Back to Feed
PolicyJul 24, 2026

CJEU - C-162/22 - Lietuvos Respublikos generalinė prokuratūra

CJEU rules data from electronic communications can't be used for disciplinary offenses.

Summary

The Court of Justice of the European Union (CJEU) ruled in case C-162/22 that data obtained by authorities from electronic communications providers for combating serious crime cannot be used for investigating mere disciplinary offenses. This decision stems from a case where a Lithuanian prosecutor's misconduct was investigated using intercepted communications, leading to their dismissal. The CJEU clarified that such access to data is only permissible for serious crime or public security threats, not for lesser offenses.

Full text

Help CJEU - C-162/22 - Lietuvos Respublikos generalinė prokuratūra: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 10:16, 17 July 2026 view sourceDs (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators223 editsmTag: Visual edit← Older edit Latest revision as of 12:11, 24 July 2026 view source Sfl (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators512 editsm Tag: Visual edit Line 16: Line 16: |EU_Law_Name_1=Article 15 ePrivacy Directive 2002/58/EC|EU_Law_Name_1=Article 15 ePrivacy Directive 2002/58/EC |EU_Law_Link_1=https://eur-lex.europa.eu/eli/dir/2002/58/oj/eng|EU_Law_Link_1=https://eur-lex.europa.eu/eli/dir/2002/58/oj |EU_Law_Name_2=Article 5 ePrivacy Directive 2002/58/EC|EU_Law_Name_2=Article 5 ePrivacy Directive 2002/58/EC |EU_Law_Link_2=https://eur-lex.europa.eu/eli/dir/2002/58/oj/eng|EU_Law_Link_2=https://eur-lex.europa.eu/eli/dir/2002/58/oj |EU_Law_Name_3=Article 6 ePrivacy Directive 2002/58/EC|EU_Law_Name_3=Article 6 ePrivacy Directive 2002/58/EC |EU_Law_Link_3=https://eur-lex.europa.eu/eli/dir/2002/58/oj/eng|EU_Law_Link_3=https://eur-lex.europa.eu/eli/dir/2002/58/oj |EU_Law_Name_4=Article 9 ePrivacy Directive 2002/58/EC|EU_Law_Name_4=Article 9 ePrivacy Directive 2002/58/EC |EU_Law_Link_4=https://eur-lex.europa.eu/eli/dir/2002/58/oj/eng|EU_Law_Link_4=https://eur-lex.europa.eu/eli/dir/2002/58/oj |EU_Law_Name_5=|EU_Law_Name_5= |EU_Law_Link_5=|EU_Law_Link_5= Latest revision as of 12:11, 24 July 2026 CJEU - C-162/22 Lietuvos Respublikos generalinė prokuratūra Court: CJEU Jurisdiction: European Union Relevant Law: Article 15 ePrivacy Directive 2002/58/ECArticle 5 ePrivacy Directive 2002/58/ECArticle 6 ePrivacy Directive 2002/58/ECArticle 9 ePrivacy Directive 2002/58/EC Decided: 07.09.2023 Parties: Case Number/Name: C-162/22 Lietuvos Respublikos generalinė prokuratūra European Case Law Identifier: ECLI:EU:C:2023:631 Reference from: Language: 24 EU Languages Original Source: Judgement Initial Contributor: elu The CJEU held that under the E-Privacy Directive data provided to authorities by electronic communications providers for the purpose of combating serious crime cannot be used to investigate mere disciplinary offenses. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources English Summary Facts The Lithuanian Prosecutor General´s Office investigated one of its public prosecutors, who was found responsible of misconduct in its office. The research into the public prosecutor´s misconduct was authorised by a court order, allowing for the interception and recording of data transmitted over electronic communication. Following these findings, the Prosecutor General´s Office dismissed the public prosecutor from office. The public prosecutor contested the decision before the Regional Administrative Court (Vilniaus apygardos administracinis teisma), which dismissed the claim due to the lawfulness of the criminal intelligence operations and process behind the data gathered. The controller then appealed the case to the Supreme Administrative Court (Lietuvos vyriausiasis administracinis teisma), as he alleged that the access by intelligence bodies to traffic data and actual content of electronic communications was such a serious interference with fundamental rights that access could only be granted to combat serious crime. The Supreme Administrative Court considered it apparent that Article 15(1) ePrivacy Directive 2002/58/EC, together with Article 3ePrivacy Directive 2002/58/EC thereof, extends the scope of that directive only to legislative measures requiring providers of electronic communications