lagen.nu
EDPS yttrande 16/2026

EDPS Opinion 16/2026 on the Proposal for a Directive regarding the European Investigation Order in criminal matters and the European Remote Participation Order (recast)

Utgivare
Europeiska datatillsynsmannen
Antagen
2026-08-10
Språk
engelska
Ämnesord
Transfers of data
Källa
www.edps.europa.eu
Endast på engelskaEuropeiska datatillsynsmannen har inte publicerat någon svensk version av detta dokument. Texten nedan återges på engelska, så som den publicerats av Europeiska datatillsynsmannen.

Opinion 16/2026

on the Proposal for a Directive regarding the European Investigation Order in criminal matters and the European Remote Participation Order

0

The European Data Protection Supervisor (EDPS) is an independent institution of the EU, responsible under Article 52(2) of Regulation 2018/1725 ‘With respect to the processing of personal data… for ensuring that the fundamental rights and freedoms of natural persons, and in particular their right to data protection, are respected by Union institutions and bodies’, and under Article 52(3)‘… for advising Union institutions and bodies and data subjects on all matters concerning the processing of personal data’.

Wojciech Rafał Wiewiórowski was appointed as Supervisor on 5 December 2019 for a term of five years. The selection procedure for a new EDPS mandate for a term of five years is still ongoing.

Under Article 42(1) of Regulation 2018/1725, the Commission shall ‘following the adoption of proposals for a legislative act, of recommendations or of proposals to the Council pursuant to Article 218 TFEU or when preparing delegated acts or implementing acts, consult the EDPS where there is an impact on the protection of individuals’ rights and freedoms with regard to the processing of personal data’.

This Opinion relates to the Proposal for a Directive of the European Parliament and of the Council regarding the European Investigation Order in criminal matters and the European Remote Participation Order (recast) . This Opinion does not preclude any future additional comments or recommendations by the EDPS, in particular if further issues are identified or new information becomes available. Furthermore, this Opinion is without prejudice to any future action that may be taken by the EDPS in the exercise of his powers pursuant to Regulation (EU) 2018/1725. This Opinion is limited to the provisions of the Proposal that are relevant from a data protection perspective.

Executive Summary

On 23 June 2026, the European Commission adopted a Proposal for a Directive of the European Parliament and of the Council regarding the European Investigation Order in criminal matters and the European Remote Participation Order (recast).

The objective of the Proposal is to improve legal clarity and operational effectiveness in the crossborder gathering of evidence in the EU by addressing targeted deficiencies identified in the application of the current Directive. It also aims to draw up common rules for requesting assistance to make it easier for suspects, accused persons and victims to participate remotely in criminal court hearings from another Member State.

The EDPS supports the efforts to devise and refine the models of co-operation between the competent authorities and to address the shortcomings identified in the application of the EIO Directive thus far. To ensure an appropriate level of data protection, the EDPS makes several recommendations to clarify the applicable legal framework, the roles of the actors who may be involved in processing of personal data under the Proposal, and when personal data should be deleted in case of refusal of the European Investigation Order (‘EIO’).

In particular, the EDPS recommends clarifying the roles of the actors who may be involved in processing of personal data under the Proposal in the enacting terms of the Proposal, taking into account Regulation (EU) 2023/2844. In addition, the Proposal should specify that personal data obtained prior to the decision refusing the recognition or execution of an EIO should be deleted immediately, unless it is strictly necessary to prevent an immediate and serious threat to public security. Finally, the Proposal should expressly clarify that any means of transmission should also ensure an adequate level of security of the communicated personal data.

