Live, Die, Repeat: The fight against data retention and boundless access to data
Klaus Landefeld
39th Chaos Communication Congress (39C3): Power Cycles · Day 2 · Saal Zero
Overview
Klaus Landefeld's talk, "Live, Die, Repeat: The fight against data retention and boundless access to data," delves into the persistent and escalating battle against mandatory data retention policies, particularly within the European Union and globally. Landefeld, a long-time expert and advocate against such measures, highlights how legislative bodies continue to push for broader data collection and access powers for law enforcement, despite repeated rejections by the European Court of Justice (ECJ) and a lack of empirical evidence supporting their efficacy. The talk exposes the mechanisms through which these policies are being reintroduced and expanded, revealing significant implications for privacy, civil liberties, and cybersecurity.

Key moments
- 0:00 Introduction: History of EU data retention initiatives
- 1:30 ECJ abolishes first EU data retention directive (2014)
- 2:50 ECJ's 2022 ruling against general data retention
- 4:00 Persistence of national data retention laws (2023)
- 4:30 Shift to OTT services: Impact on data retention
- 6:05 International data storage and varied retention periods
- 7:35 Introduction of EU's cross-border e-evidence regulation (2023)
- 8:45 Broad scope of e-evidence: Who is affected?
Live, Die, Repeat: The fight against data retention and boundless access to data
Speakers: Klaus Landefeld
Conference: 39C3
YouTube: https://www.youtube.com/watch?v=Cq3OH5gUGLo
Overview
Klaus Landefeld's talk, "Live, Die, Repeat: The fight against data retention and boundless access to data," delves into the persistent and escalating battle against mandatory data retention policies, particularly within the European Union and globally. Landefeld, a long-time expert and advocate against such measures, highlights how legislative bodies continue to push for broader data collection and access powers for law enforcement, despite repeated rejections by the European Court of Justice (ECJ) and a lack of empirical evidence supporting their efficacy. The talk exposes the mechanisms through which these policies are being reintroduced and expanded, revealing significant implications for privacy, civil liberties, and cybersecurity.
The core of Landefeld's presentation is a critical analysis of new directives and conventions that facilitate cross-border access to electronic evidence, such as the EU's e-evidence regulation and the Second Additional Protocol to the Budapest Convention. He meticulously details how these frameworks, alongside a recent ECJ ruling on IP address retention, are creating a landscape where personal data—ranging from subscriber information to full content—can be accessed by a multitude of national and international authorities with alarming ease and minimal oversight. The talk serves as a stark warning about the atomization of surveillance measures that, when combined, lead to what Landefeld terms the "glass citizen" – a state of pervasive mass surveillance.
This article aims to unpack Landefeld's comprehensive analysis, providing a detailed technical and legal perspective on the current state of data retention. It explores the historical context, the specific legislative instruments, the technical vulnerabilities inherent in these systems, and the dire defensive implications for individuals and service providers. Ultimately, it underscores the urgent need for civil society to continue its uphill battle against policies that fundamentally undermine digital rights and security under the guise of crime fighting.
Background
▶ Watch: Introduction: History of EU data retention initiatives (0:00)
The struggle against data retention is a cyclical one, a theme Landefeld notes has re-emerged repeatedly since 2004. The initial push for mandatory data retention at the EU level began in the late 1990s with the "going dark" argument, where law enforcement claimed diminishing access to data due to the rise of internet services, contrasting it with their prior unfettered access to telecommunications data. This concern gained significant traction after 9/11, leading to a proposal in 2004 from France, Ireland, Sweden, and the UK.
This culminated in the EU Data Retention Directive in 2006, mandating all member states to implement national laws for retaining telecommunication data. This directive remained in force for eight years until April 2014, when it was abolished by the European Court of Justice (ECJ). Subsequent ECJ rulings in 2016, 2022, and 2023 consistently reiterated that national implementations requiring general and indiscriminate data retention are non-compliant with EU law and must be abolished.
