Executive summary
The European Data Protection Supervisor has issued an opinion on proposed changes to the data-protection framework governing EU institutions and bodies, including the treatment of operational personal data in the justice and home-affairs field.
The reform has an understandable objective: reduce fragmentation and make the rules more coherent across an institutional environment in which Europol, Eurojust, the European Public Prosecutor’s Office and other EU bodies increasingly exchange and analyse large volumes of sensitive information.
But legal consistency and democratic accountability are not the same thing.
A simpler framework is useful only if it preserves clear limits on processing, meaningful individual rights, traceable institutional responsibility and an independent supervisor with sufficient powers and resources to intervene when those limits are crossed.
The central Civic Forensics question is therefore straightforward:
If the rules become more uniform, will it also become easier to determine who processed what data, under which authority, for which purpose, and who can order the processing to stop?
Why the reform matters
Regulation (EU) 2018/1725 performs for EU institutions, bodies, offices and agencies a role broadly comparable to that performed by the GDPR for national public authorities and private-sector controllers.
The justice and home-affairs environment is particularly complex. Operational personal data may move between national authorities and EU bodies whose mandates differ substantially. The information may concern suspects, witnesses, victims, associates or people whose connection to criminal activity has not yet been established.
That complexity creates a genuine case for harmonisation.
Fragmented rules can make compliance harder, create uncertainty about applicable safeguards and complicate supervision. But harmonisation can also create a different risk: rules designed to make data flows easier may gradually turn exceptional forms of processing into routine administrative infrastructure.
That is why the quality of supervision matters as much as the wording of the processing rules themselves.
Simplification must not become a reduction of safeguards
Regulatory simplification is often presented as a neutral administrative objective. In data governance, it is not neutral.
Every simplification changes something: a procedure, a legal threshold, a reporting requirement, a division of responsibility or a supervisory step.
The correct forensic question is not whether the new framework contains fewer or more provisions. It is whether an affected person, auditor, court or supervisory authority can still reconstruct the processing operation.
A defensible system should allow an external reviewer to establish at least:
- which institution obtained the data;
- where the data originated;
- the legal basis and purpose of processing;
- whether the information was subsequently reused for another purpose;
- which institutions or third parties received it;
- how long it was retained;
- whether automated or AI-supported analysis was applied;
- which safeguards applied to particularly sensitive information;
- which authority was responsible for supervision;
- what remedy was available to the affected person.
If harmonisation makes data movement easier while making those questions harder to answer, administrative efficiency will have been purchased at the cost of accountability.
The importance of independent supervision
The EDPS is not merely an advisory body. It is the independent data-protection supervisor for EU institutions and agencies and has enforcement responsibilities in an environment where processing can have serious consequences for fundamental rights.
The history of Europol supervision illustrates why that independence is important. In 2022, the EDPS took legal action after amendments to the Europol Regulation affected processing operations that had previously been subject to an EDPS deletion order. The dispute raised a structural question that remains relevant to any new reform: what happens when legislative expansion of an agency’s powers intersects with an independent supervisor’s previous enforcement action?
The lesson is broader than Europol.
Independent supervision is meaningful only when the supervisor can obtain the necessary records, inspect processing, issue binding measures where legally provided, and exercise those powers without the regulated institution or subsequent political intervention effectively neutralising the result.
Data-intensive agencies require an evidence trail
Justice and home-affairs agencies increasingly operate through interconnected information systems, cross-border exchanges, analytical platforms and, progressively, AI-assisted tools.
That makes conventional privacy notices insufficient as an accountability mechanism.
Oversight increasingly depends on evidence generated inside the system itself: access logs, transfer records, retention controls, purpose flags, data-quality assessments, model documentation and records of human review.
The reform should therefore be judged partly by whether it strengthens or weakens this evidence layer.
A rule saying that processing is permitted is only the beginning. A functioning accountability system should also make it possible to demonstrate that a particular processing operation remained within that permission.
The AI dimension
The issue becomes more significant as EU bodies adopt algorithmic analysis and artificial intelligence.
The EDPS has already identified the use of AI in criminal justice and law enforcement as an area requiring effective independent supervision. The AI Act also gives the EDPS supervisory responsibilities for AI systems developed or used by EU institutions, bodies, offices and agencies.
This creates an increasingly important overlap between data-protection governance and AI governance.
An AI system may be legally procured and technically authorised while still depending on personal data whose collection, combination, retention or reuse raises separate questions under data-protection law.
Forensic review should therefore avoid treating AI compliance and data protection as separate checklists. The same evidence trail may be relevant to both.
A practical accountability test
For each significant operational processing system, an oversight review should ask four questions.
1. Authority
What precise legal provision permits the processing, and does the actual use remain within the purpose for which that authority was granted?
2. Traceability
Can the institution reconstruct where the data came from, who accessed them, what transformations were performed and where the information was subsequently transmitted?
3. Supervision
Can the independent supervisory authority inspect the relevant systems and records and take effective action where it finds non-compliance?
4. Remedy
Can an affected individual meaningfully exercise rights or challenge unlawful processing, including where several institutions participated in the data chain?
A reform that improves all four would represent genuine simplification with stronger accountability. A reform that improves only the speed of institutional data exchange would not.
Why this matters beyond privacy
Operational data processing is often discussed as a specialised privacy issue. It is also an issue of public administration and the rule of law.
The ability of public institutions to collect, combine and analyse information is a form of administrative power. The more scalable that power becomes, the more important it is that its exercise remains attributable, reviewable and contestable.
This is particularly important in justice and law enforcement, where inaccurate data, incorrect associations or opaque analytical conclusions can affect investigations and individual rights.
The appropriate standard is therefore not simply data protection by design.
It is accountability by evidence.
Preliminary finding
Greater consistency across the EU institutional data-protection framework can reduce unnecessary legal fragmentation. But consistency should not be used as a proxy for accountability.
The real test of the reform will be whether it leaves independent supervision stronger, weaker or merely more administratively convenient.
For Civic Forensics, the most useful monitoring question is:
After the reform, can an external reviewer reconstruct the full chain of authority, data movement, analysis, supervision and responsibility more easily than before?
If the answer is yes, simplification may strengthen governance. If the answer is no, a cleaner legal framework may conceal a less transparent operational system.
Sources
European Data Protection Supervisor, opinions and legislative consultation work on Regulation (EU) 2018/1725 and EU justice and home-affairs data processing: https://www.edps.europa.eu/data-protection/our-work/our-work-by-type/opinions_en
European Data Protection Supervisor, Use of AI in the field of Criminal Justice and Law Enforcement: https://20years.edps.europa.eu/en/initiatives/use-ai-field-criminal-justice-and-law-enforcement
European Data Protection Supervisor, EDPS takes legal action as new Europol Regulation puts rule of law and EDPS independence under threat, 22 September 2022: https://www.edps.europa.eu/press-publications/press-news/press-releases/2022/edps-takes-legal-action-new-europol-regulation-puts-rule-law-and-edps-independence-under-threat_en
Limitations
This is a policy and accountability analysis of the reform direction and the EDPS supervisory perspective. It does not constitute a definitive assessment of the final legislative text, which may change during the EU legislative process.