2

THE EUROPEAN DATA PROTECTION SUPERVISOR,

Having regard to the Treaty on the Functioning of the European Union,

Having regard to Regulation (EU) 2018/1725 of the European Parliament and of the Council of 23 October 2018 on the protection of natural persons with regard to the processing of personal data by the Union institutions, bodies, offices and agencies and on the free movement of such data, and repealing Regulation (EC) No 45/2001 and Decision No 1247/2002/EC (‘EUDPR’) , and in particular Article 42(1) thereof,

HAS ADOPTED THE FOLLOWING OPINION:

1. Introduction

1. On 23 June 2026, the European Commission adopted a Proposal for a Directive of the European Parliament and of the Council regarding the European Investigation Order in criminal matters and the European Remote Participation Order (recast) (‘the Proposal’).

2. The objective of the Proposal is to improve legal clarity and operational effectiveness in the cross-border gathering of evidence in the EU by addressing targeted deficiencies identified in the application of the current Directive. It also aims to draw up common rules for requesting assistance to make it easier for suspects, accused persons and victims to participate remotely in criminal court hearings from another Member State.

3. The EDPS has previously issued an Opinion on the initiative for a Directive of the European Parliament and of the Council regarding the European Investigation Order in criminal matters .

4. The present Opinion of the EDPS is issued in response to a consultation by the European Commission of 23 June 2026, pursuant to Article 42(1) of EUDPR. The EDPS welcomes the reference to this consultation in Recital 78 of the Proposal. The EDPS also positively notes that he was already previously informally consulted pursuant to recital 60 of EUDPR.

2. General remarks

5. Directive 2014/41/EU (‘the EIO Directive’) established the European Investigation Order (‘EIO’) as an instrument for cross-border gathering of evidence in criminal matters. The Directive was a response to a well-identified practical need for a comprehensive framework, based on mutual recognition, for obtaining evidence in cases with a crossborder dimension .

6. The EDPS is aware that criminal activities are becoming increasingly a global and, in the great majority of the cases, cross-border phenomenon, thus requiring close cooperation between authorities in different countries. Effective cross-border judicial cooperation in criminal matters plays a vital role in enabling the collection and transfer of evidence across national boundaries, strengthening criminal investigations and prosecutions, and enhancing the capacity of the European Union and its Member States to counter these threats effectively. The EDPS therefore supports the efforts to further improve and refine the models of co-operation between the competent authorities in the EU and welcomes the aim of the Proposal to address the shortcomings identified in the application of the EIO Directive thus far, in order to contribute to a more efficient judicial cooperation and enhance mutual trust between Member States.

7. The EDPS notes that the EIO is to be issued for the purpose of having one or more specific investigative measure(s) carried out in the executing Member State with a view of gathering evidence (potentially not in existence when the order is issued) and transferring it to the requesting Member State. Evidence collected by way of an EIO will typically contain personal data such as information on bank and other financial accounts (Article 26), information on banking and other financial operations (Article 27), real time geolocation, audio or visual data (Article 28), telecommunications data (Article 31) etc. For these reasons the Proposal has a significant impact on the lives of the individuals concerned and their rights to privacy and to the protection of personal data.

8. The EDPS recalls that any interference with the fundamental rights to privacy and data protection guaranteed by Articles 7 and 8 of the Charter of Fundamental Rights of the EU (the ‘Charter’), must fulfil the requirements of Article 52(1) of the Charter. In that regard the EDPS positively notes that Article 1(2) of the Proposal states that “this Directive shall not have the effect of modifying the obligation to respect the fundamental rights and legal principles as enshrined in Article 6 of the TEU” .

9. This Opinion focuses on the provisions of the Proposal that are specifically relevant from a data protection perspective, with the aim to provide constructive and objective advice with a view of ensuring the appropriate level of data protection, as guaranteed by the Charter.

3. Data protection legislative framework

10. As one of EU fundamental rights is the right to data protection, the EDPS welcomes the insertion of a dedicated recital reminding that the processing of personal data under the EIO Directive must comply with Directive (EU) 2016/680 (‘LED’), or in certain, limited 10 11 cases , with Regulation (EU) 2016/679 (‘GDPR’), as well as EUDPR and Regulation (EU) 12 13 2018/1727 for Eurojust and EUDPR and Regulation (EU) 2017/1939 for the European Public Prosecutor’s Office (‘EPPO’).

