Communications metadata can reveal detailed information about an individual even without exposing the content of a call or message.
Traffic and location data can show who communicated with whom, when communications took place, the devices involved and, in some circumstances, where users were located.
When combined over time, those data can reveal detailed patterns concerning an individual’s movements, relationships and private life.
At the same time, historical communications data can be important to criminal investigations, national-security work and judicial proceedings.
That tension has shaped European data-retention law for more than two decades.
The EU initially attempted to harmonise national retention rules through Directive 2006/24/EC.
The Court of Justice invalidated that Directive in 2014.
Since then, the legal position has developed through a long sequence of CJEU judgments addressing:
- general and indiscriminate retention;
- targeted retention;
- national-security threats;
- serious crime;
- IP addresses;
- civil-identity data;
- access to retained data;
- and expedited preservation.
The original Privacy Minders article, published in 2022, examined this developing framework and the policy options then being considered by the European Commission.
This updated edition preserves that history and adds the significant developments that followed.
HOW THE EU DATA-RETENTION FRAMEWORK DEVELOPED
The EU’s original Data Retention Directive
Directive 2006/24/EC entered into force in 2006.
Its objective was to harmonise Member State rules requiring providers of publicly available electronic communications services and public communications networks to retain communications data for law-enforcement purposes.
The Directive concerned metadata rather than the content of communications.
It required retention of information capable of identifying matters such as:
- the source of a communication;
- its destination;
- date and time;
- duration;
- type of communication;
- communication equipment used;
- subscriber or registered-user information;
- calling and called telephone numbers;
- internet identifiers, including IP-address information;
- and location information associated with mobile communications.
The retained information could therefore allow authorities to reconstruct important aspects of communications behaviour without retaining the communications content itself.
Member States were required to ensure that covered data were retained for periods of not less than six months and not more than twenty-four months.
The data were then capable of being made available to competent national authorities in accordance with national law.
National courts were already challenging retention laws
The Data Retention Directive generated constitutional challenges before the Court of Justice ultimately invalidated it.
The original Privacy Minders article highlighted developments in several Member States.
In Romania, national legislation implementing the Directive was challenged before the Constitutional Court on grounds including privacy and confidentiality of communications.
A later Romanian implementing law was also found unconstitutional.
National courts in other Member States, including Germany and the Czech Republic, also scrutinised domestic measures implementing broad data-retention obligations.
Those cases illustrated an important feature of the debate from an early stage:
the controversy was not merely about whether communications data could assist law enforcement.
It was about whether requiring data relating to large numbers of individuals to be retained in advance could be reconciled with constitutional and fundamental-rights protections.
Digital Rights Ireland invalidated the EU Directive
On 8 April 2014, the Court of Justice declared Directive 2006/24/EC invalid in the joined Digital Rights Ireland proceedings.
The Court considered that the Directive entailed a wide-ranging and particularly serious interference with the rights to respect for private life and protection of personal data.
Although the Directive did not require communications content to be retained, the metadata could make it possible to draw detailed conclusions about individuals’ private lives.
The Court identified several problems with the framework.
In particular, the Directive did not sufficiently differentiate or limit:
- the persons whose data were retained;
- the categories of information;
- the relationship between retained data and the public-interest objective pursued;
- the applicable retention periods;
- conditions governing access by authorities;
- and safeguards against abuse or unlawful access.
The Directive applied broadly to communications data without requiring a sufficient connection between the data retained and a particular threat or serious-crime objective.
The judgment removed the harmonised EU retention framework.
It did not, however, eliminate national data-retention legislation.
After annulment, the debate moved to national law
Following the invalidation of the Directive, Member States continued to operate or adopt domestic data-retention regimes.
The legal debate therefore shifted.
Instead of asking whether Directive 2006/24/EC itself was compatible with fundamental rights, the Court increasingly had to determine how Article 15(1) of the ePrivacy Directive constrained national legislation.
The result was a fragmented landscape.
