Provisional text OPINION OF ADVOCATE GENERAL SZPUNAR delivered on 3 September 2026 ( 1 ) Case C ‑ 661/24 Ordre des barreaux francophones et germanophone, Académie Fiscale ASBL, UA, vzw Liga voor Mensenrechten, Ligue des droits humains ASBL, JU, LV, Ministry of Privacy v Premier ministre/Eerste Minister (Request for a preliminary ruling from the Cour constitutionnelle (Constitutional Court, Belgium)) ( Reference for a preliminary ruling – Telecommunications sector – Processing of personal data and the protection of privacy in the electronic communications sector – Directive 2002/58/EC – Option of Member States to adopt measures for data preservation in order to safeguard the prevention, investigation, detection and prosecution of unauthorised use of the electronic communication system ) I. Introduction 1. By adopting the loi du 20 juillet 2022 relative à la collecte et à la conservation des données d’identification et des métadonnées dans le secteur des communications électroniques et à la fourniture de ces données aux autorités (Law of 20 July 2022 on the collection and retention of identification data and metadata in the electronic communications sector and the provision of such data to the authorities; ‘the Law of 20 July 2022’), the Belgian legislature intended to bring the national legislation into line with the judgment of the Cour constitutionnelle (Constitutional Court, Belgium) annulling the loi du 29 mai 2016 relative à la collecte et à la conservation des données dans le secteur des communications électroniques (Law of 29 May 2016 on the collection and retention of data in the electronic communications sector). ( 2 ) 2. That judgment had been delivered following the judgment in La Quadrature du Net and Others , ( 3 ) relating to the interpretation of Article 15(1) of Directive 2002/58/EC, ( 4 ) read in the light of Articles 7, 9 and 11 and Article 52(1) of the Charter of Fundamental Rights of the European Union (‘the Charter’). 3. Now that five actions for annulment in whole or in part of the Law of 20 July 2022 have been brought before it, the Cour constitutionnelle (Constitutional Court) once again asks the Court of Justice for an interpretation of those provisions in the light of the new national legislation which permits, inter alia, the retention of certain traffic and location data. 4. The present case therefore provides the Court with the opportunity to clarify its existing case-law on the subject, particularly with regard to the scope of the latest developments in that respect stemming from the judgment in La Quadrature du Net and Others (Personal data and action to combat counterfeiting) . ( 5 ) II. Legal framework A. European Union law 5. Recitals 2, 6, 7, 11, 14, 15, 20, 22, 26, 29, 30, 35 and 36 of Directive 2002/58 state: ‘(2) This Directive seeks to respect the fundamental rights and observes the principles recognised in particular by the [Charter]. In particular, this Directive seeks to ensure full respect for the rights set out in Articles 7 and 8 of that Charter. … (6) The Internet is overturning traditional market structures by providing a common, global infrastructure for the delivery of a wide range of electronic communications services. Publicly available electronic communications services over the Internet open new possibilities for users but also new risks for their personal data and privacy. (7) In the case of public communications networks, specific legal, regulatory and technical provisions should be made in order to protect fundamental rights and freedoms of natural persons and legitimate interests of legal persons, in particular with regard to the increasing capacity for automated storage and processing of data relating to subscribers and users. … (11) Like Directive 95/46/EC, [( 6 )] this Directive does not address issues of protection of fundamental rights and freedoms related to activities which are not governed by [EU] law. Therefore it does not alter the existing balance between the individual's right to privacy and the possibility for Member States to take the measures referred to in Article 15(1) of this Directive, necessary for the protection of public security, defence, State security (including the economic well-being of the State when the activities relate to State security matters) and the enforcement of criminal law. Consequently, this Directive does not affect the ability of Member States to carry out lawful interception of electronic communications, or take other measures, if necessary for any of these purposes and in accordance with the Convention for the Protection of Human Rights and Fundamental Freedoms, [signed at Rome on 4 November 1950 (‘ECHR’], as interpreted by the rulings of the European Court of Human Rights [(‘ECtHR’)]. Such measures must be appropriate, strictly proportionate to the intended purpose and necessary within a democratic society and should be subject to adequate safeguards in accordance with the [ECHR]. … (14) Location data may refer to the latitude, longitude and altitude of the user’s terminal equipment, to the direction of travel, to the level of accuracy of the location information, to the identification of the network cell in which the terminal equipment is located at a certain point in time and to the time the location information was recorded. (15) A communication may include any naming, numbering or addressing information provided by the sender of a communication or the user of a connection to carry out the communication. Traffic data may include any translation of this information by the network over which the communication is transmitted for the purpose of carrying out the transmission. Traffic data may, inter alia, consist of data referring to the routing, duration, time or volume of a communication, to the protocol used, to the location of the terminal equipment of the sender or recipient, to the network on which the communication originates or terminates, to the beginning, end or duration of a connection. They may also consist of the format in which the communication is conveyed by the network. … (20) Service providers should take appropriate measures to safeguard the security of their services, if necessary in conjunction with the provider of the network, and inform subscribers of any special risks of a breach of the security of the network. Such risks may especially occur for electronic communications services over an open network such as the Internet or analogue mobile telephony. It is particularly important for subscribers and users of such services to be fully informed by their service provider of the existing security risks which lie outside the scope of possible remedies by the service provider. Service providers who offer publicly available electronic communications services over the Internet should inform users and subscribers of measures they can take to protect the security of their communications for instance by using specific types of software or encryption technologies. The requirement to inform subscribers of particular security risks does not discharge a service provider from the obligation to take, at its own costs, appropriate and immediate measures to remedy any new, unforeseen security risks and restore the normal security level of the service. The provision of information about security risks to the subscriber should be free of charge except for