Overview of national data retention policies

Aus Freiheit statt Angst!
(Weitergeleitet von Transposition)
Zur Navigation springen Zur Suche springen

Overview of national data retention policies (outdated, for updates see below)

Please update this table by entering information on data retention in your country:

Data retention transposition schedule

Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

(EU directive)

no longer in force 6-24 months (formerly) directive, 15 March 2006

Directive's requirements:

  1. the calling telephone number;
  2. the name and address of the subscriber or registered user;
  3. the number(s) dialled (the telephone number(s) called), and, in cases involving supplementary services such as call forwarding or call transfer, the number or numbers to which the call is routed;
  4. the name(s) and address(es) of the destination subscriber(s) or registered user(s);
  5. the date and time of the start and end of the communication;
  6. the telephone service used;
  7. the calling and called telephone numbers;

Directive's requirements:

  1. the calling telephone number;
  2. the name and address of the subscriber or registered user;
  3. the number(s) dialled (the telephone number(s) called), and, in cases involving supplementary services such as call forwarding or call transfer, the number or numbers to which the call is routed;
  4. the name(s) and address(es) of the destination subscriber(s) or registered user(s);
  5. the date and time of the start and end of the communication;
  6. the telephone service used;
  7. the calling and called telephone numbers;
  8. the International Mobile Subscriber Identity (IMSI) of the calling party;
  9. the International Mobile Equipment Identity (IMEI) of the calling party;
  10. the IMSI of the called party;
  11. the IMEI of the called party;
  12. in the case of pre-paid anonymous services, the date and time of the initial activation of the service and the location label (Cell ID) from which the service was activated;
  13. the location label (Cell ID) at the start of the communication;
  14. data identifying the geographic location of cells by reference to their location labels (Cell ID) during the period for which communications data are retained.

Directive's requirements:

  1. the user ID(s) allocated;
  2. the user ID and telephone number allocated to any communication entering the public telephone network;
  3. the name and address of the subscriber or registered user to whom an Internet Protocol (IP) address, user ID or telephone number was allocated at the time of the communication;
  4. the name(s) and address(es) of the subscriber(s) or registered user(s) and user ID of the intended recipient of the communication;
  5. the date and time of the log-in and log-off of the Internet e-mail service or Internet telephony service, based on a certain time zone;
  6. the Internet service used;
  7. the calling telephone number for dial-up access;
  8. the digital subscriber line (DSL) or other end point of the originator of the communication;

Directive's requirements:

  1. the user ID(s) allocated;
  2. the user ID and telephone number allocated to any communication entering the public telephone network;
  3. the name and address of the subscriber or registered user to whom an Internet Protocol (IP) address, user ID or telephone number was allocated at the time of the communication;
  4. the date and time of the log-in and log-off of the Internet access service, based on a certain time zone, together with the IP address, whether dynamic or static, allocated by the Internet access service provider to a communication, and the user ID of the subscriber or registered user;
  5. the calling telephone number for dial-up access;
  6. the digital subscriber line (DSL) or other end point of the originator of the communication;

Directive's requirements:

  1. the user ID(s) allocated;
  2. the user ID and telephone number allocated to any communication entering the public telephone network;
  3. the name and address of the subscriber or registered user to whom an Internet Protocol (IP) address, user ID or telephone number was allocated at the time of the communication;
  4. the user ID or telephone number of the intended recipient(s) of an Internet telephony call;
  5. the name(s) and address(es) of the subscriber(s) or registered user(s) and user ID of the intended recipient of the communication;
  6. the date and time of the log-in and log-off of the Internet e-mail service or Internet telephony service, based on a certain time zone;
  7. the Internet service used;
  8. the calling telephone number for dial-up access;
  9. the digital subscriber line (DSL) or other end point of the originator of the communication;
-
providers of publicly available electronic communications services or of a public communications network
competent national authorities in specific cases for the purpose of the investigation, detection and prosecution of serious crime, as defined by each Member State in its national law
annulled in 2014 by EU Court of Justice EDRi
Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Austria

no









data retention legislation annulled by Constitutional Court in 2014 AK Vorrat
Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Belgium