National governments pursued different approaches to:
- the scope of retained data;
- retention periods;
- public-security objectives;
- serious-crime investigations;
- safeguards;
- and access by authorities.
That fragmentation became one of the recurring policy arguments for renewed EU-level action.
Tele2 Sverige and Watson restricted general national retention
On 21 December 2016, in the joined Tele2 Sverige and Watson proceedings, the Court considered national legislation requiring communications providers to retain traffic and location data.
The Court held that Article 15(1) of the ePrivacy Directive, read in light of the Charter, precludes national legislation requiring the general and indiscriminate retention of traffic and location data as a preventive measure for the purpose of fighting crime.
The significance of the judgment was that invalidation of the 2006 Directive had not created a free space for Member States to reproduce equivalent blanket-retention regimes through domestic legislation.
National measures remained constrained by EU law.
Article 15(1) permits restrictions, but not without limits
The ePrivacy Directive establishes confidentiality protections for electronic communications and related traffic data.
As a general rule, traffic data that are no longer needed for the transmission of a communication must be erased or made anonymous, subject to the Directive’s specific exceptions.
Article 15(1) permits Member States to adopt legislative measures restricting certain ePrivacy rights where the measures are necessary, appropriate and proportionate in a democratic society for specified public-interest objectives.
Those objectives include:
- national security;
- defence;
- public security;
- and prevention, investigation, detection and prosecution of criminal offences.
However, Article 15(1) is not a general authorisation for unlimited communications-data retention.
The CJEU case law has progressively developed different rules depending on:
- the public-interest objective;
- the category of data;
- the breadth of the retention measure;
- duration;
- targeting;
- access safeguards;
- and the seriousness of the interference with fundamental rights.
The 2020 judgments introduced a more differentiated framework
In October 2020, the Court delivered important judgments in Privacy International and the joined La Quadrature du Net proceedings.
The Court maintained the fundamental prohibition on general and indiscriminate traffic and location data retention for ordinary crime-control purposes.
At the same time, it recognised that different categories of retention could be treated differently.
In particular, the case law recognised that where a Member State faces a serious threat to national security that is genuine and present or foreseeable, general and indiscriminate retention of traffic and location data may be ordered for a limited period where strict safeguards and review requirements are satisfied.
For the purposes of combating serious crime or preventing serious threats to public security, the Court also recognised possibilities including:
- targeted retention of traffic and location data;
- general retention of IP addresses under specified conditions;
- general retention of civil-identity information;
- and expedited preservation of relevant data.
This distinction between different data categories and different public-interest objectives became central to the later case law.
Cyprus and the 2021 Supreme Court decision
Cyprus provides an important national example of how the CJEU case law affected domestic retention legislation.
Law 183(I)/2007 had introduced data-retention obligations following the former EU Data Retention Directive.
The regime required specified telecommunications data to be retained for a defined period and permitted access by competent authorities under the applicable national procedure.
In October 2021, the plenary of the Supreme Court of Cyprus considered the compatibility of the challenged general-retention provisions with the ePrivacy Directive and the developing CJEU case law.
The Court concluded, by majority, that the general and indiscriminate retention framework challenged before it was incompatible with the applicable EU-law requirements.
The Cyprus regime was therefore directly affected by the Court of Justice’s insistence that broad traffic and location data retention cannot be justified merely by general crime-control objectives.
Cyprus Supreme Court decision →
HISTORICAL POLICY CONTEXT · 2021 TO 2022
The following options formed part of the EU policy discussion at the time of the original article. They were exploratory approaches, not adopted EU rules.
What the Commission was considering when the original article was written
One of the most valuable parts of the original Privacy Minders article was its discussion of the European policy debate taking place before publication.
By 2021, several Member States were again calling for a more harmonised European approach to data retention.
A Commission non-paper discussed a number of possible policy directions.
The original article identified three broad institutional approaches:
- no new EU initiative;
- non-binding EU guidance; and
- a new EU legislative initiative.
Those alternatives reflected the central policy dilemma.
Leaving the matter entirely to national law risked continued fragmentation.
