On Monday, the 6th of July, Front-LEX filed a complaint with the European Data Protection Supervisor (‘EDPS’), the independent authority responsible for supervising the right to data protection at EU agencies, against the European Union Agency for Law Enforcement Cooperation (‘Europol’).

A journalistic investigation published by the media outlets Solomon, Correctiv, and Computer Weekly, revealed “[f]or the first time in the agency’s history, several former high-ranking officials have come forward to reveal that elements of this shadow environment […] appear to have been concealed for years from” the EDPS. The complaint provides prima facie evidence that Europol has been unlawfully and secretly operating parallel processing environments for years, in which there are prima facie evidence that the complainant’s data have been processed.

Europol has given several names to those parallel processing environments for the last ten years: Computer Forensic Network, Internet Facing Operational Environment, Pressure Cooker, the current pilot, and Internet Facing Operational Environment Quick Reaction Area. But what those systems have in common is that they operate alongside Europol Operational Network (‘OPS NET’), without due diligence design and/or basic and proper Information and Communication Technology (ICT) controls relating to the access, logging, and processing of personal data. A former senior Europol official told journalists that the agency has grown accustomed to it because “having a parallel processing environment where guardrails cease to exist is cheaper, faster, and more effective.”

The EDPS has failed to uncover those parallel systems and identify the scale of Europol’s unlawful conduct in cases where Europol consulted the supervisory authority with partial information, and when it was tasked by individuals to act on their behalf to verify that the agency was storing lawful and accurate information about them. The complainants see no other option for accessing their files but to ask the EDPS to impose a temporary or definitive ban on the parallel processing environments.

Even in the case Europol would dare to claim that it is technically possible to retrieve personal data on the complainants, the nature of the parallel environments and the lack of control over who accesses them and what they can do means that any information stored about a person could have been modified, kept in another form or generated by an automated system without explanation about how it has been produced. It makes it impossible for anyone to trust the accuracy of the data the agency shares.

Asking for access to Europol’s data is futile until the parallel environments are banned. The EDPS has so far been having “polite conversations” with the agency in investigating its processing environments, which falls far short of what it can do and what it should do to guarantee that individuals’ right of access is granted to the fullest extent by Europol. If the EDPS refuses to follow up on our request, we will file an annulment request with the CJEU within three months.

 

Presentation of the complainants:

The complainants, represented by Front-LEX, are only part of a larger group of individuals, particularly migrants, who could have brought a case against the EDPS and Europol for mishandling their data and failing to monitor the agency’s wrongdoings. The decision to ban the parallel processing environments will benefit all individuals who suffered from unjust criminalisation facilitated by Europol.

First Complainant:

Frank van der Linde is a political activist who has sought access to his file at Europol for the last six years, including by filing a complaint with the EDPS. A former Europol official affirmed in the journalistic investigation that Europol processed the activist data in one of the parallel processing environments and deliberately concealed from the EDPS data processed about Mr. van der Linde. Despite numerous instances in the investigation where the EDPS should have been alerted to the unlawful conduct of Europol in dealing with the activist data, and came close to uncovering its processing in a parallel environment, he has failed to provide a response to the data subject’s request after a six-year-long investigation.

Second Complainant:

Natalie Gruber is the former President of Josoor International Solidarity, a human rights defender who has been criminalised by Greece for her work assisting in the rescue of people seeking refuge in Europe and denouncing pushbacks. Europol is storing data about Mrs Gruber because she was accused of “forcing the rescue of people”, a crime we failed to identify in the mandate of the agency, which should only be dealing with serious and real crime. The complainant sought an explanation from the EDPS about Europol’s processing of her data, including the possibility that Frontex forwarded information about the applicant organisation through debriefing interviews in Greece. The vagueness in Europol’s response to Ms. Gruber and the fact that, due to its limited competence, the agency lacked the legal authority to access and process data about her suggest that the applicant’s data could be stored in parallel environments.

Third Complainant:

David Yambio, is the president of Refugee in Libya, a migrant-led organisation that defends the rights of refugees and people on the move in Libya and in Europe. He suspects that Frontex has been sharing information about him and his organisation with Europol, which would have been stored in the parallel system. Mr Yambio’s vocal denunciation of Europe’s collaboration with the Libyan Coast Guard also made him the victim of a spyware attack, allegedly from Italy. If the Member State concerned had shared with Europol datasets extracted from the complainant’s phone, those datasets would likely have required the high-volume forensic processing capacities associated with Europol’s CFN.

 

Quotes from the complainants:

David Yambio, President of Refugees in Libya (NGO, Italy):

“What I know is this: in 2023–2024, the Italian intelligence services were already spying on me, and in 2024 my phone was targeted by a spyware attack. This happened while I was speaking out as loudly as I could against Meloni’s role in enabling Almasri to flee the country and evade justice. The Italian Government denied responsibility for hacking my phone. It did, however, allude to criminal proceedings concerning me – although, to date, I have found no evidence that any such proceedings exist. What I do not know is this: how much of the personal data hacked from my phone, or of the information unlawfully obtained by Frontex from asylum seekers it “debriefed” immediately after their disembarkation on Lampedusa and along other parts of the Sicilian coast, was then unlawfully processed by Europol through its secretive parallel systems. For as long as theEDPS allows these unlawful systems to remain in place, I remain exposed not only to further intimidation and attempts to criminalise me, but also unable to exercise my right of access to the information Europol is processing about me.”

 

Natalie Gruber

“For years, I lived under the threat and with the consequences of a criminal investigation that should never have happened. When that investigation finally collapsed, I still could not move on because the Greek authorities’ defamation campaign reached Europol. Trying to clear my name, I was not met with transparency but with years of secrecy, delays, and incomplete answers. The revelations about Europol’s parallel data-processing systems only reinforced my concern that the agency has been shielding not only unlawful practices by Member States, but also its own unlawful processing from meaningful oversight. European citizens should be deeply concerned by the steady erosion of the rule of law in the name of security. The EDPS now has both the opportunity and the duty to bring these unlawful practices to an end.”

 

Frank van der Linde

“Constantly finding out that there is more data being processed about me frightens me a lot. Hopefully, the EPDS acts fast now, and the illegal data processing stops.”

 

Quote from Front-LEX Legal Team:

“In a European Union with a functioning Data Protection Supervisor, our complaint would not have had to be brought. The complaints rely on a meticulous journalistic investigation, evidence consisting of leaked Europol emails and documents, as well as the EDPS’ own decisions and opinions. The EDPS has failed for more than ten years to investigate the functioning of those parallel shadow environments and to impose a temporary or definitive ban on them, in accordance with its powers. The legislator did not confer such far-reaching powers on the EDPS for no reason. We are now offering him the opportunity to act in accordance with his duties, and if he fails to do so, we will bring the matter before the Court.”

 

Authors of the complaint:

Advocate Iftach Cohen, Co-Director
Advocate Spyridoula Katsoni, Senior Legal Advisor
Romain Lanneau, Legal advisor