Germany's experience mirrored this pattern. Its first iteration of data retention from 2007 to 2010 was abolished by the Federal Constitutional Court (Bundesverfassungsgericht). A second iteration, from 2015 to 2023, faced similar challenges. While the law existed, its implementation was stayed by courts, eventually leading to the ECJ ruling on September 20, 2022, that general retention is only permissible for national security and serious crime. Consequently, the German law was deemed non-conformant, though it technically remains on the books, unexecuted. Landefeld points out that despite the ECJ rulings, over 20 EU jurisdictions still retain some form of data retention in their laws, with many even amending them to become executable again after 2022.
A critical shift in the communication landscape underpins this debate: the migration from traditional telecommunication services to Over-The-Top (OTT) services. In 2001, over 90% of communication was access provider-based (email, telephone, SMS). By 2024, an astonishing 97% of all interpersonal communication occurs via OTT services like messenger apps, social networks, and web-based email. This shift renders traditional telco-focused data retention mandates largely meaningless for the vast majority of digital interactions. Even for telephony, where telcos still store data for billing purposes (3-12 months), specific mandatory data retention periods are often redundant.
Furthermore, digital services are increasingly international. Law enforcement traditionally relied on multilateral agreements for cross-border data access, a slow, paper-based process taking months. This delay often meant data was no longer available due to varying retention periods across jurisdictions. Some jurisdictions, particularly for business purposes, have no data retention limits, allowing providers (especially US companies) to store data "forever." Even GDPR's limits on storage are often overridden by national data retention laws. This creates a significant "jurisdictional arbitrage" problem: while Germany might debate a few months of retention, data from German users communicating via services hosted in Ireland could be retained for 12 months, or in Poland for five years, and be accessible to law enforcement under new regimes.
Key Findings
▶ Watch: ECJ's 2022 ruling against general data retention (2:50)
The central finding of Landefeld's talk is that despite repeated legal setbacks and a lack of proven effectiveness, the push for expansive data retention and boundless data access is not only continuing but evolving through new, more insidious legislative mechanisms. These efforts are characterized by an atomization of surveillance measures, where individual provisions appear less invasive but collectively enable mass surveillance.
Firstly, the EU's e-evidence directive and regulation, passed in 2023, fundamentally changes cross-border access to electronic evidence within the EU. It establishes a fully digital request system, mandatory for service providers to register by August 2026. Crucially, its scope extends beyond traditional telecommunication providers to include Internet infrastructure providers (DNS services, registration data, privacy/proxy services) and, most significantly, Information Society Service Providers. This broad category encompasses virtually any service where users communicate or data is processed for customers, including shop systems, gaming services, cloud providers, and file storage. This means law enforcement from one EU state can directly request data from a service provider in another EU state, bypassing traditional mutual legal assistance processes.
Secondly, the Second Additional Protocol to the Budapest Convention on Cybercrime represents an even broader international threat. Originating from 2001, the Budapest Convention has 81 signatory countries (with 51 signing the Second Protocol). This protocol, expected to be enacted by mid-2027, will allow law enforcement from these diverse countries to directly request data from service providers in other signatory states. Its scope is even wider than e-evidence, potentially covering financial data, administrative services, and even IP rights violations, which Landefeld highlights as a significant problem due to its lower severity threshold.
Thirdly, a pivotal development is the ECJ Hadoopi ruling in 2024. Landefeld describes this as a "significant battle lost" because the ECJ effectively separated IP address storage from service provider data storage. This ruling, unfortunately, re-energized the push for IP address retention across Europe. Legislators interpreted it as a green light to mandate IP address retention for all sorts of crimes, not just serious ones or national security threats. While the ECJ stipulated that IP data must be stored separately and not overlaid with service data by providers to create profiles, the underlying intent of law enforcement is clearly to combine these datasets, leading to mass surveillance.
Finally, Landefeld reveals the "wet dream list" of member states' proposals from a November 2023 presidency insight. This wish list includes:
- A minimum of 6 months IP data retention, extendable by national laws.
