Overview of national data retention policies

From Freiheit statt Angst!

(Redirected from Transposition)
Jump to: navigation, search
Overview of national data retention policies

Contents


Please update this table by entering information on data retention in your country:

Data retention transposition schedule

Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] (EU directive)

no longer in force 6-24 months (formerly) directive, 15 March 2006

Directive's requirements:

  1. the calling telephone number;
  2. the name and address of the subscriber or registered user;
  3. the number(s) dialled (the telephone number(s) called), and, in cases involving supplementary services such as call forwarding or call transfer, the number or numbers to which the call is routed;
  4. the name(s) and address(es) of the destination subscriber(s) or registered user(s);
  5. the date and time of the start and end of the communication;
  6. the telephone service used;
  7. the calling and called telephone numbers;

Directive's requirements:

  1. the calling telephone number;
  2. the name and address of the subscriber or registered user;
  3. the number(s) dialled (the telephone number(s) called), and, in cases involving supplementary services such as call forwarding or call transfer, the number or numbers to which the call is routed;
  4. the name(s) and address(es) of the destination subscriber(s) or registered user(s);
  5. the date and time of the start and end of the communication;
  6. the telephone service used;
  7. the calling and called telephone numbers;
  8. the International Mobile Subscriber Identity (IMSI) of the calling party;
  9. the International Mobile Equipment Identity (IMEI) of the calling party;
  10. the IMSI of the called party;
  11. the IMEI of the called party;
  12. in the case of pre-paid anonymous services, the date and time of the initial activation of the service and the location label (Cell ID) from which the service was activated;
  13. the location label (Cell ID) at the start of the communication;
  14. data identifying the geographic location of cells by reference to their location labels (Cell ID) during the period for which communications data are retained.

Directive's requirements:

  1. the user ID(s) allocated;
  2. the user ID and telephone number allocated to any communication entering the public telephone network;
  3. the name and address of the subscriber or registered user to whom an Internet Protocol (IP) address, user ID or telephone number was allocated at the time of the communication;
  4. the name(s) and address(es) of the subscriber(s) or registered user(s) and user ID of the intended recipient of the communication;
  5. the date and time of the log-in and log-off of the Internet e-mail service or Internet telephony service, based on a certain time zone;
  6. the Internet service used;
  7. the calling telephone number for dial-up access;
  8. the digital subscriber line (DSL) or other end point of the originator of the communication;

Directive's requirements:

  1. the user ID(s) allocated;
  2. the user ID and telephone number allocated to any communication entering the public telephone network;
  3. the name and address of the subscriber or registered user to whom an Internet Protocol (IP) address, user ID or telephone number was allocated at the time of the communication;
  4. the date and time of the log-in and log-off of the Internet access service, based on a certain time zone, together with the IP address, whether dynamic or static, allocated by the Internet access service provider to a communication, and the user ID of the subscriber or registered user;
  5. the calling telephone number for dial-up access;
  6. the digital subscriber line (DSL) or other end point of the originator of the communication;

Directive's requirements:

  1. the user ID(s) allocated;
  2. the user ID and telephone number allocated to any communication entering the public telephone network;
  3. the name and address of the subscriber or registered user to whom an Internet Protocol (IP) address, user ID or telephone number was allocated at the time of the communication;
  4. the user ID or telephone number of the intended recipient(s) of an Internet telephony call;
  5. the name(s) and address(es) of the subscriber(s) or registered user(s) and user ID of the intended recipient of the communication;
  6. the date and time of the log-in and log-off of the Internet e-mail service or Internet telephony service, based on a certain time zone;
  7. the Internet service used;
  8. the calling telephone number for dial-up access;
  9. the digital subscriber line (DSL) or other end point of the originator of the communication;
-
providers of publicly available electronic communications services or of a public communications network
competent national authorities in specific cases for the purpose of the investigation, detection and prosecution of serious crime, as defined by each Member State in its national law
annulled in 2014 by EU Court of Justice EDRi
Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Austria

no









data retention legislation annulled by Constitutional Court in 2014 AK Vorrat
Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Belgium

12 months Reported:
  1. Loi du 21 mars 1991 portant réforme de certaines entreprises publiques économiques. Loi; Moniteur Belge , date pub: 27/03/1991 ; ref.: (MNE(2007)58028)
  2. Arrêté royal du 9 janvier 2003 portant exécution des articles 46bis, § 2, alinéa 1er, 88bis, § 2, alinéas 1er et 3, et 90quater, § 2, alinéa 3, du code d'instruction criminelle ainsi que de l'article 109ter, E, § 2, de la loi du 21 mars 1991 portant réforme de certaines entreprises publiques économiques. Arrêté royal; Moniteur Belge , date pub: 10/02/2003 ; ref.: (MNE(2007)58029)


