Belgium spent four years trying to rebuild a data retention regime that survives judicial review. On 3 September an Advocate General told the Court of Justice the second attempt fails too.
Maciej Szpunar delivered his opinion in Case C-661/24, Académie Fiscale and Others, a reference from Belgium’s Constitutional Court. At issue is the 2022 law governing how telecom operators collect and keep identification data and metadata. Lawmakers framed the regime around fraud, network abuse and security breaches, and set a retention period of twelve months. Szpunar proposes that European law precludes several of its core rules.
His central objection concerns separation. The law lets operators retain a very broad set of traffic and location data without technical arrangements that keep categories genuinely apart. Szpunar used a phrase that will follow this case: the regime must ensure a genuinely watertight separation, so that nobody can draw precise conclusions about a person’s private life from what the provider holds. Belgian law, in his reading, offers no such guarantee, and the interference therefore exceeds what necessity allows.
A second objection cuts at who decides. The legislation leaves essential elements of the regime to the providers themselves. Companies judge which data they need, and they may extend how long they keep it. That delegation strips the rules of clarity and precision, two qualities the Court has repeatedly demanded whenever a state interferes with privacy and data protection. The court press service summarised the opinion in those terms.
Opinions do not bind the judges, and the Court departs from them often enough that governments rarely treat one as a verdict. Still, the direction travels with a long line of case law. Since the retention directive fell in 2014, national parliaments have written, lost and rewritten these regimes in a slow loop, each time narrowing the categories and each time discovering that the narrowing was not enough. Monitoring services counted Belgium as the latest entry in that sequence rather than a departure from it.
Police forces and prosecutors will read the opinion with dismay. Metadata underpins ordinary investigative work, and a ruling that voids twelve-month retention forces investigators back toward targeted orders that take time to obtain. Privacy groups counter that the convenience of bulk access is precisely the problem, and that a regime nobody can audit invites exactly the profiling Szpunar describes.
The wider stake sits at European level. The Commission has been examining whether to propose a common framework on lawful access to data, and every national defeat strengthens the case that fragmented rewriting has run its course. A harmonised instrument would face the same constitutional test, but at least it would face it once.
Judgment in C-661/24 will follow in the coming months. Whichever way it lands, the operational question for providers is already visible: can a network actually hold identification data in one compartment and behavioural traces in another, with no bridge between them? Engineers, not legislators, may decide whether Europe’s data retention compromise has a future.





