Europol 2.0 Needs More Than More Data: The Accountability Question Behind the New Framework

Executive summary

The European Data Protection Supervisor has issued an opinion on the proposed new regulatory framework for Europol.

The debate is often framed as a balance between two legitimate objectives: giving Europol sufficient capabilities to support Member States against serious and cross-border crime, while protecting the fundamental rights of the people whose data enter its systems.

That framing is necessary but incomplete.

The central accountability problem is not simply how much data Europol may process. It is whether the resulting analytical system remains reconstructable from evidence.

As Europol’s mandate, datasets and analytical capabilities expand, external oversight should be able to answer a basic set of questions: where did the data come from, why were they processed, what analysis was performed, what role did algorithms or AI play, who reviewed the result, where was the information sent, and who was accountable for the final operational use?

More analytical capacity therefore requires more than additional legal authority.

It requires a stronger evidence trail.

Europol’s data problem is also an accountability problem

Europol operates in an unusual position. It supports national law-enforcement authorities while processing information originating from multiple jurisdictions and sources. That information can include large and complex datasets in which the relevance of every person to criminal activity may not be established when the data first arrive.

This creates an obvious operational challenge. Investigators may need to analyse large datasets precisely in order to determine which information is relevant.

But it creates an equally important rights problem.

The larger and less structured a dataset becomes, the greater the possibility that information concerning witnesses, victims, associates or people with no established connection to criminal conduct is processed alongside data concerning suspects.

The correct oversight question is therefore not simply:

How much data may Europol hold?

It is:

What controls demonstrate that each stage of processing remains necessary, proportionate and within Europol’s legal mandate?

The historical warning

This is not a theoretical concern.

In January 2022, the EDPS ordered Europol to erase certain datasets concerning individuals whose link to criminal activity had not been established after the permitted categorisation period. Later amendments to the Europol Regulation introduced provisions affecting those processing operations.

The EDPS subsequently challenged two of those provisions before the Court of Justice, arguing that the amendments undermined legal certainty and the independence of its supervisory role.

Whatever position one takes on the underlying institutional dispute, the episode illustrates a recurring governance risk.

If an independent supervisor finds a processing practice unlawful, and the legal framework is subsequently changed in a way that affects that finding, the relationship between operational policy, legislation and independent enforcement becomes part of the rule-of-law analysis.

A future Europol framework should avoid reproducing that uncertainty.

More data changes the nature of supervision

Traditional supervision can focus on policies, formal authorisations and sample case files.

Large-scale digital analysis requires something more.

If millions of records move through analytical systems, effective oversight increasingly depends on technical evidence generated by those systems themselves.

Relevant evidence may include:

  • source and ingestion records;
  • data-subject categorisation;
  • purpose and access controls;
  • retention and deletion logs;
  • records of searches and analytical queries;
  • data transfers to national authorities or third parties;
  • automated flags and scores;
  • model and algorithm documentation;
  • records of human review;
  • incident and correction logs.

Without these records, legality may exist on paper while actual processing becomes difficult to reconstruct.

That distinction is central to Civic Forensics: formal authority is not evidence of compliant execution.

AI raises the stakes

Europol’s analytical future cannot be separated from artificial intelligence.

AI systems can identify patterns across volumes of information that human analysts could not realistically review manually. That can provide significant investigative value.

But AI can also increase the distance between raw evidence and operational conclusion.

An analyst may receive a prioritised lead, inferred connection, anomaly score or generated summary without seeing every intermediate step that produced it.

This makes meaningful human oversight more demanding, not less.

A person appearing at the end of an automated workflow does not automatically make the workflow accountable. The reviewer must have enough information to understand the basis of the output, identify significant limitations and reject the result when the underlying evidence does not support it.

The important distinction is therefore between a human who approves an output and a human who can independently evaluate it.

Data protection and AI supervision converge

The EDPS occupies a particularly important position because it supervises data protection at EU institutions and also has responsibilities under the AI Act for AI systems used by EU institutions, bodies, offices and agencies.

For Europol, these two regimes can intersect directly.

An AI system may comply with one set of technical governance requirements while its input data raise separate questions concerning purpose limitation, necessity, retention, accuracy or sensitive information.

