LOGO

EU Council Calls for Secure Encryption & Lawful Data Access

December 14, 2020
EU Council Calls for Secure Encryption & Lawful Data Access

The Council of the European Union, the organization representing the governments of each EU Member State, has issued a resolution regarding encryption, advocating for both “security through encryption and security despite encryption.”

The Council states that “Competent authorities must possess the ability to access data in a legally justified and focused manner, fully respecting fundamental rights and applicable data protection regulations, while simultaneously maintaining cybersecurity.”

Reports last month indicated that a draft Council resolution signaled EU political leaders were considering measures impacting end-to-end encryption; however, neither the draft nor the finalized document, released today, explicitly proposes a ban. Instead, both versions demonstrate support for “the development, implementation, and utilization of robust encryption.”

The recently adopted, non-legally binding resolution articulates the EU body’s support for strong encryption while asserting that targeted, lawful access to encrypted data is crucial for gathering electronic evidence to combat criminal activities, including terrorism, organized crime, child sexual abuse, and various forms of cybercrime.

The resolution emphasizes the need to “right balance” between these two aspects, ensuring adherence to fundamental EU legal principles like necessity and proportionality, to “uphold the principle of security through encryption and security despite encryption in its entirety.”

The Council also stresses the “extremely important” need to safeguard the privacy and security of communications through encryption, while also “upholding the possibility for competent authorities in the area of security and criminal justice to lawfully access relevant data for legitimate, clearly defined purposes in fighting serious and/or organized crimes and terrorism, including in the digital world, and upholding the rule of law.”

“Any measures undertaken must carefully weigh these interests against the principles of necessity, proportionality, and subsidiarity,” the Council asserts, as political objectives once again encounter the inherent limitations of secure encryption. 

The Council has not specified what actions EU lawmakers should take to achieve the challenging goal of accessing encrypted data held by criminals without compromising encryption for all users.

However, they intend to collaborate with the technology industry in this latest attempt to reconcile encryption with accessibility, explicitly mentioning “joining forces with the tech industry.” The resolution lacks specifics regarding the nature of this collaboration, beyond seeking a ‘balance’ between secure and insecure systems.

“Technical solutions for accessing encrypted data must adhere to the principles of legality, transparency, necessity, and proportionality, including built-in data protection,” the Council clarifies, defining ‘lawful’ access and implicitly rejecting mandatory backdoors as disproportionate, unnecessary, and unlawful.

The resolution later explicitly states that there will be no mandated, single, EU-wide technical solution for breaking encryption, stating: “There should be no single prescribed technical solution to provide access to encrypted data.”

“Given that there is no single approach to achieving these goals, governments, industry, research institutions, and academia must collaborate transparently to strategically create this balance,” the Council writes, seemingly discouraging confidential discussions between policymakers and industry regarding potential ‘targeted backdoors.’

“Possible solutions should be developed transparently in cooperation with national and international communication service providers and other relevant stakeholders,” the Council continues, seemingly rejecting secret agreements between policymakers and tech providers to provide the desired ‘targeted and lawful’ access—unless cooperation is transparent to policymakers, industry stakeholders, and potentially academic researchers, but not to the general public or communications service users, which would contradict the resolution’s spirit of transparency.

This latest development in the ongoing debate over encryption may not alleviate concerns that EU lawmakers are moving towards enlisting the tech industry to undermine encryption through mandatory backdoors.

However, it is significant that the Council’s resolution, despite its frustratingly ambiguous nature, rejects a single technical solution to achieve its objectives, instead referencing multiple “potential” technical and operational solutions.

The resolution appears to be a (political) effort to demonstrate action, and at best, a call to convene stakeholders to ensure alignment and avoid duplication of effort, with the Council advocating for coordination, joint work, and “tailored high-quality training” across EU institutions to analyze new technologies, while also encouraging research and academia “to ensure the continued implementation and use of strong encryption technology.”

The Council may also be attempting to prevent individual entities within the bloc from pursuing unsuccessful attempts to compromise end-to-end encryption. Instead, they collectively endorse a slogan — “security through encryption and security despite encryption” — hoping to halt further detrimental actions toward encryption.

Last week, EU lawmakers also indicated they would support ‘lawful’ data access as part of a broader counter-terrorism agenda, with the Commission committing to “work with Member States to identify possible legal, operational, and technical solutions for lawful access and promote an approach which both maintains the effectiveness of encryption in protecting privacy and security of communications, while providing an effective response to crime and terrorism.”

However, this agenda remained focused on identifying ‘possible solutions’ for lawful access to encrypted data, even while reaffirming the importance of maintaining encryption’s effectiveness. Thus, the cycle continues…

#EU Council#encryption#data access#lawful access#privacy#security