Uncategorized

How Europol is Supervised: EDPS & CJEU (2026)

Europol processes millions of personal data records annually in criminal investigations across the EU. Two independent bodies keep it accountable: the European Data Protection Supervisor (EDPS) monitors day-to-day compliance under Article 43 of Regulation (EU) 2016/794, while the Court of Justice of the European Union (CJEU) provides judicial review when disputes arise. If your data ends up in a Europol database, you can lodge a complaint with the EDPS or challenge decisions in court—a dual safeguard that ties security cooperation to fundamental rights.

European Data Protection Supervisor (EDPS) – an independent EU authority established by Regulation (EU) 2018/1725, tasked with supervising how EU institutions and bodies, including Europol, process personal data and ensuring compliance with data-protection rules.

Court of Justice of the European Union (CJEU) – the EU’s judicial institution comprising the Court of Justice and the General Court, empowered to interpret EU law and review the legality of acts by EU bodies, including supervisory decisions by the EDPS and data-processing operations by Europol.

Key Takeaways

  • Article 43 of Regulation (EU) 2016/794 grants the EDPS exclusive supervisory authority over Europol—with power to inspect premises, order data deletion, and impose fines. Before 2022, it could only recommend; now it can compel.
  • You can submit a complaint to the EDPS within a reasonable time of discovering unlawful processing. The EDPS must investigate and respond within three months (six if complex), though timelines flex with case difficulty.
  • Judicial review works two ways: you can challenge an EDPS dismissal before the General Court within two months of notification, or the EDPS itself can refer Europol operations to the Court of Justice if a legality question looms.
  • The 2022 amendments gave the EDPS real teeth—the ability to suspend data flows to other countries and levy fines proportionate to the breach’s severity and scope. Europol can no longer simply ignore corrective orders.
  • Transparency is mandatory. The EDPS publishes annual reports detailing what it found, what it ordered, and how Europol responded. These reports sit on the EDPS website for public view—no immunity from sunlight.

Why Does Europol Require Independent Oversight?

Europol coordinates cross-border criminal investigations into terrorism, organised crime, and cybercrime. It maintains databases holding biometric identifiers, travel records, financial transactions, and communications metadata from 27 EU Member States and dozens of third-country partners. That scale matters. Without external checks, function creep—where data collected for one purpose leaks into unrelated investigations—becomes almost inevitable.

The European Parliament flagged this risk in its 2021 resolution on Europol’s expanded mandate. Large-scale data processing without judicial or parliamentary scrutiny, the Parliament argued, undermines the Charter of Fundamental Rights, particularly Article 8 (data protection) and Article 47 (the right to an effective remedy). Law enforcement sensitivity does not exempt Europol from these standards; it makes them more urgent.

The EDPS operates independently—its budget comes straight from the EU general budget, and staff cannot take instructions from any government or EU institution. This structural independence mirrors national data-protection authorities under the GDPR. Europol faces the same level of scrutiny as a private-sector data controller, despite its security mission.

Then the CJEU adds teeth. Administrative supervision by the EDPS catches day-to-day violations, but only a court can definitively rule whether a law or processing activity violates the Treaties or the Charter. In Schrems II, the Court of Justice struck down the EU-US Privacy Shield, proving that even international security agreements must pass fundamental-rights tests. Within the EU, Europol’s legal basis must clear the same hurdle, and individuals must have access to a judge.

What Powers Does the EDPS Hold Over Europol?

Article 43 of Regulation (EU) 2016/794 grants the EDPS a sweeping supervisory mandate. The EDPS can:

  • Access all personal data Europol processes—operational databases (the Europol Information System, analysis work files) and administrative records (staff files, contractor agreements)—plus any other information needed to investigate.
  • Enter Europol premises, including secure data centres and operational floors, if there are reasonable grounds to believe processing is underway.
  • Order rectification, erasure, or destruction of data processed unlawfully, or ban specific processing operations outright if they breach the Regulation.
  • Suspend data flows to other countries or international organisations if the transfer violates Chapter V of the Europol Regulation or if the recipient has misused the data. This weapon can freeze operations within days.
  • Impose administrative fines scaled to the breach’s gravity, duration, and the number of people affected. Calculations follow Article 58 of Regulation (EU) 2018/1725.

