Data retention rules returned to the agenda of EU home affairs ministers on 1 October 2026, when the Justice and Home Affairs Council in Luxembourg listed data retention among its discussion items alongside Schengen, readmission and the Migration and Asylum Pact. The debate matters because the Union still has no harmonised regime for how long telecom and online providers must keep communications metadata.
The history explains the tension. The Court of Justice annulled the original Data Retention Directive in Digital Rights Ireland in 2014, and later judgments including Tele2 Sverige and La Quadrature du Net held that general and indiscriminate retention of communications data cannot be justified under EU law. National rules have varied widely since then, and each has faced legal challenges.
Governments want change. Reporting on member state positions during the Danish presidency said capitals asked for a minimum retention period of six months, preferably one year, with room for longer. They also asked that messaging services such as WhatsApp, Signal and Telegram store communication metadata, including location and traffic data. The Commission and most capitals read a 2024 Court of Justice ruling as reopening the door to new data retention rules.
The Commission has been preparing the ground. Commissioner Magnus Brunner said a legislative decision would follow an impact assessment due in early 2026, and the German outlet heise reported that the Commission’s home affairs department was targeting mid-2026 for a proposal. The sources reviewed for this article did not confirm a tabled legislative text, so the ministers’ exchange should be read as political steering rather than negotiation of a draft.
Civil society is already organised. A coalition of 55 organisations warned against proposals promoting maximal access to personal data, and European Digital Rights argues that retained metadata can reveal habits, beliefs and social connections. A High-Level Group on access to data for effective law enforcement produced 42 recommendations, including harmonised data retention rules and a duty to keep identifying data such as IP addresses and port numbers.
The design questions are therefore sharp. Ministers must decide whether data retention rules should cover only serious crime, how long providers must store data, which online services fall in scope, and how independent courts or authorities will approve access. Each choice will be tested against the case law of the Court of Justice, and a text that overreaches risks annulment years after adoption.
Data retention rules will not be settled in Luxembourg this week, but the 1 October exchange shows which capitals want a firm timetable. Companies that carry communications data should watch the Commission’s next step, because the scope of the rules will decide who has to store what and for how long.





