What Happened
Belgium's third attempt at establishing a lawful data retention regime in 2022 required online service providers to store identification, traffic, and location metadata to combat cybercrime and online fraud. On September 4, 2026, CJEU Advocate General Maciej Szpunar recommended striking down this law as it conflicted with fundamental privacy rights under EU law. This is the third consecutive failure of a Belgian data retention scheme since 2014.
The law required retention of origin and destination identifiers, timestamps, terminal location and port information, phone numbers, IP addresses, and other metadata. Szpunar found the regime violated Article 15(1) of the ePrivacy Directive and the Charter of Fundamental Rights because it covered a "particularly broad set of data" without adequate separation controls or precise retention criteria.
Timeline
2014: The CJEU invalidated the EU-wide Data Retention Directive, stating that indiscriminate collection and storage of telecommunications metadata constitutes mass surveillance without justification and sufficient access controls. The violation occurs at the point of collection and storage.
2020: After Belgium's second attempt at compliance, the CJEU ruled that national data retention laws must be targeted with robust access safeguards. Indefinite storage of IP addresses might be acceptable for serious crime prevention if properly controlled.
2022: Belgium enacted its third data retention law, expanding the scope of retained metadata while attempting to address previous court objections.
2024: The CJEU ruled that indiscriminate collection and storage of IP addresses and customer identity information for copyright enforcement is permissible if different metadata types remain separated until a lawful basis exists for combining them.
September 4, 2026: Advocate General Szpunar recommended striking down Belgium's 2022 law and suggested the CJEU reconsider its data retention jurisprudence to allow broader retention if "effectively watertight" separation and oversight controls exist.
Which Controls Failed or Were Missing
The Belgian regime failed on three specific control requirements:
Separation architecture: The law didn't ensure watertight separation of different data categories. Without technical and organizational measures to prevent combined use at the storage stage, the regime disproportionately interfered with Articles 7 and 8 of the Charter (respect for private life and protection of personal data).
Precision in scope and duration: The legislation left communications providers to decide which data to retain and for how long. This lack of precision meant controllers lacked clear legal obligations, and data subjects couldn't understand the extent of processing affecting them.
Oversight mechanisms: While Szpunar suggested strong oversight could mitigate rights interference, the Belgian law lacked the independent authorization and review mechanisms necessary to ensure access requests met proportionality requirements.
What the Relevant Standard Requires
Article 5(1)(c) of the GDPR establishes data minimization as a core principle: collect personal data that's adequate, relevant, and limited to what's necessary. As a processor, you're bound by Article 32 to implement appropriate technical and organizational measures ensuring a level of security appropriate to the risk.
Article 15(1) of the ePrivacy Directive allows member states to restrict confidentiality obligations when necessary, appropriate, and proportionate for specific legitimate aims. The CJEU has consistently held that bulk retention without targeted justification fails this test.
The court's 2024 ruling established that separation controls can transform indiscriminate retention into lawful processing. Your technical architecture must prevent recombination of separated metadata types without independent authorization. If you're storing IP addresses separately from timestamps and location data, your systems must enforce that separation at the database level.
Szpunar's opinion suggests future regimes might satisfy proportionality if they implement:
- Technical separation preventing combined queries without legal authorization
- Independent oversight bodies reviewing access requests before data combination
- Precise retention periods tied to specific data categories and purposes
- Clear legal criteria defining when and how separated data may be recombined
Lessons and Action Items for Your Team
Map your retention obligations to specific legal bases, not national implementing laws. Belgium's third failure shows that implementing legislation doesn't shield you from Charter obligations. If you're retaining communications metadata under member state law, document which GDPR lawful basis applies (likely Article 6(1)(c) for legal obligation) and conduct a necessity assessment under Article 15(1) ePrivacy Directive. If your national law gets struck down, you need independent justification for continued processing.
Build separation into your data architecture now. The CJEU's evolving approach suggests metadata retention will remain lawful only with watertight technical controls. If you store traffic data, location data, and identity data for the same communications, implement database-level separation. Don't rely on application-layer access controls. Consider a scenario where your incident response team needs IP addresses to investigate a breach: can your systems provide that data without exposing timestamps, geolocation, or communication patterns? If not, you're storing combined datasets that may not survive proportionality review.
Document your retention periods with category-specific justification. The Belgian law's imprecision contributed to its failure. Your Article 30 processing records should specify retention periods for each metadata category with reference to the lawful basis requiring that duration. "Retained per national law" isn't sufficient. You need: "IP addresses retained for 12 months under [specific national provision] to enable investigation of [specific offence categories]."
Prepare for regulatory flux. The European Commission is developing pan-EU data retention rules to replace the 2014 Directive. Your current compliance framework may need restructuring when those rules emerge. Identify which retention practices depend on national implementing laws that might change, and which rest on direct GDPR obligations that won't. Build flexibility into your data architecture so you can adjust retention periods and separation controls without rebuilding systems.
Review your processor agreements if you're a communications provider. When controllers instruct you to retain metadata under national law, your Article 28 agreement should specify which party bears liability if that law gets invalidated. Belgium's repeated failures show this isn't theoretical risk. If you're storing data under a controller's instruction based on potentially invalid national law, document that the lawful basis assessment is the controller's responsibility.
The advocate general's opinion signals potential movement toward accepting broader retention with stronger controls. But three failed Belgian laws in 12 years prove that good intentions don't satisfy proportionality requirements. Your technical architecture must enforce separation that survives judicial scrutiny, not just audit review.



