Introduction
In July 2024, Austria approved a bill that allows police officers to access private messages of suspects (Reuters, 2025). The catalyst for this decision was the discovery of a planned terrorist attack during a Taylor Swift concert that summer. Until recently, Austria relied on cooperation with third countries, such as the United States (US) or the United Kingdom (UK), to get such information, a dependency that raised concerns about national sovereignty and the efficiency of domestic security. The new law represents Austria’s attempt to close this gap, prioritising safety in a modern debate that questions what holds greater value: security or privacy.
The Austrian case is not unique, as during the past several years, governments across Europe have been struggling to balance the protection of fundamental rights and anti-terrorism investigations. At the centre of this debate lies encryption, an essential tool for ensuring privacy, but one often perceived as an obstacle by law enforcement.
Encryption as a Human Right
End-to-end encryption is “an application of cryptography mechanisms and properties in communication systems between endpoints” (IETF, 2023). Simply put, encryption is a method of securing communication so that a message is encrypted on the sender’s device and can only be decrypted on the receiver’s device, using cryptographic keys unique to them. Even if the message is intercepted in transit or stored by the service provider, it remains unreadable to all except the intended parties.
This software safeguards Article 8 of the European Convention on Human Rights, which grants the right to privacy, including the right to privacy in private correspondence. It also upholds Article 10, which grants the right to freedom of expression, including the right “to receive and impart information and ideas without interference by public authority” (Council of Europe, 1950), as private discussions are susceptible to intrusion without encryption.
Allowing the authorities to read encrypted messages may hinder those rights while providing greater public safety. Because of the secure nature of end-to-end encrypted messaging apps, they also enable illegal acts such as drug dealing, child exploitation, trafficking, and even terrorism. Governments argue that this makes the usa of encryption a public safety issue, which cannot be resolved without providing the government access to it.
The UN Special Rapporteur on Freedom of Expression stated in a UN Report (2015) that encryption is critical to protecting privacy and freedom of expression (Special Rapporteur on freedom of opinion and expression, 2015). Similarly, the European Court of Human Rights (ECHR) has always insisted that surveillance policies must be lawful, necessary, and proportionate (Claburn, 2024). Arbitrary interception or retention without a significant cause is not lawful or necessary. Moreover, in a UK court case, Big Brother Watch v. UK (2018), it was ruled that surveillance schemes violated Article 8 of the ECHR (Open Society Justice Initiative, n.d).
European Union Level Regulations
At the EU level, data protection and privacy are enforced through the General Data Protection Regulation (GDPR), which came into force in 2018. The GDPR restricts data gathering and storage, allowing data to be collected only for legitimate purposes, such as preventing serious crime or protecting national security. Bulk and indiscriminate surveillance is specifically prohibited (Regulation (EU) 2016/679).
The second key legislative framework is the Digital Services Act (DSA), enacted in 2022, which aims to make a safer online environment without inserting encryption backdoors (European Commission, 2022). However, if a controversial chat control regulation proposal proceeds, platforms would need to scan for child sexual abuse material (CSAM) in encrypted chats (EUR-Lex, 2022). Critics of the proposal, including the European Data Protection Board and European Digital Rights (EDRi), along with other civil liberties groups, argue that the proposal in its current form fundamentally undermines the principle of end-to-end encryption and poses security threats to all its users (European Data Protection Board, 2024; European Digital Rights, 2024).
National Legislation
4.1 Germany
Germany has been involved in a long-standing legal battle with the EU over data retention. In July 2017, Germany passed a regulation that required “the general and indiscriminate retention of traffic and location data” from the country’s mobile service providers (Jowitt, 2023). Two of these providers, DT’s Telekom Deutschland and internet service provider SpaceNet AG, challenged the obligation in court (Jowitt, 2023). According to the new regulation, companies were required to store data about the customer’s traffic and location and share the data with law enforcement if requested.
