Independent EU data-protection counsel

Europol Third-Country Data Transfer

Europol may transfer your data to non-EU countries only under strict legal pathways in Regulation 2016/794. Learn how to file an EDPS complaint, request…

When Europol shares your personal data with a law enforcement agency in the United States, United Arab Emirates or another non-EU country, it must comply with strict legal safeguards under Regulation (EU) 2016/794. Any transfer that breaches those rules can be challenged through the European Data Protection Supervisor (EDPS), and—if necessary—the Court of Justice of the European Union (CJEU). Our independent legal team, operating from Limassol and London, specialises in data-protection challenges against Europol across twenty-eight jurisdictions, helping individuals enforce their rights when their data crosses EU borders without adequate protection.

Third-country data transfer – the transmission of personal data by Europol to a state or international organisation outside the European Economic Area, permitted only where the European Commission has adopted an adequacy decision under Article 36 of Directive (EU) 2016/680, an international agreement under Article 218 TFEU provides adequate safeguards, or a pre-2017 cooperation agreement under Article 23 of Decision 2009/371/JHA exists (Europol Regulation 2016/794, Article 25).

Key Takeaways

  • Article 25 of Regulation (EU) 2016/794 sets three exclusive pathways for Europol to transfer your data to third countries: Commission adequacy decision, international treaty, or legacy cooperation agreement.
  • The Executive Director may authorise exceptional case-by-case transfers only if strictly necessary, concerning an individual case, where appropriate safeguards exist and no fundamental rights override the public interest (Article 25(2)).
  • The 2022 amendments (Regulation (EU) 2022/992) expanded Europol's power to share data with private parties in third countries on a case-by-case basis, subject to the same strict-necessity test.
  • Data subjects may request access to their Europol data via their national authority or directly, with national authorities required to refer requests to Europol within one month (EDPB draft guidance, July 2023).
  • Challenges to unlawful transfers are brought before the EDPS in the first instance, with onward judicial review by the CJEU.

The Legal Framework: Three Pathways and One Exception

Europol may transfer your data to a non-EU country only under one of three conditions. First, the European Commission must have issued an adequacy decision under Article 36 of Directive (EU) 2016/680, determining that the receiving country ensures an adequate level of data protection. Second, an international agreement concluded under Article 218 of the Treaty on the Functioning of the European Union may establish adequate safeguards, forming the legal basis for the transfer. Third, a cooperation agreement concluded before May 2017 under Article 23 of Decision 2009/371/JHA remains valid, provided it contains appropriate privacy guarantees.

Where none of these three pathways exists, the Executive Director may still authorise a transfer on an exceptional, case-by-case basis. Article 25(2) of Regulation (EU) 2016/794 requires four cumulative conditions: the transfer must be strictly necessary, concern an individual and specific case, provide appropriate safeguards, and present no overriding fundamental rights that outweigh the public interest. This fourth pathway is narrow. Europol must document why the standard routes cannot be used and demonstrate proportionality before each transfer.

The 2022 amendments introduced a further dimension: Regulation (EU) 2022/992 allows Europol to transfer personal data to private entities in third countries—banks, airlines, technology firms—where the receiving party assists in a specific case and the Executive Director grants prior authorisation. The same strict-necessity test applies, and the private party must commit to adequate safeguards through a written agreement.

Europol vs. National Authorities: Who Transfers What

Europol holds two categories of data: operational information processed in its own systems and data contributed by EU member states through their National Units. When your data originates from a national law-enforcement database and is shared via Europol's Secure Information Exchange Network Application (SIENA), the legal responsibility for the initial transfer rests with the contributing member state, not Europol. Once Europol holds the data in its operational environment, however, any onward transfer to a third country engages Europol's own obligations under Article 25.

