Abstract
The scope of digital criminal investigations is rapidly expanding, as they have become indispensable in prosecuting not only cybercrime but all kinds of crimes involving digital evidence. Digital investigations often involve a high degree of intrusiveness, granting law enforcement authorities large-scale access to personal data, programs, and systems. As a result, it is essential to critically assess the legitimacy of digital investigations to prevent potential abuses. When balancing the social need for crime control with the protection of citizens’ rights and interests, we find, on one side of the scale, the public interest of countering and preventing serious crime in a digital world. But which parameters must be incorporated on the other side of the scale? While most attention is given to privacy and data protection in European law to regulate the collection and processing of personal data by law enforcement in criminal proceedings, we propose that another increasingly vital interest needs to be factored in as well: the protection of cybersecurity.
Keywords
Setting the scene
In today’s information-driven era, every facet of our public and private lives is undergoing digitization, transforming everything into data. As a consequence, access to data and information has become a crucial element in the criminal justice system, where investigative activities must evolve digitally to remain effective. While the digitization of criminal investigations enhances crime-fighting and strengthens public security, it also widens the technological vulnerabilities of modern society. Cyber-intrusions into fundamental rights can now potentially also originate from Law Enforcement Authorities (LEAs) within the criminal justice system. Indeed, digital investigations have the potential to lead to technology-facilitated abuses of power, driven by an unchecked pursuit of public security. 1
To prevent misuse in this direction, it is essential to strike a balance between conflicting interests, while upholding the principle of proportionality as provided for in Article 52 of the EU Charter of Fundamental Rights. 2 Limitations on the exercise of rights and freedoms can be legitimate if they are well-grounded on both substantive and procedural levels. Substantively, the level of intrusiveness into citizens’ rights must be proportionate to the seriousness of the crime under investigation. Procedurally, the modes of data collection and analysis must be expressly regulated with procedures and guarantees provided for by law.
Digital criminal investigations can tread on a slippery slope when it comes to safeguarding fundamental rights, especially the right to protection of personal data. To address this concern, the EU developed a set of legal instruments that regulate personal data collection and processing by criminal justice authorities. The most relevant one is Directive EU/2016/680, the so-called Law Enforcement Directive (LED). 3 However, digital investigative activities keep widening their scope, and new digital tools can perform very intrusive operations and process various types of data besides personal data. Given this evolution, the regulation of digital investigations must encompass not only the procedural guarantees provided by criminal procedural law, but also the protection of other conflicting interests beside the right to the protection of personal data. 4
We need to consider the potential of new digital investigations to intrude into private systems, programs and devices, which lowers their security and compromises their confidentiality and integrity. Hence, there is a wider balance to consider besides public security vs individuals’ data protection. The regulation of digital investigative techniques must consider the citizens’ legitimate interest in performing personal activities securely and confidentially on their digital devices. We can frame this interest by the term “cybersecurity”, which will be developed in the following sections. This paper suggests that we need to start considering cybersecurity as another interest to weigh in the balance, in addition to the right to the protection of personal data, when imposing restraints on digital investigative techniques.
The first part of the paper will outline the most critical features and the differences of two illustrative types of digital investigation. The limitations they impose on conflicting interests will be highlighted, using the Italian legal system as an instructive example of how national law, within the framework of international legal instruments, regulates digital investigations. The character and the level of intrusiveness that comes with these types of digital investigations demonstrate significant differences. We will see how the first type of digital investigations considered – data production orders – raises concerns mainly regarding the right to the protection of personal data, whereas the second type – lawful hacking – triggers a broader range of conflicting interests and therefore requires a broader set of safeguards. Based on this analysis, in the final part of the paper, we will suggest that the protection of cybersecurity needs to be considered in addition to the right to personal data protection, to define the necessary safeguards for legitimate intrusions into citizens’ rights by digital criminal investigations.
Digital investigations: data production orders and lawful hacking
Digital investigations differ in their degree of intrusiveness, depending on their technical potentialities, the severity of their effects, and the potential damage they may cause to third parties. From the wide range of digital investigations, we discuss two main types of activities, namely production orders of stored computer data and lawful hacking, to illustrate the differences between a more traditional, generally lower-intrusive and well-regulated type of investigation and a newly emerging, highly intrusive and under-regulated type of investigation.