The Court of Justice reiterated its position on traffic and location data retention, which is that it can only be carried out in exceptional circumstances, such as a threat to national security, and ruled that the regulation violated EU-wide GDPR standards (DW, 2025).
4.2 France
The 2015 terrorist attacks in Paris substantially influenced current French legislation in the digital area and established the country’s firm position that internet service providers must cooperate with the state on its anti-terrorist agenda. The 2017 counterterrorism law raised concerns regarding the protection of human rights because it granted prefects and security forces previously unremarked powers and introduced a revised scheme for online surveillance (Freedom House, 2024).
According to a 2020 French Court of Cassation ruling, it is obligatory to turn over decryption keys to the police when asked (Freedom House, 2024). In 2023, French prosecutors also set a dangerous precedent regarding the usa of encrypted messages as evidence of intended wrongdoing during the trial of the seven people related to the “December 8” case (Freedom House, 2024).
4.3 The Netherlands
In the Netherlands, some authorities enforce the GDPR, and the country adheres strictly to the rules of the regulation. There are no laws that permit law enforcement to intercept and decrypt encrypted messages, and authorities must rely on targeted device access and lawful hacking (BBC, 2016). The controversial Intelligence and Security Services Law, passed in 2017, allowed bulk interception of internet traffic but was revised after public backlash and a referendum in 2018 (BBC, 2018).
4.4 Spain
Spain has recently faced backlash due to the apparent use of Pegasus spy software by its intelligence agency. This software is sold exclusively to governmental structures and is not accessible to regular users (Jones, 2022). Although the country ostensibly upholds the GDPR regulations, it was discovered that Spain utilised the software to target Catalan independence leaders, as well as Spanish politicians, including the prime minister and the defence minister.
The scandal, even though it concerned only politicians and activists, has nevertheless shed light on possible human rights abuses in the digital sphere in the country. If the phones of the county’s top officials can be hacked, bypassing laws and regulations against it, then the rights of regular citizens and the privacy of their data can also be at risk.
4.5 United Kingdom
Passed in 2023, the United Kingdom’s Online Safety Act has faced international criticism on an international scale for its provisions that could force messaging services to scan encrypted messages for harmful content. Companies like Signal and WhatsApp have expressed that they may have to stop operating in the UK if the government’s requirements for scanning messages persist (McCallum & Vallance, 2023).
Impact on Human Rights
Encryption is not just a technical tool but a necessary part of democracy. When people fear that their information is being scanned, flagged, or stored while communicating in private, they tend to self-censor or refrain from communicating altogether. This effect is exacerbated for vulnerable groups, including journalists, activists, whistleblowers, and minorities who need safe channels for communicating sensitive content without consequences.
Another danger lies in surveillance creep. History shows that tools built for narrow purposes, such as CSAM, rarely remain confined to their original scope. Once the infrastructure for scanning encrypted content is in place, it becomes tempting for governments to extend it to other areas, including political dissent or vaguely defined “harmful” speech.
There are also serious security concerns. Any system that provides access to encrypted information creates inherent vulnerabilities, meaning these mechanisms cannot provide both safety and privacy simultaneously. Encrypted platforms use these tools to serve the public better, while also making ordinary people less safe and secure by allowing malicious actors, such as cybercriminals or hostile states, access to the information.
Lastly, the erosion of encryption legislation in countries regarded as democracies is concerning. If one country regards scanning mechanisms as legitimate, other countries are likely to follow, which undermines the overall security of the digital space. In this way, decisions involving encryption made in Europe have a ripple effect that extends far beyond its borders.
Conclusion
Austrian legislation is an example of a much larger dilemma faced by Europe: how to protect all citizens from harm while preserving the privacy infrastructure required for democracy. The tension between security and privacy can be framed as an either-or scenario, when in fact the real challenge is finding a balance between the two. As Europe confronts the challenge of being the global leader in human rights, it should not be drawn in by a fast and easy option to undermine encryption, but rather invest in security that is proportional, transparent, and respects the human rights of all.