12 months Electronic Telecommunications Act, 13th June 2005

Judicial coordination unit, examining magistrates, public prosecutor, criminal police for the investigation and prosecution of criminal offences, the prosecution of abuse of emergency services telephone number, investigation into malicious abuse of electronic communications network or service, for the purposes of intelligence-gathering missions undertaken by the intelligence and security services EU Court of Justice (pending): Reference of 2 August 2018 on Belgian data retention law (Ordre des barreaux francophones and germanophone) Liga voor Mensenrechten, NURPA, Ligue des droits de l'Homme / Ordre des barreaux francophones and germanophone
Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Bulgaria

yes 6 months Data retention law annulled by Constitutional Court in March 2015 but reinacted on 26 Mar




completed Access to Information Programme (AIP)
Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Cyprus

yes 6 months

Reported:

Ο Περί Διατήρησης Τηλεπικοινωνιακών Δεδομένων με Σκοπό τη Διεύρηνση Σοβαρών Ποινικών Αδικημάτων Νόμος του 2007. Νόμος , no.: Ν. 183(Ι)/2007; Cyprus Gazette , no.: 4154 , date pub: 31/12/2007 , page: 01466-01483 ; date into force/en vigueur: 31/12/2007 ; ref.: (MNE(2008)50638)







For investigation of a serious criminal offence Supreme Court ruled 1 Feb 2011 that retained data can only be accessed "in cases of convicted and unconvicted prisoners and business correspondence and communication of bankrupts during the bankruptcy administration" (Art. 17 of Constitution)
Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Czech Republic

yes, reimplementation as of November 2012 6 months Act 273/2012 Coll (amendment of the data retention acts)

public notice (adjustment circuit stored data, transmission of data etc.)


being considered Iuridicum Remedium (IuRe)
Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Denmark

yes
12 months

Reported:

  1. Bekendtgørelse om udbydere af elektroniske kommunikationsnets og elektroniske kommunikationstjenesters registrering og opbevaring af oplysninger om teletrafik. Bekendtgørelse , no.: 988; Lovtidende A , date pub: 13/10/2006 ; date into force/en vigueur: 15/09/2007 ; ref.: (MNE(2007)56962)
  2. Bekendtgørelse om udbydere af elektroniske kommunikationsnets og elektroniske kommunikationstjenesters registrering og opbevaring af oplysninger om teletrafik. Bekendtgørelse , no.: 988; Lovtidende A , date pub: 13/10/2006 ; date into force/en vigueur: 15/09/2007 ; ref.: (MNE(2007)56966)
  3. Bekendtgørelse om udbydere af elektroniske kommunikationsnets og elektroniske kommunikationstjenesters registrering og opbevaring af oplysninger om teletrafik (logningsbekendtgørelsen). Bekendtgørelse , no.: 988; Lovtidende A , date pub: 13/10/2006 ; date into force/en vigueur: 15/09/2007 ; ref.: (MNE(2007)56970)

first and last cell used during the communication to be retained
location of hotspots needs to be registered
Implementation applies even to non-public communication services except for public institutions
For the investigation and prosecution of criminal acts no
Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Estonia

yes, as of 01/01/2008 (Internet 15/03/2009) 12 months

Reported:

ELEKTROONILISE SIDE SEADUSE JA RAHVATERVISE SEADUSE MUUTMISE SEADUS. seaduse parandus , no.: RTI, 07.12.2007, 63, 397 ; Elektrooniline Riigi Teataja , no.: RTI, 07.12.2007, 63, 397 ; ref.: (MNE(2007)58607)








for criminal proceedings of a criminal offence [in the first degree or an intentionally committed criminal offence in second degree with a penalty of imprisonment of at least three years]

Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Finland

yes, as of 23/05/2008 (Internet 15/03/2009) 6-12 months Reported:
  1. Viestintäviraston määräys tunnistamistietojen tallennusvelvollisuudesta / Kommunikationsverkets föreskrift om skyldighet att lagra identifieringsuppgifter
  2. Laki sähköisen viestinnän tietosuojalain muuttamisesta / Lag om ändring av lagen om dataskydd vid elektronisk kommunikation

English translation


12 months
6 months 9 months
Only operators of certain size For investigating, detecting and prosecuting serious crimes as set out in Chapter 5a, Article 3(1) of the Coercive Measures Act no
Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

France

yes, as of 24/03/2006 12 months

Reported:

