From Export Control to Unknown Exports: How the EU’s Dual-Use Regime Falls Short on Tackling Spyware
The continued misuse and abuse of commercial spyware, particularly by states, continues to pose a serious threat to democratic resilience across the European Union. Despite widespread evidence of misuse targeting journalists, activists, political opponents and public officials, the EU still lacks an effective, coherent framework capable of preventing the proliferation of these tools and safeguarding fundamental rights.
Today, CDT Europe publishes From Export Control to Unknown Exports: How the EU’s Dual-Use Regime Falls Short on Tackling Spyware, our first research report examining how the Dual Use regulation which oversees export controls is enforced in practice across four EU Member States, and whether the legislation addresses ongoing human rights concerns in relations to the export of spyware technologies. In brief, the findings show that the current system lacks sufficient enforcement and oversight, and is therefore not fit to meet the scale or the urgency of the problem.
A worsening threat with limited institutional response
In recent years, investigations and parliamentary inquiries have documented spyware abuses within the Union, including against elected officials and members of the press. Yet the European Parliament’s recommendations, including those issued by the PEGA Committee in 2022, have not been followed by meaningful institutional action. Meanwhile, spyware vendors continue to operate with limited oversight, and the tools they develop continue to proliferate within the internal market.
This regulatory gap leaves individuals, civic organisations and democratic institutions exposed. It also enables spyware companies to exploit differences between Member States approaches to enforcement, and take advantage of opaque licensing systems, minimal transparency requirements and diverging interpretations of human rights risks.
How national systems fall short: lessons from four Member States
To understand how the EU’s only binding framework governing spyware exports is implemented in practice, CDT Europe conducted case studies in France, Germany, Italy and the Netherlands. Despite differences in institutional design, the research reveals a consistent pattern of weaknesses across all four systems:
• Limited transparency Licensing decisions are shielded from public scrutiny. National reports, where they exist, provide only aggregated data, with little insight into how licensing decisions are made or how human rights risks are assessed.
• Fragmented due diligence requirements Exporters face inconsistent expectations across Member States. Many lack guidance on how to conduct human rights risk assessments or identify problematic end uses. Authorities often provide little feedback, even when licences are refused.
• Absence of end-use monitoring Once spyware leaves EU borders, there are virtually no binding obligations for exporters to verify how it is used. Authorities and companies alike acknowledged that visibility over the final deployment of these tools is extremely limited.
• Divergent national procedures and capacity constraints Member States operate with different levels of expertise, staffing and institutional coordination. These divergences enable forum shopping, where companies route exports through jurisdictions perceived as more permissive.
Our research exposes that unlike exports to third countries, intra-EU transfers of spyware face virtually no oversight. Once inside the internal market, these tools can circulate freely among Member States with very little licensing or accountability measures, despite the risks of domestic misuse.
These findings highlight an urgent need to reinforce EU-level safeguards and close the gaps that national systems alone cannot address.
A critical moment for EU action
With the European Commission preparing to evaluate the Dual-Use Regulation, the EU has a unique opportunity to address the structural shortcomings identified in our research and ensure that export controls meaningfully protect fundamental rights.
Our report outlines concrete, actionable steps that EU Institutions should take to prevent spyware abuse and reinforce democratic resilience:
• Close the intra-EU gap by establishing a framework to govern the movement of spyware within the Union.
• Strengthen transparency with harmonised, disaggregated reporting on licence applications and decisions.
• Reinforce due diligence by requiring robust human rights risk assessments throughout the lifecycle of surveillance technologies.
• Introduce systematic end-use monitoring to verify whether exported tools are misused after licensing.
• Build capacity within national authorities and embed independent oversight and parliamentary scrutiny.
• Improve information-sharing and align procedures across Member States to limit forum shopping.
• Lead international coordination efforts to raise global standards and curb spyware proliferation beyond the EU.
CDT Europe and Partners Call for Enforceable Safeguards on Commercial Spyware
CDT Europe, alongside 25+ other civil society organisations, has joined a call on governments and industry to build enforceable human rights and accountability safeguards into the forthcoming Pall Mall Industry Guidelines on Commercial Cyber Intrusion Capabilities (CCICs), a category that includes commercial spyware.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.
Responding to the EU-US Negotiations on Reciprocal Data Exchanges for Border Procedures
CDT Europe, together with 29 other civil society organisations and academics, sent an open joint letter to the Council of the EU regarding the worrying direction taken by the European Commission in the EU-US border negotiations with the U.S. government.
Open Joint Letter on a Public Reassessment of the EU-US Adequacy Decision
On 29 June, the US Supreme Court ruled that US President Trump can remove the leaders of independent agencies and commissions, overturning nearly 90 years of precedent limiting executive power. This decision raises serious questions about one of the key safeguards underpinning the EU-US Data Privacy Framework adopted in 2023: independent supervision.