Euractiv – Governments spying on citizens: Who is to blame, what can the EU do?
This op-ed, authored by CDT Europe’s Silvia Lorenzo Perez, first appeared in Euractiv on May 22, 2024.A portion of the text has been pasted below.
The Polish Ministry of Justice recently revealed nearly 600 individuals were targeted with Pegasus spyware during the previous administration. This announcement provides further evidence of the troubling reality the European Parliament’s PEGA committee uncovered: EU governments deploy spyware surveillance against their citizens for nefarious purposes unrelated to national security.
Before the Pegasus revelations, debates on regulatory aspects of spyware had been confined to cybersecurity, trade, defence and foreign policy. That lens placed responsibility and potential criminal liability primarily on the private entities, known as cyber mercenaries, who developed or wielded the tools to conduct cyber intrusion operations that threatened states’ national security.
Governments evaded accountability for their actions, shielding themselves from guilt with the secrecy surrounding national security operations. However, the spotlight rightfully shines on the state as a key perpetrator after the Pegasus scandal.
When attributing responsibility for spyware abuse, we should question whether placing all the responsibility on the private actors who develop and sell the tools will adequately address the problem.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.
Responding to the EU-US Negotiations on Reciprocal Data Exchanges for Border Procedures
CDT Europe, together with 29 other civil society organisations and academics, sent an open joint letter to the Council of the EU regarding the worrying direction taken by the European Commission in the EU-US border negotiations with the U.S. government.
Open Joint Letter on a Public Reassessment of the EU-US Adequacy Decision
On 29 June, the US Supreme Court ruled that US President Trump can remove the leaders of independent agencies and commissions, overturning nearly 90 years of precedent limiting executive power. This decision raises serious questions about one of the key safeguards underpinning the EU-US Data Privacy Framework adopted in 2023: independent supervision.
Return of Mass Scanning of Private Communications through Undemocratic Procedure
CDT Europe responds to the European Parliament's vote to revive the interim derogation from the ePrivacy Directive, commonly known as “Chat Control 1.0”, which provides the legal basis for the voluntary, indiscriminate scanning of private communications for known and new Child Sexual Abuse Material (CSAM), and for the solicitation of children.