any nominal costs which the subscriber may incur while receiving or collecting the information, for instance by downloading an electronic mail message. Security is appraised in the light of Article 17 of Directive [95/46]. … (22) The prohibition of storage of communications and the related traffic data by persons other than the users or without their consent is not intended to prohibit any automatic, intermediate and transient storage of this information in so far as this takes place for the sole purpose of carrying out the transmission in the electronic communications network and provided that the information is not stored for any period longer than is necessary for the transmission and for traffic management purposes, and that during the period of storage the confidentiality remains guaranteed. … … (26) The data relating to subscribers processed within electronic communications networks to establish connections and to transmit information contain information on the private life of natural persons and concern the right to respect for their correspondence or concern the legitimate interests of legal persons. Such data may only be stored to the extent that is necessary for the provision of the service for the purpose of billing and for interconnection payments, and for a limited time. Any further processing of such data … may only be allowed if the subscriber has agreed to this on the basis of accurate and full information given by the provider of the publicly available electronic communications services about the types of further processing it intends to perform and about the subscriber’s right not to give or to withdraw his/her consent to such processing. Traffic data used for marketing communications services … should also be erased or made anonymous … … (29) The service provider may process traffic data relating to subscribers and users where necessary in individual cases in order to detect technical failure or errors in the transmission of communications. Traffic data necessary for billing purposes may also be processed by the provider in order to detect and stop fraud consisting of unpaid use of the electronic communications service. (30) Systems for the provision of electronic communications networks and services should be designed to limit the amount of personal data necessary to a strict minimum. … … (35) In digital mobile networks, location data giving the geographic position of the terminal equipment of the mobile user are processed to enable the transmission of communications. Such data are traffic data covered by Article 6 of this Directive. However, in addition, digital mobile networks may have the capacity to process location data which are more precise than is necessary for the transmission of communications and which are used for the provision of value added services such as services providing individualised traffic information and guidance to drivers. The processing of such data for value added services should only be allowed where subscribers have given their consent. Even in cases where subscribers have given their consent, they should have a simple means to temporarily deny the processing of location data, free of charge. (36) Member States may restrict the users’ and subscribers’ rights to privacy with regard to calling line identification where this is necessary to trace nuisance calls and with regard to calling line identification and location data where this is necessary to allow emergency services to carry out their tasks as effectively as possible. For these purposes, Member States may adopt specific provisions to entitle providers of electronic communications services to provide access to calling line identification and location data without the prior consent of the users or subscribers concerned.’ 6. Article 1(1) of that directive, headed ‘Scope and aim’, provides: ‘This Directive provides for the harmonisation of the national provisions required to ensure an equivalent level of protection of fundamental rights and freedoms, and in particular the right to privacy and confidentiality, with respect to the processing of personal data in the electronic communication sector and to ensure the free movement of such data and of electronic communication equipment and services in the [European Union].’ 7. Under Article 2 of that directive, headed ‘Definitions’: ‘Save as otherwise provided, the definitions in Directive [95/46] and in Directive 2002/21/EC of the European Parliament and of the Council of 7 March 2002 on a common regulatory framework for electronic communications networks and services (Framework Directive) ( 7 ) shall apply. The following definitions shall also apply: (a) “user” means any natural person using a publicly available electronic communications service, for private or business purposes, without necessarily having subscribed to this service; (b) “traffic data” means any data processed for the purpose of the conveyance of a communication on an electronic communications network or for the billing thereof; (c) “location data” means any data processed in an electronic communications network or by an electronic communications service, indicating the geographic position of the terminal equipment of a user of a publicly available electronic communications service; (d) “communication” means any information exchanged or conveyed between a finite number of parties by means of a publicly available electronic communications service. This does not include any information conveyed as part of a broadcasting service to the public over an electronic communications network except to the extent that the information can be related to the identifiable subscriber or user receiving the information; …’ 8. As set out in Article 5 of that directive, headed ‘Confidentiality of the communications’: ‘1. Member States shall ensure the confidentiality of communications and the related traffic data by means of a public communications network and publicly available electronic communications services, through national legislation. In particular, they shall prohibit listening, tapping, storage or other kinds of interception or surveillance of communications and the related traffic data by persons other than users, without the consent of the users concerned, except when legally authorised to do so in accordance with Article 15(1). This paragraph shall not prevent technical storage which is necessary for the conveyance of a communication without prejudice to the principle of confidentiality. … 3. Member States shall ensure that the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user is only allowed on condition that the subscriber or user concerned has given his or her consent, having been provided with clear and comprehensive information, in accordance with Directive [95/46], inter alia, about the purposes of the processing. This shall not prevent any technical storage or access for the sole purpose of carrying out the transmission of a communication over an electronic communications network, or as strictly necessary in order for the provider of an information society service explicitly requested by the subscriber or user to provide the service.’ 