The Court of Justice of the EU might soon change a decade of precedent. If it follows Advocate-General Maciej Szpunar's September 2026 recommendation, your data retention obligations could shift from "collect less" to "collect broadly, but separate strictly." This matters because the European Commission is drafting new EU-wide rules to replace the Data Retention Directive struck down in 2014, and Szpunar's logic offers a preview of where the law might land.
You're facing a choice: design your retention architecture around minimal collection, or prepare for a regime where broad collection is lawful if your separation controls are "effectively watertight."
The Decision You Are Facing
Do you build retention systems that minimize metadata collection upfront, or do you invest in separation and access controls that allow broader retention while keeping data categories isolated until you establish a lawful basis to combine them?
This isn't theoretical. The CJEU ruled in 2024 that indiscriminate retention of IP addresses and customer identity data for copyright enforcement is lawful if those datasets remain separate until legally justified recombination. Szpunar now argues the same principle should extend to traffic and location metadata used for cybercrime prosecution.
If the court adopts his reasoning, you'll need to decide whether your organization can operationalize "watertight" separation or whether tighter collection limits remain the safer compliance path.
Key Factors That Affect Your Choice
Your threat model. If you're defending against cybercrime that requires reconstructing communication patterns after an incident, broader retention may become defensible. Szpunar explicitly cited "systemic impunity for offenses committed exclusively online" as justification for retaining origin and destination identifiers, timestamps, and location data. If your service enables transactions or communications that criminals exploit, supervisory authorities may expect you to retain evidence.
Your technical architecture. The 2024 CJEU ruling and Szpunar's opinion hinge on separation controls. Can you store IP addresses, traffic metadata, and location data in distinct systems with access controls that prevent recombination without documented legal authorization? If your infrastructure already mingles these categories or your access logging can't prove separation, you're not ready for this regime.
Your supervisory authority's interpretation. Even if the CJEU endorses Szpunar's framework, national supervisory authorities will interpret "watertight" differently. Some may require cryptographic separation; others may accept logical partitions with audit trails. You need to know which standard applies in your lead supervisory authority's jurisdiction before committing resources.
Your data volume and retention periods. Szpunar criticized the Belgian law for covering a "particularly broad set of data" without specifying retention periods, leaving providers to guess. If the new pan-EU rules mirror this ambiguity, you'll face a choice: retain conservatively (shorter periods, fewer categories) or retain expansively and defend your interpretation if challenged.
Path A: Minimize Collection and Retention
Choose this path if you cannot implement credible separation controls or if your service doesn't face significant cybercrime risk.
When this works. You operate in a jurisdiction where your supervisory authority has signaled skepticism of broad retention, or your technical stack cannot enforce category separation without a complete rebuild. You're willing to accept that some post-incident investigations may lack sufficient metadata.
What you retain. Only what you need for immediate operational purposes: IP addresses for fraud detection, session identifiers for debugging, location data for service delivery. Delete everything within 30-90 days unless a specific legal obligation (a court order, an active investigation) requires longer retention.
Controls you need. Clear retention schedules tied to defined purposes under Article 5(1)(b). Automated deletion workflows that don't require manual intervention. Documentation showing you assessed whether longer retention was necessary and concluded it wasn't.
Risk you accept. If a cybercrime incident occurs and investigators need traffic metadata you've already deleted, you cannot help. If the new pan-EU rules make broader retention mandatory, you'll need to retrofit your systems.
Path B: Retain Broadly With Separation Controls
Choose this path if you anticipate mandatory retention requirements and you can implement technical and organizational measures that keep metadata categories isolated.
When this works. You're a communications provider, payment processor, or platform where cybercrime prosecution depends on reconstructing user activity. Your infrastructure can enforce access controls at the dataset level. You have legal and compliance resources to document every instance of data recombination.
What you retain. Origin and destination identifiers, timestamps, IP addresses, location metadata, terminal information. Store each category in a separate system or database partition with distinct access credentials.
Controls you need. Role-based access that prevents any single person from querying multiple categories without approval. Audit logs that record every access request and the lawful basis cited. A formal approval process (legal review, DPO sign-off) before recombining datasets. Encryption or pseudonymization where feasible to add another separation layer.
What "watertight" means in practice. Your systems must prevent a customer service representative from cross-referencing IP logs with location data on a whim. Access to combined datasets requires documented legal authorization: a court order, a supervisory authority request, or an internal investigation with DPO approval and a legitimate interests assessment on file.
Risk you accept. Supervisory authorities may challenge whether your controls are truly watertight. You're creating a larger attack surface: more retained data means more exposure if your separation controls fail or an attacker compromises multiple systems. Digital rights groups argue this "creates inadmissible data security risks," and they're not wrong.
Path C: Hybrid Retention With Tiered Controls
Choose this if your service has mixed risk: some functions require broad metadata, others don't.
When this works. You're a platform with both low-risk features (public content hosting) and high-risk features (financial transactions, private messaging). You can segment retention policies by service function.
What you retain. Apply Path A to low-risk services: minimal retention, short periods. Apply Path B to high-risk services: broader retention with separation controls. Document the risk assessment that justifies the difference.
Controls you need. Everything from Path B for high-risk services, plus clear internal guidelines on which services fall into which category. Regular reviews to confirm your risk classification still holds as your product evolves.
Risk you accept. Complexity. You're running two retention regimes in parallel, which means more documentation, more training, and more room for implementation errors.
Summary Matrix
| Factor | Path A: Minimize | Path B: Separate | Path C: Hybrid |
|---|---|---|---|
| Retention scope | Operational minimum only | All relevant metadata categories | Varies by service function |
| Retention period | 30-90 days | Undefined (awaiting new rules) | Mixed |
| Separation controls | Not required | Mandatory, auditable, technical + organizational | Required for high-risk services |
| Technical investment | Low | High | Medium to high |
| Supervisory authority risk | Low if justified, high if new rules mandate retention | Medium (depends on "watertight" interpretation) | Medium |
| Cybercrime investigation support | Limited | Extensive | Selective |
| Data security risk | Low (less data retained) | Higher (larger attack surface) | Medium |
The CJEU hasn't ruled yet. The European Commission hasn't published its proposal. But if you're designing retention systems now, you need to pick a direction. Szpunar's opinion suggests the court may allow broader retention than the 2014 Data Retention Directive ever did, provided your separation controls can withstand scrutiny. Whether you can build those controls, and whether your supervisory authority will accept them, determines which path you take.