11. The EDPS notes that for the EPPO the recital mentions that “As regards the processing of personal data by the European Public Prosecutor’s Office, Regulation (EU) 2018/1725 should apply as of the date of the entry into force of the amendments to Regulation (EU) 2017/1939”. The EDPS understands that this wording anticipates the forthcoming revision of the EPPO founding act Regulation (EU) 2017/1939 . However, in the interest of legal clarity, as there could possibly be additional amendments of the Regulation at some point in the future, the EDPS suggests clarifying explicitly in the recital which amendments it refers to.

12. The EDPS also welcomes the clear ground for refusal, in Article 21(5)(c) of the Proposal, for consent to an onward transfer of personal data to a third country or an international organisation, in case the transfer would not comply with the conditions laid down in Chapter V of the GDPR or the LED.

4. Roles and responsibilities

13. The EDPS welcomes that recital 75 of the Proposal aims to clarify the roles of the different actors who may be involved in processing of personal data under the Proposal. Ensuring clarity of the role of each actor involved in the processing of personal data is important to promote transparency of processing and the effective exercise of data subject rights. Moreover, it is key to enable a determination of who will be responsible for what. Determining the role of controller from the outset also helps to avoid any possible problems of interpretation in assessing that role.

14. Therefore, the EDPS considers that the designation of an entity as controller, joint controller or processor should take place in the enacting terms (operative text) of the Proposal rather than in the recitals accompanying them .

15. The EDPS also recalls that, where transmission takes place using the decentralised IT system, as defined in Article 2, point (3) of Regulation (EU) 2023/2844 , the roles of the competent authorities and of the Commission have already been specified in Article 14 of Regulation (EU) 2023/2844 . Under that Regulation, “central authorities” are considered as “competent authorities” and are designated as controllers (and not as processors). Recital 75 of the Proposal, on the other hand, indicates that central authorities may also act as processors when processing personal data on behalf of competent authorities.

16. While it is not excluded that a central authority may also act as a processor in the context of the Proposal, the relationship between the roles as defined by the Proposal and the roles already specified under Regulation (EU) 2023/2844 should be clear and coherent.

17. Finally, the EDPS recalls that any relationship between (joint) controllers and processors must be governed by appropriate legal arrangements .

5. Deletion of data in case of refusal of EIO

18. Under the principle of data minimisation, personal data which is processed must be adequate, relevant and limited to what is necessary in relation to the purposes for which they are processed .

19. Pursuant to Article 13(5) of the Proposal, provisional execution of a measure referred to in paragraph 4, point (c), shall cease where the recognition or execution of the EIO is refused. Any material (including personal data) obtained may be used only where strictly necessary to prevent an immediate and serious threat to public security. Article 30(6)(f) provides for the same solution in case of the refusal of recognition or execution of the EIO regarding cross-border surveillance.

20. While fully supporting the strict limitation of the use of any material (including personal data) obtained before the decision on the refusal is made, the EDPS recommends clarifying in Articles 13(5) and 30(6)(f) of the Proposal that the material obtained prior to the decision refusing the recognition or execution of the EIO should be deleted, unless it is strictly necessary to prevent an immediate and serious threat to public security .

6. Means of communication

21. The EDPS notes that Article 51(2) of the Proposal provides for the possibility of certain communication to take place “by the swiftest and most appropriate means of transmission”. However, the provision does not expressly require that such means of transmission meet any specific security requirements. As this communication may also contain personal data, the EDPS considers that these “appropriate means of transmission” should ensure an adequate level of security of the communicated personal data and recommends clarifying that the means of transmission must also be secure.

7. Statistics

22. The EDPS notes that Article 55 of the Proposal obliges Member States to collect comprehensive statistics to allow the Commission to monitor the application of the EIO Directive.

23. In that regard, the EDPS welcomes that, in line with the data minimisation, the provision expressly indicates that the statistics transmitted to the Commission must be limited to aggregated data and must not contain personal data.