Judicial coordination unit, examining magistrates, public prosecutor, criminal police for the investigation and prosecution of criminal offences, the prosecution of abuse of emergency services telephone number, investigation into malicious abuse of electronic communications network or service, for the purposes of intelligence-gathering missions undertaken by the intelligence and security services yes, by Liga voor Mensenrechten, Ligue des Droits de l’Homme, Ordre des barreaux francophones et germanophone Liga voor Mensenrechten, NURPA, Ligue des droits de l'Homme
Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Bulgaria

yes
12 months
Reported:
  1. Electronic Communications Act, promulgated in State Gazette No.41 as of May 22, 2007, amended State Gazette No.27 as of April 9,2010;;
  2. Regulation # 40 on the categories of data and the procedure under which they would be retained and disclosed by companies providing publicly available electronic communication networks and/or services for the needs of national security and crime investigation, promulgated in State Gazette No. 9 as of January 29, 2008, amended State Gazette No.108 as of December 19, 2008;

compulsory identification of users of prepaid SIM cards by name, address and EGN / passport number



Providers of public communications networks and/or publicly available electronic communications services The head officer of the:

1. Specialized departments, the local units and the independent territorial directorates within the State Agency for National Security; 2. Directorate General “Criminal Police”, Directorate General “Fight against organized crime” and its local units, Directorate General “Security”, Directorate General “Border Police”, directorate “Internal security”, Sofia Directorate of Internal affairs, the regional directorates within the MoI; 3. The Military Information Service and the “Military Police” within the Ministry of Defence; 4. National Intelligence Service The data is retained for the purposes of detection and investigation of serious crimes and crimes under Art. 319a - 319e of the Penal Code (cybercrimes), and for the location of missing or wanted persons. Access id granted only after a court warrant.

completed Access to Information Programme (AIP)
Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Cyprus

yes 6 months

Reported:

Ο Περί Διατήρησης Τηλεπικοινωνιακών Δεδομένων με Σκοπό τη Διεύρηνση Σοβαρών Ποινικών Αδικημάτων Νόμος του 2007. Νόμος , no.: Ν. 183(Ι)/2007; Cyprus Gazette , no.: 4154 , date pub: 31/12/2007 , page: 01466-01483 ; date into force/en vigueur: 31/12/2007 ; ref.: (MNE(2008)50638)







For investigation of a serious criminal offence Supreme Court ruled 1 Feb 2011 that retained data can only be accessed "in cases of convicted and unconvicted prisoners and business correspondence and communication of bankrupts during the bankruptcy administration" (Art. 17 of Constitution)
Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Czech Republic

yes, reimplementation as of November 2012 6 months Act 273/2012 Coll (amendment of the data retention acts)

public notice (adjustment circuit stored data, transmission of data etc.)


being considered Iuridicum Remedium (IuRe)
Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Denmark

yes
12 months

Reported:

  1. Bekendtgørelse om udbydere af elektroniske kommunikationsnets og elektroniske kommunikationstjenesters registrering og opbevaring af oplysninger om teletrafik. Bekendtgørelse , no.: 988; Lovtidende A , date pub: 13/10/2006 ; date into force/en vigueur: 15/09/2007 ; ref.: (MNE(2007)56962)
  2. Bekendtgørelse om udbydere af elektroniske kommunikationsnets og elektroniske kommunikationstjenesters registrering og opbevaring af oplysninger om teletrafik. Bekendtgørelse , no.: 988; Lovtidende A , date pub: 13/10/2006 ; date into force/en vigueur: 15/09/2007 ; ref.: (MNE(2007)56966)
  3. Bekendtgørelse om udbydere af elektroniske kommunikationsnets og elektroniske kommunikationstjenesters registrering og opbevaring af oplysninger om teletrafik (logningsbekendtgørelsen). Bekendtgørelse , no.: 988; Lovtidende A , date pub: 13/10/2006 ; date into force/en vigueur: 15/09/2007 ; ref.: (MNE(2007)56970)

first and last cell used during the communication to be retained
location of hotspots needs to be registered
Implementation applies even to non-public communication services except for public institutions
For the investigation and prosecution of criminal acts no
Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Estonia

yes, as of 01/01/2008 (Internet 15/03/2009) 12 months

Reported:

