BRIEFING
Setting spyware standards after the Pegasus scandal SUMMARY In June 2023, following its investigation into Europe's spyware scandal, the European Parliament issued a final recommendation identifying country-specific shortcomings and proposing EU standards for the use of spyware. In line with EU competences, Parliament proposes a narrow focus for its spyware surveillance standards, limiting them to law enforcement activities. Among these spyware surveillance standards, Parliament proposed a range of safeguards, including prior judicial approval, necessity and proportionality requirements, strong and independent post-surveillance oversight, the duty to notify targeted persons and other persons concerned, access to redress and meaningful remedies, and data deletion requirements. Member States embroiled in the spyware scandal are making progress – albeit uneven – towards meeting these standards. Greece has amended its intelligence law in the wake of the spyware scandal, but it remains to be seen whether it will address outstanding shortcomings. Spain has announced further efforts to strengthen its legal framework, although Parliament considered the country's legal framework fundamentally compliant. Rule of law concerns persist in Hungary. Poland is investigating the alleged spyware abuses thoroughly, and is making decisive efforts to improve its legal framework.
IN THIS BRIEFING Introduction European Parliament spyware recommendation EU competences for setting spyware surveillance standards Parliament's spyware surveillance standards State of play of national implementation
EPRS | European Parliamentary Research Service Author: Hendrik Mildebrath Members' Research Service PE 766.262 – November 2024
EN