnerability disclosure rules in the Cyber Resilience Act could also cause a “chilling effect” on security researchers
By Ross Kelly
-
Are you ready for NIS2?
WEBINAR Find out what you should be doing to prepare for the EU’s latest data protection regulation and UK equivalent with our free webinar
By ITPro
-
EU regulators are digging their heels in despite big tech’s Data Act pushback
Analysis EU regulators are no strangers to big tech regulatory push back, so why do companies still persist?
By Ross Kelly
-
Microsoft's EU Data Boundary will begin staggered rollout in January 2023
News Public sector and commercial customers will be the first to benefit when the rollout begins on 1 January across all of Microsoft's core services
By Ross Kelly
-
EU watchdog fights against rules permitting Europol's ‘unlawful’ data practices
News The pushback follows allegations that Europol was allowed to write its own rules when it came to handling sensitive data
By Connor Jones
-
EU to introduce strict IoT security regulation
News Manufacturers will be required to assess all risks, and notify the EU of issues within 24hrs
By Rory Bathgate