Non-binding guidance could encourage greater consistency without creating a new harmonised obligation.
A legislative initiative could create greater harmonisation, but any new EU framework would have to comply with the restrictions developed by the Court of Justice.
Option 1: leave the framework primarily to national law
Under the “no EU initiative” approach discussed at the time, Member States would remain responsible for designing their domestic data-retention regimes within the boundaries established by the Charter and CJEU case law.
The Commission could continue monitoring national developments and supporting Member States without introducing a new regulatory or non-regulatory instrument.
The advantage of that model was flexibility for national legal systems.
The disadvantage was continued divergence across the Union in:
- covered services;
- categories of retained data;
- retention periods;
- access safeguards;
- and enforcement procedures.
Option 2: EU guidance without new legislation
A second approach contemplated a non-regulatory EU initiative.
Under that model, the Commission could issue recommendations, guidance or other non-binding material intended to help Member States align national regimes with the developing CJEU jurisprudence.
The objective would be greater consistency without recreating a harmonised mandatory retention regime equivalent to the invalidated 2006 Directive.
Such an approach could potentially assist national legislators with concepts such as:
- targeting criteria;
- data categories;
- serious-crime thresholds;
- safeguards;
- and access conditions.
Its principal limitation would be the absence of binding harmonisation.
Option 3: a new EU legislative framework
The third broad possibility was renewed EU legislation.
The Commission material discussed several possible mechanisms capable of forming part of a future framework.
The original Privacy Minders article examined those possibilities in some detail.
They included:
- retention associated with national-security threats;
- targeted retention based on categories of persons;
- targeted retention based on geographic criteria;
- expedited preservation or “quick freeze”;
- retention of source IP addresses;
- and retention of civil-identity data.
These were not equivalent mechanisms.
Each involved different levels of interference with fundamental rights and different practical uses for authorities.
Targeted retention based on persons or geographic criteria
One policy option concerned retention targeted through objective criteria rather than applying indiscriminately to every user.
Potential criteria discussed in the policy debate included categories of persons or geographic areas connected with heightened risks of serious criminal activity.
This approach raised its own legal and policy questions.
Targeting needs objective and non-discriminatory criteria.
It can also create risks of:
- over-inclusion;
- discriminatory impact;
- persistent monitoring of particular communities;
- or retention measures extending beyond what is strictly necessary.
The CJEU case law therefore requires targeted retention to remain tied to objective criteria and proportionality.
Expedited preservation or “quick freeze”
Another option discussed in the original article was expedited preservation, commonly described as “quick freeze”.
This model differs fundamentally from general retention.
Rather than requiring providers to store broad categories of all users’ communications data in advance, a competent authority can require identified existing data to be preserved because those data may become relevant to a specific investigation or proceeding.
The 2020 CJEU case law had already recognised expedited retention as one of the mechanisms potentially available under strict conditions.
This distinction became increasingly important in later EU legislation and case law.
IP-address retention emerged as a distinct category
The Commission’s policy discussion also considered retention of source IP addresses.
The CJEU had already recognised that IP-address retention may raise a different level of interference from retention of a complete set of traffic and location data.
The distinction is important because IP addresses can be essential to identifying the user associated with an online activity.
At the same time, the legal analysis depends on the conditions governing:
- retention;
- technical separation;
- access;
- linking with other data;
- and the conclusions capable of being drawn about private life.
The Court developed this issue significantly further in 2024.
Civil-identity information was treated differently again
Another option concerned general retention of information relating to users’ civil identity.
This category can include identifying subscriber information without necessarily including a detailed record of communications behaviour or movements.
The Court has generally treated civil-identity information as presenting a lower level of interference than comprehensive traffic and location data.
The distinction matters because EU law does not subject every category of communications-related information to precisely the same retention threshold.
The debate was already expanding beyond traditional telecom providers
The original 2022 article also identified an important shift in the scope of the policy debate.
Traditional data-retention legislation had largely focused on telecommunications providers.
The Commission’s policy discussion increasingly considered the role of online and over-the-top communications services.