The first one finds a definition in the Cybercrime Convention of the Council of Europe. 5 According to Article 18, public authorities can order a person to submit specified computer data in that person’s possession or control, which are stored in a computer system. They can also order a service provider operating within their jurisdiction to submit subscriber information related to the services offered. In other words, LEAs can issue orders of data acquisition to individuals and service providers. As we will see in the next section, this activity is regulated in stricter terms in the Italian legal system.
A more intrusive practice is lawful hacking. LEAs use hacking techniques to “lawfully access and examine evidence at rest on devices and evidence in motion across communications networks”. 6 The spectrum of lawful hacking is quite wide, as we will see in the following sections. Generally speaking, we can say that through these techniques LEAs secretly access computer systems to copy data or to intercept communications. 7 Some of these operations, namely search and seizure of stored computer data and real-time collection of computer data, are also regulated in the Cybercrime Convention (Article 19 and Articles 20-21), but this refers to traditional measures of search and seizure and interception, not to collecting data through hacking computer systems.
The next sections will outline the most significant safeguards aimed at balancing the limitations on rights and freedoms caused by these digital investigation activities. We will argue that while data production orders are largely bound to the rules provided by data protection law, the set of safeguards related to lawful hacking should also encompass a specific regulation of the technical tools employed to safeguard cybersecurity.
Data production orders
International context: The European debate on data retention
The balance between legitimate digital investigations and fundamental rights protection finds a specific application in the data retention obligations that have been imposed on service providers, to which production orders of stored data are directed. In particular, these obligations regulate the retention of traffic data, i.e., the “external” or metadata of communications, such as data about the source and the destination of a communication; the date, time and duration of a communication, and the geographic location of the mobile phone during a communication. This subject raised an articulated debate and resulted in a series of European case law and legislation. Even though data retention was considered indispensable for the detection and prevention of serious crime, the EU started the process of re-evaluating the rules on data retention obligations in European Member States already in 2010, 8 before the General Data Protection Regulation (GDPR) and the LED.
A turning point was the well-known case of the Court of Justice of the European Union (CJEU) Digital Rights Ireland, which declared Directive 2006/24/EC on data retention disproportionately invasive of the rights protected by Articles 7, 8 and 11 of the EU Charter of Fundamental Rights. 9 The CJEU acknowledged that traffic data allow to draw precise conclusions concerning the private lives of data subjects, and that the regulation of Directive 2006/24/EC did not include a sufficiently “targeted” data retention obligation. There were insufficient limitations, such as those related to the categories of data subjects, the scope of criminal offences to which the obligation applied, and the maximum period of retention. 10
The issue of the compatibility of traffic data retention with EU law was addressed also in the case Tele 2, 11 where the arguments of Digital Rights Ireland were reaffirmed. Moreover, in the case Ministerio Fiscal, 12 the Court identified a gradation of the levels of interference against the rights to privacy and personal data protection. Among the most serious limitations to these rights, the EU judges included every use of traffic data that reveals precise contents of the private life of citizens, such as the geographic location of a mobile device. 13 Subsequently, also the cases Quadrature du Net (2020), Prokuratur (2021) and G.D. v The Commissioner (2022) addressed the matter. 14 Moreover, in 2022, the CJEU returned to address some important issues concerning the boundaries within which Member States’ national law may restrict data protection in case of relevant needs of data retention and access to personal traffic and location data by national LEAs. 15
The CJEU judgments express the pressing need to identify shared and proportionate standards in this field. While we cannot delve into the specifics of each case, we can outline that, summarizing the CJEU’s arguments, the necessary safeguards in this field must include the following: (a) a necessary link between the data subject and the crime investigated, in line with the principles of purpose limitation, data minimisation and accuracy provided by the LED; (b) a limitation of the crimes for which an acquisition order of the data retained can be issued, crimes that must grow in seriousness proportionally to the intrusiveness of the investigative activity; (c) a judicial authorization to the acquisition order; (d) regulated time limits to store data, in line with the principle of storage limitation provided by the LED; (e) security measures for the retained data, in line with the principles of integrity and confidentiality provided by the LED.