Décret no 2006-358 du 24 mars 2006 relatif à la conservation des données des communications électroniques. Décret , no.: 2006-358; Journal Officiel de la République Française (JORF) , date pub: 26/03/2006 ; date into force/en vigueur: 27/03/2006 ; ref.: (MNE(2007)56763)







For the detection, investigation, and prosecution of criminal offences, and for the purpose of providing judicial authorities with information needed, and for the prevention of acts of terrorism and protecting intellectual property EU Court of Justice (pending): Reference of 3 August 2018 on French data retention law La Quadrature du Net and others
Member State Data retention in force? Data Retention Period Legal instruments and date of entry into force Data to be retained beyond the directive's requirements: fixed line telephony Data to be retained beyond the directive's requirements: mobile telephony Data to be retained beyond the directive's requirements: E-Mail Data to be retained beyond the directive's requirements: Internet access Data to be retained beyond the directive's requirements: Internet telephony Data to be retained beyond the directive's requirements: other Who is compelled to retain data? Who is authorised to access retained data and for what purposes? Legal challenges pending? Competent NGO

Germany

Legislation in force, but currently not being applied due to court order

4 to 10 weeks

Telecommunications Act, Art. 113b

-

main direction of mobile telephone antennas

(not covered)

-

-

Any person providing or assisting in providing telecommunications services and in so doing allocating subscription IDs or providing telecommunications connections for IDs allocated by other parties (applies to telephony and DSL lines, including prepaid services, but not e-mail services) is to collect, prior to activation, and store the name and address of the allocation holder, the date of birth and in the case of fixed lines, additionally the address for the line, even if such data are not required for operational purposes (§ 111 TKG). The subscriber directories are electronically accessible by all German law enforcement and intelligence agencies (§ 112 TKG).

providers of publicly accessible telecommunications services for end user

  1. the police, courts and public prosecutors for the prosecution of crime
  2. the police for the prevention of substantial dangers to public safety
  3. secret services for intelligence purposes (IP addresses)

yes, several complaints with the Federal Constitutional Court

Working Group on Data Retention (AK Vorrat), Digitalcourage and others

Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Greece

yes 12 months Data retention law no. 3917 dated 21-02-2011




providers of publicly available electronic communications services or public communications networks For the purpose of detecting particularly serious crimes

Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Hungary

yes 12 months Reported: 15 acts







To enable investigating bodies, the public prosecutor, the courts and national

security agencies to perform their duties, and to enable police and the National Tax and Customs Office to investigate intentional crimes carrying a prison term of two or more years

yes, Constitutional Court challenge brought by theHungarian Civil Liberties Union (HCLU)
Hungarian Civil Liberties Union (HCLU)
Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Ireland

Yes.

25 months phone records, 13 months Internet records (may be kept for up to 25 months). Communications (Retention of Data) Act 2011. Unsuccessful calls to be retained Unsuccessful calls to be retained For the prevention of serious offences (i.e. offences punishable by imprisonment for a term of 5 years or more, or an offence in schedule to the transposing law), safeguarding of the security of the state and the saving of human life. Data may be accessed
  • with consent of a person to whom data relates or
  • in accordance with a court order (including civil litigation) or
  • authorised by the Data Protection Commissioner or
  • Garda not below rank of Chief Superintendent or
  • Officer not below rank of colonel of Permanent Defence Force or
  • Officer of Revenue Commissioners not below rank of principal officer

yes, High Courtchallenge brought by DRI (latest updates), still pending

Digital Rights Ireland

See background on Irish law here.

Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Italy

yes
24 months, Internet 12 months

Reported:

Attuazione della direttiva 2006/24/CE riguardante la conservazione dei dati generati o trattati nell'ambito della fornitura di servizi di comunicazione elettronica accessibili al pubblico o di reti pubbliche di comunicazione e che modifica la direttiva 2002/58/CE.








