On 1 April 2025, the European Commission unveiled ProtectEU, a strategic blueprint intended to tackle what it frames as internal security challenges facing the continent. The initiative echoes its predecessor, the Security Union Strategy, which has already generated significant concerns among digital rights advocates. That earlier framework spawned the controversial 'chat control' proposal—still pending despite political resistance—and twice expanded the surveillance mandate of Europol, the EU's police cooperation body, granting it substantially greater powers to monitor populations in transit.

ProtectEU perpetuates the EU's reliance on technological enforcement as a security fix. The strategy channels resources toward what it calls 'public spending for security' alongside 'security research and investment', much of it channelled through private firms. This techno-solutionist approach treats complex social problems as engineering challenges solvable through tools alone. Yet history shows such systems prove both ineffective and deeply harmful—sometimes most of all to those they purport to shield. Meanwhile, funding diverted to surveillance infrastructure drains resources from genuine protective measures.

Encryption under siege

The strategy commits to drafting a Technology Roadmap on encryption designed to "identify and assess technological solutions that would enable law enforcement authorities to access encrypted data in a lawful manner". This echoes guidance from the High Level Group on Access to Data for Effective Law Enforcement, which introduced the concept of 'lawful access by design'—requiring all internet service providers, from telecom carriers to messaging platforms, to modify their security infrastructure to grant law enforcement entry to encrypted communications as needed.

In practice, this amounts to mandating encryption backdoors across every connected device and service. Such vulnerabilities undermine both fundamental rights and collective cybersecurity. The Commission is already recruiting technology experts to develop the roadmap, yet a basic truth remains: introducing weaknesses into digital systems without degrading their overall security is technically impossible. The EU claims to prioritize cybersecurity and fundamental rights protection, yet this path contradicts both.

Data retention returns

Another 2025 priority involves producing "an assessment of the impact of data retention rules at EU level". Commission President Von der Leyen signalled this intent in her mission letter to Home Affairs candidate Magnus Brunner, calling for an 'update' to law enforcement's digital access tools and retention frameworks.

The EU's history with data retention is fraught. Over a decade ago, the Court of Justice of the European Union struck down the Data Retention Directive following a case brought by EDRi member Digital Rights Ireland. Despite that landmark judgment, most Member States have continued operating mass retention schemes in open violation of EU law. Rather than enforce compliance and address this rule-of-law crisis, the Commission looked away. Now certain Member States and multinational corporations are pushing for EU-wide harmonisation to replace the current patchwork of national regimes.

Proposals from the High Level Group would worsen the situation. They envision an EU instrument requiring companies to retain data enabling identification of any user, while dramatically expanding which internet service providers face this obligation. The result would exceed the surveillance scope of the old European legal framework. At stake is the ability to use online services anonymously—essential for free expression when civic space narrows and protest faces criminalisation across Europe. Mass retention regimes chill access to information, undermine press freedom, and suppress online political participation.

Agencies gain power and resources

To strengthen "EU security capabilities", the Commission pledges to reinforce its home affairs agencies. Europol receives particular attention, promised "an ambitious overhaul" of its mandate "to turn it into a truly operational police agency". One legislative proposal for this transformation is already in motion; a second reform expanding its powers and resources remains under discussion among EU policymakers. The previous overhaul, adopted just three years ago, faced fierce objections from data protection authorities and civil society organisations.

Europol's record of abuse is well-established. Yet successive reforms continue accumulating, allowing the agency to amass personal data with minimal oversight, train algorithms for national police forces without assessing discriminatory effects, and deploy untested and unaudited data mining methods. Since the effects of earlier reforms have never been properly evaluated, the full scope of the mandate revision remains unclear.

Frontex, the border control agency, and Eurojust, the judicial cooperation body, will both receive expanded missions. European Border and Coast Guard personnel are slated to triple to 30,000 over time, accompanied by deployment of "advanced technology for surveillance and situational awareness". This expansion comes despite Frontex's documented history of illegal pushbacks and human rights violations at EU borders, its sidelining of its own internal data protection officer while illegally sharing data with Europol, and its failed attempt to launch an unlawful social media surveillance programme.

Rather than deter the Commission, these scandals and data protection breaches appear to strengthen its resolve. The home affairs agencies will gain new surveillance capabilities, expanded budgets, additional personnel, new technologies, and enhanced mechanisms for "swift mutual exchange of information, including for operational purposes" among themselves.

The road ahead

ProtectEU sidesteps genuine security challenges in favour of entrenching an oppressive law enforcement apparatus notorious for systematically over-policing and under-protecting marginalised communities—migrants and racialised populations especially. This infrastructure rests on expanded data collection, analysis, and sharing across Member States, EU agencies, third countries, and private corporations. Law enforcement routinely secures broad exemptions from fundamental rights safeguards and public oversight in EU law, leaving data protection and privacy defences vulnerable to erosion.

Digital rights advocates must prepare to contest these proposals. EDRi has committed to active monitoring and engagement in EU policy debates to challenge harmful technology-driven securitisation measures.

Source: EDRi (European Digital Rights)