- Access for all sorts of criminal offenses.
- Mandatory service-level retention for all electronic services – telecommunication, OTT, DNS, VPN, cloud, file storage, financial services, online shops, gaming, hotels, taxi, food deliveries, and more – also for 6 months plus.
This comprehensive wish list, if implemented, would lead to pervasive surveillance, directly contradicting previous ECJ rulings against general and indiscriminate data retention and the prohibition of creating profiles of individuals. Landefeld argues there is no evidence that more than four weeks of data retention meaningfully increases case resolution for the vast majority of crimes, with current processes often streamlining within that timeframe.
Technical Deep Dive
▶ Watch: Shift to OTT services: Impact on data retention (4:30)
The new legislative landscape introduces several complex technical and operational challenges, alongside significant security vulnerabilities.
EU e-evidence Directive and Regulation (2023)
This framework aims to streamline cross-border access to electronic evidence within the EU.
- Deployment Model: It mandates a fully digital request system utilizing E-codex, a central platform for inter-state communication, which also handles other judicial exchanges (e.g., parking tickets, land ownership). National implementations will include web services for law enforcement and service providers, with larger providers able to connect via API.
- Affected Entities:
- Telecommunication and Electronic Communication Service Providers: Already accustomed to such demands.
- Internet Infrastructure Providers: DNS services, registration data, privacy/proxy services.
- Information Society Service Providers: A broad category encompassing any service facilitating user communication or storing/processing customer data, such as shop systems, gaming platforms, cloud services, and file storage.
- Data Categories and Access Levels:
- Subscriber Data: Can be requested by law enforcement without special provisions or judicial oversight.
- Traffic and Content Data: Requires a "serious offense" (minimum three-year maximum sentence) and a judge's signature. However, significant exceptions exist: if the offense is entirely cyber-related, terrorism-related, or involves Child Sexual Exploitation Material (CESM), content data can be requested irrespective of sentence length.
- Privacy Concerns and Technical Flaws:
- Protected Individuals: The directive theoretically protects data pertaining to lawyers, priests, journalists, and members of parliament. However, Landefeld highlights a critical flaw: law enforcement from a requesting country would have no way of knowing if an individual in another country holds such protected status. The responsibility to uphold this protection falls on the service provider's country, which further complicates verification, as the user's home country is not involved.
- Encryption: Service providers' requests for mandatory end-to-end encryption for all released evidence were rejected by some member states, citing the system's inherent security.
- Digital Signatures: While required, digital signatures for law enforcement requests are no longer verifiable by service providers because they have lost access to the Central Database (CDB) where participant information and encryption keys are stored. Service providers must supply their data to CDB but cannot query it.
- Language Barriers: Orders are typically signed in the requesting judge's native language. Machine translation of complex legal and technical terms is unreliable, creating ambiguity for service providers in other countries.
Budapest Convention's Second Additional Protocol
This protocol extends direct access to data beyond the EU.
- Scope: 81 countries have subscribed, with 51 signing the Second Additional Protocol, expected to be enacted by mid-2027. It allows law enforcement from signatory countries to directly request data from service providers in other signatory states.
- Broader Data Types: The scope is broader than e-evidence, potentially including financial data, administrative services, and requests related to intellectual property rights violations.
- Verification Issues: Unlike e-evidence, there is no provision for a central database to verify the legitimacy of requesting law enforcement agencies or judicial signatures. This creates a severe risk of impersonation. Landefeld notes that "docers" (individuals posing as law enforcement) already regularly attempt to gain access to data in the US, an "everyday occurrence" for major providers like Meta and Google.
- Encryption and Signatures: No provisions for end-to-end encryption of response data, and no requirement for digital signatures on orders. Some African countries, for instance, prefer data to be sent "as is," unencrypted, which directly conflicts with GDPR requirements for European service providers.
IP Address Data Retention Post-Hadoopi
The ECJ Hadoopi ruling (2024) has significantly impacted the landscape of IP address retention.