This distinction matters for challenges. If Italian authorities upload your biometric data to Europol's system and Europol subsequently shares it with United States Immigration and Customs Enforcement without an adequacy decision, you may challenge both the initial contribution (under Italian data-protection law and Directive (EU) 2016/680) and the onward transfer (under Regulation (EU) 2016/794 before the EDPS). The two proceedings run in parallel but address different legal acts.

A comparison clarifies the division of responsibility:

Phase Data controller Legal basis Supervisory authority
Upload by national authority National law-enforcement body Directive (EU) 2016/680, national transposition National data-protection authority
Storage in Europol systems Europol Regulation (EU) 2016/794 European Data Protection Supervisor
Onward transfer to third country Europol (if Europol initiates); national authority (if acting independently) Article 25, Regulation (EU) 2016/794; or Article 38, Directive (EU) 2016/680 EDPS (Europol transfers); national DPA (national transfers)

Takeaway: If Europol passes your data to a non-EU agency, Europol bears responsibility for compliance with Article 25. If a national police force transfers the same data directly, national data-protection law governs, and you challenge the national authority first. Always identify which entity initiated the transfer before filing a complaint.

⚠️ Time is critical — every day matters

Get a free case assessment

Our team specialises in cases with an international element. We review applicable treaties, assess risks, and prepare an action plan.

Free Consultation → 🔒 Confidential · Response within 24h · No obligation

Private-Party Transfers After the 2022 Amendments: A New Frontier

The 2022 changes to the Europol Regulation created something that didn’t exist before: sharing your data with private companies in third countries. Airlines, banks, tech firms, logistics operators. If they help Europol in a specific case and the Executive Director says yes, the transfer happens.

Why? Europol investigators need passenger lists from non-EU carriers, bank transfers from offshore institutions, metadata from US tech platforms. The safeguards, though, are thin. The company must sign a contract promising to limit use, keep quiet, and destroy the data when done. No independent audits. No requirement to tell you your data moved. No penalty if they break the rules.

Here’s the gap: when Europol sends data to a foreign police force, that force has its own data-protection law and often an independent watchdog. Send the same data to a private company, and the only check is a contract. Europol can’t enforce it across borders, can’t sue a US corporation for breach, can’t do much if the company hands your file to someone else. You’re left hoping the Executive Director is monitoring—and the Executive Director has limited staff and no power over foreign private actors.

Same complaint path as before: file with the EDPS, argue the transfer wasn’t necessary, the safeguards are hollow, or the company’s country lets government agencies grab data without a warrant. The EDPS hasn’t issued detailed rules on private transfers yet, so early cases will shape what comes next.

What Happens If You Miss the Deadline: Time Limits for Access Requests and Complaints

Access requests have no deadline. Ask Europol for your data tomorrow or in five years—there’s no statute of limitations. But wait too long and you lose anyway. Europol keeps operational data for six months (supporting another member state’s investigation) up to ten years (serious crime or terrorism). After that, deletion or anonymization happens automatically. A transfer from years back may leave no trace.

Complaints to the EDPS face a different clock. No fixed deadline exists, but delay hurts your case. File in March 2026 about a transfer you learned of in January 2024, and the EDPS will wonder why you waited. If Europol has already erased the records, you have nothing to challenge.

Court deadlines are strict and final. An action to annul an EDPS decision must be filed within two months of you receiving notice—extendable by ten days for distance only. A failure-to-act claim can be brought two months after you ask the EDPS to act and it fails to respond within two months of your request. Miss these windows and you lose all right to judicial review. No exceptions. No second chances.

Why Choose Us: Independent EU Data-Protection Specialists

We work alone, not for Europol, not for any law-enforcement agency, not for government. Our clients are individuals across the EU and beyond who face data-protection breaches, surveillance challenges, extradition cases tied to Europol sharing. We’re based in Limassol and London, with data-protection counsel across twenty-eight jurisdictions, so your access request reaches the right desk and your complaint hits every procedural mark.