Data production orders in Italy
The principles and guidelines provided by EU data protection law (LED) and judgements on data retention must find a specific implementation in national legislation. The most suitable policy might be to implement these in the national laws related to both data protection and criminal procedure, to better coordinate these two different sets of disciplines.
Looking at the Italian legal system, production orders and traffic data retention obligations are regulated by Article 132 of the Italian Data Protection Act (Codice Privacy). 16 According to this provision, LEAs can order the acquisition of traffic data for the purpose of investigating, detecting and prosecuting serious crimes. 17 Serious crimes in this context are considered crimes punished with a maximum of at least three years’ imprisonment, and crimes of threatening and harassing by means of the telephone, when the threat, harassment and disturbance are serious. Even though the acquisition order is limited to the fight against specific crimes, there is a notable paradox in the Italian legislation, since the data retention obligation is not equally limited, but is generalized to all crimes and to all subjects. As argued in previous works, 18 this element is sufficient to consider the national legislation on the matter as violating EU data protection law principles and rules, and it should therefore be reformed by the legislator.
One of the main consequences of this paradox is that, since the provider cannot know which crime its data retention obligation serves, it will likely store all the data for the maximum time required by the law, which is seventy-two months in case of investigations against crimes of terrorism.
Beside the list of crimes for which traffic data production orders can be executed, there are other procedural safeguards. Production orders require a motivated authorization by a judge and can only be issued if there is sufficient evidence of crime (which is a lower threshold than the Criminal Procedure Code applies for other, high-intrusive investigative measures such as interception, which requires serious evidence of crime). From the EU safeguards listed above, we note another relevant gap in the national legislation, namely the lack of a regulation of security measures for the retained data, which are required also by Article 29 of the LED.
Lawful hacking
International context: Limited guidance
Lawful hacking is a commonly used term for hacking by the police; it is an umbrella term that can include different types of activities, which can be divided into three main groups: (a) online surveillance or monitoring; (b) online search and seizure; 19 (c) communication surveillance/interception. 20
Online surveillance is the most intrusive measure, consisting in a covert long-time monitoring of the computer system. 21 Online search refers to remote access to data and information that are at a given moment in a computer system, which can then be seen, copied, or extracted. 22 Communications interception can include communications transmitted by computer systems (comparable to traditional wiretapping) and communications between persons present in the same place (so-called oral interception). The latter is done by activating the microphone of the hacked device hacked – a more “advanced” version of the traditional placing of a bug or using a directional microphone.
Even though lawful hacking includes a wide range of activities, characterized by different levels of intrusiveness, one of its main challenges is that, from a technical point of view, all these different activities can be realized with the same tool: with, for instance, spyware software, LEAs can execute all the activities just mentioned. Considering their high intrusiveness, these activities must be specifically regulated with adequate, necessary and proportionate safeguards provided for by law, in accordance with Article 8 ECHR. Moreover, privacy and data protection law might be insufficient in regulating these activities, since lawful hacking infringes citizens’ fundamental rights before the collection and processing of personal data. The access to a private device itself, defined as a “window to our inner private lives”, 23 is already a relevant intrusion into the privacy of its owner, regardless of the collection and further processing of personal data acquired through the hacked device. Therefore, the normative framework in these cases must also consider the interest in protecting private programs, systems and devices against external intrusions.
There are currently no judgements from the European Court of Human Rights on lawful hacking, nor is this type of criminal investigation power regulated in international instruments such as the Cybercrime Convention. There is, however, some regulation of police hacking at the national level that has emerged over the past years. Some national law-makers have focused especially on the risks related to online surveillance. In this perspective, a relevant reference point is given by the German Constitutional Court (Bundesverfassungsgericht), which was one of the first national courts to have addressed the balance between fundamental rights protection and the public interest of fighting crime through effective digital investigations. In two cases of 2008, 24 the Constitutional Court was presented with a question of the constitutionality of the German regulation on online searches, which pertained to the rules allowing a public intelligence agency (Verfassungsschutzbehörde) to secretly monitor the internet and gain secret access to computer systems and all resources stored or processed therein. The Court’s judgments also addressed the issues raised by online surveillance activities. The infringement of fundamental rights caused by these new investigative activities were considered unconstitutional, given their high level of intrusiveness into the personal sphere and the lack of sufficient safeguards.