- Not Reduced Scope: Landefeld emphasizes that this is not a reduced scope but rather a continuation and expansion of existing IP data retention practices. Access providers have always stored IP addresses with timestamps for assignment.
- Increased Data Requirements: The new push requires an increased amount of data, including ports, MZ (mobile zone), and potentially other identifiers like MAC addresses, to ensure precise user identification.
- Separation and Use: While the ECJ ruled that IP data must be stored separately from service data and not used by the service provider to build user profiles, the intent of law enforcement is clearly to combine these datasets post-request. This data is now usable for all sorts of criminal offenses, potentially including IP rights violations, which is a major concern.
- Storage and Deletion: Data must be stored in "safe systems" and support "safe deletion," though the practical implications of these terms are unclear.
- Timeframes: Member states, in their "wet dream list," are advocating for a minimum of 6 months IP data retention, extendable by national laws, to accommodate existing longer periods in some countries (e.g., 12 months up to six years).
German Reintroduction of Data Retention (Third Iteration)
Germany is currently in its third iteration of data retention discussions.
- Limited to IP Data: The draft law (December 2023) specifically calls for IP address assignment retention only, including ports, location, MZ, and MAC addresses, without general service retention.
- Epoch PR (Preservation Order) Abuse: A critical concern is the transposition of the Epoch PR concept from e-evidence. While e-evidence's Epoch PR is for preserving existing data up until a request, the German draft law extends this to be forward-looking. This means law enforcement could request data preservation for future activities for 3-6 months based on a mere "risk" assessment, without demonstrating probable cause or requiring a judge's signature. This transforms a data preservation tool into a surveillance measure, bypassing judicial oversight.
Demo / Proof of Concept
▶ Watch: International data storage and varied retention periods (6:05)
Klaus Landefeld's talk did not include a live technical demonstration or a proof of concept. Instead, the presentation focused on dissecting the legal frameworks and highlighting theoretical, yet highly probable, systemic vulnerabilities and potential for abuse, which he categorizes as invitations to side-channel attacks.
Defensive Implications
▶ Watch: Broad scope of e-evidence: Who is affected? (8:45)
The legislative developments discussed by Landefeld carry profound defensive implications for individuals, service providers, and civil society at large. The core message is that these systems, while ostensibly designed to combat crime, are inherently insecure and will lead to pervasive surveillance and abuse.
Systemic Vulnerabilities and Side-Channel Attacks
Landefeld explicitly states that the entire system is "demonstrably unsecure" and that "hacks will happen." He outlines several critical vulnerabilities:
- Compromised Law Enforcement Accounts (e-evidence): Any compromised law enforcement account within the EU's e-evidence system can request all subscriber data from any service provider. If a judge's or court account is compromised, it can even request full content data, including cloud storage, social media streams, and emails. Landefeld notes that bribing officials, even judges in some countries, can be "shockingly cheap," potentially "single-digit thousands of euros" for access to competitor or adversary data. The EU itself has acknowledged the problem of organized crime bribing police in the context of drug wars.
- Scale and Complexity: The e-evidence system stretches across 27 countries, involves over 10,000 law enforcement agencies, and 400,000 service providers, each with diverse implementations. Securing such a vast, distributed system is practically impossible.
- Lack of Security Measures: There is no commitment to a zero-trust environment, meaning trust is assumed between participants. Crucially, there is no IDS (Intrusion Detection System) to monitor for abuse. The claim that the system is "secure by definition" is dismissed as a dangerous fallacy. Furthermore, the web interfaces and APIs for service providers are open to the internet, increasing their attack surface.
- Budapest Convention Verification Failure: The absence of a central database for verifying the legitimacy of requesting entities under the Second Additional Protocol to the Budapest Convention creates an open invitation for impersonation. Landefeld points out that "docers" already pose as law enforcement to gain data from major tech companies, describing it as an "everyday occurrence" for Meta and Google. Without a reliable verification mechanism, service providers are highly susceptible to fraudulent requests.
