CDT Europe and Partners Call for Enforceable Safeguards on Commercial Spyware
CDT Europe, alongside 25+ other civil society organisations, has joined a call on governments and industry to build enforceable human rights and accountability safeguards into the forthcoming Pall Mall Industry Guidelines on Commercial Cyber Intrusion Capabilities (CCICs), a category that includes commercial spyware.
Following the adoption of a Code of Practice for States in 2025, the Pall Mall Process, under the leadership of the United Kingdom and France, is currently developing Industry Guidelines on Commercial Cyber Intrusion Capabilities (“the Guidelines”). The Guidelines are expected to be finalised in November 2026. This submission brings together critical perspectives from civil society organisations that have consistently documented the significant harms commercial spyware inflicts on people, communities and institutions, including transnational harms that have profoundly negative impacts across borders and undermine national security, rule of law, and human rights.
The joint submission warns that the Guidelines are a historic opportunity to make accountability the industry norm, but that weak or diluted language risks legitimising an industry already linked to serious human rights abuses, including arbitrary surveillance and detention as well as transnational repression.
The signatories call for a hard, enforceable baseline well above current industry self-regulation, we call on States to:
Set strict, clear limits, grounded in transparent and accessible legal frameworks, on the sale, export, facilitation, and use of CCICs for both States and companies.
Restrict access to CCICs to actors that meet clear human rights and accountability requirements while protecting legitimate digital security research.
Require robust human rights due diligence prior to and throughout ongoing relationships with CCIC companies.
Require independent and effective oversight of CCIC development, procurement, and use.
Require effective accountability mechanisms and remedy for human rights abuses involving CCICs, including across borders
Joint Statement: Pegasus in the European Parliament, the EU Must Act Now
CDT Europe is publishing a joint statement with civil society organisations and individual signatories calling on the EU institutions to regulate spyware technologies after the 2026 Citizen Lab revelations.
Response to the OHCHR’s Call for Inputs on Protection of Human Rights Defenders in the Digital Age
CDT and CDT Europe welcome the opportunity to provide input into OHCHR’s drafting process of the report of the UN High Commissioner for Human Rights pursuant to HRC resolution 58/23 on “Human rights defenders and new and emerging technologies: protecting human rights defenders, including women human rights defenders, in the digital age”.
From Export Control to Unknown Exports: How the EU’s Dual-Use Regime Falls Short on Tackling Spyware
CDT Europe’s first research report examines how the Dual Use regulation which oversees export controls is enforced in practice across four EU Member States, and whether the legislation addresses ongoing human rights concerns in relations to the export of spyware technologies.