services to grant the competent national authorities access to data (as found in C-623/17 Privacy International). Moreover, it follows from C-746/18 Prokuratuur, that only actions to combat serious crime and measures to prevent serious threats to public security are capable of justifying serious interference with Article 7 CFR and Article 8 CFR (hereinafter: the Charter). However, the CJEU did not yet rule on the impact of the subsequent use of the data concerned on the interference with fundamental rights. The Supreme Administrative Court doubted whether such subsequent use constituted a serious interference with Article 7 CFR and Article 8 CFR, and whether such use is justifiable only for the purposes of combating serious crime and preventing serious threats to public security. Thus, the Supreme Administrative Court of Lithuania referred to the CJEU the following preliminary question: - Whether Article 15(1) ePrivacy Directive 2002/58/EC precludes the use, in connection with investigations into corruption-related misconduct in office, of personal data relating to electronic communications retained, pursuant to an authorised order, by providers of electronic communications services and subsequently made available to the competent authorities to combat serious crime? Holding The CJEU pointed out that the referring court only questions the subsequent use of personal data retained by electronic communication providers on the basis of Article 15(1) Directive 2002/58. Thus, the data to be considered in this preliminary ruling decision is the data retained on the basis of Article 65(2) of Lithuanian Law on Electronic Communications, which, together with Annex I, requires electronic service providers to retain, generally and indiscriminately, traffic and location data relating to such communications for the purpose of combating serious crime. The CJEU considered that the subsequent use of traffic and location data relating to electronic communications, to combat serious crime, is only possible on two conditions: - retention of those data by providers of electronic communications services must be consistent with Article 15(1) ePrivacy Directive 2002/58/EC; and - access to those data granted to the competent authorities must be itself consistent with that provision. In C-793/19 SpaceNet and Telekom Deutschland, legislation allowing the pre-emptive retention of traffic and location data was considered not in line with EU law. However, legislation allowing for data retention under strict requirements to combat serous crime and prevent serious threats to public security was allowed under ePrivacy Directive 2002/58/EC. In light of these preliminary remarks, the CJEU started its analysis by stating that Article 15 ePrivacy Directive 2002/58/EC allows Member States to introduce exceptions to the obligations laid out in Article 5(1) ePrivacy Directive 2002/58/EC for the safeguard of national security, defence and public security, and the prevention, investigation, detection and prosecution of criminal offences or of unauthorised use of the electronic communication system. However, the CJEU considered that Article 15 ePrivacy Directive 2002/58/EC cannot expand excessively the exception to the principle of confidentiality and data storage present in Article 5 Directive 2002/58. Thus, the CJEU reiterated that the objectives listed in Article 15(1) ePrivacy Directive 2002/58/EC is exhaustive. Once having established that no other objectives can be added to the ones laid out in Article 15 ePrivacy Directive 2002/58/EC, the CJEU considered that there is a hierarchy behind the objectives according to their importance, which in turn needs to be balanced against the seriousness of the interference to an individual´s life it entails (C-140/20 Commissioner of An Garda Síochána and Others). The objective of safeguarding national security exceeds in importance the other objectives of Article 15 Directive 2002/58 and, thus, can justify more serious interference with Article 7 CFR and 8 CFR. Differently, with regards to the objective of preventing, investigating, detecting and prosecuting criminal offenses, only actions to combat serious crime and serious threats to public security can justify a serious interference with A

Entities

ePrivacy Directive 2002/58/EC (product)