Data retention

- Data retention: the indiscriminate storage of personal telecommunications data for security purposes.
- Declared unlawful multiple times by the Federal Constitutional Court and the European Court of Justice.
- Stores telephone and internet data; access is generally only permitted with a judicial warrant.
- The 2006 EU directive obligated member states to implement data retention, a policy that remains legally contentious.
- Criticized for surveillance risks, questionable effectiveness, and potential violations of fundamental rights.
What is the purpose of data retention?
When it comes to mandatory data retention, various interests collide. On one hand, there is the freedom of communication in broader media (the right to informational self-determination, telecommunications secrecy, etc.). These are no longer fully guaranteed if location data and telephone numbers for calls, as well as IP addresses for internet traffic, are stored for at least a certain period without a specific reason. On the other hand, the state also has a duty to look after general security in the interest of its citizens. Data retention allows for the creation of personality profiles without even needing to access the content of communications. Proponents of indiscriminate data retention see it as a viable way to prevent crimes and to apprehend perpetrators more quickly after a crime has been committed. Furthermore, aspects of telecommunications are already managed at the state level, for example, by the Federal Network Agency. Within the EU, there has been a consensus since 2006 that some form of data retention should exist. After all, all members were obligated at the time via directive authority to create corresponding national regulations, though this is repeatedly challenged legally.
What is stored? Who is allowed to access it and when?
Since the topic of data retention remains unresolved, there are no definitive answers to these questions yet. Fundamentally, it involves the collection of all telecommunications data, i.e., communication via telephone and the internet. Regarding the question of who may access it and when, a distinction between connection data and subscriber data will likely play a role. Connection data is more sensitive because it contains information about who we communicate with, when, and where. Access to this data will likely only be possible with a court order. Subscriber data, on the other hand, is less protected, even though it already reveals quite a bit, such as which person a specific IP address or phone number belongs to. The majority of requests concern this type of data, which is currently passed on to authorities fully automatically. Estimates suggest that in 2018 alone, the matching of phone numbers to owners was requested by German authorities approximately 14 million times. When and by whom actual communication content may be accessed also remains unclear.
Problematic legal situation regarding data retention
In 2006, all member states were obligated by an EU directive to draft national regulations for mandatory data retention. The German legislature failed with its first implementation of EU Directive 2006/24/EC in 2008. Due to mass lawsuits, the Federal Constitutional Court declared the national law unconstitutional in 2010 and ordered all German telecommunications providers to delete the data collected up to that point. Specifically, it was criticized that the implementation of data retention lacked appropriate measures regarding data security and that government agencies could access personal data too easily. This was seen as a violation of Article 10(1) of the Basic Law (GG).
The European Court of Justice (ECJ) followed suit in 2014 and declared Directive 2006/24/EC invalid, as it was incompatible with the Charter of Fundamental Rights of the European Union. In the meantime, the storage of personal data at the national level for 7 days for internal purposes by internet providers had been permitted by a decision of the Federal Court of Justice (BGH).
On December 18, 2015, a new German law entered into force and was scheduled to be implemented by July 1, 2017. These regulations were also attacked from many sides from the beginning, and a multitude of constitutional complaints have been filed with the Federal Constitutional Court.
On December 31, 2016, the ECJ found, surprisingly for some parties, that indiscriminate data retention is illegal per se. Consequently, the Higher Administrative Court of North Rhine-Westphalia declared on June 23, 2017, that the new law on data retention was incompatible with EU law and suspended data retention for the time being.
Even with the entry into force of the GDPR, there is no final decision on the legality of or obligation for data retention. Due to the principle of purpose limitation under Article 5(1)(b) of the GDPR, which states that personal data must be collected for specified, explicit, and legitimate purposes, one could assume a ban on data retention, as a clear, specified purpose is questionable in the case of blanket storage. On the other hand, there is no explicit prohibition anchored in the GDPR.
On September 25, 2019, the Federal Administrative Court ruled that the ECJ is responsible for the final interpretation of the ePrivacy Directive. Until a judgment is reached, data retention remains suspended in Germany.
Criticism of data retention
Data retention has been subject to constant criticism from many different sides for years. A frequently cited point of criticism is the questionable benefit of mandatory data retention. Professional criminals in particular can bypass surveillance, and no significant reduction in crime has been observed in countries where data retention takes place. Furthermore, the broad surveillance of all citizens (regardless of any suspicion of a crime) and the danger of developing into a total surveillance state are viewed critically. This is likely the main reason for the numerous protests and petitions that have taken place against data retention in recent years. The intrusion into the private lives of all citizens and the effort that mandatory data retention entails are generally perceived as disproportionate. Telecommunications companies also oppose data retention, as they would be responsible for its implementation. The costs for the necessary infrastructure and maintenance would not be offset by any profits (the federal government does not provide for subsidies), which is why telecommunications services would pass the losses on to their customers. Thus, we would ultimately be financing our own surveillance. Data retention could also jeopardize the right to informational self-determination and freedom of expression on the internet. Support services, such as addiction and suicide hotlines or online psychological counseling, also see their work at risk, as user anonymity plays a major role here.
The criticism will likely last as long as the discussion about data retention itself.
Is data retention at an end?
For the relevant service providers, the topic of data retention has so far been associated with considerable legal uncertainty. In view of the ECJ's decision, it is questionable whether mandatory data retention without a specific reason could be implemented in a legally valid manner at all.
It remains to be seen how the Federal Constitutional Court and the ECJ will ultimately assess the situation. However, there is much to suggest that the storage of personal data without a specific reason is generally and without exception incompatible with current European law. The interpretation of the vague legal term "specific reason" is likely to cause the lawyers involved many headaches.
The topic of data retention repeatedly shows how great the conflict of interest between data protection and the investigative and law enforcement interests of state agencies actually is. At present, it is hardly discernible how this conflict could be appropriately resolved for both sides.
Legal uncertainty also persists to the extent that the corresponding decision of the BGH on the possibility of 7-day storage for internal purposes dated July 3, 2014 (III ZR 391/13) is likely to remain in effect, but is also difficult to reconcile with EU law under a narrow interpretation of the corresponding ECJ view.
It is urgently necessary that a final legal clarification on the subject of data retention takes place, as the current state of affairs is not satisfactory for any party.
Do you have further questions on this topic? Our experts will be happy to advise you free of charge.