9. Article 6 of Directive 2002/58, headed ‘Traffic data’, provides: ‘1. Traffic data relating to subscribers and users processed and stored by the provider of a public communications network or publicly available electronic communications service must be erased or made anonymous when it is no longer needed for the purpose of the transmission of a communication without prejudice to paragraphs 2, 3 and 5 of this Article and Article 15(1). 2. Traffic data necessary for the purposes of subscriber billing and interconnection payments may be processed. Such processing is permissible only up to the end of the period during which the bill may lawfully be challenged or payment pursued. 3. For the purpose of marketing electronic communications services or for the provision of value added services, the provider of a publicly available electronic communications service may process the data referred to in paragraph 1 to the extent and for the duration necessary for such services or marketing, if the subscriber or user to whom the data relate has given his or her prior consent. Users or subscribers shall be given the possibility to withdraw their consent for the processing of traffic data at any time. … 5. Processing of traffic data, in accordance with paragraphs 1, 2, 3 and 4, must be restricted to persons acting under the authority of providers of the public communications networks and publicly available electronic communications services handling billing or traffic management, customer enquiries, fraud detection, marketing electronic communications services or providing a value added service, and must be restricted to what is necessary for the purposes of such activities.’ … 10. Article 9 of that directive, headed ‘Location data other than traffic data’, provides, in paragraph 1 thereof: ‘Where location data other than traffic data, relating to users or subscribers of public communications networks or publicly available electronic communications services, can be processed, such data may only be processed when they are made anonymous, or with the consent of the users or subscribers to the extent and for the duration necessary for the provision of a value added service. The service provider must inform the users or subscribers, prior to obtaining their consent, of the type of location data other than traffic data which will be processed, of the purposes and duration of the processing and whether the data will be transmitted to a third party for the purpose of providing the value added service. …’ 11. Article 15 of that directive, headed ‘Application of certain provisions of Directive [95/46]’, states: ‘1. Member States may adopt legislative measures to restrict the scope of the rights and obligations provided for in Article 5, Article 6, Article 8(1), (2), (3) and (4), and Article 9 of this Directive when such restriction constitutes a necessary, appropriate and proportionate measure within a democratic society to safeguard national security (i.e. State security), defence, public security, and the prevention, investigation, detection and prosecution of criminal offences or of unauthorised use of the electronic communication system, as referred to in Article 13(1) of Directive [95/46]. To this end, Member States may, inter alia, adopt legislative measures providing for the retention of data for a limited period justified on the grounds laid down in this paragraph. All the measures referred to in this paragraph shall be in accordance with the general principles of [EU] law, including those referred to in Article 6(1) and (2) [TEU]. … 2. The provisions of Chapter III on judicial remedies, liability and sanctions of Directive [95/46] shall apply with regard to national provisions adopted pursuant to this Directive and with regard to the individual rights derived from this Directive. …’ B. Belgian law 12. The Law of 20 July 2022 amended, inter alia, the Law of 17 January 2003 on the status of the Belgian regulator for the postal and telecommunications sectors (‘the Law of 17 January 2003’) and the Law of 13 June 2005 on electronic communications (‘the Law of 13 June 2005’). 1. The Law of 17 January 2003 13. Article 25/1 of the Law of 17 January 2003, as amended by Article 24 of the Law of 20 July 2022, is worded as follows: ‘§ 1. For the purposes of investigating, detecting or prosecuting an offence referred to in Article 145(3) or (3 bis ) of the [Law of 13 June 2005] or point 2 of Article 24(1), a senior law-enforcement officer of the [Belgian Institute for postal services and telecommunications (‘the Institute’)] may, in writing: 1° require an operator to respond to a request for identification data which is necessary for those purposes; 2° request the cooperation of the persons and institutions referred to in Article 46 quater (1) of the Code d’instruction criminelle [(Code of Criminal Procedure)] and associations representing them, on the basis of the online payment reference specific to an electronic communications service which has previously been provided by an operator in accordance with point 1, in order to identify the person who paid for the service; 3° request the cooperation of closed centres or accommodation facilities within the meaning of Articles 74/8 and 74/9 of the Law of 15 December 1980 on the admission to the territory, residence, settlement and removal of foreign nationals, where the subscriber has subscribed to an electronic communications service, on the basis of the contact details of the centre or accommodation facility which have previously been provided by an operator in accordance with point 1, for the purpose of identifying the subscriber; 4° request the cooperation of any other legal person who is the subscriber of an operator or who subscribes to an electronic communications service in the name and on behalf of natural persons, on the basis of data previously provided by an operator in accordance with point 1, for the purpose of identifying the subscriber or habitual user of the service. A request referred to in the first subparagraph may be transmitted to a person referred to in that subparagraph only with the written authorisation of a senior law-enforcement officer referred to in Article 24(2). Such authorisation may be granted only on the basis of a written and reasoned request sent to that officer in accordance with paragraph 5. § 2. For the purposes of performing his or her tasks, a senior law-enforcement officer of the Institute may require an operator, in writing, to respond to a request for metadata which is necessary for the purposes of investigating, detecting or prosecuting an offence referred to in Article 145(3) or (3 bis ) of the [Law of 13 June 2005], or in point 2 of Article 24(1). Except in duly justified cases of urgency, the senior law-enforcement officer of the Institute may send the request to the operator only after submitting a written and reasoned request to the investigating judge and with the latter’s written authorisation. In a duly justified case of urgency as referred to in the second subparagraph, the senior law-enforcement officer of the Institute shall, without delay after the request has been sent to the operator, provide the investigating judge with a copy of that request, the grounds for the request and the justification for the urgency. A subsequent review shall be carried out by the investigating judge. Where, following that subsequent review, the investigating judge refuses to confirm the validity of the request sent by the senior law-enforcement officer of the Institute to the operator, that