ELEKTROONILISE SIDE SEADUSE JA RAHVATERVISE SEADUSE MUUTMISE SEADUS. seaduse parandus , no.: RTI, 07.12.2007, 63, 397 ; Elektrooniline Riigi Teataja , no.: RTI, 07.12.2007, 63, 397 ; ref.: (MNE(2007)58607)








for criminal proceedings of a criminal offence [in the first degree or an intentionally committed criminal offence in second degree with a penalty of imprisonment of at least three years]

Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Finland

yes, as of 23/05/2008 (Internet 15/03/2009) 6-12 months Reported:
  1. Viestintäviraston määräys tunnistamistietojen tallennusvelvollisuudesta / Kommunikationsverkets föreskrift om skyldighet att lagra identifieringsuppgifter
  2. Laki sähköisen viestinnän tietosuojalain muuttamisesta / Lag om ändring av lagen om dataskydd vid elektronisk kommunikation

English translation


12 months
6 months 9 months
Only operators of certain size For investigating, detecting and prosecuting serious crimes as set out in Chapter 5a, Article 3(1) of the Coercive Measures Act no
Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] France

yes, as of 24/03/2006 12 months

Reported:

Décret no 2006-358 du 24 mars 2006 relatif à la conservation des données des communications électroniques. Décret , no.: 2006-358; Journal Officiel de la République Française (JORF) , date pub: 26/03/2006 ; date into force/en vigueur: 27/03/2006 ; ref.: (MNE(2007)56763)







For the detection, investigation, and prosecution of criminal offences, and for the purpose of providing judicial authorities with information needed, and for the prevention of acts of terrorism and protecting intellectual property No. A challenge was rejected by the Constitutional Court (decision of 07/08/2007). However, the Court decided providers must be reimbursed (decision of 07/08/2007).
Member State EU directive transposed? Data Retention Period Legal instruments and date of entry into force Data to be retained beyond the directive's requirements: fixed line telephony Data to be retained beyond the directive's requirements: mobile telephony Data to be retained beyond the directive's requirements: E-Mail Data to be retained beyond the directive's requirements: Internet access Data to be retained beyond the directive's requirements: Internet telephony Data to be retained beyond the directive's requirements: other Who is compelled to retain data? Who is authorised to access retained data and for what purposes? Legal challenges pending? Competent NGO

[edit] Germany

no (declared unconstitutional on 2 March 2010)

-

-

-

-

-

-

-

Any person providing or assisting in providing telecommunications services and in so doing allocating subscription IDs or providing telecommunications connections for IDs allocated by other parties (applies to telephony and DSL lines, including prepaid services, but not e-mail services) is to collect, prior to activation, and store the name and address of the allocation holder, the date of birth and in the case of fixed lines, additionally the address for the line, even if such data are not required for operational purposes (§ 111 TKG). The subscriber directories are electronically accessible by all German law enforcement and intelligence agencies (§ 112 TKG).

Working Group on Data Retention (AK Vorrat)

Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Greece

yes 12 months Data retention law no. 3917 dated 21-02-2011




providers of publicly available electronic communications services or public communications networks For the purpose of detecting particularly serious crimes

Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Hungary

yes 12 months Reported: 15 acts







To enable investigating bodies, the public prosecutor, the courts and national

security agencies to perform their duties, and to enable police and the National Tax and Customs Office to investigate intentional crimes carrying a prison term of two or more years

yes, Constitutional Court challenge brought by theHungarian Civil Liberties Union (HCLU)
Hungarian Civil Liberties Union (HCLU)
Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Ireland

Yes.

25 months phone records, 13 months Internet records (may be kept for up to 25 months). Communications (Retention of Data) Act 2011. Unsuccessful calls to be retained Unsuccessful calls to be retained For the prevention of serious offences (i.e. offences punishable by imprisonment for a term of 5 years or more, or an offence in schedule to the transposing law), safeguarding of the security of the state and the saving of human life. Data may be accessed
  • with consent of a person to whom data relates or
  • in accordance with a court order (including civil litigation) or
  • authorised by the Data Protection Commissioner or
  • Garda not below rank of Chief Superintendent or
  • Officer not below rank of colonel of Permanent Defence Force or
  • Officer of Revenue Commissioners not below rank of principal officer

yes, High Courtchallenge brought by DRI (latest updates), still pending

Digital Rights Ireland

See background on Irish law here.

Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Italy

yes
24 months, Internet 12 months

Reported:

Attuazione della direttiva 2006/24/CE riguardante la conservazione dei dati generati o trattati nell'ambito della fornitura di servizi di comunicazione elettronica accessibili al pubblico o di reti pubbliche di comunicazione e che modifica la direttiva 2002/58/CE.








