[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fYXVrK4Yz3QBfeD2nnC8M1jTE8a3wvpnsFqg5TGjvxlY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"e8fbf13c-af05-4d6c-bdd0-c2dc2ccf6d9e","cjeu-rules-surveillance-data-cannot-be-repurposed-for-minor-offenses","1fee58fd-a3e3-4451-9e2d-b721c094797d","CJEU Rules Surveillance Data Cannot Be Repurposed for Minor Offenses","The CJEU ruling in C-162\u002F22 establishes a critical principle: data collected under lawful authority for serious crime investigations cannot be repurposed for lesser purposes such as disciplinary proceedings. This case highlights the legal concept of 'purpose limitation,' a cornerstone of EU data protection law under the ePrivacy Directive and GDPR, which prohibits using personal data beyond its originally authorized scope. The misuse of intercepted communications data — even by authorized government actors — constitutes a violation of proportionality and fundamental rights. Organizations and public authorities must recognize that lawful collection does not imply lawful reuse, and that each use case requires its own legal basis.","**Immediate actions:**\n- Audit all existing data-sharing agreements and interception authorizations to ensure they specify permitted use cases and scope.\n- Establish a legal review gate before any law enforcement or regulatory data is shared across departments or repurposed for unintended investigations.\n\n**Policy & Governance improvements:**\n- Implement a formal purpose limitation policy that requires documented legal justification for every secondary use of intercepted or collected communications data.\n- Train legal, compliance, and investigative staff on the proportionality principle and the restrictions imposed by the ePrivacy Directive and GDPR Article 5(1)(b).\n- Create a data access register that logs who requested data, the legal basis cited, the offense category, and the outcome of each access request.\n\n**Detection & Accountability measures:**\n- Deploy audit logging on all systems holding intercepted communications data to flag cross-purpose access attempts for compliance review.\n- Establish an independent oversight body or ombudsman process to review data access decisions and ensure alignment with judicial authorizations.",[12,13,14,15,16,17,18,19,20,21],"GDPR Article 5(1)(b) – Purpose Limitation","GDPR Article 6 – Lawfulness of Processing","EU ePrivacy Directive 2002\u002F58\u002FEC – Article 15","CJEU Case C-162\u002F22 – Lietuvos Respublikos generalinė prokuratūra","NIST SP 800-53 AC-3 – Access Enforcement","NIST SP 800-53 AU-2 – Audit Events","NIST SP 800-53 PT-2 – Authority to Process Personally Identifiable Information","CIS Control 3 – Data Protection","CIS Control 6 – Access Control Management","ITIL – Information Security Management (Service Design)","published","2026-07-24T14:21:43.073286+00:00","2026-07-24T14:21:42.97+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=CJEU_-_C-162\u002F22_-_Lietuvos_Respublikos_generalin%C4%97_prokurat%C5%ABra&diff=52477&oldid=52361","cjeu-c-162-22-lietuvos-respublikos-generaline-prokuratura-622249","CJEU - C-162\u002F22 - Lietuvos Respublikos generalinė prokuratūra",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"c0dcc566-3654-4d70-8ede-262a198e732f","Regulatory Compliance","regulatory-compliance","GDPR, NIS2, DORA, sector-specific violations","#ec4899",{"id":43,"name":44,"slug":45,"description":46,"color":47},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]