Comparing the international context of data production orders and lawful hacking, there is a striking difference in clear anchor points for regulation at the national level. While data production orders are regulated in the Cybercrime Convention and are also embedded in conspicuous EU case law on data retention, the European legal discourse on lawful hacking by police and criminal justice authorities is not equally articulated. This makes it all the more important to assess how this investigation power is regulated at the national level. We turn to Italian law as an instructive example of emerging regulation of this relatively new investigative activity.
Lawful hacking in Italy: Safeguards in its limits of use
The practice of lawful hacking has created a wide-ranging and articulated debate in Italy. In this practice, digital investigations are carried out by using a so-called Remote Administration Tool (RAT) (in Italian called captatore informatico), which is a type of Trojan horse that is covertly installed on a remote computer. The captatore is a software that can acquire a level of privilege to interact with the hardware as if it were the system administrator (“root”). It can, therefore, take complete control of the infected system. 25 Installing an intrusive agent on a device can damage data or system integrity, and expose it to cyber-incidents, such as allowing unauthorized access or data processing by others. The same risks occur also when the RAT is removed from the device at the end of the investigative activity.
Moreover, the investigative tool may not allow a technical selection of the personal data collected according to the purpose limitation and data minimization principles required by the LED. The purpose limitation principle is regulated in the LED (literally transposed by the Italian legislator in Legislative Decree no. 51/2018), requiring that personal data are collected and processed for specified, explicit and legitimate purposes and in a way that is not incompatible with those purposes. Collection and processing must also be proportionate (adequate, relevant and not excessive) in relation to the purposes. Personal data must furthermore be preserved in a form which allows the identification of the data subjects for a period not exceeding the achievement of the purposes for which they are processed. It is unclear whether these principles are or can be fulfilled in practice when a RAT is installed and operated.
Given the high level of intrusiveness of this tool, which deeply penetrates into private data and systems, a set of strict safeguards is required. The safeguards should be embedded in legal procedures that regulate the way it is used by LEAs, including legal limitations to its use. Italian legislation follows the same position as the German Constitutional Court, in the sense that online surveillance activities are not allowed, because they are considered too intrusive. Indeed, Legislative Decree no. 216 of 29 December 2017 limits the use of RATs to oral interception (eavesdropping directly on conversations), regardless of the other technical potentialities these tools have. Although this at first sight seems a strong limitation, a safeguard that only limits police hacking activities to oral interception is insufficient as such, since also safeguards are needed in the procedural rules for situations in which it is, in principle, allowed.
Lawful hacking in Italy: Safeguards in its procedural rules
The procedural safeguards that regulate how these activities can be executed are of prime importance. They include, for instance, the requirement of judicial authorizations and the regulation of how and to what extent the data collected can be used as evidence in the criminal justice system. 26 One of the main procedural safeguards regards the restriction of RATs for the detection and prosecution of certain crimes, according to Legislative Decree no. 216 of 29 December 2017. Interception in private residences (which occurs if a RAT is installed on someone’s private desktop computer, or on a smartphone or laptop that is (also) used in someone’s home) is allowed only where there are reasonable grounds to believe that criminal activity is being carried out in such places. There is a specific exception to this requirement, namely in case of serious crimes, such as organized crime. This exception has been expanded by Decree Law no. 161 of 20 December 2019 to some specific criminal offences committed by public officials. The latest reform (Law no. 7, 28 February 2020) 27 requires that, to execute interception in private residences by using a RAT tool for the investigation of criminal offences committed by public officials, a prior indication of the reasons justifying its use must be provided in the authorization decree.