These powers match those granted to national supervisory authorities under the GDPR. Before the 2022 amendments, the EDPS could recommend but not enforce; Europol sometimes delayed or disputed corrective orders. The updated framework closes that loophole. The EDPS can now compel immediate compliance and levy fines if Europol misses deadlines.

The EDPS conducts both reactive investigations (complaints from individuals) and proactive inspections without waiting for complaints. Article 43(5) of the Europol Regulation mandates an annual EDPS report on supervisory activities, transmitted to Parliament, the Council, the Commission, and Europol’s Management Board. These reports go public on the EDPS website—a transparency layer absent from traditional law-enforcement oversight and difficult for Europol to spin or bury.

How Can Individuals Complain to the EDPS?

You can lodge a complaint with the EDPS under Article 63 of Regulation (EU) 2018/1725 if you believe Europol has processed your personal data unlawfully. The process unfolds in stages:

  1. Submission. File a written complaint (email, online form, or post) detailing the alleged infringement, the data involved, and any prior contact with Europol. No special form required—just clarity on what was processed and why you think it was illegal.
  2. Admissibility check. Within 30 days, the EDPS determines whether the complaint concerns Europol’s data processing and whether you have standing (are directly affected). Most complaints pass this gate, but vague or third-party complaints may not.
  3. Investigation. If admissible, the EDPS opens a case file, requests documents from Europol, and may inspect facilities. Europol must respond within 15 to 30 days—failure to do so itself becomes evidence of non-cooperation that the CJEU may later weigh.
  4. Decision. The EDPS issues a binding decision: either ordering corrective action (data deletion, access provision, transfer suspension) or dismissing the complaint. The decision states the legal grounds, factual findings, and what you can do next.

Timelines are not rigid—complexity, data volume, and Europol’s responsiveness all stretch deadlines. That said, Article 58(5) of Regulation (EU) 2018/1725 sets a floor: the EDPS must inform you of progress within three months and reach a final outcome within six months unless the case genuinely requires longer.

Confidentiality is built in. The EDPS will not reveal your identity without consent and can anonymise your communications with Europol if exposure would put you at risk. This matters in cases involving organised crime networks, where challenging law enforcement can trigger retaliation.

What Role Does the CJEU Play in Reviewing Europol’s Operations?

The CJEU reviews Europol’s legality through two routes: annulment proceedings under Article 263 TFEU (Treaty on the Functioning of the European Union) and preliminary references

Annulment Proceedings (Direct Actions)

You, Member States, EU institutions, or the EDPS can bring an action before the General Court (the CJEU’s trial tribunal) challenging the legality of a Europol act or EDPS decision. Article 263 TFEU allows individuals to challenge an EU act that directly and individually concerns them, or a regulatory act that directly concerns them without needing further implementation.

Case T-578/22 illustrates the standing threshold. The EDPS sought to annul two provisions in the amended Europol Regulation that expanded Europol’s data-processing powers. The General Court ruled the action inadmissible, holding that the EDPS was not “directly concerned” because the contested provisions merely expanded Europol’s competences—which the EDPS would supervise anyway. The lesson: the EDPS cannot block legislative expansions of Europol’s mandate simply because they increase supervisory workload; standing requires a change to the EDPS’s own legal position. This ceiling on the EDPS’s own judicial power paradoxically strengthens individuals’ standing to challenge instead.