8. Conclusions

24. In light of the above, the EDPS makes the following recommendations: (1) to clarify in Recital 75 to which amendments to Regulation (EU) 2017/1939 it refers; (2) to specify in the enacting terms (operative text) of the Proposal the roles of the actors who may be involved in processing of personal data under the Proposal (as controller, joint controller or processor), taking into account Regulation (EU) 2023/2844; (3) to clarify in Articles 13(5) and 30(6)(f) that in cases where the personal data obtained prior to the decision refusing the recognition or execution of the EIO may not be used, such data should immediately be deleted; (4) to clarify in Article 51(2) that “appropriate means of transmission” should ensure an adequate level of security of the communicated personal data. Brussels, 10 August 2026 (e-signed) Wojciech Rafał WIEWIÓROWSKI 8

Fotnoter

  1. 1 COM(2026) 313 final. 1
  2. 2 OJ L 295, 21.11.2018, p. 39. 3 COM(2026) 313 final, p. 1. 4 Opinion of the European Data Protection Supervisor on the initiative of the Kingdom of Belgium, the Republic of Bulgaria, the Republic of Estonia, the Kingdom of Spain, the French Republic, the Italian Republic, the Republic of Hungary, the Republic of Poland, the Portuguese Republic, Romania, the Republic of Finland and the Kingdom of Sweden for a Directive of the European Parliament and of the Council on the European Protection Order, and on the initiative of the Kingdom of Belgium, the Republic of Bulgaria, the Republic of Estonia, the Kingdom of Spain, the Republic of Austria, the Republic of Slovenia and the Kingdom of Sweden for a Directive of the European Parliament and of the Council regarding the European Investigation Order in criminal matters, issued on 29 December 2010. 4
  3. 5 Directive 2014/41/EU of the European Parliament and of the Council of 3 April 2014 regarding the European Investigation Order in criminal matters (OJ L 130, 1.5.2014, p. 1). See Recital 5 of the Proposal. 7 See also Recital 74 of the Proposal. 5
  4. 8 Recital 75 of the Proposal. 9 Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ L 119, 4.5.2016, p. 89). 10 See Article 5, points (b), (c) and, in connection to such proceedings, point (d) of the Proposal. 11 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, p. 1). 12 Regulation (EU) 2018/1727 of the European Parliament and of the Council of 14 November 2018 on the European Union Agency for Criminal Justice Cooperation (Eurojust), and replacing and repealing Council Decision 2002/187/JHA (OJ L 295, 21.11.2018, pp. 138). 13 Council Regulation (EU) 2017/1939 of 12 October 2017 implementing enhanced cooperation on the establishment of the European Public Prosecutor’s Office (‘the EPPO’) (OJ L 283, 31.10.2017, pp. 1). 14 See also COM(2026) 314 final, p. 3 and Article 2(2) of the Proposal to amend Regulation (EU) 2018/1725. 6
  5. 15 See also EDPS Guidance for co-legislators on key elements of legislative proposals, issued on 7 May 2025, para 27. 16 Regulation (EU) 2023/2844 of the European Parliament and of the Council of 13 December 2023 on the digitalisation of judicial cooperation and access to justice in cross-border civil, commercial and criminal matters, and amending certain acts in the field of judicial cooperation, OJ L, 2023/2844, 27.12.2023, ELI: http://data.europa.eu/eli/reg/2023/2844/oj. 17 The scope of the draft Directive is broader, however, as it also concerns the collection, use and even transfers to third countries and international organisations which does not fall under Regulation (EU) 2023/2844. 18 See Article 2(1) of Regulation (EU) 2023/2844. 19 See also EDPS Guidance for co-legislators on key elements of legislative proposals, issued on 7 May 2025, para 28-35. 20 See Art. 5(1)(c) GDPR as well as 4(1)(c) of LED and EUDPR. 21 Similarly as done in Article 33(4)(b) of the Proposal. 7