For detecting and suppressing criminal offences

Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Latvia

yes, as of 07/06/2007 (Internet 15/02/2009) 18 months

Reported:

  1. Kārtība, kādā pirmstiesas izmeklēšanas iestādes, operatīvās darbības subjekti, valsts drošības iestādes, prokuratūra un tiesa pieprasa un elektronisko sakaru komersants nodod saglabājamos datus, kā arī kārtība, kādā apkopo statistisko informāciju par saglabājamo datu pieprasījumiem un to izsniegšanu. Ministru Kabineta noteikumi , no.: 820; Latvijas Vēstnesis , no.: 197 , date pub: 07/12/2007 ; date into force/en vigueur: 08/12/2007 ; ref.: (MNE(2008)50003)
  2. Grozījumi Elektronisko sakaru likumā. Likums; Latvijas Vēstnesis , no.: 83 , date pub: 24/05/2007 ; date into force/en vigueur: 07/06/2007 ; ref.: (MNE(2007)54265)







To protect state and public security or to ensure the investigation of criminal offences, criminal prosecution and criminal court proceedings

Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Lithuania

yes
6 months

Reported:

  1. Lietuvos Respublikos asmens duomenų teisinės apsaugos įstatymo pakeitimo įstatymas Nr. X-1444
  2. Lietuvos Respublikos elektroninių ryšių įstatymas Nr. IX-2135







For the investigation, detection and prosecution of serious and very serious crimes, as defined by the Lithuanian Criminal Code

Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Luxemburg

yes 6 months

Reported:

Loi concernant la protection de la vie privée dans le secteur des communications électroniques

Règlement grand-ducal du 24 juillet 2010 déterminant les catégories de données à caractère personnel générées ou traitées dans le cadre de la fourniture de services de communications électroniques ou de réseaux de communications publics








For the detection, investigation, and prosecution of criminal offences carrying a criminal sentence of a maximum one year or more

Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Malta

yes
12 months, Internet 6 months

Reported:

  1. L.N. 198 of 2008 Data Protection Act (Cap. 440) Processing of Personal Data(Electronic Communications Sector) (Amendment) Regulations, 2008
  2. L.N. 199 of 2008 Electronic Communications (Regulation) Act (CAP. 399)Electronic Communications (Personal Data and Protection of Privacy) (Amendment) Regulations, 2008








For investigation, detection or prosecution of serious crime

Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Netherlands

no Court annulled data retention law in March 2015








Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Poland

yes
12 months 1. The Telecommunication Law Amendment of 24 April 2009 (Journal Od Laws of 2009, No.85 item 716).
2.The Regulation of the Minister of Infrastructure of 28 December 2009 on a detailed specification of data and types of operators of public telecommunications networks or providers of publicly available telecommunications services obliged for its retention and storage, Journal of Laws of 2009, No 226 item 1828, went into force on 1 January 2010.
unsuccessful call attempts unsuccessful call attempts, data identifying beam and working range of antenna of BTS



No court order required. Six secret services, police, courts and prosecution have a right to request data. For the prevention or detection of crime (even if not serious), for prevention and detection of fiscal offences, for use by prosecutors and courts if relevant to the court proceedings pending, for the purpose of the Internal Security Agency, Foreign Intelligence Agency, Central Anti-Corruption Bureau, Military Counter-intelligence Services and Military Intelligence Services to perform their tasks no Panoptykon
Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Portugal

yes, as of 08/2009 12 months

Reported:

Assembleia da República-Transpõe para a ordem jurídica interna a Directiva n.º 2006/24/CE, do Parlamento Europeu e do Conselho, de 15 de Março, relativa à conservação de dados gerados ou tratados no contexto da oferta de serviços de comunicações electrónicas publicamente disponíveis ou de redes públicas de comunicações








For the investigation, detection and prosecution of serious crime

Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Romania

no, as of 2014








data retention legislation annulled by Constitutional Court in 2014 APTI

Comisariatul pentru Societatea Civila

Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Slovakia

no, as of April 2015 - declared unconstitutional











European Information Society Institute (EISI)
Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Slovenia

no






data retention legislation annulled by Constitutional Court in 2014
Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Spain

yes, as of 09/11/2007 12 months; can be reduced or extended to a minimum of 6 months and a maximum of 24 months, on request of the compentent authorities

Reported:

LEY 25/2007, de 18 de octubre, de conservación de datos relativos a las comunicaciones electrónicas y a las redes públicas de comunicaciones. Ley , no.: 25/2007; Boletín Oficial del Estado ( B.O.E ) , no.: 251/2007 , date pub: 19/10/2007 , page: 42517-42523 ; date into force/en vigueur: 08/11/2007 ; ref.: (MNE(2007)57464)

