When the EU’s own data protection watchdog tells the EU’s own law enforcement agency to slow down, it is worth reading past the headline. That is what happened this week, when the European Data Protection Supervisor issued an opinion on the European Commission’s plan to significantly expand Europol’s powers, and found the safeguards attached to that expansion wanting.
A bigger Europol, on paper, since June
The Commission’s proposal, published 24 June, would roughly double Europol’s budget to around 3 billion euros over the 2028-2034 period, funding a larger staff and, notably, more advanced technological capability. That is a substantial expansion for an agency whose core function is coordinating cross-border law enforcement data across 27 member states, and technological capability, in Europol’s case, means expanded capacity to collect, process and match personal data at scale.
The watchdog’s objection is about oversight, not the mission
The EDPS opinion does not challenge the case for a stronger Europol. It challenges whether the proposal, in its current text, gives that stronger Europol the oversight and enforcement mechanisms needed to keep its expanded data processing inside EU data protection law. The EDPS has been explicit that Europol’s new legal framework needs robust, effective mechanisms for exactly that, not as an afterthought bolted on later, but built into the regulation before the expanded powers take effect. That is a meaningful distinction: an agency can be under-resourced and simultaneously under-supervised, and adding budget and headcount without adding proportionate oversight tends to widen that gap rather than close it.
This has happened before, and Brussels remembers how it ended
This is not the EDPS’s first objection to a Europol power grab. In 2022, the same regulator took the unusual step of legal action against an earlier amended Europol Regulation, warning at the time that it weakened data protection and threatened both the rule of law and the EDPS’s own independence to supervise the agency. An institution that has already gone to court once over this exact pattern is not raising red flags lightly the second time.
Why this matters beyond Brussels
The proposal is not law yet, it now moves into negotiation between the Parliament and Council, where the EDPS opinion carries real weight. But the direction of travel is clear: European law enforcement’s appetite for personal data is growing, and the institutions meant to check that appetite are actively pushing back rather than rubber-stamping it. For any organisation operating in the EU, that is a signal worth acting on now rather than after the regulation lands. Companies that hold personal data likely to be requested by law enforcement, telecoms, cloud and hosting providers, payment processors, financial institutions, should not assume today’s data-request handling process will look adequate once a reformed Europol has more reach and more capability to ask for it. Reviewing how your organisation verifies legal basis, documents disclosure decisions and logs law enforcement data requests is worth doing while the regulation is still being negotiated, not after it takes effect.
If your organisation wants a review of how it handles law enforcement data requests, or a broader check on whether your GDPR compliance posture is ready for a more data-hungry EU regulatory environment, contact Excello Digital. We help European organisations stay ahead of where data protection obligations are heading, not just where they stand today.
