Expanded Europol Powers Must Not Come at the Expense of Robust EU Data Protection & Legal Safeguards

Expanded Europol Powers Must Not Come at the Expense of Robust EU Data Protection and Legal Safeguards - Report and Analysis
Image Credit: Designed by Magnific

Helping Keep Small Business CYBERSafe!
Gibraltar: Friday 28 August 2026 at 07:00 CET

Expanded Europol Powers Must Not Come at the Expense of Robust EU Data Protection and Legal Safeguards – Report and Analysis
Published in Collaboration with: Nord VPN
By Iain Fraser – Cybersecurity Journalist & Authority Writer
Via SME Cyber Insights – First for SME Cybersecurity News
Google Indexed on: 280826 at 10:30 CET | SERPS: LLM(AI) Google
#CyberJourno #CyberEssentials #CyberResilience #CyberSafe #CyberSecurity #Cybersecurity #NCSC #SME #SMECyberInsights #SMECybersecurity #SMECyberInsights #ThreatIntelligence #Europol

Expanded Europol Powers Must Not Come at the Expense of Robust EU Data Protection and Legal Safeguards – The latest warning from the European Data Protection Supervisor lands in a familiar but increasingly important policy space: how far should law enforcement powers expand when data systems grow more complex and more intrusive? In its new opinion on the European Commission’s proposed Europol regulation, the EDPS supports stronger security cooperation in principle, but argues that broader powers must come with equally strong legal safeguards, oversight, and limits on personal data processing.

What the EDPS is warning about

The EDPS is responding to a European Commission proposal that would replace the current Europol Regulation and strengthen Europol’s role as an information hub, operational hub, and technology and innovation hub.

That may sound administrative, but the privacy consequences are substantial. According to the EDPS, the proposal would expand Europol’s tasks and data-processing capabilities, increasing both the volume of personal data processed and the complexity of how that data is handled.

The sharpest warning concerns people with no established links to criminal investigations or proceedings. EDPS Supervisor Wojciech Wiewiórowski said:

“Modern security threats demand sophisticated responses, but we cannot sacrifice fundamental rights in pursuit of security.”

He added that the proposal creates “serious risks” regarding the processing of personal data belonging to individuals with no established criminal links.

Why this matters beyond Brussels

This is not only a technical EU governance issue. It goes to the centre of how democratic systems justify surveillance, intelligence-sharing, and law enforcement data use.

More power usually means more data

If Europol becomes a stronger coordination and technology body, it will almost certainly process:

* more personal data
* more sensitive categories of data
* more cross-border information
* more data involving people not accused of any crime

That does not automatically make the proposal wrong. But it does increase the burden on legislators to ensure legal clarity, narrow purpose limits, and real accountability.

Vague powers create predictable problems

The EDPS is especially concerned about how Europol would decide whether it is “relevant and necessary” to process the personal data of individuals with no established connection to criminal activity.

That phrase matters. If the threshold is vague, the power can expand in practice far beyond what lawmakers may intend on paper.

The EDPS says the proposal in its current form fails to provide sufficient safeguards and effective oversight mechanisms. That is not a drafting quibble. It is a warning that powers may outpace protections.

The core safeguards the EDPS wants

The EDPS is not arguing against law enforcement cooperation as such. In fact, it explicitly recognises that Member States face increasingly sophisticated cross-border crime and internal security threats.

Its position is narrower and more important: if Europol’s powers expand, the legal framework must remain precise, foreseeable, and enforceable.

The EDPS recommends stronger safeguards around:

* purpose limitation
* storage limitation
* legal certainty on when data processing is allowed

* effective oversight and enforcement
* supervision of processing activities
* cooperation with national supervisory authorities
* security of Europol services and tools

In plain terms, the message is that security policy cannot rely on broad trust alone. It needs hard rules, narrow boundaries, and visible supervision.

Expanded Europol Powers Must Not Come at the Expense of Robust EU Data Protection and Legal Safeguards - Report and Analysis

FAQs

FAQs note: These FAQs are derived from recurring live audience questions and discussion themes on Reddit and Quora relevant to privacy, surveillance, EU regulation, law enforcement data use, and digital rights. They are not generated from the article body.

1. Is the EDPS opposing stronger Europol powers altogether?

No. The EDPS says it supports the overall objective of strengthening Europol’s role, but argues that any expansion must come with robust data protection safeguards and effective oversight.

2. Why is data about people with no criminal link such a big concern?

Because once authorities can process personal data relating to people with no established link to a criminal investigation, the risk of overreach increases sharply. That raises obvious concerns about proportionality and fundamental rights.

3. What does “purpose limitation” mean here?

It means personal data should only be used for clearly defined and lawful purposes, not kept or repurposed broadly just because it may become useful later.

4. Why does legal certainty matter so much in EU data law?

Because vague standards create room for inconsistent or overly broad use of power. In sensitive law enforcement systems, people need to know that rules are clear, foreseeable, and enforceable.

Looking Forward

The EDPS opinion reflects a broader truth about modern security policy: governments increasingly want stronger data-driven tools, but public trust depends on whether those tools remain bounded by law. Europol may well need updated powers for a more complex threat environment. The issue is whether those powers are matched by safeguards strong enough to protect people who are not suspected of any crime.

That is the real test of this proposal. Expanding capability is easy on paper. Preserving rights while doing it is the harder part.

SME Cybersecurity
Image Credit: IfOnlyCommunications

ABOUT IAIN FRASER – I am a Gibraltar based, Accredited Journalist, (*NUJ, IFJ & ONA) Authority Writer,  Commentator & Publisher of SMECyber and cover all aspects of Cybersecurity [Awareness, Threat Management, Best Practice Compliance & Mitigation] and report throughout Europe & the UK

LinkedIn Bio: IainFraserJournalist
Email: iain@iainfraser.net | www.iainfraser.net

CYBERInsights | Practical Small Business Cybersecurity
Image Credit: IfOnlyCommunications

UK Small Business Owner? Join SMECyber Free Now! & Access the SME Cyber Forum – Read, Learn, Engage, Share …

The Latest SME Cybersecurity News, Threat Intelligence & Analysis, Timely Scam Alerts, Best-practice Compliance, Mitigation & Resources specifically curated for UK Based SMEs in a Single Weekly Email direct to your Inbox or Smart Device together with Unrestricted Free Access to our entire SME Cyber Knowledge & Tutorial Library.

What is a VPN & Does my SME Need one? A VPN is a Virtual Private Network a method of securing your communications credentials. When it comes to SMEs, the choice of VPNs can significantly impact the security and efficiency of their operations. NordVPN secures your Internet data with military-grade encryption, ensures your activity remains private and helps bypass geographic content restrictions online.   Join NordVPN Today and Save up to 73% and Get 3 months Extra Free – Rude Not to …!