Those services can include platforms and applications providing communications functionality over the internet rather than through traditional telecommunications infrastructure.
That shift reflected a broader technological reality.
Modern communications increasingly take place through:
- messaging applications;
- social platforms;
- internet-based calling;
- cloud services;
- and other digital intermediaries.
Any future European framework therefore raises questions not only about what data may be retained, but also which categories of service provider should fall within scope.
“Serious crime” and data categories also require definition
The original article correctly identified another recurring difficulty.
Retention frameworks frequently depend on concepts such as:
“serious crime”
and:
“civil identity data”.
The legal significance of those concepts means they cannot remain completely open-ended.
Different Member States may otherwise adopt materially different thresholds.
A harmonised framework would need sufficient clarity concerning:
- the offences capable of justifying retention or access;
- categories of data;
- applicable safeguards;
- and the level of interference associated with each measure.
This problem remains relevant in the current EU policy debate.
WHAT CHANGED AFTER THE ORIGINAL 2022 ARTICLE?
The original Privacy Minders article captured the EU debate at a point when the Commission was still considering whether and how to re-enter the data-retention field. Subsequent CJEU judgments clarified several of the options that had been discussed, while the Commission later reopened the possibility of EU-level action more formally.
The Court reinforced the prohibition on blanket crime-control retention in 2022
On 5 April 2022, the Grand Chamber delivered its judgment in Case C-140/20, Commissioner of An Garda Síochána and Others.
The Court again confirmed that the objective of combating serious crime does not, by itself, justify general and indiscriminate retention of traffic and location data.
The judgment also reiterated the alternative measures available under the CJEU framework, including:
- targeted retention;
- retention of IP addresses subject to the applicable conditions;
- retention of civil-identity information;
- and expedited preservation of relevant data.
The judgment therefore reinforced the distinction between:
the importance of the law-enforcement objective,
and
the breadth of the retention measure used to pursue it.
Short retention periods do not cure indiscriminate retention
On 20 September 2022, the Grand Chamber delivered judgment in the joined SpaceNet and Telekom Deutschland cases.
The German regime required certain traffic data to be retained for ten weeks and location data for four weeks.
Those periods were significantly shorter than many earlier retention regimes.
The Court nevertheless concluded that the short duration did not make a general and indiscriminate retention requirement compatible with EU law.
The retained data remained capable, when combined, of allowing precise conclusions to be drawn about users’ private lives.
The judgment is particularly important because it corrects a possible misunderstanding in the original 2022 article:
duration matters, but short duration does not by itself make blanket traffic and location data retention lawful.
Market-abuse investigations did not justify a different rule
On the same day, the Court delivered judgment in the joined VD and SR cases.
Those cases concerned traffic-data retention used in connection with investigations of market abuse, including insider dealing.
The Court held that the objective of protecting the integrity of financial markets did not justify legislative measures requiring general and indiscriminate retention of traffic data.
The significance of the decision extends beyond market-abuse enforcement.
It confirms that a substantial public-interest objective does not automatically displace the requirements of Article 15(1) ePrivacy and the Charter.
La Quadrature du Net II refined the position on IP addresses
A major development followed on 30 April 2024 in Case C-470/21, commonly referred to as La Quadrature du Net II.
The case concerned a French system used to identify individuals suspected of online copyright infringement.
The Court held that Member States may require internet access providers to retain IP addresses in a general and indiscriminate manner for the purposes of combating criminal offences in general, provided that the retention architecture prevents those data from being used to draw precise conclusions about the private life of the person concerned.
A central requirement is what the Court described as genuinely watertight separation between categories of retained data.
In particular, technical arrangements may need to prevent IP-address data from being combined with civil-identity or other data in a way capable of constructing a detailed picture of private life.
The judgment therefore made technical architecture part of the proportionality analysis.
It also clarified that access to civil-identity data associated with an IP address may, under the relevant conditions, be permitted for the purpose of identifying the person suspected of involvement in an offence.