officer shall notify the operator concerned without delay and delete the metadata obtained. § 3. By way of derogation from paragraphs 1 and 2, for the purpose of monitoring compliance with Articles 126, 126/1, 126/2, 126/3 or 127 of the [Law of 13 June 2005] and the orders implementing them, and at the written and reasoned request of a senior law-enforcement officer of the Institute, an operator shall, within the period specified in the requisition, grant access for consultation of its databases which implement one of those articles or implementing orders. A request referred to in subparagraph 1 may be transmitted to an operator only with written authorisation from a senior law-enforcement officer of the Institute referred to in Article 24(2). Such authorisation may be granted only on the basis of a written and reasoned request in accordance with paragraph 5. The request sent to the operator shall state the names of the senior law-enforcement officers of the Institute who may access the database. Those officers may take copies of the data and documents consulted pursuant to subparagraph 1 only for the purpose of detecting offences committed by the operator. § 4. For the purposes of paragraphs 1 and 2, the persons referred to in the first subparagraph of paragraph 1, from whom a senior law-enforcement officer of the Institute has requested data, shall provide him or her with those data in real time or, as the case may be, at the time stated in the requisition. For the purposes of paragraphs 1 to 3, any person who, in the performance of his or her duties, becomes aware of the measure or assists in its implementation shall be bound by an obligation of secrecy. Any breach of that obligation shall be punishable in accordance with Article 458 of the Criminal Code. Any person who refuses to provide the data or who fails to provide them in real time or, as the case may be, at the time specified in the requisition, shall be liable to a fine of between EUR 26 and EUR 10 000. Any person who refuses to permit consultation of the database in accordance with paragraph 3, or who fails to permit such consultation within the period specified in the requisition, shall be liable to a fine of between EUR 26 and EUR 10 000. § 5. For the purposes of paragraphs 1 to 3, the grounds for the request sent to the senior law-enforcement officer referred to in Article 24(2) or to the investigating judge must be set out having regard to the circumstances of the investigation. For the purposes of paragraphs 1 and 2, those grounds shall specify: 1° the link between the data requested and the objective of investigating, detecting or prosecuting the specific offence justifying the request; 2° why the data requested are strictly necessary for the purposes of the investigation. § 6. The senior law-enforcement officers of the Institute shall record in a register: 1° all the requests referred to in paragraphs 1, 2 and 3; 2° the grounds for the request and the justification for the urgency with which the investigating judge was provided in accordance with the third subparagraph of paragraph 2; 3° the authorisations provided for in paragraphs 1, 2 and 3.’ 2. The Law of 13 June 2005 14. Article 2 of the Law of 13 June 2005, as amended by Article 2 of the Law of 20 July 2022, provides: ‘For the purposes of this law: … 5/5° “fraud” means a dishonest act carried out with the intention of deceiving, in breach of the law, regulations or a contract, and of procuring for oneself or another person an unlawful advantage to the detriment of the operator or the end-user, by means of the use of an electronic communications service; 5/6° “malicious use of the network or service” means use of the electronic communications network or service for the purpose of harassing the addressee or causing damage; … 11° “operator” means any person who has submitted a notification in accordance with Article 9; …’ 15. Article 122 of that law, as amended by Article 5 of the Law of 20 July 2022, provides: ‘ § 1. Operators shall delete traffic data relating to subscribers or end-users, or make such data anonymous, as soon as they are no longer needed for transmission of the communication. … § 4. By way of derogation from paragraph 1, in order to be able to take the appropriate measures referred to in Article 121/8(1), to enable fraud or malicious use of the network or service to be established or its perpetrator or origin to be identified, and in so far as the operator processes or generates the data in connection with the provision of that network or service, the operator shall: 1° retain, in connection with the provision of an interpersonal communications service and for four months from the date of the communication, the traffic data necessary for those purposes from among the following traffic data: – the identifier of the origin of the communication; – the identifier of the destination of the communication; – the precise dates and times of the start and end of the communication; – the location of the terminal equipment of the parties to the communication at the start and end of the communication; 2° retain for 12 months from the date of communication the following traffic data relating to incoming communications in connection with the provision of interpersonal communications services for the purpose of identifying the originator of the communication: – the telephone number from which the incoming communication originated, or; – the IP address used to send the incoming communication, the time stamp and the port used, and; – the precise dates and times of the start and end of the incoming communication; 3° retain the data referred to in point 1 relating to a specific identified case of fraud or identified instance of malicious use of the network for as long as is necessary for its analysis and resolution, where appropriate beyond the four-month period referred to in point 1; 4° retain the traffic data referred to in point 2 relating to a specific instance of malicious use of the network for as long as is necessary to deal with the latter, where appropriate beyond the 12-month period referred to in point 2; 5° process the traffic data necessary for those purposes, including, where necessary, the data referred to in paragraph 2. By way of derogation from paragraph 1, in order to be able to take the appropriate measures referred to in Article 121/8(1), to enable fraud or malicious use of the network or service to be established, or its perpetrator or origin to be identified, the operator may retain and process data other than those referred to in the first subparagraph which are considered necessary for those purposes. The King may, by decree deliberated in the Council of Ministers and after obtaining the opinion of the Institute and the Data Protection Authority, specify and extend the categories of traffic data whose retention must be regarded as necessary for the purposes laid down in this paragraph. In the event of suspected fraud or suspected malicious use, operators may transmit to the competent authorities all data lawfully retained in connection with the suspected fraud or suspected malicious use. § 4/1. By way of derogation from paragraph 1, operators may retain and process traffic data which are necessary to ensure the security and proper functioning of their electronic communications networks and services, and in