None
None
None
None
None
None
same as the Directive: telecomunications providers; los operadores que presten servicios de comunicaciones electrónicas disponibles al público o exploten redes públicas de comunicaciones (art.2)
All Police/Security forces when acting under an order of the Attorney General or Courts of Justice

Miembros de las Fuerzas y Cuerpos de Seguridad del Estado, cuando desempeñen funciones de Policia Judicial (art.6.2.a)

Funcionarios de la Dirección Adjunta de Vigilancia Aduanera, en el desarrollo de sus competencias como policía judicial (art.6.2.b)

El personal del Centro Nacional de Inteligencia en el curso de investigaciones de seguridad sobre personas o entidades (art.6.2.c)

For the detection, investigation and prosecution of the serious crimes considered in the Criminal Code or in the special criminal laws

None (as yet)
Access Info Europe (http://www.access-info.org/en/civil-liberties)

Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Sweden

yes, as of May 2012 6 months









New Renaissance
Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

United Kingdom

yes, as of 26/07/2007 (Internet 06/04/2009) 12 months

Reported:

The Data Retention (EC Directive) Regulations 2007. Statutory instrument (SI) , no.: Statutory Instrument 20; Her Majesty's Stationery Office (HMSO) , no.: ISBN 978 0 11 078328 4 ; date into force/en vigueur: 01/10/2007 ; ref.: (MNE(2007)57200)

The Data Retention (EC Directive) Regulations 2009. Statutory instrument (SI), number: 2009 no 859; Official Journal: Her Majesty's Stationery Office (HMSO), number: SI 2009 no 859, Entry into force: 06/04/2009; Reference: (MNE(2010)53135)








For the investigation, detection and prosecution of serious crime EU Court of Justice (pending): Reference of 31 October 2017 on UK bulk communications data orders Privacy International
Non-EU- State
Data retention implemented ?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Iceland

yes
Telecommunication Act 81/2003 (as amended in April 2005)









Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Liechtenstein

no









Member State
Data retention in force?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Norway

no, law enacted in April 2012 has never been implemented








planned digitaltpersonvern.no
Non-EU-State
Data retention implemented ?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Switzerland

yes, as of 2002 6 months




Buyers of prepaid mobile phone cards must be identified and registered by ID document (name, address, date of birth). According to a court decision, web server access logs including IP addresses must be retained for 6 months. operators of fixed line and mobile telephony, public ip-based telecommunications services
no
Non-EU-State
Data retention implemented ?
Data Retention Period
Legal instruments and date of entry into force
Data to be retained beyond the directive's requirements: fixed line telephony
Data to be retained beyond the directive's requirements: mobile telephony
Data to be retained beyond the directive's requirements: E-Mail
Data to be retained beyond the directive's requirements: Internet access
Data to be retained beyond the directive's requirements: Internet telephony
Data to be retained beyond the directive's requirements: other
Who is compelled to retain data?
Who is authorised to access retained data and for what purposes?
Legal challenges pending?
Competent NGO

Turkey

Censorship & Data retention regulated by Law 5651 in 2007 6 months to 2 years Phone lines are tapped by police and used as 'evidence' for prosecuting activities vaguely associated with 'terrorist organizations', based on anti-terror law TMK.
Mobile phones are tapped for the same reason. They also secretly record 'audio surveillance' from meetings of legal parties, unions, even mayor's office, state institutions.
E-mails can also be used as 'evidence', but not used as much as audio surveillance and phone tapping, yet. ICTA develops DPI systems, considers it 'state secret'.
Law 5651 requires every ISP to block any illegal content of any user upon being informed, if technically possible. It has to inform ICTA 3 months before closing down, and give the traffic records to ICTA (state authority)
Same with e-mail. Yet to come.
MOBESE is the system of police department where they collect all kinds of data for every citizen. They randomly make 'identity controls' on the street. Officers gain 'points' for doing so. Internet service providers, GSM operators. internet publishers, if they don't want to take responsibility. 'Data protection law' is being 'prepared' for over 10 years, so god knows who. Law 5397 authorizes the national intelligence agency MIT to request data and documents about "issues in its field of duty"
Social challenges pending! More so than legal challenges. Alternative Informatics Association english presentation in CCC


Please update this table by entering information on data retention in your country:

See also