When you challenge an EDPS decision dismissing your complaint, the barriers are lower. A decision addressed to you is an act of “direct and individual concern,” and you have two months from notification to sue (or from publication in the Official Journal if not addressed to you individually). The General Court examines whether the EDPS made an error of law, a manifest error of fact assessment, or a procedural mistake. If the Court annuls the decision, it goes back to the EDPS for a fresh investigation aligned with the Court’s legal reasoning—not a rubber stamp, but a genuine restart with corrected legal foundations.

Preliminary References (Indirect Review)

National courts in EU Member States can—and sometimes must—refer questions of EU law to the Court of Justice when a case raises uncertainty about how to interpret or apply an EU rule. Article 267 TFEU sets the rule: if a national court of last instance (supreme or constitutional court) faces a question of EU law that could decide the case, it must refer the question to Luxembourg unless the answer is so obvious that no reasonable judge could disagree (acte clair doctrine). This requirement exists because a national court at the highest level has no superior court to correct its interpretation of EU law.

For Europol, preliminary references matter because they let individuals challenge the agency’s legal framework without suing Europol directly. Picture this: a defendant in a national criminal trial argues that evidence Europol processed violated the Europol Regulation or the Charter of Fundamental Rights. The national court isn’t sure whether Europol’s processing was lawful, so it refers the question to the Court of Justice. Once the Court rules, that ruling binds not only the referring court but every other EU court facing the same issue—creating precedent across the entire Union rather than resolving just one case.

This mechanism has already reshaped EU agency law. In Opinion 1/15, the Court of Justice ruled that an international agreement allowing bulk transfer of passenger name records (PNR data) to a third country without independent oversight and individualised suspicion violated Articles 7 and 8 of the Charter. Although that case concerned a proposed EU-Canada PNR agreement, the same principles apply to Europol’s data transfers with non-EU partners. The ruling set a boundary that constrains what Europol can lawfully share.

“The Court of Justice has held that any processing of personal data by an EU body must be subject to review by an independent authority, and that individuals must have access to judicial redress—principles enshrined in Articles 8(3) and 47 of the Charter. Europol cannot operate in a legal vacuum; its activities remain subject to the same fundamental-rights standards as any public authority within the Union.”

Article 58(4) of Regulation (EU) 2018/1725 gives the EDPS a special power: it can refer matters to the Court of Justice ex post—after issuing its own decision—if it believes a question of EU law interpretation or validity has surfaced. This lets the EDPS seek judicial clarification without waiting for an individual complainant to sue, which speeds up how supervisory case law develops.

How Do EDPS Supervision and CJEU Review Interact in Practice?

The EDPS and CJEU don’t operate as separate parallel tracks. They’re complementary. The EDPS handles first-level enforcement: investigating complaints, ordering corrective measures, imposing fines. The CJEU provides second-level legality control: reviewing whether the EDPS applied the law correctly and whether Europol’s legal basis itself complies with the Treaties and the Charter.

A typical case works like this:

  1. An individual discovers that Europol holds a criminal-intelligence file linking them to an organised-crime investigation. They request access under Article 37 of the Europol Regulation; Europol refuses, citing Article 38 (safeguarding criminal proceedings).
  2. The individual complains to the EDPS. They argue the refusal was unjustified because the investigation concluded two years ago. The EDPS investigates, requests the case file from Europol, and finds the investigation remains formally open but dormant with no active proceedings. The EDPS orders Europol to grant access within 30 days. If Europol delays, the EDPS can impose fines on the agency itself—not just issue recommendations that Europol’s board can ignore.
  3. Europol complies but redacts portions of the file. The individual considers the redactions excessive. They bring an action for annulment before the General Court, challenging both the EDPS decision (for not ordering full disclosure) and Europol’s redacted response.
  4. The General Court reviews the EDPS decision for legality and examines whether the redactions comply with Article 38 of the Europol Regulation. If the Court finds the EDPS misapplied the law or that Europol over-redacted, it annuls the contested decision or act and may order Europol to disclose additional information.
  5. Either party may appeal the General Court’s judgment to the Court of Justice on points of law (not fact). Appeal requires leave, which the Court of Justice rarely grants. A final judgment from the Court of Justice binds all EU institutions and national authorities. This is the end of the line.