particular for the detection and analysis of a potential or actual breach of that security, including identification of the origin of that breach. Operators may retain such data for a period of 12 months from the date of the communication. Operators may retain the data referred to in the first subparagraph relating to a specific breach of network security for the period necessary to deal with that breach, where appropriate beyond the 12-month period referred to in the second subparagraph. In the event of a breach of the security of their electronic communications networks and services, operators may transmit to the competent authorities all data lawfully retained in relation to that security breach. § 4/2. By way of derogation from paragraph 1, operators shall retain and process the traffic data necessary to comply with an obligation imposed by a formal legislative provision, for the period required for that purpose. § 5. The data listed in this Article may be processed only by persons tasked by the operator to carry out billing or traffic management, handle subscribers’ requests for information, combat fraud or malicious use of the network, ensure network security, ensure compliance with its legal obligations, market its own electronic communications services or provide services that make use of traffic or location data, and by members of its Coordination Unit referred to in Article 127/3. …’ 16. Article 123 of that law, as amended by Article 6 of the Law of 20 July 2022, is worded as follows: ‘§ 1. Without prejudice to the application of [Regulation (EU) 2016/679 ( 8 )] and the Law of 30 July 2018, mobile network operators may retain and process location data other than traffic data relating to a subscriber or end-user only in the following cases: 1° where this is necessary for the proper functioning and security of the network or service, data being retained for a maximum of 12 months from the date of the communication, except in the event of a specific breach of network security requiring the retention of the data concerned to be extended beyond that period; 2° where this is necessary to detect or analyse fraud or malicious use of the network, data being retained for a maximum of four months from the date of communication, except in the event of a specific case of fraud or specific instance of malicious use requiring the retention of the data concerned to be extended beyond that period; 3° where the data have been made anonymous; 4° where the processing is part of the provision of a service which makes use of traffic or location data; 5° where the processing is necessary to comply with an obligation imposed by a formal legislative provision. … § 4. The data referred to in this Article may be processed only by persons working under the authority of the operator or the third party providing the service that makes use of traffic or location data, or by the operator’s Coordination Unit referred to in Article 127/3. Processing shall be limited to what is strictly necessary to be able to provide the service concerned with traffic or location data. …’ III. The facts of the dispute in the main proceedings, the questions referred for a preliminary ruling and the procedure before the Court 17. The non-profit associations Académie Fiscale ASBL, Ordre des barreaux francophones et germanophone, the Liga voor Mensenrechten VZW, the Ligue des droits humains ASBL, the private foundation Ministry of Privacy, UA, LV and JU have brought before the Cour constitutionnelle (Constitutional Court) five actions seeking the annulment in whole or in part of the Law of 20 July 2022 on the ground that it infringes Articles 10, 11, 12, 13, 15, 22, 23 and 29 of the Belgian Constitution, read in conjunction with Articles 5, 6, 8, 9, 10, 11, 14 and 18 of the ECHR, Articles 7, 8, 11 and 47, and Article 52(1) of the Charter, Article 5(4) TEU, Article 6 of Directive 2002/58, Directive (EU) 2016/680 ( 9 ) and the GDPR. 18. That court considers that only the applicants’ complaints concerning Articles 5, 6 and 24 of the Law of 20 July 2022 give rise to doubts within the meaning of the case-law resulting from the judgments of 6 October 1982, Cilfit (283/81, EU:C:1982:335) and of 6 October 2021, Consorzio Italian Management and Catania Multiservizi (C‑561/19, EU:C:2021:799) as to the interpretation of Article 15 of Directive 2002/58. 19. First of all, as regards Article 5 of that law, the applicants in the main proceedings have, in essence, argued, inter alia, that that article imposes on providers of electronic communications services a general and indiscriminate obligation to retain traffic data and location data for long or indefinite periods, without such retention being necessary or limited to what is strictly necessary. 20. It was apparent from the travaux préparatoires that Article 5(4) and (5) of that law is intended, inter alia, to transpose Article 15(1) of Directive 2002/58. The Belgian legislature stated in those travaux préparatoires that it was not possible to provide for data retention that is ‘reactive and targeted from the outset’ on account of the very structure of the networks and services concerned. It was also considered that the system for the retention of traffic data provided for in Article 5(4) and (5) of the Law of 20 July 2022 is ‘in the interests of the end-users of the operator’s services’ and intended to enable victims of fraud or a malicious use of the network to identify the perpetrator thereof. Furthermore, in those travaux préparatoires , that data retention was described as being ‘intrinsically linked to the provision of electronic communications services’ and as enabling the modernisation of the Law of 13 June 2005 in the light of the increasing importance of the objective of combating fraud and malicious use of the network in EU law ( Doc. parl., Chambre , 2021-2022, DOC 55 2572/001, pp. 26 to 29). 21. In the view of the referring court, it is necessary to examine whether the interference with the fundamental rights to respect for private life and the protection of personal data, which Article 122(4) and Article 122(4/1) of that law, as incorporated by points 4 and 5 of Article 5 of the Law of 20 July 2022, entails, produces disproportionate effects on the persons whose data is concerned. 22. Article 122(4) of the Law of 13 June 2005 imposed an obligation on operators to retain various traffic data with a view to ‘taking the appropriate measures referred to in Article 121/8(1), to establish fraud or the malicious use of a network or service, or to identify the perpetrator and the origin thereof’, in so far as operators process such data ‘in connection with the provision of that network or service’. The traffic data to be retained were ‘the identifier of the origin of the communication’, ‘the identifier of the destination of the communication’, ‘the precise dates and times of the start and end of the communication’ and ‘the location of the terminal equipment of the parties to the communication at the start and end of the communication’ (paragraph 1 of point 1 of Article 122(4)). It was also provided that those operators were to retain several items of traffic data relating to incoming communications for the purposes of identifying the originator of the communication, that is to say ‘the telephone number from which the incoming communication originated’, ‘the IP address used to send the incoming communication, the time stamp and the port used’, and ‘the precise dates and times of the start and end of the incoming communication’ (paragraph 1 of point 2 of Article 122(4)). 