Between 10 and 11 August 2026 the European Data Protection Supervisor adopted four Opinions on the legislative package that the European Commission presented on 24 June 2026 to strengthen Europol and Eurojust and to overhaul the cross-border gathering of evidence. The press releases came out between 12 and 14 August, in the middle of the summer break, and they make the same point four times over: the expansion of processing powers is not matched by a corresponding strengthening of supervision and enforcement. The sharpest passage concerns Europol, which under the Proposal could process the personal data of individuals with no established links to criminal investigations or proceedings, for an extensive and unspecified period of time. On that point the Supervisor states that the Proposal in its current form provides neither the safeguards nor the oversight mechanisms required.
What the Commission proposed on 24 June
The package works on four fronts. Two Regulations replace the legal bases of the two agencies in full, Regulation (EU) 2016/794 on Europol and Regulation (EU) 2018/1727 on Eurojust. A targeted revision amends Regulation (EU) 2018/1725, the rules on the processing of personal data by Union institutions and bodies, for the part concerning operational personal data processed by the bodies involved in judicial and police cooperation in criminal matters. A Directive then recasts the rules on the European Investigation Order and introduces a new European Remote Participation Order, which would allow suspects, accused persons and victims to take part remotely in criminal court hearings from another Member State.
On the operational side the Commission points, for Europol, to automated and faster information sharing, to Europol Support Offices staffed by former Europol officers, to a technology and innovation hub that would provide an EU wide picture of capability needs for law enforcement, and to closer cooperation with Eurojust and the European Public Prosecutor’s Office. For Eurojust it envisages the ability to act on its own initiative in order to identify links between cases, and an expanded mandate covering emerging areas of crime such as cybercrime, gender based violence and violations of EU restrictive measures. This is an expansion of tasks that translates, first of all, into a greater volume and a greater complexity of personal data processing.
Europol and data on people with no link to an investigation
Opinion 18/2026 is the most severe of the four. The Supervisor recognises that the Union and its Member States face increasingly complex and technologically sophisticated cross-border crime, and supports the objective of strengthening Europol’s role. He considers, however, that the Proposal would introduce new and more complex processing operations covering additional categories of personal data and of data subjects, including individuals with no established links to criminal investigations or proceedings. In the press release accompanying the Opinion, Wojciech Wiewiórowski states that modern security threats demand sophisticated responses but that fundamental rights cannot be sacrificed in the pursuit of security, and that the Proposal must provide robust safeguards and real oversight.
The concern is not so much the category of data as the combination of an absent link to an investigation with an undefined time limit. The Supervisor therefore calls for strict purpose and storage limitation, and above all for legal certainty and foreseeability in the criteria on which Europol would decide whether it is relevant and necessary to process the personal data of a person with no established connection to a criminal activity. Around that question the Opinion raises points on the rules for access to and query of Europol systems, on the processing of personal data obtained directly from private parties, on the supervision of processing carried out by Europol staff in Member States and on the security of the agency’s services and tools. This is a matter of scope before it is a matter of information security, and in structure it recalls the debate on the threshold beyond which data ceases to be personal: there too the contested issue was not the sensitivity of the information but the breadth of the test used to decide what may be processed.
Eurojust, where the design convinces and the detail does not
Opinion 19/2026 strikes a different tone. The Supervisor welcomes the streamlining of the data protection rules for Eurojust’s operational data, which in his view removes fragmentation, eliminates duplication and creates clarity. He supports in particular the principle that any automated processing of operational personal data should take place within the integrated data processing environment of the Case Management System, subject to limited exceptions, and the obligation that communication between competent national authorities and Eurojust should continue to take place primarily through a network of IT systems and interoperable e-CODEX access points, the EU’s secure channel for cross-border judicial communication. He also welcomes the safeguards maintained in Chapter IV of the Proposal, including defined categories of data and strict storage limits.