Retention and access must be analysed separately
The CJEU case law distinguishes between two questions:
- whether data may lawfully be retained; and
- under what conditions an authority may later access those data.
A lawful retention measure does not automatically make every access request lawful.
Depending on the seriousness of the interference, access may require safeguards such as:
- a defined investigative purpose;
- proportionality;
- prior judicial review;
- review by an independent administrative authority;
- restrictions on data use;
- and appropriate security measures.
The exact safeguards depend on the data and the circumstances.
Retention and access should therefore not be collapsed into a single legal question.
Preservation now also forms part of the EU e-Evidence framework
The distinction between retention and preservation became even more practically significant through the EU e-Evidence package.
Regulation (EU) 2023/1543 on European Production Orders and European Preservation Orders became applicable on 18 August 2026.
A European Preservation Order allows a competent judicial authority to require specified existing electronic evidence to be preserved pending a subsequent production process.
This should be distinguished from a blanket obligation to retain categories of data relating to all users in advance.
Preservation is:
- case-specific;
- directed at identified data;
- linked to criminal proceedings;
- and designed to prevent relevant existing evidence from being deleted before it can lawfully be obtained.
The transposition deadline for the related Directive concerning designated establishments and legal representatives for gathering electronic evidence was 18 February 2026.
This framework is therefore relevant to the practical distinction that the original article already identified when discussing “quick freeze”.
There is still no harmonised EU-wide data-retention framework
Despite the extensive case law, the EU still does not have a harmonised legislative framework replacing the invalidated 2006 Data Retention Directive.
Member States continue to operate divergent national regimes.
Those differences can concern:
- covered providers;
- categories of retained information;
- retention periods;
- serious-crime thresholds;
- access conditions;
- procedural safeguards;
- and institutional oversight.
Some Member States do not maintain general retention rules of this kind.
The resulting fragmentation affects both:
- law-enforcement and judicial cooperation; and
- service providers operating across several Member States.
The Commission has reopened the possibility of EU-level action
The policy debate captured in the original 2022 article has therefore returned in a more formal form.
The Commission’s High-Level Group on Access to Data recommended consideration of an EU framework governing retention of data for law-enforcement purposes, with appropriate safeguards.
The issue was subsequently incorporated into the Commission’s ProtectEU internal-security work and Roadmap for lawful and effective access to data.
In May 2025, the Commission launched an impact-assessment process concerning retention of data by service providers for criminal proceedings.
The Commission states that the assessment is examining:
- the scale of problems created by divergent national rules;
- possible regulatory measures;
- possible non-regulatory measures;
- security impacts;
- effects on the market for communications services;
- and fundamental-rights implications.
As of 29 September 2026, the Commission continues to describe this work as an impact-assessment process.
European Commission current data-retention policy →
A September 2026 Advocate General Opinion may affect the next stage
On 3 September 2026, Advocate General Maciej Szpunar delivered his Opinion in Case C-661/24, Académie Fiscale and Others.
The case concerns Belgian legislation governing retention of identification, traffic and location data in the electronic-communications sector.
The Opinion examines the significance of the Court’s 2024 approach in La Quadrature du Net II.
The Advocate General suggests that the concept of technical separation may potentially have relevance beyond the specific IP-address context considered in that judgment.
Under the approach proposed in the Opinion, technical measures ensuring genuinely watertight separation of data categories could affect the assessment of whether a retention regime allows precise conclusions to be drawn about private life.
However, the Advocate General considered that the Belgian regime before the Court did not satisfy the necessary requirements.
The Opinion is not a judgment of the Court, and the Court is not bound to follow it.
Académie Fiscale Advocate General Opinion →
WHAT DOES THE FRAMEWORK LOOK LIKE TODAY?
What remains generally prohibited?
The CJEU case law continues to reject general and indiscriminate retention of complete traffic and location datasets for general crime-control objectives.
The fact that:
- the offence is serious;
- the public-interest objective is important;
- or the retention period is relatively short
does not, by itself, justify blanket retention.
A retention regime must be analysed in light of the type of data, purpose and interference with fundamental rights.