This process balances speed with fairness. The EDPS can act quickly at the investigation stage. Courts have the final word on legality, but that word comes after months or years of proceedings. The EDPS lacks power to override EU legislation itself; if it concludes that a provision of the Europol Regulation violates the Charter, it must refer the question to the Court of Justice rather than declare the provision void. Only the CJEU can invalidate EU legislation.

What Are the Limits of EDPS and CJEU Oversight?

Three structural constraints shape what the supervisory system can actually do:

Classified-Information Barriers

Europol processes intelligence shared by national security agencies, including material classified at national or NATO levels. Article 43(2) of Regulation (EU) 2016/794 says the EDPS has access to all data it needs for supervision, but doesn’t explicitly address classified material. In practice, EDPS staff with security clearance review classified files on Europol premises—they can’t take copies away. EDPS reports redact operational details that could compromise ongoing investigations.

This creates a real problem for individuals. You cannot access the classified evidence that shaped the EDPS’s decision about your complaint. The General Court softens this through in camera review—examining classified material in private without disclosing it to you—but your ability to contest the EDPS’s factual findings remains constrained. The Court of Justice has accepted that restrictions on accessing classified material are permissible if balanced by procedural safeguards, including an EDPS obligation to provide a non-classified summary sufficient for meaningful judicial review. Still, you’re fighting with one hand tied.

Jurisdictional Boundaries

The EDPS supervises Europol’s own processing, not the processing carried out by Member State authorities before or after data reaches Europol. If a national police force unlawfully collects data and transmits it to Europol, the EDPS cannot order the national authority to delete it at source—that’s the job of the national data-protection authority in that country. The EDPS can order Europol to refuse or delete data received in breach of Article 19 of the Europol Regulation (which sets conditions for transmitting data to Europol).

The CJEU reviews EU acts, not national laws. If a Member State enacts domestic legislation requiring its law-enforcement agencies to share data categories with Europol that exceed what the Europol Regulation permits, you must first challenge the national law in national courts. Only if a question of EU law arises can the national court refer to the Court of Justice. Direct access to the CJEU isn’t available for purely national breaches.

Remedies for Past Harm

EDPS decisions are forward-looking: they order Europol to cease unlawful processing, delete data, or provide access. They don’t award damages. Article 67 of Regulation (EU) 2018/1725 gives you the right to claim compensation before national courts for material or non-material damage from Europol’s unlawful processing. The national court applies Article 340 TFEU (non-contractual liability of the Union), which requires proof of three things: a sufficiently serious breach, actual damage, and a causal link between them. Getting compensation means filing a separate civil action—often lengthy and costly—after the EDPS has confirmed the infringement. This process can stretch across years. The General Court cannot award damages in annulment proceedings; a successful annulment creates the legal basis for a subsequent damages claim but doesn’t itself provide money.

How Has Oversight Evolved Under the 2022 Europol Regulation Amendments?

Regulation (EU) 2022/991 entered force in June 2022 and reshaped supervision in three ways:

EDPS powers now match those under the general data-protection regulation: The amended Article 43 incorporates investigative and corrective powers listed in Article 58 of Regulation (EU) 2018/1725, including fines up to 1% of Europol’s annual budget for serious or repeated infringements. Before the 2022 amendments, the EDPS could recommend corrective action, but Europol’s Management Board decided whether to implement recommendations. That intermediary step is gone. EDPS decisions are now binding without requiring endorsement by Europol’s governance structures. This matters because it removes a veto point where Europol could resist supervision.