We don’t use template letters. Every access request targets the specific data categories Europol likely holds. Every EDPS complaint cites the applicable legal basis. Every judicial application draws on the most recent CJEU case law. When Europol invokes an international agreement, we obtain the treaty text, identify gaps in the safeguards and prepare a detailed legal opinion demonstrating non-compliance. Article 25(2)? We dissect the necessity assessment, request the Executive Director’s written authorisation and challenge any failure to consider alternative measures.

Our track record speaks: EDPS complaints resulting in deletion orders. General Court judgments annulling Europol decisions. Negotiated settlements where Europol agreed to notify third-country authorities and request data return. We don’t guarantee outcomes—data-protection litigation is fact-intensive, and the EDPS and courts retain broad discretion—but we provide transparent analysis, realistic timelines and relentless advocacy at every stage.

This article is published by an independent law firm for informational purposes only and does not represent or claim affiliation with any government body, international organisation, or official authority.

FAQ

Frequently asked questions

Can I request a copy of all data Europol has transferred to third countries?

Yes. Article 36 of Regulation (EU) 2016/794 gives you the right to request confirmation of whether Europol holds data about you, which categories of data, which recipient countries and the legal basis for each transfer. Europol has three months to respond—extendable by another three months if your request is complex. File directly with Europol or go through your national data-protection authority. The practical upshot: if you file in January, expect an answer by April at the earliest. Plan accordingly if you need this information for legal proceedings or a visa application.

What can I do if Europol refuses to disclose the recipients of my data?

Europol can refuse on only three grounds: national security, prevention or detection of crime, or protection of third-party rights. When Europol invokes an exemption, it must notify the EDPS and state the specific legal basis. You may file an EDPS complaint challenging the refusal. The EDPS then conducts an independent assessment of whether the exemption is justified. That said, the burden falls on you to articulate why the refusal is improper—vague objections rarely succeed.

How do I know if the third country has adequate data-protection safeguards?

Start by checking whether the European Commission has adopted an adequacy decision for the country under Article 36 of Directive (EU) 2016/680. If not, Europol must either rely on an international agreement under Article 218 TFEU or obtain Executive Director authorisation under Article 25(2). Request a copy of the international agreement or the Executive Director’s decision as part of your access request. If you can’t obtain it, that’s often a red flag worth raising with the EDPS.

Can Europol share my data with a private company in the United States?

Yes, under the 2022 amendments (Regulation (EU) 2022/992)—but only if the Executive Director grants prior authorisation. The transfer must be strictly necessary for a specific investigation, and the private entity must sign a written agreement requiring confidentiality, purpose limitation and deletion after use. You may challenge the transfer by filing an EDPS complaint. Common grounds: the conditions aren’t actually met, or the safeguards are illusory in practice.

What happens if Europol transferred my data unlawfully—can I demand that the third country delete it?

If the EDPS finds that a transfer violated Article 25, it may order Europol to notify the third-country authority and request return or destruction of the data. Here’s the catch: Europol cannot compel the third country to comply. Most law-enforcement cooperation agreements include reciprocal deletion obligations, but enforcement depends on the recipient country’s willingness. If it refuses, you’d need to bring proceedings in that country’s domestic courts—a costly, uncertain remedy that may not recognise EU data-protection rights at all.

Related

Related services & guides

Europol Lawyers (hub)

Overview of every route to enforce your data-protection rights against Europol.

EDPS Complaint

Complain to the European Data Protection Supervisor about Europol.

Europol Litigation (CJEU)

Actions before the Court of Justice of the EU when remedies fail.

Europol, Interpol & SIS II Explained

How the EU data systems connect and your rights across them.

Speak to a Europol data-protection lawyer

Confidential, no-obligation assessment of your Europol data, EDPS complaint or CJEU matter. Available 24/7 for urgent cases.

Strictly confidential · Legally privileged · No obligation

Get Free Legal Advice

Message us — we reply within minutes. Consultations are confidential.

Chat on WhatsApp