For detecting and suppressing criminal offences

Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Latvia

yes, as of 07/06/2007 (Internet 15/02/2009) 18 months

Reported:

  1. Kārtība, kādā pirmstiesas izmeklēšanas iestādes, operatīvās darbības subjekti, valsts drošības iestādes, prokuratūra un tiesa pieprasa un elektronisko sakaru komersants nodod saglabājamos datus, kā arī kārtība, kādā apkopo statistisko informāciju par saglabājamo datu pieprasījumiem un to izsniegšanu. Ministru Kabineta noteikumi , no.: 820; Latvijas Vēstnesis , no.: 197 , date pub: 07/12/2007 ; date into force/en vigueur: 08/12/2007 ; ref.: (MNE(2008)50003)
  2. Grozījumi Elektronisko sakaru likumā. Likums; Latvijas Vēstnesis , no.: 83 , date pub: 24/05/2007 ; date into force/en vigueur: 07/06/2007 ; ref.: (MNE(2007)54265)







To protect state and public security or to ensure the investigation of criminal offences, criminal prosecution and criminal court proceedings

Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Lithuania

yes
6 months

Reported:

  1. Lietuvos Respublikos asmens duomenų teisinės apsaugos įstatymo pakeitimo įstatymas Nr. X-1444
  2. Lietuvos Respublikos elektroninių ryšių įstatymas Nr. IX-2135







For the investigation, detection and prosecution of serious and very serious crimes, as defined by the Lithuanian Criminal Code

Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Luxemburg

yes 6 months

Reported:

Loi concernant la protection de la vie privée dans le secteur des communications électroniques

Règlement grand-ducal du 24 juillet 2010 déterminant les catégories de données à caractère personnel générées ou traitées dans le cadre de la fourniture de services de communications électroniques ou de réseaux de communications publics








For the detection, investigation, and prosecution of criminal offences carrying a criminal sentence of a maximum one year or more

Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Malta

yes
12 months, Internet 6 months

Reported:

  1. L.N. 198 of 2008 Data Protection Act (Cap. 440) Processing of Personal Data(Electronic Communications Sector) (Amendment) Regulations, 2008
  2. L.N. 199 of 2008 Electronic Communications (Regulation) Act (CAP. 399)Electronic Communications (Personal Data and Protection of Privacy) (Amendment) Regulations, 2008








For investigation, detection or prosecution of serious crime

Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Netherlands

Yes 12 months for telephony, 6 months for Internet communications Wet bewaarplicht telecommunicatiegegevens, passed Senate on 7 July 2009 No.






For investigation and prosecution of serious offences for which custody may be imposed. No review by court or some independent body prior to the access to the data. No obligation to notify (afterwards) the subscriber whose data has been accessed.

Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Poland

yes
12 months 1. The Telecommunication Law Amendment of 24 April 2009 (Journal Od Laws of 2009, No.85 item 716).
2.The Regulation of the Minister of Infrastructure of 28 December 2009 on a detailed specification of data and types of operators of public telecommunications networks or providers of publicly available telecommunications services obliged for its retention and storage, Journal of Laws of 2009, No 226 item 1828, went into force on 1 January 2010.
unsuccessful call attempts unsuccessful call attempts, data identifying beam and working range of antenna of BTS



No court order required. Six secret services, police, courts and prosecution have a right to request data. For the prevention or detection of crime (even if not serious), for prevention and detection of fiscal offences, for use by prosecutors and courts if relevant to the court proceedings pending, for the purpose of the Internal Security Agency, Foreign Intelligence Agency, Central Anti-Corruption Bureau, Military Counter-intelligence Services and Military Intelligence Services to perform their tasks no Panoptykon
Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Portugal

yes, as of 08/2009 12 months

Reported:

Assembleia da República-Transpõe para a ordem jurídica interna a Directiva n.º 2006/24/CE, do Parlamento Europeu e do Conselho, de 15 de Março, relativa à conservação de dados gerados ou tratados no contexto da oferta de serviços de comunicações electrónicas publicamente disponíveis ou de redes públicas de comunicações








For the investigation, detection and prosecution of serious crime

Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Romania

no, as of 2014








data retention legislation annulled by Constitutional Court in 2014 APTI

Comisariatul pentru Societatea Civila

Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Slovakia

yes, but suspended in 2014 by Constitutional Court 12 months, 6 months for Internet services