The EDPS can now suspend data flows: Article 43(7) grants the EDPS power to halt transfers to a specific recipient—whether a Member State authority, a third-country agency, or an international organisation—if the recipient breached transfer conditions or if Europol transmitted data without adequate safeguards. This power is independent of Europol’s cooperation agreements. Even if Europol has a working arrangement with a third-country partner approved by the Council, the EDPS can stop transfers on a case-by-case basis if a data-protection issue emerges.

Transparency reporting became granular: Article 43(5) now requires the EDPS’s annual report to specify not only complaints received and investigations opened, but also corrective orders issued, fines imposed, and appeals lodged with the General Court. Civil-society organisations and the European Parliament can now monitor how intensively the EDPS enforces its mandate and compare Europol’s compliance record with other EU bodies.

These changes responded to concerns from the European Data Protection Board and civil-liberties advocates. Europol’s expanding mandate—particularly its authority to process large datasets for pre-defined purposes even without a link to a specific investigation—demanded stronger oversight. During the legislative process, the European Parliament’s rapporteur said “greater powers demand greater accountability,” and the final text reflects that principle by giving the EDPS enforcement tools that match Europol’s data operations in scale.

What Remedies Are Available if Oversight Fails?

If you believe the EDPS has not adequately investigated a complaint or that a General Court judgment has not been implemented, three escalation routes exist:

Complaint to the European Ombudsman: The Ombudsman investigates maladministration by EU institutions and bodies, including the EDPS. You can complain if you experience unreasonable delay, receive no reasons for a decision, or are denied access to documents. The Ombudsman won’t overturn EDPS decisions, but can issue recommendations and special reports to the European Parliament—a move that often sparks political pressure for change when other remedies stall.

Infringement action by the European Commission: When a Member State systematically refuses to cooperate with EDPS investigations or ignores CJEU judgments on Europol, the Commission can launch infringement proceedings under Article 258 TFEU. This happens rarely. It has been used, though, when national authorities brushed aside preliminary rulings about data-retention laws.

Reference to the European Parliament’s LIBE Committee: The Committee on Civil Liberties, Justice and Home Affairs holds hearings on Europol and the EDPS’s supervisory track record. You and NGOs can submit petitions or ask MEPs to raise questions during these sessions. The Parliament can’t issue binding orders, but its control over Europol’s and the EDPS’s budgets gives it real leverage.

These routes don’t replace judicial review. Instead, they layer political and administrative accountability on top. In practice, sustained pressure through multiple channels—a complaint to the Ombudsman, a petition to Parliament, ongoing dialogue with your national DPA—tends to work better than betting everything on a single procedure.

Comparison: EDPS Supervision vs. National Data-Protection Authority Supervision

Below is how EDPS oversight of Europol stacks up against national data-protection authorities (DPAs) supervising national law-enforcement agencies under the Law Enforcement Directive (Directive (EU) 2016/680):

Dimension EDPS (Europol) National DPA (Member State Police)
Legal basis Article 43, Regulation (EU) 2016/794; Regulation (EU) 2018/1725 Directive (EU) 2016/680, transposed into national law
Complaint submission Online form, email, or post to EDPS Brussels office National DPA in the Member State where processing occurred
Investigation timeline No fixed deadline; EDPS must inform complainant within 3–6 months Varies by Member State; some DPAs impose 90-day targets
Corrective powers Data deletion, transfer suspension, fines up to 1% of Europol budget Data deletion, processing ban, administrative fines (capped by national law)
Access to classified material EDPS staff with security clearance review on-site; no copies removed DPA access subject to national-security exemptions; often more restrictive
Judicial review General Court (EU), then Court of Justice on appeal National administrative/civil courts, with possible preliminary reference to CJEU
Annual reporting Mandatory under Article 43(5); published on EDPS website Required under Directive 2016/680; publication practice varies
Damages claims National court, applying Article 340 TFEU (Union liability) National court, applying national liability rules

Key takeaway: The EDPS offers centralised oversight with direct access to EU courts, but national DPAs often move faster on complaints and face fewer obstacles with classified information in purely domestic cases. If Europol and a national police force both process your data, filing parallel complaints to the EDPS and your national DPA—rather than choosing one—maximizes your chances of getting full redress.