23. However, the list of data set out in the first subparagraph of Article 122(4) of that law was not exhaustive since the second subparagraph of that provision allowed operators to retain and process data other than those referred to in the first subparagraph of that provision, which are considered necessary for the purpose of establishing fraud or malicious use of the network or service or identifying its perpetrator and origin. That option for operators to retain and process data other than those referred to in the first subparagraph of Article 122(4) was not subject to a prior opinion of the Institute or the Data Protection Authority or to notification to those authorities. The travaux préparatoires for that provision did not provide any justification for that option. 24. Next, the third subparagraph of Article 122(4) of that law provided that ‘the King may, by decree deliberated in the Council of Ministers and after obtaining the opinion of the [Institute] and the Data Protection Authority, specify and extend the categories of traffic data whose retention must be regarded as necessary for the purposes laid down in this paragraph’. The travaux préparatoires justified that power by the fact that fraud evolves significantly over time and that the data retained may differ according to the type of electronic communications service, the size of the operator, the tools available to it and the users of the service. 25. As regards the retention periods, the data referred to in point 1 of the first subparagraph of Article 122(4) of the Law of 13 June 2005 were in principle retained for four months, whilst the data referred to in point 2 of the first subparagraph of Article 122(4) of that law were in principle retained for 12. Those retention periods could be extended. In that regard, point 3 of the first subparagraph of Article 122(4) of that law provided that the data referred to in point 1 of that provision which related to specific fraud or specific malicious use of the network could be retained ‘for as long as is necessary for its analysis and resolution, where appropriate beyond the four-month period referred to in point 1’. In addition, point 4 of Article 122(4) of that law states that the data referred to in point 2 of that provision relating to a specific instance of malicious use of the network may be retained ‘for as long as is necessary to deal with the latter, where appropriate beyond the 12-month period referred to in point 2’. 26. Article 122(4/1) of the Law of 13 June 2005 provides that operators may retain and process data ‘necessary to ensure the security and proper functioning of their electronic communications services, and in particular for the detection and analysis of a potential or actual breach of that security, including identifying the origin of that breach’. That option for operators is likewise not subject to a prior opinion from the Institute or the Data Protection Authority or notification to those authorities. The data referred to could thus be retained in principle for a basic period of 12 months under the third subparagraph of Article 122(4/1). However, data relating to a ‘specific’ breach of network security could be retained ‘for the period necessary to deal with that breach, where appropriate beyond the 12-month period referred to in the second subparagraph’. 27. The referring court concludes that Article 122(4) of that law provides for the general and systematic retention of the traffic data to which it refers and that the obligation to retain data constitutes the rule rather than the exception. That finding applies all the more since, under the fourth subparagraph of Article 122(4) of that law, traffic data retained by operators connected with suspected fraud or suspected malicious use may be transferred to the competent authorities, in particular to the judicial authorities, the police services and the senior law-enforcement officers of the Institute, so that the retention and processing of data by operators on the basis of Article 122(4) of the Law of 13 June 2005 may give rise to criminal proceedings. 28. As regards Article 122(4/1) of that law, the referring court observes that that provision does not specify which data may be retained. Moreover, data relating to a ‘specific breach’ of network security may be retained ‘beyond the 12-month period referred to in the second subparagraph’ and neither the wording of Article 122(4/1) of that law nor the travaux préparatoires for the Law of 20 July 2022 specify what constitutes a specific breach. 29. The referring court observes that the Court has not yet ruled on the interpretation of Article 15 of Directive 2002/58 where measures for the retention of electronic communications data in order to ensure the prevention, investigation, detection and prosecution of unauthorised uses of the electronic communications system are at issue. In addition, the parties’ views on the interpretation of Article 15(1) of that directive, which have been presented before it, differ. 30. Next, as regards Article 6 of the Law of 20 July 2022, the referring court notes that the applicants’ complaints concerned the retention of location data, other than traffic data, which come within the scope of Article 15(1) of that directive and which are referred to in points 1, 2 and 5 of Article 123(1) of the Law of 13 June 2005, as replaced by Article 6 of the Law of 20 July 2022. 31. Article 123(1) of the Law of 13 June 2005 provides that the operators concerned may retain and process those location data relating to a subscriber or end user only ‘where this is necessary for the proper functioning and security of the network or service’ (point 1 of Article 123(1)) and ‘where this is necessary to detect or analyse fraud or malicious use of the network’ (point 2 of Article 123(1)). The data referred to in point 1 of Article 123(1) of that law were in principle to be retained for 12 months from the date of the communication, whilst those referred to in point 2 of Article 123(1) of that law were in principle to be retained for four. 32. The situations referred to in points 1 and 2 of Article 123(1) of that law sought to ensure the prevention, investigation, detection and prosecution of unauthorised uses of the electronic communications system within the meaning of Article 15(1) of Directive 2002/58. 33. It is for the referring court to ascertain whether the interference with the fundamental rights of respect for private life and the protection of personal data, which those provisions entail, is necessary, reasonable and proportionate within a democratic society in order to prevent unauthorised use of the electronic communications system. In that regard, the referring court notes that it is for the operators to identify the location data other than traffic data which they consider necessary to retain and process. Those operators also assessed, in each case, the need for such retention and processing. Furthermore, it was provided that the 12-month period may be extended ‘in the event of a specific breach of network security requiring the retention of the data concerned beyond that period’ and that the four-month period referred to above may be extended ‘in the event of a specific case of fraud or specific instance of malicious use requiring the retention of the data concerned beyond that period’. Lastly, it was for those operators to decide whether or not the retention period should be extended. 