The recommendations therefore bear on implementation. The Supervisor addresses the Case Management System, Eurojust’s ability to cross-check data against relevant databases, the determination of roles and responsibilities in processing, the functioning of the hit and no-hit mechanism through which other Union bodies obtain indirect access to information held by the agency, information security and transfers of operational personal data to third countries. He closes with a point that applies to Europol as well, the validity of the cooperation agreements and working arrangements concluded under Decision 2002/187/JHA or under the 2018 Regulation.
Regulation 2018/1725 and the enforcement problem
Opinion 17/2026 deals with the revision of Regulation (EU) 2018/1725 for operational personal data processed by Union justice and home affairs bodies, that is Europol, Eurojust, the European Public Prosecutor’s Office and, to a limited extent, Frontex. In the press release the Supervisor recalls having long called for a consistent and effective framework for these agencies and welcomes the objective of the Proposal, while adding that such an objective can only be achieved through effective supervision and enforcement, and that the opportunity should not be missed.
These are the most concrete recommendations in the whole package, because they touch the powers of the authority itself. The Supervisor asks that his authority to issue binding compliance orders when infringements occur be clarified, and that interim protective measures be made available in urgent cases. He also asks for cooperation with national supervisory authorities to be streamlined, and for the legacy cooperation agreements that allow Europol and Eurojust to exchange operational personal data with third countries to be brought into full alignment with current EU data protection law. It is the same architectural problem the EDPB raised in July when it called for a legal basis for information sharing between regulators: without an express rule stating who may do what, cooperation between authorities remains a good intention.
The fourth Opinion and the recast of the European Investigation Order
The picture is completed by Opinion 16/2026 of 10 August, on the Directive concerning the European Investigation Order in criminal matters and the European Remote Participation Order. Treating the four instruments separately reflects their different nature, but the combined effect is a single one: the package redraws, in one move, who gathers evidence abroad, who pools it and under which data protection rules. For anyone advising companies or individuals involved in cross-border proceedings this is the point to watch, because a change in the channels of collection and exchange affects the rights of the defence before it affects compliance.
Who supervises, and with what resources
In all four Opinions the Supervisor underlines the need for additional human and financial resources for his own office, corresponding to the substantial expansion of the tasks and data processing capabilities of the Union agencies. The request is not a formality. An authority asking for the power to issue binding orders and interim measures is asking to be able to intervene in processing operations that concern ongoing investigations, and that requires technical expertise, the capacity to verify on site and continuity over time. One further fact, published by the EDPS at the foot of its own press releases, is worth adding: the five year term of Wojciech Wiewiórowski began on 6 December 2019 and the selection procedure for the next mandate is still ongoing. The authority asking for sharper powers is doing so while it waits to learn who will lead it.
Procedurally, the Opinions remain advisory. The Supervisor adopts them because the Commission is legally obliged to seek his guidance on any legislative proposal with an impact on the protection of personal data, under Article 42(1) of Regulation (EU) 2018/1725. They do not bind the legislator, that is the European Parliament and the Council, which will now examine the proposals. Their effect depends on how far they are taken up in the compromise texts, and it is at that stage that it will become clear whether the safeguards sought for data on people outside investigations enter the enacting terms or stay in the recitals. A comparable question of rank arose with the Council of Europe Framework Convention on artificial intelligence, where the reach of the commitments undertaken depends largely on implementation choices.
What remains with the Union legislator is an explicit choice: either to write into the Regulation the criteria that circumscribe the processing of data on people with no link to an investigation, or to leave that definition to agency practice. What remains with national supervisory authorities is the burden of a cooperation that the Proposal does not simplify enough. For practitioners the calendar that matters is not the one for entry into application, which is distant, but the one for parliamentary scrutiny: that is where the Supervisor’s recommendations either become amendments or do not, and in the meantime it is worth checking which data flows towards Europol and Eurojust already pass through one’s own systems today, and on what legal basis.