It should be stressed that lawful hacking using a constantly evolving technological tool, despite legal limitations regarding its use, remains an inherently invasive investigation power, whose potential, as previously stated, goes far beyond the interception of communication flows. To manage the risks posed by this high invasive measure, substantive criminal law comes in aid. The criminalization of certain behaviour by public authorities serves a functional deterrent against potential abuses by LEAs. In the Italian criminal justice system, the criminal offence of illegal access to a computer system provides for an aggravating circumstance when committed by public officers who abuse their powers or violate the duties of their public function. 28 The ratio legis is quite clear: the aggravation of the criminal punishment for public agents is based on the fact that they acted by exploiting their public function.
The offence of illegal access might be committed not just when the agent accesses a computer system, but also after a legitimate access, if the agent violates the limits of the authorized access and therefore unlawfully remains in the computer system. In other words, even when public officials are authorized to lawfully access a computer system, they cannot “stay” logged-in beyond the limits set by the access authorization.
These considerations underline the importance of the judicial authorization decree (as stipulated in criminal procedure law), whose motivation must be adequately expressed and which must set the scope of the investigative action. Limitations of use and procedural safeguards in case of RAT tools are essential since, from a technical point of view, their functioning makes it possible to execute all the different kind of police hacking activities described before. According to the Italian Supreme Court, a technological tool of this type allows: (a) detecting all the incoming and outcoming traffic data from the targeted device (e.g., web browsing and e-mails); (b) activating the device’s microphone, which allows to eavesdrop on the conversations taking place in its surrounding; (c) activating the device’s camera to capture images; (d) searching the device’s hard disk to copy its memory units; (e) deciphering everything typed on the keyboard (keylogger); (f) real-time visualizing what appears on the screen of the targeted device; and so forth. 29
Therefore, the captatore is a tool that can support activities not only of communications interception (with the limits provided by law), but also of online searches, by remotely accessing the device, its data, and its networks. The fact that both these activities can be executed with the same tool blurs the distinction between them. Moreover, the capacity of eavesdropping on communications in the vicinity of the hacked device (i.e., using it as a “bug”), as well as of intercepting communications during their transmission through devices (i.e., using it as “wiretapping”), in combination with the large quantity and quality of the data that can be collected (e.g., location data of the movements of the device’s owner), question the perimeter and the identification of the investigative act as mere “interception”. 30
In short, the strict distinction between communication interception and online searches is losing significance in the technology-facilitated practice of lawful hacking. This raises questions about the Italian normative framework, which regulates them separately and with different limitations and safeguards.
Because of its all-encompassing nature and high intrusiveness, police hacking is one of the major developments in the present technological context, which is characterized by mobile technologies and the ubiquitous nature of data and information. Consequences of this change are, on the one hand, a substantive transformation of the traditional concepts of privacy and confidentiality – or at least of the way in which these interests can be protected by law, and, on the other hand, the emergence of new interests that require protection in criminal law and procedure.
The protection of different interests
In regulating digital investigations, a methodological approach that focuses on the conceptual framework of the various interests that need protection can be useful, since an interest-based approach is able to comply with the principle of technological neutrality. 31 However, when it comes to digital criminal investigations, other interests than the protection of privacy and personal data need to be considered. 32
From the protection of the confidentiality, integrity and availability of computer data and systems…
Beside the fundamental rights of privacy and data protection, digital investigations need to be balanced with other relevant interests protected by EU and national law. To identify which interests are at stake, we can examine the interests protected by the criminal laws that penalize unlawful hacking. Indeed, intrusive actions against private computer systems, when not realized by LEAs as an investigative measure, are considered a crime, in particular the crime of illegal access to a computer system, i.e., hacking.
The nature and the contents of the interests protected by this crime have generated an articulated debate among Italian scholars. For the Italian legal system, it has been argued that the offence of hacking protects the fundamental right to privacy, understood not only as the “right to be let alone”, 33 but also as a right to the confidentiality of computer systems, programs, data and information. 34
Some scholars have suggested that the interests protected by the criminalization of hacking-related conducts ought to be considered differently from the fundamental right to privacy, even though it is linked to its manifestation in the digital dimension. 35 According to this position, the offence of hacking protects people’s right to an exclusive sphere of computer confidentiality, emerging from the personal activities and interpersonal relationships that are realized online or through information and communication technologies. We should understand it as the interest to the exclusivity of access to one or more computer systems – regardless of the nature of the data and information stored therein – and as the interest to their availability against illegitimate interference by third parties. 36 This protection of the confidentiality, integrity and availability of computer systems and data is positively reflected in European and international sources, transposed into national systems. The criminal offences provided by Directive 2013/40/EU, 37 in line with the Cybercrime Convention, 38 aim to provide an adequate level of protection of these interests.
