Wannes Bellaert, PhD researcher and academic assistant, Ghent University
Photo
credit: OSeveno,
via Wikimedia Commons
Once again a new Europol legal framework
On the 24th of June 2026, the
European Commission proposed a new legal framework for Europol (i.e. the
European Union Agency for Law Enforcement Cooperation). As reflected in the preparatory documents and the proposal itself, the
intentions are clear: extending Europol’s competencies, while refraining from
remedying existing shortcomings in Europol’s accountability framework.
Back then, when candidate Commission President
Von Der Leyen suggested making Europol a “truly operational police agency”, uncertainty reigned over what she
intended. Both the preparatory documents and the proposal demonstrate that a
European FBI is still far off. Nonetheless, the European Commission envisages
an expansion and codification of several elements. As regards the expansion,
the European Commission envisages expanding the scope of cooperation with
private parties, Europol’s Prüm competencies (ie a bigger role in the exchange
of specific types of data for criminal law purposes), Europol’s
interconnectivity with Member States, the obligation(s) to provide Europol
data, and Europol’s presence in Member States. All of the preceding happens
without remedying the existing accountability shortcomings in Europol’s legal
framework.
Strengthening its competencies …
The 2016 Europol Regulation envisioned some restricted
cooperation with private parties. Following the 2022 amending Europol Regulation, Europol could exchange personal
data with private parties and request data via the national competent
authorities to combat terrorism, extremism and online child sexual abuse
material. With its proposal, the Commission proposes an overhaul and extension
of these competencies to all crime areas for which Europol is competent and limiting
the existing restrictions (absence of “upon their request”). In combination
with Europol’s Open Source Intelligence (OSINT) collection, this could enable
Europol to collect a vast amount of data, either without or with only limited
involvement of the Member States. While the collection of this data is not
necessarily a problem (as long as the legal framework is respected), Europol
cannot conduct its own investigations, leaving open the question of where this
leads.
The 2024 Prüm II Regulation enables Europol to consult national
police databases when receiving information from third countries. Even though
the framework is not yet operational, the Commission already proposes to extend
it to data from Member States. With this extension, Europol should become more
efficient and effective. Why the European Commission has refrained from
offering Europol a general ability to check (including for data from private
parties and EU agencies) remains unclear. National competent authorities can
easily consult Prüm II, thereby limiting the purpose of extended Europol access
rights based on their information. On the contrary, allowing Europol to use
Prüm II based on information from private parties and EU agencies could be
beneficial, as it would enable Europol to identify interested Member States. Extending
Europol’s access rights for Prüm II would still leave the overarching system
incomplete as Europol has no access rights to the European Criminal
Record Information System (ECRIS).
With its proposal, the Commission
seeks to strengthen the interconnectivity between the Member States and Europol
by establishing a Europol Cloud Infrastructure. It is intended to support
Member States, EU entities and third countries to access Europol’s tools,
collaborative environments and other operational and analytical capabilities,
including the Joint Operational Analysis Cases (JOACs). Additionally, the Europol
Cloud Infrastructure should enable Member States to connect their national
system to it through the EU Police Digital Identity. From the proposal, it
cannot be deduced how this system will operate. It is unclear what the
connection between the national system and the Europol Cloud will entail. Likewise,
the impact for JOAC’s remains unclear, as they also remain part of the Europol
Analytical Environment. Hence, Member States can have different JOACs in
different environments. Furthermore, following the legal
abolition of Europol’s pre-determined data systems (e.g. EIS), Europol
created a so-called “data
lake”. How this “data lake” will interact with the Europol Cloud Infrastructure
remains uncertain.
Another interesting point is the
obligation to provide Europol with information. For a very long time, the
Europol Regulation required Member States only to provide Europol with the “necessary
information”. Following the 2005
Council Decision on Terrorism, they should provide Europol with specific
information on terrorism. Under the 2025
amending Europol Regulation, Europol should receive information from Member
States when participating in Operational Task Forces. However, this new
proposal raises several problems. While, in principle, the general obligation
to provide Europol with all “necessary” information is retained, the proposed
Article 38 on Europol’s cross-checking service obliges Member States to provide
the service with “any data that relates to forms of crime falling within the
scope of Europol’s competence”. Without any reference to the earlier necessary
obligation, this entails a new obligation. Additionally, immigration liaison
officers “shall provide Europol with relevant information”. This seems to
diverge from the earlier “necessary” obligation once again. Furthermore, the
Operational Task Forces should “ensure the continuous and structured exchange
of all relevant information”. As a result, three different obligations exist
concerning the provision of data. Most important is the first problem: should
Member States provide Europol with all information, or only all information
concerning crimes for which the Member States find it “necessary”?