Bibliography
BBC. (2018, March 22). Dutch referendum: Spy tapping powers ‘rejected’. <https://www.bbc.com/news/world-europe-43496739>. Accessed August 31, 2025.
BBC. (2016, January 7). Dutch government says no to ‘encryption backdoors’. <https://www.bbc.com/news/technology-35251429>. Accessed August 31, 2025.
Council of Europe. (1950). Convention for the protection of human rights and fundamental freedoms
Claburn, T. (2024, February 15). European Court of Human Rights declares backdoored encryption is illegal. The Register. <https://www.theregister.com/2024/02/15/echr_backdoor_encryption/>/. Accessed August 31, 2025.
DW (2020, September 20). ECJ rules against mass data retention in Germany. <https://www.dw.com/en/german-data-retention-rules-not-compatible-with-eu-law-says-top-court/a-63178438). Accessed August 31, 2025.
EUR-Lex. (2016, April 27). Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). <https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng>
European Commission. (2022, October 27). Legal documents on The Digital Services Act. <https://commission.europa.eu/publications/legal-documents-digital-services-act_en>
EUR-Lex. (2022, May 11). Proposal for a REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL laying down rules to prevent and combat child sexual abuse. <https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52022PC0209>.
European Data Protection Board. (2024, February 14). Statement 1/2024 on legislative developments regarding the Proposal for a Regulation laying down rules to prevent and combat child sexual abuse. <https://www.edpb.europa.eu/our-work-tools/our-documents/statements/statement-12024-legislative-developments-regarding-proposal_en>
European Digital Rights. (2024, June 3). Open letter: The dangers of the May 2024 Council of the EU compromise proposal on EU CSAM. <https://edri.org/our-work/open-letter-the-dangers-of-the-may-2024-council-of-the-eu-compromise-proposal-on-eu-csam/>
France: freedom of the Net 2024. (2024). Freedom House. <https://freedomhouse.org/country/france/freedom-net/2024 >. Accessed August 31, 2025.
Jones, S. (2022, May 15). Use of Pegasus spyware on Spain’s politicians causing ‘crisis of democracy’. The Guardian. <https://www.theguardian.com/world/2022/may/15/use-of-pegasus-spyware-on-spains-politicians-causing-crisis-of-democracy>. Accessed August 31, 2025.
Jowitt, T. (2022, September 21). EU Top Court Rules German Data Law Illegal. Silicon. <https://www.silicon.co.uk/e-regulation/surveillance/eu-top-court-rules-german-data-law-illegal-476735>. Accessed August 31, 2025.
Knodel,M., Celi, S., Kolkman, O., Grover, G. (2023, June 21). Definition of End-to-end Encryption. Internet Engineering Task Force. <https://www.ietf.org/archive/id/draft-knodel-e2ee-definition-11.html>. Accessed August 31, 2025.
McCallum, S. & Vallance, C. (2023, April 18). WhatsApp and other messaging apps oppose ‘surveillance’. BBC. <https://www.bbc.com/news/technology-65301510>. Accessed August 31, 2025.
Open Society Justice Initiative (n.d.). Big Brother Watch v. United Kingdom. <https://www.justiceinitiative.org/litigation/big-brother-watch-v-united-kingdom>. Accessed August 31, 2025.
Reuters. (2025, July, 9). Austrian lower house passes bill on monitoring of secure messaging. <https://www.reuters.com/business/media-telecom/austrian-lower-house-passes-bill-monitoring-secure-messaging-2025-07-09/>. Accessed August 31, 2025.
Special Rapporteur on freedom of opinion and expression. (2015, May 22). Report on encryption, anonymity, and the human rights framework. <https://www.ohchr.org/en/calls-for-input/report-encryption-anonymity-and-human-rights-framework>
