EU Advocate General Wants Belgium's Data Retention Law Struck Down — And the EU's Top Court Should Listen

Europe's most senior privacy adviser has recommended that the bloc's highest court strike down Belgium's data retention law, designed to fight cybercrime. The case could determine whether the EU's privacy stance survives the new surveillance era.

By THEYDIDNTASK
On 4 September 2026, Advocate General Maciej Szpunar — the most senior privacy adviser at Europe's highest court — recommended that the Court of Justice of the European Union (CJEU) strike down a Belgian data retention law that was largely intended to fight cybercrime. In his opinion, the law violates fundamental privacy rights under the EU Charter. If the Court follows Szpunar's recommendation when it rules — typically within twelve to eighteen months — it would be the latest in a fifteen-year line of decisions narrowing what national governments can require telecoms and online services to retain about their users. The question now is whether the CJEU draws the line harder than ever before, or folds to the rising political pressure for "going dark" exceptions. What Belgium's law actually required The Belgian data retention law — adopted in 2016 and amended several times since — required telecom operators and certain online services to retain traffic and location data on every customer for between six and twelve months. The data was held for the stated purpose of fighting cybercrime: serious online fraud, child exploitation material, and similar investigations. On its face, that sounds reasonable. Nobody defends unlimited criminal encryption. The problem is scope and access: under the Belgian law, retained data was available not only to investigators pursuing serious crime, but also to a wider set of public authorities, sometimes on relatively minor procedural grounds. The data covered everyone — including people never suspected of any offence — and was retained in centralised, queryable form that made mass access practical rather than theoretical. This is the same structural problem the CJEU has now struck down in roughly a dozen cases over the past decade, most prominently the 2014 Digital Rights Ireland decision and the 2020 Privacy International ruling. The pattern is well-established: general and indiscriminate retention of traffic and location data of an entire population is incompatible with the Charter. Why Szpunar's opinion is sharper than the previous line of cases Szpunar is not a fringe voice. He is the AG whose opinions the CJEU follows in the overwhelming majority of data protection cases. His reasoning in the Belgian matter is sharper than his earlier positions in several respects: He frames general retention as presumptively unlawful, not merely as needing strict justification. Previous CJEU decisions left room for member states to argue necessity; Szpunar's framing leaves that room narrower than ever. He questions the cybersecurity rationale itself, noting that a regime designed to fight cybercrime by retaining everyone's data is both over-inclusive and under-targeted — it captures innocent people in volume while not necessarily giving investigators better tools than narrower, evidence-led powers would. He signals that the Court may need to revisit its 2022 Quadrature du Net decision, which preserved limited retention in narrow cases. If the Court follows Szpunar, that door closes further. The practical consequence, if the Court follows the opinion, is that Belgium — and indirectly any member state with a similar law — must either narrow its retention regime to genuinely serious, time-limited cases with independent oversight, or stop relying on blanket retention entirely. The political backdrop matters The opinion lands in a notably different political environment from prior data retention cases. Two trends are working in tension: Law enforcement pressure for "going dark" exceptions. The EU has been debating the ChatControl proposal — a regulation that would require messaging platforms to scan private messages for child sexual abuse material. Multiple member states have pushed for client-side scanning mandates. The German government in particular has championed a version that would force platforms to scan content before encryption. The CJEU's privacy line and ChatControl sit in direct conflict. A broader privacy backlash. The EU's Digital Services Act, the Digital Markets Act, the AI Act, and the GDPR enforcement apparatus are creating a regulatory environment where member states face increasing pressure to align national law with Charter rights. Belgium's data retention law is a holdover from an earlier era of cybersecurity policy. Szpunar's opinion is, in effect, a reminder that the Charter still constrains what national security and law enforcement arguments can justify — even when those arguments are politically popular. What changes if the Court follows the opinion If the CJEU rules as Szpunar recommends, the consequences will be: Belgium must amend its retention law or stop relying on it. Other member states with similar regimes — France, the UK (post-Brexit but with EU-style rules), Hungary, and several eastern member states — face pressure to revise their laws too. Cross-border investigations face disruption. Law enforcement authorities that have built workflows around bulk-retention access will need to switch to targeted preservation orders, which are slower and require per-case authorisation. The ChatControl precedent shifts. A clear CJEU ruling against general retention makes a client-side scanning mandate much harder to defend on Charter grounds, because scanning is an even more intrusive form of general surveillance. The trade-off is real. Targeted, evidence-led investigation is slower and harder than bulk-retention-driven fishing expeditions. There is a credible argument that some forms of short-duration, narrowly-scoped retention can be justified for specific serious crimes. The question the Court will decide is whether "some" can mean "general", or whether it can only mean "limited, justified, and oversight-bounded". What this does not fix Honest limits worth noting: Member states retain significant room to demand preservation orders, real-time interception, and other targeted investigative tools. A ruling against general retention does not rule out narrower, more accountable tools. ChatControl is a separate legal track under a different proposal. Even a strong CJEU ruling here will not automatically block scanning mandates; it will raise the legal cost and likely shift the debate. National security carve-outs remain politically difficult to challenge. The Charter binds EU institutions and member states when implementing EU law. National security itself is largely outside the Charter's scope, and several member states have used that gap to claim that broad retention for "national security" purposes is different. The Court will rule on the specific Belgian facts. The question is whether its reasoning reaches further, into the broader class of retention and scanning regimes. Szpunar's opinion suggests it will. For anyone designing infrastructure that processes EU users' communications, this is the second warning in two years that "general" retention and "general" scanning are on borrowed time.