Europol Data Deletion Request
Europol cannot retain data indefinitely. We challenge unlawful data retention, file deletion requests, and pursue EDPS complaints to remove inaccurate or disproportionate Europol records.
📋 On This Page
Right to Deletion of Europol Data
Under Regulation (EU) 2018/1725 and the Europol Regulation, individuals have the right to request rectification or erasure of inaccurate, incomplete, or unlawfully processed personal data held by Europol. Data must be deleted when it is no longer necessary for the purpose for which it was collected, or when the data subject withdraws consent and no other legal basis exists.
Grounds for Europol Data Deletion
We regularly pursue deletion on the following grounds:
- Acquittal or discontinuation of criminal proceedings — the legal basis for retention no longer exists
- Expiry of retention periods under Europol’s data retention rules
- Inaccuracy — the data held is factually incorrect or misleading
- Disproportionality — the retention is no longer necessary for the stated law enforcement purpose
- Violation of fundamental rights — retention itself constitutes a breach of EU fundamental rights law
The Deletion Request Process
We submit a formal deletion request to Europol’s Data Protection Function with full legal submissions. If Europol refuses, we file a complaint with the European Data Protection Supervisor (EDPS). The EDPS has independent supervisory authority over Europol and can order deletion. As a final recourse, judicial review before the CJEU is available.
Legal Basis for Europol Data Deletion
The right to request deletion of personal data held by Europol is established under Article 67(2) of the Europol Regulation (EU) 2016/794. Europol is required to delete data that is: inaccurate; no longer necessary for the purposes for which it was collected; processed in violation of the Europol Regulation or other applicable law; or the subject of a successful data challenge upheld by the EDPS or CJEU. These grounds correspond broadly to the “right to erasure” established in the GDPR, adapted to the specific law enforcement data processing context.
Unlike the GDPR right to erasure — which is available to private data controllers — the Europol data deletion process runs through a specific institutional framework: the request goes to Europol’s Data Protection Function, appeals go to the EDPS, and judicial review is before the CJEU. Cyprus courts do not have direct jurisdiction over Europol data processing, but Cyprus lawyers can manage the full challenge process through these EU channels.
Challenging Data Shared Between Europol and Third Countries
Europol has concluded operational cooperation agreements with many non-EU countries including the United States, Canada, Australia, Colombia, Albania, and others. These agreements allow Europol to share data with non-EU law enforcement authorities. If data held by Europol has been shared with a third country — particularly the United States, which has its own law enforcement databases and sharing arrangements with its allies — the practical consequences of the data extend beyond the EU.
The deletion of data from Europol’s own databases does not automatically result in deletion from third-country databases to which the data was previously shared. However, a successful Europol deletion establishes a formal finding that the data was improperly held, which can support parallel challenges in the receiving country’s data protection framework — for example, through an FBI Privacy Act request in the United States or similar data rights mechanisms in other countries.
Emergency Data Suspension Pending Review
In cases where ongoing Europol data processing is causing immediate and concrete harm — for example, by informing Schengen Information System (SIS) flags that are causing repeated border detentions — an emergency application to the EDPS for suspension of the data processing pending review can be made. The EDPS has the authority to order Europol to suspend data processing as an interim measure. This is a high-threshold remedy but is available in genuine emergency cases where demonstrable harm from the ongoing data processing is established.
Frequently Asked Questions
After receiving a data deletion request, Europol’s Data Protection Function reviews the request and the underlying data. Europol must respond within 3 months. It may either: delete the data and confirm deletion; partially delete data and explain what remains and why; or refuse deletion with reasons. If the response is unsatisfactory, the next step is a complaint to the EDPS, which must investigate and respond within 6 months.
This is one of the complexities of Europol data deletion. Europol often holds data that was originally provided by a member state’s national law enforcement agency. In such cases, Europol may refer the deletion request to the providing member state and defer to that state’s decision on whether the data should be deleted. If the member state opposes deletion, Europol may decline to delete the data independently. In this scenario, a parallel challenge in the providing member state’s national courts or data protection authority may be necessary.
No. Europol data deletion removes data from Europol’s own systems but does not automatically remove data from member states’ national law enforcement databases. National databases are separate systems, and each requires a separate data challenge under national law. However, if Europol data deletion results from a finding that the data was inaccurate or unlawfully processed, that finding strengthens a parallel challenge in national databases.
The Europol data deletion process, from initial request to confirmed deletion, typically takes 12-30 months depending on the complexity of the case and whether the EDPS needs to intervene. An initial response from Europol should be received within 3 months. If an EDPS complaint is required, a further 6-12 months should be anticipated. If EDPS is unsatisfied with Europol’s response and issues a formal recommendation, Europol is required to comply within a specified period.
Not directly. Europol, Interpol, and OFAC are separate organisations with separate databases. Deletion from one does not automatically affect the others. However, a successful Europol data deletion may remove one of the intelligence sources that informed an Interpol notice or a sanctions designation, which can strengthen parallel challenges to those records. A coordinated data challenge strategy covering all relevant databases simultaneously provides the most comprehensive protection.