The Hague: Europe’s data protection supervisor has told legislators to draw far tighter boundaries around what Eurojust may search, cross-check and keep. In an opinion dated 11 August 2026, the European Data Protection Supervisor examined the Commission’s plan to scrap the agency’s founding regulation and replace it with a broader mandate, and found several core provisions too loosely drafted.
The Commission adopted that proposal on 24 June 2026. It would repeal Regulation (EU) 2018/1727 and rebuild the legal basis of the agency that coordinates prosecutors across the 27 member states from its seat in this city. The text extends the remit to cybercrime, gender-based violence and breaches of EU restrictive measures, including cases with a hybrid dimension, and it sharpens the agency’s role in resolving jurisdiction conflicts over European Arrest Warrants, European Investigation Orders and cross-border freezing and confiscation orders.
Most of the new capability is digital. The proposal equips the agency with an automated hit and no-hit system for exchanging data with Europol, the European Public Prosecutor’s Office and the anti-fraud office OLAF, expands its Core International Crimes Evidence Database, and gives it a defined role in ECRIS-TCN, the system that reveals which member states hold criminal records on third-country nationals.
The supervisor’s objection is precise rather than sweeping. The opinion says the text should state explicitly which databases the agency may cross-check and on what conditions, instead of leaving the perimeter to implementing practice. It also insists that whoever sends information to the agency must specify the purposes for which it may later be processed, and that any further use must pass a necessity and proportionality test rather than inherit an open-ended licence.
Automated matching is where the two concerns meet. A hit and no-hit query reveals only whether another body holds something on a given person, which sounds modest. In practice it creates a record of the query, invites follow-up requests, and produces false positives that follow a name across four agencies. The supervisor wants those conditions written into the regulation, where Parliament can amend them, rather than into technical annexes.
The proposal does not stand alone. The Commission tabled it alongside revisions to the Europol Regulation, the European Investigation Order Directive and the data protection rules governing the Union’s own institutions, a package meant to be read as a single architecture for cross-border criminal justice. Specialists warn that assessing each file separately understates how much personal data will move between bodies once all four take effect.
The groundwork was laid earlier. The Commission published its first evaluation of the Eurojust Regulation in July 2025, covering late 2019 to 2024, and concluded that the agency’s digital case management had fallen behind the crimes it was asked to coordinate against.
Parliament’s civil liberties committee and the Council’s justice working party now take the file. Member states generally favour a wider mandate for the agency; the Parliament has historically pushed back on data retention and onward transfer. The supervisor’s opinion hands rapporteurs a ready-made list of amendments, and files of this kind have been reshaped by exactly such interventions before.





