This provision is one of the most controversial ones in the European Union’s data
protection legal framework. It led to the approval of the Data Retention Directive,
130
which was considered invalid by the CJEU.
131 The Court decided that the Directive
did not strike an adequate balance between personal data protection and the public
interests underlying criminal investigations. The Data Retention Directive provided
that Member States should impose electronic communications service providers the
obligation to retain certain communications data, such as traffic data, for a certain
period of time. If necessary, these communications data could be used in the
investigation of serious crimes. Among other aspects stressed by the Court, this
Directive did not define precise boundaries or adequate safeguards concerning the
period of time during which data retention could take place or concerning the entities
which could access those data. This judgment is illustrative of the position of the
European Union regarding restrictions to personal data protection, since it establishes a very demanding level of requirements for the lawfulness of these restrictions,
and highlights the fact that the EU and the US are evolving in opposite directions.
A brief reference to another topic that may raise an interesting debate in respect of
digital forensics, particularly with regard to its limits, is in order. As cyberspace
challenges existing State borders, digital forensics rules aimed at extracting evidence
from computer systems should take into account the sovereignty of States and create
limits whenever a computer system spreads throughout several States. Some of the
legal systems comprised in this study seem to have a very broad understanding of
these limits, at least in specific circumstances. According to recent amendments to
the Singaporean Criminal Procedure Code, investigators located in Singapore may
inspect and search, in or from Singapore, any data stored on or available to a
computer implicated in the investigation, regardless of whether the computer is
located inside or outside Singapore.
132 While the stated intent is to enable access
to data on web-based email accounts or web storage accounts residing in computers
outside Singapore, the wording remains fairly broad.
133 In Portugal, the Cybercrime
Law also has a controversial provision on computer data searching, providing that
whenever, in the course of a search, there are reasons to believe that the data sought
are found elsewhere in the system, this search may be extended to other parts of that
system. This provision raises several doubts as to its exact territorial scope.
134
130 Directive 2006/24/EC of the European Parliament and of the Council of 15 March 2006 on the
retention of data generated or processed in connection with the provision of publicly available
electronic communications services or of public communications networks and amending Directive
2002/58/EC, 2006 OJ L 105, 13.04.2006, p. 54.
131 See the judgment of the CJEU of 8 April 2014, joined cases C-293/12 and C-594/12, Digital
Rights Ireland v Seitlinger, ECLI:EU:C:2014:238. In a similar vein, although relating to national
legislation which had transposed the data Retention Directive, see the judgment of the CJEU of
21 December 2016, joined cases C-203/15 and C-698/15, Tele2 Sverige AB v Secretary of State for
the Home Department, ECLI:EU:C:2016:970.
132 See the Singaporean National Report, Sect. 3.2.
133 See the Singaporean National Report, Sect. 3.2.
134 See article 15(5) of the Portuguese Cybercrime Law (Law section 109/2009, of
15 September 2009).
Data Protection in the Internet: General Report
27
Précédent

- 36/540

Suivant