Paradoxically, it has been after Lisbon and the establishment of a specific legal basis in EU Treaties that data protection has been progressively dismantled by a combined action of the Commission and Interior Ministers in the Council. The European Parliament gave up. And only Data Protection Authorities and the Court of justice are still standing but with several difficulties as EU institutions do not comply with rulings on data protection (EU-US privacy Shield, PNR Directive, Data Retention). Moreover, in the JHA several instruments are being adopted based on a new private-government cooperation blurring the line between GDPR and LED, data controller and data processor, and territoriality (e-evidence). Further, intrusive instruments based on a “false” legal basis of Art. 114 are being adopted challenging classical law enforcement and data protection understanding (e-privacy derogation). The EU is following the preventive security model.
Forget, C. (2023). CHRONICLE OF A DEATH FORETOLD: IS EU PREDICTIVE SECURITY POLICY KILLING DATA PROTECTION? CHRONICLE OF A DEATH FORETOLD: IS EU PREDICTIVE SECURITY POLICY KILLING DATA PROTECTION?, Bruxelles. https://hdl.handle.net/2078.5/164830