34. For the same reasons as those at issue in relation to Article 5 of the Law of 20 July 2022, Article 6 of that law raised doubts as to the interpretation of Article 15(1) of Directive 2002/58. 35. As regards, lastly, Article 24 of that law, the referring court notes that that provision inserts, in the Law of 17 January 2003, Article 25/1 governing access by a senior law-enforcement officer of the Institute to metadata. The applicant’s complaints seeking the annulment of Article 24 were based on the infringement of the fundamental rights to respect for private life and the protection of personal data, guaranteed by Article 22 of the Belgian Constitution, Article 8 of the ECHR, Articles 7 and 8 and Article 52(1) of the Charter, Directive 2002/58, Directive 2016/680 and the GDPR. Since Article 24 of the Law of 20 July 2022 refers to Articles 5 and 6 of that law in respect of which it was necessary to refer questions to the Court for a preliminary ruling, the national court considers that it is appropriate to stay the proceedings on the examination of the complaints relating to Article 24, pending the Court’s answer to those questions. 36. It is in those circumstances that the Cour constitutionnelle (Constitutional Court) decided to stay the proceedings and to refer the following questions to the Court of Justice for a preliminary ruling: ‘(1) Must Article 15(1) of [Directive 2002/58], read in conjunction with Articles 7 and 8 and Article 52(1) of the [Charter], be interpreted as: (a) precluding national legislation which lays down an obligation for operators of electronic communications services to retain and process the traffic data referred to in that legislation in the context of the provision of that network or service for a period of 4 or 12 months, as the case may be, for the purposes of taking appropriate, proportionate, preventive and remedial measures in order to prevent fraud and misuse of their networks and to prevent end users suffering harm or inconvenience, as well as to establish fraud or malicious use of the network or service or enable the perpetrators or origin thereof to be identified; (b) precluding national legislation which allows those operators to retain and process the traffic data concerned beyond the abovementioned time limits, in the case of identified specific fraud or identified specific malicious use of the network, for the time required for its analysis and resolution or the time necessary to process that malicious use; (c) precluding national legislation which, without laying down an obligation to request a prior opinion or to notify an independent authority, allows those operators to retain and process data other than those referred to in the law, with a view to making it possible to establish fraud or malicious use of the network or service, or to identify its perpetrator and origin; (d) precluding national legislation which, without laying down an obligation to request a prior opinion or to notify an independent authority, allows those operators to retain and process for a period of 12 months the traffic data which they consider necessary to ensure the security and proper functioning of their electronic communications networks and services, and in particular for the detection and analysis of a potential or actual breach of that security, including identifying the origin of that breach and, in the event of a specific breach of network security, for the period necessary to process it? (2) Must Article 15(1) of [Directive 2002/58], read in conjunction with Articles 7 and 8 and Article 52(1) of the [Charter], be interpreted as: (a) precluding national legislation which allows mobile network operators to retain and process location data, without the legislation describing precisely which data are covered, in the context of the provision of that network or service, for a period of 4 or 12 months, as the case may be, where necessary for the proper functioning and security of the network or service, or to detect or analyse fraud or malicious use of the network; (b) precluding national legislation which allows those operators to retain and process location data beyond the abovementioned time limits, in the event of a specific breach and in the case of specific fraud or specific malicious use? (3) If, on the basis of the answers to the first or the second question, the [Cour constitutionnelle (Constitutional Court)] should conclude that certain provisions of the [Law of 20 July 2022] infringe one or more of the obligations arising from the provisions referred to in those questions, may it maintain on a temporary basis the effects of the abovementioned provisions of the Law of 20 July 2022 in order to avoid legal uncertainty and to enable the data previously collected and retained to continue to be used for the objectives pursued by the law?’ 37. Written observations were submitted by the Ligue des droits humains, the Belgian, Estonian, Irish, Spanish and Finnish Governments and the European Commission. Those parties, as well as the Académie Fiscale and the Italian Government, presented oral argument at the hearing on 14 April 2026. IV. Analysis A. Preliminary remarks 38. The compatibility of national regimes for the retention of and access to traffic and location data with Article 15(1) of Directive 2002/58, read in the light of Articles 7 and 8 of the Charter, has been examined by the Court on many occasions. 39. Nevertheless, the Court continues to receive regular requests for guidance in that regard. The continuing stream of references for preliminary rulings concerning the interpretation of those provisions can undoubtedly be explained by the highly fact-specific nature of the questions put to the Court in this area. It cannot be overlooked that this case-law has recently undergone substantial developments, as the Court has, for the first time, been called upon to consider the retention of and access to traffic data in relation to the detection and prosecution of offences committed exclusively online. It therefore seems appropriate to provide a brief overview of that case-law, in particular its most recent developments (section B). 40. However, these continued references may also be a sign of the difficulties that national courts may encounter in their day-to-day practice in applying the Court’s case-law, particularly where they are called upon to assess the compatibility with EU law of national law on the retention of and access to traffic and location data. It seems to me that the Court’s relevant case-law may, on account of its case-by-case development, appear complex or even, in some respects, difficult to understand (section C). 