Moreover, the protection of the confidentiality, integrity and availability of computer data and systems is not only a private interest of individuals. In the era of interconnection and global communications, where resources can be accessed and used online and through any mobile communication device, computer systems have also acquired a public dimension. In other words, the protection of confidentiality, integrity and availability does not end with the interests of the single owner of the hacked systems, programs and data, but it includes a collective interest that computer systems are adequately protected. In that light, a terminological shift might be necessary: the protection of the confidentiality, integrity and availability of computer data and systems can be understood as a manifestation of the protection of an adequate level of cybersecurity.
… to the protection of cybersecurity
The need for criminal law to ensure protection of cybersecurity expresses the need to safeguard a shared infrastructural condition in the information society, which has become dependent on the proper functioning of the computer systems and networks. 39 The interest of cybersecurity is not only political or military, but also economic, social, and cultural. A clarification of terminology is useful here. The term cybersecurity is the result of a combination of two “fuzzy concepts” – “cyber” and “security”, which can be interpreted differently. 40 The former originates from the concept of cyberspace, 41 which can be understood, in its immaterial dimension, as a conceptual space where people interact using computer-mediated communication technologies. “Security” expresses multiple meanings, but generally indicates freedom from dangers or threats. The concept of cybersecurity is related to various notions, such as computer security, i.e., the interest in ensuring the availability and proper operability of computer systems, 42 information security, centred on the need to protect the confidentiality, integrity and availability of information and data, 43 ICT security, network security, infrastructure protection 44 and cyber-safety. 45
Combining key aspects of its constitutive elements and related notions, cybersecurity can be defined as the interest in the protection against threats to the confidentiality, integrity and availability and reliability of data and information, as well as of computers, devices, networks or systems through which such data and information are processed. 46 The notion of cybersecurity can be articulated on at least three levels: (a) infrastructural (devices, hardware, software and networks); (b) informational (i.e., concerning the information of the person or entity, not necessarily of a private nature); (c) personal in a strict sense (concerning personal data protection).
Focusing now briefly on the legal status of cybersecurity, we can see that the regulatory response to cybersecurity issues recently generated a rich set of laws and policies. Recent EU laws and policies addressed multiple issues related to the protection to cybersecurity, such as the NIS and NIS II Directives (EU/2016/1148 and EU/2022/2555), the Cybersecurity Act (regulation EU/2019/881) and the European cybersecurity certification scheme it installed. Moreover, also the EU proposal for a regulation on artificial intelligence (“AI Act”) addresses the need to ensure the security of AI systems and applications, resorting generically to the term cybersecurity. 47 At the Italian national level, we can see a similar development. Following various laws that implemented, inter alia, the NIS Directive, most recently, Decree-Law no. 82 of 14 June 2021 48 understands cybersecurity as the set of activities necessary to protect networks, information systems, computer services and electronic communications from cyber-threats, safeguarding their confidentiality, integrity and availability, and guaranteeing their resilience, also for the purpose of protecting national security and the national interests in cyberspace. 49
Despite these regulatory efforts, the theoretical framework around cybersecurity is still much open. The EU and national regulations focus primarily on cybersecurity as a national security concern. However, if we adopt a human-centric approach, 50 the protection against cyber-threats can be seen as a condition for the exercise of many fundamental rights, given that our devices have become an extension of our private lives and personalities. Indeed, those who enjoy cybersecurity are not computer systems, or the data stored in them, but the persons having rights and freedoms in connection with those technologies. The protection of computer and information security is not the beginning or the end of cybersecurity, but it is a means to provide protection to the natural and legal persons involved in the functioning of the information and communication technologies.
