Monday, 24 August 2026

With greater power comes no extra accountability: the proposed new Europol Regulation


 


Wannes Bellaert, PhD researcher and academic assistant, Ghent University

Photo credit: OSeveno, via Wikimedia Commons

Once again a new Europol legal framework

On the 24th of June 2026, the European Commission proposed a new legal framework for Europol (i.e. the European Union Agency for Law Enforcement Cooperation). As reflected in the preparatory documents and the proposal itself, the intentions are clear: extending Europol’s competencies, while refraining from remedying existing shortcomings in Europol’s accountability framework.

Back then, when candidate Commission President Von Der Leyen suggested making Europol a “truly operational police agency”, uncertainty reigned over what she intended. Both the preparatory documents and the proposal demonstrate that a European FBI is still far off. Nonetheless, the European Commission envisages an expansion and codification of several elements. As regards the expansion, the European Commission envisages expanding the scope of cooperation with private parties, Europol’s Prüm competencies (ie a bigger role in the exchange of specific types of data for criminal law purposes), Europol’s interconnectivity with Member States, the obligation(s) to provide Europol data, and Europol’s presence in Member States. All of the preceding happens without remedying the existing accountability shortcomings in Europol’s legal framework.

Strengthening its competencies …

The 2016 Europol Regulation envisioned some restricted cooperation with private parties. Following the 2022 amending Europol Regulation, Europol could exchange personal data with private parties and request data via the national competent authorities to combat terrorism, extremism and online child sexual abuse material. With its proposal, the Commission proposes an overhaul and extension of these competencies to all crime areas for which Europol is competent and limiting the existing restrictions (absence of “upon their request”). In combination with Europol’s Open Source Intelligence (OSINT) collection, this could enable Europol to collect a vast amount of data, either without or with only limited involvement of the Member States. While the collection of this data is not necessarily a problem (as long as the legal framework is respected), Europol cannot conduct its own investigations, leaving open the question of where this leads.

The 2024 Prüm II Regulation enables Europol to consult national police databases when receiving information from third countries. Even though the framework is not yet operational, the Commission already proposes to extend it to data from Member States. With this extension, Europol should become more efficient and effective. Why the European Commission has refrained from offering Europol a general ability to check (including for data from private parties and EU agencies) remains unclear. National competent authorities can easily consult Prüm II, thereby limiting the purpose of extended Europol access rights based on their information. On the contrary, allowing Europol to use Prüm II based on information from private parties and EU agencies could be beneficial, as it would enable Europol to identify interested Member States. Extending Europol’s access rights for Prüm II would still leave the overarching system incomplete as Europol has no access rights to the European Criminal Record Information System (ECRIS).

With its proposal, the Commission seeks to strengthen the interconnectivity between the Member States and Europol by establishing a Europol Cloud Infrastructure. It is intended to support Member States, EU entities and third countries to access Europol’s tools, collaborative environments and other operational and analytical capabilities, including the Joint Operational Analysis Cases (JOACs). Additionally, the Europol Cloud Infrastructure should enable Member States to connect their national system to it through the EU Police Digital Identity. From the proposal, it cannot be deduced how this system will operate. It is unclear what the connection between the national system and the Europol Cloud will entail. Likewise, the impact for JOAC’s remains unclear, as they also remain part of the Europol Analytical Environment. Hence, Member States can have different JOACs in different environments. Furthermore, following the legal abolition of Europol’s pre-determined data systems (e.g. EIS), Europol created a so-called “data lake”. How this “data lake” will interact with the Europol Cloud Infrastructure remains uncertain.

Another interesting point is the obligation to provide Europol with information. For a very long time, the Europol Regulation required Member States only to provide Europol with the “necessary information”. Following the 2005 Council Decision on Terrorism, they should provide Europol with specific information on terrorism. Under the 2025 amending Europol Regulation, Europol should receive information from Member States when participating in Operational Task Forces. However, this new proposal raises several problems. While, in principle, the general obligation to provide Europol with all “necessary” information is retained, the proposed Article 38 on Europol’s cross-checking service obliges Member States to provide the service with “any data that relates to forms of crime falling within the scope of Europol’s competence”. Without any reference to the earlier necessary obligation, this entails a new obligation. Additionally, immigration liaison officers “shall provide Europol with relevant information”. This seems to diverge from the earlier “necessary” obligation once again. Furthermore, the Operational Task Forces should “ensure the continuous and structured exchange of all relevant information”. As a result, three different obligations exist concerning the provision of data. Most important is the first problem: should Member States provide Europol with all information, or only all information concerning crimes for which the Member States find it “necessary”?