Finally, one of the most
interesting developments is the “support offices”. It is a misjudgement to
compare these with local FBI offices; more apt is it to see them as permanent
mobile offices, which Europol currently uses on
action days. The Commission proposes to have Europol staff as liaison
officers in the Member States “to ensure appropriate uptake by Member States of
Europol’s support”. While this concerns Europol staff (thus EU staff), these
should act under the responsibility of both Europol and the Member States. The
Europol Management Board will set out the division of responsibilities, yet also
decide on the organisation and functioning of these support offices. Additionally,
the European Commission proposes provisions on the deployment of Europol staff,
yet without any actual limits, leaving it open for almost all tasks. Interestingly,
in this perspective, is the inclusion of: “to ensure that the outputs produced
through operational support … may be used as evidence in national investigative
and judicial proceedings”. If adopted, this would link deployment of Europol
staff to the production of evidence, yet would not remedy the non-inclusion of
the rapporteur’s
failed attempt to include a similar provision in the 2025 amending Europol
Regulation.
... but leaving its
accountability framework untouched
When all preceding elements are
combined, Europol’s competencies are clearly expanding once again. Europol
should take up more tasks, but most interestingly, its ability to provide
Member States with instruments and tools will significantly expand. Still, the number
of and the competencies of its accountability forums have not been significantly
revised in the proposal. While this could be considered a shortcoming of the
European Commission, it is not. The biggest shortcoming is the European
Commission’s reluctance to address existing shortcomings in Europol’s legal
framework.
Undeniably, the European Data Protection Supervisor (EDPS) and Europol’s data protection officer (DPO)
have a strong position to hold Europol accountable for its data processing, yet,
unfortunately, without requirements concerning its staffing. Even though the
FRO is offered formal independence in the proposal, its tasks remain limited,
while these could be expanded and it could be provided with stronger tools to
enhance its point of view. Furthermore, the annual reports of Europol’s fundamental rights officer (FRO) and DPO are not provided to the JPSG
or the European Parliament. These reports should be made available on a
confidential basis to these forums to enable them to be properly informed about
Europol’s conduct.
Similarly, the JPSGs' and the
European Parliament’s tasks have remained unchanged, without formal ability to
sanction Europol or its executive director, besides the discharge procedure for
the European Parliament. Meanwhile, the European Commission has proposed to
strengthen its own position regarding Europol’s Executive Director. Why not the
other way around? Why not allow the joint
parliamentary scrutiny group (JPSG)
and the European Parliament to propose the dismissal of Europol’s Executive
Director? If so, the European Parliament should have the competence to request
the Executive Director’s attendance at a public hearing, in contrast to the
European Commission’s and the Management Board’s closed-door session. Furthermore,
in the proposal, the Council’s powers are limited in comparison to the current
legal framework, as it would no longer be able to appoint or dismiss the
Executive Director. Europol’s Internal Investigation Service is not offered a
specific legal basis either. The inclusion thereof should go alongside the
inclusion of specific competencies to combat fraud and corruption within
Europol (e.g. access rights to documents).
If all proposed changes are
adopted, Europol’s responsibility and autonomy to tackle crime can no longer be
ignored or denied. Already, Members of the German Bundestag argue that Europol
is a partner, and
not merely a supportive entity. As a partner, one should take responsibility
and be held accountable. Therefore, besides the previously suggested changes, the
immunity of Europol staff cannot be retained when performing similar tasks, as
when Europol staff
is part of a Joint Investigation Team (JIT), particularly given the divided
responsibility (see Supra). As a result, a general waiver should be
included in the EU legal framework, and a specific waiver procedure should be
included in the Europol Regulation (in conformity with existing CJEU case law).
Similarly, the liability of Europol and its staff should be clarified to ensure
proper criminal and civil liability.
Additionally, as previously
mentioned, the European Commission’s proposal falls short of offering rules
concerning the testimony of Europol staff in national courts. The preceding is
essential, as in a trial
in Malta conflicts arose concerning this practice. The Union legislator
should include specific obligations for Europol staff, e.g. when they can
refuse to answer a judge, when they can refuse to appear, what information they
can disclose and subject to what rules (EU or national rules).
Finally, the new proposal contains
no rules concerning the use of information used as evidence in court. The 2023
Exchange of Information Directive copies the phrase of its predecessor
(i.e. the Swedish
Framework Decision) requiring prior approval from the providing Member
State to use information as evidence, but the European Commission falls short of
including rules to prevent the Europol Regulation being used to circumvent the 2023
Directive, especially with SIENA becoming the regular instrument for exchanging
information. Furthermore, it offers no rules concerning the use of evidence
collected as part of a JIT, even though rules have existed since the Naples
II convention on customs cooperation.
More power, not more control,
just the needed control
If the Union legislator were to
adopt this European Commission proposal, Europol would significantly expand its
competencies, yet remain a supportive agency without executive powers. Still, concerning
some competencies, questions arise about their use. Concerning other competencies,
the underlying relationship should be clarified to ensure Europol has a clear
legal framework without contradictions. While it is common to argue for increased
control over Europol when competencies expand, no additional accountability
obligations are required. Europol has a strong accountability framework when
considering the powers of the EDPS and its DPO. Nevertheless, shortcomings in
its accountability framework exist that should be remedied to ensure Europol is
held properly accountable.
No comments:
Post a Comment