The paradigm shift that characterizes cybersecurity, seen no longer as the mere protection of confidentiality, integrity and availability of computer systems, but as the protection of persons against cyber-threats, may already be traced in the EU law on cybersecurity. The Cybersecurity Act (Regulation EU/2019/881) and the NIS II Directive (EU/2022/2555) have indeed shifted from a technical objective-oriented system to a rights-based approach. 51 According to this perspective, some scholars have started to emphasize the need to establish a right to cybersecurity in EU law, which would provide citizens with legal means to protect it, empowering them against the threats of the digital world. 52
Digital criminal investigations vs cybersecurity protection
What are the implications of the concept of cybersecurity for the regulation of digital investigations, in particular for comprehensive and high-intrusive measures such as lawful hacking? The Italian Data Protection Authority outlined that the use of a RAT tool for judicial purposes is undoubtedly useful. However, the innovative characteristics of this software – and, more generally, of online searches and communications interception – are such as to cause a substantial, very significant change in the effects and in the potentialities of the legal concept of “interception”. This “traditional” means of collecting evidence was conceived and regulated with quite different realities in mind. Due of their high intrusive potential, investigative tools used in lawful hacking may risk turning into means of massive surveillance, or exponentially multiply the vulnerability of evidence itself, specifically when data are stored in unsecured servers or, worse, relocated outside national borders. 53
Given the high level of intrusiveness of lawful hacking, the regulation of its limits cannot be delegated only to privacy and data protection law. Indeed, data protection law has a more limited scope. Its principles, although necessary, are insufficient to grant an adequate balancing of privacy and security in the context of digital criminal investigations. For instance, looking at the data minimization principle, the LED requirements might be too flexible in the context of lawful hacking, requiring that data are “adequate, relevant and not excessive” (art. 4 para. 1 LED). Therefore, unlike the GDPR, which requires that personal data are “adequate, relevant and limited to what is necessary” (art. 5 para. 1 GDPR), controllers under the LED can collect and process data in a less precise manner, since they do not have to demonstrate the strict necessity of the data processing. 54
Given that hacking into private systems and devices causes an intrusion into private lives, into the intimate spheres of people’s personality, the conceptual framework of the conflicting rights and interests in regulating digital criminal investigation cannot limit itself to a personal, informational approach, as offered by personal data protection and debates on “privacy versus security”. The normative framework should also include an infrastructural approach, focused on protecting the digital ecosystem on which people’s lives depend, regardless of the exact nature and number of data processed in particular parts of this ecosystem.
The benefits of adding cybersecurity to the regulation of digital criminal investigations are twofold. First, it would empower individuals by granting them legal means to protect their rights during investigation. Second, it would require the establishment of more specific obligations to LEAs, aimed at protecting a broader set of fundamental rights and interests. 55 However, unlike privacy and data protection law, cybersecurity has a younger legislation, and the debate around this concept, possibly in terms of a new fundamental right, is still at its beginning.
If the conceptual framework of conflicting interests is not broadened, this has a main drawback: it increases the risk to blindly put our trust in the normativity of the technology. Indeed, the complexity of technical-scientific languages puts judges and prosecutors at a disadvantage in terms of cognitive understanding, which in the worst cases translates into a superficial oversight that does not do justice to the level of technological progress achieved. 56
Therefore, the use of advanced technologies by public authorities must be accompanied by legislative interventions, both at the European and national levels, that establish limits and safeguards aimed at protecting the various interests and rights that may be restricted in the name of crime prevention and control. The regulation of the “technological rule” in the field of digital investigations cannot rely only on data protection law, but it requires a broader action that also includes cybersecurity protection.
Footnotes
Author contributions
Beatrice Panattoni drafted section 1 (Setting the scene) to section 4 (Lawful hacking); Roberto Flor drafted section 5 (The protection of different interests) and section 6 (Digital criminal investigations vs cybersecurity protection).
Declaration of conflicting interests
The author(s) declared no potential conflicts of interest with respect to the research, authorship, and/or publication of this article.
Funding
The author(s) received no financial support for the research, authorship, and/or publication of this article.