Reported: many








For the prevention, investigation, detection and prosecution of criminal offences yes, the Constitutional Court has preliminary suspended the law in April 2014 European Information Society Institute (EISI)
Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Slovenia

no






data retention legislation annulled by Constitutional Court in 2014
Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Spain

yes, as of 09/11/2007 12 months; can be reduced or extended to a minimum of 6 months and a maximum of 24 months, on request of the compentent authorities

Reported:

LEY 25/2007, de 18 de octubre, de conservación de datos relativos a las comunicaciones electrónicas y a las redes públicas de comunicaciones. Ley , no.: 25/2007; Boletín Oficial del Estado ( B.O.E ) , no.: 251/2007 , date pub: 19/10/2007 , page: 42517-42523 ; date into force/en vigueur: 08/11/2007 ; ref.: (MNE(2007)57464)

None
None
None
None
None
None
same as the Directive: telecomunications providers; los operadores que presten servicios de comunicaciones electrónicas disponibles al público o exploten redes públicas de comunicaciones (art.2)
All Police/Security forces when acting under an order of the Attorney General or Courts of Justice

Miembros de las Fuerzas y Cuerpos de Seguridad del Estado, cuando desempeñen funciones de Policia Judicial (art.6.2.a)

Funcionarios de la Dirección Adjunta de Vigilancia Aduanera, en el desarrollo de sus competencias como policía judicial (art.6.2.b)

El personal del Centro Nacional de Inteligencia en el curso de investigaciones de seguridad sobre personas o entidades (art.6.2.c)

For the detection, investigation and prosecution of the serious crimes considered in the Criminal Code or in the special criminal laws

None (as yet)
Access Info Europe (http://www.access-info.org/en/civil-liberties)

Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Sweden

yes, as of May 2012 6 months









New Renaissance
Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] United Kingdom

yes, as of 26/07/2007 (Internet 06/04/2009) 12 months

Reported:

The Data Retention (EC Directive) Regulations 2007. Statutory instrument (SI) , no.: Statutory Instrument 20; Her Majesty's Stationery Office (HMSO) , no.: ISBN 978 0 11 078328 4 ; date into force/en vigueur: 01/10/2007 ; ref.: (MNE(2007)57200)

The Data Retention (EC Directive) Regulations 2009. Statutory instrument (SI), number: 2009 no 859; Official Journal: Her Majesty's Stationery Office (HMSO), number: SI 2009 no 859, Entry into force: 06/04/2009; Reference: (MNE(2010)53135)








For the investigation, detection and prosecution of serious crime

Non-EU- State
Data retention implemented ?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Iceland

yes
Telecommunication Act 81/2003 (as amended in April 2005)









Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Liechtenstein

yes 6 months Telekommunikationsgesetz (2006)









Member State
EU directive transposed?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Norway

no, law enacted in April 2012 has never been implemented








planned digitaltpersonvern.no
Non-EU-State
Data retention implemented ?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Switzerland

yes, as of 2002 6 months




Buyers of prepaid mobile phone cards must be identified and registered by ID document (name, address, date of birth). According to a court decision, web server access logs including IP addresses must be retained for 6 months. operators of fixed line and mobile telephony, public ip-based telecommunications services
no
Non-EU-State
Data retention implemented ?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

[edit] Turkey

Censorship & Data retention regulated by Law 5651 in 2007 6 months to 2 years Phone lines are tapped by police and used as 'evidence' for prosecuting activities vaguely associated with 'terrorist organizations', based on anti-terror law TMK.
Mobile phones are tapped for the same reason. They also secretly record 'audio surveillance' from meetings of legal parties, unions, even mayor's office, state institutions.
E-mails can also be used as 'evidence', but not used as much as audio surveillance and phone tapping, yet. ICTA develops DPI systems, considers it 'state secret'.
Law 5651 requires every ISP to block any illegal content of any user upon being informed, if technically possible. It has to inform ICTA 3 months before closing down, and give the traffic records to ICTA (state authority)
Same with e-mail. Yet to come.
MOBESE is the system of police department where they collect all kinds of data for every citizen. They randomly make 'identity controls' on the street. Officers gain 'points' for doing so. Internet service providers, GSM operators. internet publishers, if they don't want to take responsibility. 'Data protection law' is being 'prepared' for over 10 years, so god knows who. Law 5397 authorizes the national intelligence agency MIT to request data and documents about "issues in its field of duty"
Social challenges pending! More so than legal challenges. Alternative Informatics Association english presentation in CCC


Please update this table by entering information on data retention in your country:

[edit] See also

Personal tools
Toolbox
  • What links here
  • Related changes
  • Upload file
  • Special pages
  • Printable version