⚠️ Time is critical — every day matters

Get a free case assessment

Our team specialises in cases with an international element. We review applicable treaties, assess risks, and prepare an action plan.

Free Consultation → 🔒 Confidential · Response within 24h · No obligation

This article is published by an independent law firm for informational purposes only and does not represent or claim affiliation with any government body, international organisation, or official authority.

Frequently Asked Questions

Can I complain directly to the CJEU about Europol's data processing?

No. The Court of Justice doesn’t accept individual complaints as a starting point. You must lodge a complaint with the European Data Protection Supervisor under Article 63 of Regulation (EU) 2018/1725 first. If the EDPS dismisses your complaint or issues a decision you believe breaks EU law, you can then file an action for annulment in the General Court within two months of receiving notice. The Court of Justice only enters the picture on appeal from the General Court, and only to review legal questions, not facts.

How long does an EDPS investigation into a Europol complaint typically take?

Under Article 58(5) of Regulation (EU) 2018/1725, the EDPS must update you within three months, or six months if your case needs deeper work. Cases involving large datasets, classified material, or transfers across multiple countries often exceed six months—but the EDPS is required to explain any delays and give you interim progress reports. Silence beyond six months is itself a breach. If the EDPS doesn’t respond, you can file a complaint with the European Ombudsman or seek a court order for failure to act before the General Court.

What happens if Europol ignores an EDPS order to delete my data?

Non-compliance is serious. Under the 2022 amendments to the Europol Regulation, the EDPS can impose fines calculated as a percentage of Europol’s annual budget and escalate to the Court of Justice under Article 58(4) of Regulation (EU) 2018/1725. You also have the right to go to the General Court seeking annulment of Europol’s refusal to comply, and later claim damages in a national court under Article 340 TFEU for the harm caused by ongoing unlawful processing. Europol’s Management Board bears responsibility for ensuring EDPS decisions are followed. Persistent defiance can trigger intervention by the European Commission or European Parliament.

Does the EDPS supervise data Europol receives from non-EU countries?

Yes, with limits. The EDPS oversees whether Europol lawfully accepted and processed data from third countries under Chapter V of Regulation (EU) 2016/794. This requires adequate safeguards and a legal basis for each transfer. If a third-country partner collected data unlawfully under its own rules, the EDPS can’t sanction that foreign agency, but can order Europol to delete the data or freeze future transfers from that source. The EDPS also reviews cooperation agreements between Europol and third countries to ensure they include sufficient data-protection safeguards. If they fall short of Charter standards, the EDPS recommends the Council suspend or renegotiate the agreement.

Can I appeal a General Court judgment to the Court of Justice if I lose my case against Europol?

An appeal is possible, but with strict limits. You can appeal only on points of law—not on facts—and only if the Court of Justice grants permission. Article 56 of the Statute of the Court of Justice sets the rules. Valid grounds include misapplication of EU law, procedural breaches that affected the outcome, or a judgment lacking proper reasoning. The Court of Justice rejects most appeals at the admissibility stage, especially those trying to re-argue facts or challenge how the General Court weighed evidence. If your appeal succeeds, the Court of Justice may overturn the General Court’s judgment, issue final judgment itself, or send the case back to the General Court with legal guidance to reconsider.

Related

Related services & guides

EDPS Complaint

Complain to the European Data Protection Supervisor about Europol.

Europol Litigation (CJEU)

Actions before the Court of Justice of the EU when remedies fail.

Europol Lawyers (hub)

Overview of every route to enforce your data-protection rights against Europol.

Share: Telegram

Related Articles

Get Free Legal Advice

Message us — we reply within minutes. Consultations are confidential.

Chat on WhatsApp