Conversely, a dataset may have been lawfully collected while the way an algorithm subsequently analyses it creates new risks for individuals.

A serious oversight framework therefore needs to follow the complete chain:

collection → storage → categorisation → analysis → AI inference → human review → dissemination → operational use → retention or deletion.

Breaking that chain into isolated compliance silos makes it easier for accountability gaps to appear between them.

Who is responsible when several authorities are involved?

Europol does not operate in isolation. Information can originate from Member States and other authorised sources, be analysed at EU level and then return to national authorities for operational action.

This creates another forensic problem: distributed responsibility.

When an incorrect or disproportionate outcome occurs, several explanations may be possible.

The source authority may have supplied inaccurate data. Europol may have combined information incorrectly. An analytical system may have produced an unreliable inference. A national authority may have treated an analytical lead as established fact.

An effective regulatory framework should make it possible to separate those stages rather than allowing each institution to point to another part of the chain.

That requires clear controller responsibilities, logging and documented hand-offs.

A Civic Forensics test for Europol accountability

A practical external review can be organised around five questions.

1. Provenance

Can Europol identify where the relevant information originated and under which conditions it was supplied?

2. Purpose

Can the Agency demonstrate why the data were processed for the particular analytical operation and whether later reuse remained compatible with the authorised purpose?

3. Transformation

Can investigators, supervisors and courts reconstruct how raw information became an analytical conclusion, including significant automated or AI-supported transformations?

4. Human responsibility

Can the record identify who reviewed the analytical output and whether that person had a genuine ability to question or reject it?

5. Remedy and supervision

Can the EDPS or another competent oversight body obtain the relevant evidence, and can an affected person obtain an effective remedy where unlawful processing has occurred?

If one of these links is missing, the accountability chain is incomplete.

The procurement dimension

Another area deserves greater scrutiny: procurement.

When Europol or another public body acquires advanced analytical technology from an external supplier, contractual design becomes part of public accountability.

Relevant questions include whether the institution has audit rights, access to logs, documentation of model changes, information about training data, incident-reporting obligations and sufficient technical access to investigate errors.

A public authority cannot exercise meaningful oversight over a system if the supplier’s contract or technical architecture prevents the authority itself from understanding how the system operates.

Commercial confidentiality may protect legitimate proprietary information. It should not become a mechanism that prevents a public institution from demonstrating the legality of its own exercise of public power.

The accountability boundary

The future Europol framework will inevitably involve choices about operational capability, speed, interoperability and access to information.

The useful democratic question is not whether Europol should have modern analytical tools. A modern law-enforcement agency plainly requires modern technical capabilities.

The question is where the accountability boundary is drawn.

Every expansion of analytical power should be accompanied by an identifiable evidence requirement: what must be logged, what must be reviewable, what must be retained for supervision and who remains responsible for the result.

This provides a more concrete standard than an abstract debate between security and privacy.

Preliminary finding

The strongest Europol framework would not be the one that processes the least data or the most data.

It would be the one in which legitimate analytical capacity is matched by the ability to reconstruct and challenge the exercise of that capacity.

The standard should therefore be:

More data, more analytics — more traceability.

If Europol’s capabilities expand while the evidence available to independent supervisors, courts and affected individuals does not expand with them, the accountability gap will grow even if every new capability has a formal legal basis.

Sources

European Data Protection Supervisor, legislative opinions and work concerning Europol: https://www.edps.europa.eu/data-protection/our-work/our-work-by-type/opinions_en

European Data Protection Supervisor, EDPS takes legal action as new Europol Regulation puts rule of law and EDPS independence under threat, 22 September 2022: https://www.edps.europa.eu/press-publications/press-news/press-releases/2022/edps-takes-legal-action-new-europol-regulation-puts-rule-law-and-edps-independence-under-threat_en

European Data Protection Supervisor, Use of AI in the field of Criminal Justice and Law Enforcement: https://20years.edps.europa.eu/en/initiatives/use-ai-field-criminal-justice-and-law-enforcement

Limitations

This article focuses on accountability architecture and the EDPS supervisory perspective. It does not assess the operational merits of individual Europol investigations and should be revisited as the proposed regulatory framework moves through the legislative process.

Leave a Comment