
The crime-fighting agency has failed to implement the necessary data protection measures it was told to make more than a year ago
Europol has been accused of unlawfully storing, and ignoring requests to delete, large amounts of data on individuals with no established link to criminal activity.
The European Data Protection Supervisor (EDPS) has ordered Europol to delete the data it has been storing, concluding a years-long inquiry into the crime-fighting agency’s data collection habits.
The order follows the EDPS ‘admonishment’ of Europol more than a year ago in September 2020 when it was first found to be storing large volumes of data with no Data Subject Categorisation – a requirement stipulated by the Europol Regulation.
The EDPS said that while Europol has complied with some requests and implemented “some” technical measures since then, it has not complied with other requests including failing to define an appropriate data retention period.
The measures introduced reduce, but do not remove, the possibility that individuals’ fundamental rights could be put at risk by unlawful analysis of their data by Europol, or by the data being shared with other law enforcement agencies. As such, the data being stored does not ensure compliance with the Europol Regulation, the EDPS said.
It means Europol was keeping this data for longer than was necessary and violated the principles of data minimisation and storage limitation enshrined in the Europol Regulation.