- Unencrypted Data Transmission: The lack of mandatory end-to-end encryption for data responses under the Budapest Convention poses a significant risk, especially for European service providers bound by GDPR, which prohibits sending unencrypted personal data.
The "Glass Citizen" and Mass Surveillance
The most alarming defensive implication is the inevitable creation of the "glass citizen" through the combination of various data retention and access measures.
- Overlay Problem: The talk highlights the fallacy of debating short retention periods (e.g., 3 months in Germany) when service data for the same users is retained for much longer in other jurisdictions (e.g., 12 months in Ireland) and is accessible via e-evidence. Law enforcement will simply access the longest-retained data available internationally, circumventing national protections.
- Profiling: The ECJ's Hadoopi ruling stipulated that service providers should not overlay service data with IP address data to create profiles. However, Landefeld argues that the legislative intent is clearly for law enforcement to do precisely that once they have collected the atomized data. By combining IP address retention (identifying the user) with service usage data from various providers (food delivery, gaming, social media, cloud storage), authorities can construct a comprehensive profile of an individual's digital life, effectively achieving mass surveillance.
- Atomized Measures vs. Collective Impact: States are enacting "atomized" individual legal provisions, each seemingly non-invasive on its own. However, when these measures are combined and overlaid, especially through automated international access, they create a system of pervasive surveillance that utterly fails the ECJ's tests against indiscriminate data retention and profiling.
- Uphill Battle for Civil Society: Demonstrating in court that these individual, atomized measures collectively lead to mass surveillance is an immense challenge for civil society. This requires proving the cumulative effect of disparate laws, often across different jurisdictions, against a backdrop of authorities claiming individual measures are permissible.
Defenders, including service providers and privacy advocates, must recognize the interconnectedness of these legislative efforts. The focus should not solely be on national laws but on the international interplay of data retention periods and cross-border access mechanisms. The inherent insecurity of these vast, distributed data access systems means that data will inevitably be compromised, either through direct hacking or through bribery and impersonation, making the "secure by definition" argument a dangerous illusion.
Key Takeaways
- Persistent Threat: Despite repeated ECJ rulings against general data retention, legislative bodies continue to reintroduce and expand surveillance measures, often through new, atomized legal provisions.
- Erosion of Borders: New EU (e-evidence) and international (Budapest Convention 2nd Protocol) frameworks enable direct, cross-border access to electronic evidence, significantly weakening national data protection.
- Broadened Scope: Data retention and access are no longer limited to telecommunication providers but now encompass virtually all "Information Society Service Providers," including cloud, gaming, e-commerce, and even food delivery services.
- IP Data Retention Resurgence: The ECJ Hadoopi ruling has reignited the push for mandatory IP address retention, now applicable for "all sorts of criminal offenses," including minor ones like IP rights violations, and requiring more granular data (ports, MZ).
- Systemic Insecurity: The proposed digital data access systems are inherently insecure due to their vast scale, lack of zero-trust architecture, absence of IDS, and vulnerability to compromised accounts, bribery, and impersonation, leading to inevitable data breaches and abuse.
- The "Glass Citizen": The combination of IP address retention with extended service data retention periods across multiple jurisdictions allows for the creation of comprehensive personal profiles, effectively leading to mass surveillance despite legal arguments against individual profiling.
About the Speaker(s)
Klaus Landefeld is a highly experienced and dedicated advocate against mandatory data retention. His involvement in this critical privacy issue spans decades, dating back to 1998 with the "going dark" discussions and his first presentation on the topic at Congress in 2004. He has been a pivotal figure in the fight against data retention in Germany, notably serving as an expert who helped abolish the first iteration of German data retention from 2007 to 2010. His deep understanding of the technical, legal, and political dimensions of data retention is evident in his detailed analysis. The talk also marked a personal milestone for Landefeld, celebrating his 20th anniversary of presenting at the Chaos Communication Congress.
All talks from 39th Chaos Communication Congress (39C3): Power Cycles