What forms of retention may be permitted?
01 · NATIONAL SECURITY
Where a Member State faces a serious threat to national security that is genuine and present or foreseeable, general and indiscriminate traffic and location data retention may be permitted for a limited period subject to strict conditions and review.
02 · TARGETED TRAFFIC / LOCATION RETENTION
For combating serious crime or preventing serious threats to public security, targeted retention may be possible on the basis of objective and non-discriminatory criteria.
03 · IP ADDRESSES
EU law permits broader IP-address retention than complete traffic and location data in specified circumstances.
La Quadrature du Net II further emphasises technical separation and limits on the ability to infer private-life information.
04 · CIVIL IDENTITY
Retention of subscriber and civil-identity information may be subject to a less restrictive test because those data do not necessarily reveal the same detailed behavioural picture as traffic and location data.
05 · EXPEDITED PRESERVATION
Specific existing data may be preserved under appropriate conditions where relevant to an investigation or proceeding.
Each category is subject to its own legal conditions. The permissibility of one form of retention should not be generalised to another.
Four questions service providers should separate
01 · BUSINESS RETENTION
What data does the provider retain for its own legitimate business purposes?
02 · STATUTORY RETENTION
Does national legislation require the provider to keep additional information for law-enforcement or security purposes?
03 · PRESERVATION
Has a competent authority required specified existing information to be frozen or preserved?
04 · ACCESS / PRODUCTION
What legal mechanism permits the authority to obtain the retained or preserved data?
These four questions can involve different legal bases, different deadlines and different safeguards. Retention, preservation and disclosure should therefore not be treated as interchangeable concepts.
A practical data-retention review
01 · JURISDICTION
Identify which Member State retention rules potentially apply to the organisation and its services.
02 · SERVICE SCOPE
Determine which telecommunications, communications or digital services fall within each relevant national regime.
03 · DATA CATEGORIES
Map subscriber information, civil-identity information, IP addresses, traffic data, location data and other communications metadata separately.
04 · PURPOSE AND LEGAL BASIS
Distinguish data retained for ordinary business purposes from data kept because of a statutory retention obligation or preservation order.
05 · RETENTION PERIOD
Record the applicable period for each category and legal basis.
06 · ACCESS CONDITIONS
Identify which authorities can obtain the data, for which purposes and under what judicial or independent-review requirements.
07 · TECHNICAL ARCHITECTURE
Assess whether segregation, access controls or watertight separation of different data categories is legally relevant.
08 · CROSS-BORDER REQUESTS
Determine whether the EU e-Evidence framework, mutual legal assistance or another judicial-cooperation mechanism applies.
09 · CHANGE MANAGEMENT
Monitor CJEU judgments, national legislation and the Commission’s EU-level policy process.
From blanket retention to a differentiated framework
The EU data-retention debate has changed significantly since Directive 2006/24/EC.
The original model relied on broad harmonised obligations requiring communications providers to retain large categories of metadata in advance.
Digital Rights Ireland invalidated that framework.
The judgments that followed did not establish a simple rule that communications data can never be retained.
Instead, the Court developed a differentiated framework.
That framework now distinguishes between:
- blanket and targeted retention;
- ordinary crime-control objectives and serious threats to national security;
- traffic and location data;
- IP addresses;
- civil-identity information;
- retention and access;
- and retention and preservation.
The original Privacy Minders article also documented a policy debate that remains highly relevant today.
In 2021 and early 2022, the question was whether the EU should return to this field through no action, guidance or new legislation.
By 2025 and 2026, the Commission had formally reopened that question through an impact-assessment process.
The future EU framework is therefore still developing.
For organisations handling communications data, the practical task is not simply to ask:
“How long may this data be kept?”
It is to identify:
- what data is involved;
- why it is retained;
- whether the measure is general or targeted;
- what can be inferred from the data;
- what safeguards exist;
- whether different datasets can be combined;
- and what legal mechanism ultimately permits access.
That is the framework through which EU data-retention compliance must now be understood.