Finally, one of the most interesting developments is the “support offices”. It is a misjudgement to compare these with local FBI offices; more apt is it to see them as permanent mobile offices, which Europol currently uses on action days. The Commission proposes to have Europol staff as liaison officers in the Member States “to ensure appropriate uptake by Member States of Europol’s support”. While this concerns Europol staff (thus EU staff), these should act under the responsibility of both Europol and the Member States. The Europol Management Board will set out the division of responsibilities, yet also decide on the organisation and functioning of these support offices. Additionally, the European Commission proposes provisions on the deployment of Europol staff, yet without any actual limits, leaving it open for almost all tasks. Interestingly, in this perspective, is the inclusion of: “to ensure that the outputs produced through operational support … may be used as evidence in national investigative and judicial proceedings”. If adopted, this would link deployment of Europol staff to the production of evidence, yet would not remedy the non-inclusion of the rapporteur’s failed attempt to include a similar provision in the 2025 amending Europol Regulation.

... but leaving its accountability framework untouched

When all preceding elements are combined, Europol’s competencies are clearly expanding once again. Europol should take up more tasks, but most interestingly, its ability to provide Member States with instruments and tools will significantly expand. Still, the number of and the competencies of its accountability forums have not been significantly revised in the proposal. While this could be considered a shortcoming of the European Commission, it is not. The biggest shortcoming is the European Commission’s reluctance to address existing shortcomings in Europol’s legal framework.

Undeniably, the European Data Protection Supervisor (EDPS) and Europol’s data protection officer (DPO) have a strong position to hold Europol accountable for its data processing, yet, unfortunately, without requirements concerning its staffing. Even though the FRO is offered formal independence in the proposal, its tasks remain limited, while these could be expanded and it could be provided with stronger tools to enhance its point of view. Furthermore, the annual reports of Europol’s fundamental rights officer (FRO) and DPO are not provided to the JPSG or the European Parliament. These reports should be made available on a confidential basis to these forums to enable them to be properly informed about Europol’s conduct.

Similarly, the JPSGs' and the European Parliament’s tasks have remained unchanged, without formal ability to sanction Europol or its executive director, besides the discharge procedure for the European Parliament. Meanwhile, the European Commission has proposed to strengthen its own position regarding Europol’s Executive Director. Why not the other way around? Why not allow the joint parliamentary scrutiny group (JPSG) and the European Parliament to propose the dismissal of Europol’s Executive Director? If so, the European Parliament should have the competence to request the Executive Director’s attendance at a public hearing, in contrast to the European Commission’s and the Management Board’s closed-door session. Furthermore, in the proposal, the Council’s powers are limited in comparison to the current legal framework, as it would no longer be able to appoint or dismiss the Executive Director. Europol’s Internal Investigation Service is not offered a specific legal basis either. The inclusion thereof should go alongside the inclusion of specific competencies to combat fraud and corruption within Europol (e.g. access rights to documents).

If all proposed changes are adopted, Europol’s responsibility and autonomy to tackle crime can no longer be ignored or denied. Already, Members of the German Bundestag argue that Europol is a partner, and not merely a supportive entity. As a partner, one should take responsibility and be held accountable. Therefore, besides the previously suggested changes, the immunity of Europol staff cannot be retained when performing similar tasks, as when Europol staff is part of a Joint Investigation Team (JIT), particularly given the divided responsibility (see Supra). As a result, a general waiver should be included in the EU legal framework, and a specific waiver procedure should be included in the Europol Regulation (in conformity with existing CJEU case law). Similarly, the liability of Europol and its staff should be clarified to ensure proper criminal and civil liability.

Additionally, as previously mentioned, the European Commission’s proposal falls short of offering rules concerning the testimony of Europol staff in national courts. The preceding is essential, as in a trial in Malta conflicts arose concerning this practice. The Union legislator should include specific obligations for Europol staff, e.g. when they can refuse to answer a judge, when they can refuse to appear, what information they can disclose and subject to what rules (EU or national rules).

Finally, the new proposal contains no rules concerning the use of information used as evidence in court. The 2023 Exchange of Information Directive copies the phrase of its predecessor (i.e. the Swedish Framework Decision) requiring prior approval from the providing Member State to use information as evidence, but the European Commission falls short of including rules to prevent the Europol Regulation being used to circumvent the 2023 Directive, especially with SIENA becoming the regular instrument for exchanging information. Furthermore, it offers no rules concerning the use of evidence collected as part of a JIT, even though rules have existed since the Naples II convention on customs cooperation.

More power, not more control, just the needed control

If the Union legislator were to adopt this European Commission proposal, Europol would significantly expand its competencies, yet remain a supportive agency without executive powers. Still, concerning some competencies, questions arise about their use. Concerning other competencies, the underlying relationship should be clarified to ensure Europol has a clear legal framework without contradictions. While it is common to argue for increased control over Europol when competencies expand, no additional accountability obligations are required. Europol has a strong accountability framework when considering the powers of the EDPS and its DPO. Nevertheless, shortcomings in its accountability framework exist that should be remedied to ensure Europol is held properly accountable.

No comments:

Post a Comment