41. I will therefore attempt to provide a systematic overview of the Court’s case-law on the retention of traffic and location data (section D), before examining, in the light of those principles, the questions referred to the Court for a preliminary ruling in the present case (section E). B. Case-law on the interpretation of Article 15(1) of Directive 2002/58 in relation to regimes for the retention of traffic and location data 1. The exception provided for in Article 15 (1) of Directive 2002/58 42. Directive 2002/58 sets out a number of principles surrounding the retention and processing, by providers of electronic communications services, of traffic and location data. 43. First of all, Article 5(1) of that directive lays down the principle of confidentiality of both electronic communications and related traffic data and entails, inter alia, a prohibition, in principle, on any person other than users from storing, without his or her consent, those communications and data. ( 10 ) 44. Next, Article 6(1) of that directive provides that traffic data relating to subscribers and users must be erased and made anonymous when they are no longer necessary for the transmission of a communication. ( 11 ) 45. Lastly, Article 9 of that directive provides that location data other than traffic data may be processed only subject to certain conditions and after they have been made anonymous or the consent of the users or subscribers obtained. ( 12 ) 46. Thus, in adopting Directive 2002/58, the EU legislature gave concrete expression to the rights enshrined in Articles 7 and 8 of the Charter, so that the users of electronic communications services are entitled to expect, in principle, that their communications and data relating thereto will remain anonymous and may not be recorded, unless they have agreed otherwise. Therefore, that directive does not merely create a framework for access to such data through safeguards to prevent abuse, but also enshrines, in particular, the principle of the prohibition of their storage by third parties. ( 13 ) 47. Article 15(1) of that directive specifically allows Member States to adopt legislative measures that ‘restrict the scope’ of the rights and obligations laid down, inter alia, in Articles 5, 6 and 9 of that directive, such as those arising from the principles of confidentiality of communications and the prohibition on storing related data. 48. That provision also sets out a list of objectives capable of justifying a restriction of the rights and obligations provided for, inter alia, in Articles 5, 6 and 9 of Directive 2002/58. Those objectives are the safeguarding of national security, defence and public security or the prevention, investigation, detection and prosecution of criminal offences or of unauthorised use of the electronic communications system, The Court has previously held that the list of objectives set out in the first sentence of Article 15(1) of that directive is exhaustive, as a result of which a legislative measure adopted under that provision must correspond, genuinely and strictly, to one of those objectives. ( 14 ) 49. Article 15(1) of that directive is therefore an exception to the general rule laid down in those provisions and must therefore, in accordance with settled case-law, be interpreted strictly. ( 15 ) 50. Consequently, Article 15(1) of that directive also reflects the fact that the rights enshrined in Articles 7, 8 and 11 of the Charter are not absolute rights, but must be considered in relation to their function in society. Indeed, as can be seen from Article 52(1) of the Charter, that provision allows limitations to be placed on the exercise of those rights, so long as those limitations are provided for by law, respect the essence of those rights and, in compliance with the principle of proportionality, are necessary and genuinely meet objectives of general interest recognised by the European Union or the need to protect the rights and freedoms of others. Thus, in order to interpret Article 15(1) of Directive 2002/58 in the light of the Charter, account must also be taken of the importance of the objectives of protecting national security and combating serious crime in contributing to the protection of the rights and freedoms of others and of the importance of the rights enshrined in Articles 3, 4, 6 and 7 of the Charter, which may give rise to positive obligations for public authorities. ( 16 ) 51. The Court has thus consistently held that, against the backdrop of those various positive obligations, a balance is to be struck between the different legitimate interests and rights at issue. In that context, it is clear from the very wording of the first sentence of Article 15(1) of Directive 2002/58 that the Member States may adopt a measure derogating from the principle of confidentiality where such a measure is ‘necessary, appropriate and proportionate within a democratic society’. Recital 11 of that directive specifies, in that respect, that a measure of that nature must be ‘strictly’ proportionate to the intended purpose. ( 17 ) 2. Proportionality as a central element of the analysis of a data retention regime in the light of Article 15 (1) of Directive 2002/58 52. As I stated in my second Opinion in La Quadrature du Net and Others (Personal data and action to combat counterfeiting) , the principle of proportionality therefore lies at the heart of the analysis of a national measure for the retention of traffic and location data in the light of Article 15(1) of Directive 2002/58, and has two aspects. ( 18 ) 53. First, the Court has held that, in order to satisfy the requirement of proportionality, the legislation must lay down clear and precise rules governing the scope and application of the measure in question and imposing minimum safeguards, so that the persons whose personal data is affected have sufficient guarantees that data will be effectively protected against the risk of abuse. That legislation must be legally binding under domestic law and, in particular, must indicate in what circumstances and under which conditions a measure providing for the processing of such data may be adopted, thereby ensuring that the interference is limited to what is strictly necessary. ( 19 ) In other words, it is necessary to ensure that the regime in question satisfies a number of conditions intended to limit the extent of the interference that it involves. 54. Second, it is settled case-law that the question whether the Member States may justify a limitation on the rights and obligations laid down, inter alia, in Articles 5, 6 and 9 of Directive 2002/58 must be assessed by measuring the seriousness of the interference entailed by that limitation and by verifying that the importance of the public interest objective pursued by that limitation is proportionate to that seriousness. ( 20 ) Simply put, the issue is one of ensuring that the importance of the objectives pursued corresponds to the level of seriousness of the interference that the traffic and localisation data regime entails. According to the Court, there is a hierarchy amongst those objectives according to their respective importance ( 21 ) and safeguarding national security is capable of justifying more significant interference with fundamental rights, whereas combating crime in general can only form the basis for less serious interference. 55. It is on the basis of those principles that the Court has held, inter alia, that a national measure providing for the general and indiscriminate retention of traffic and location data may be justified only by the objective of safeguarding national security, ( 22 ) whereas such a measure cannot be justified by the objective of combating crime in general. ( 23 ) 56. In that same vein, the Court accepts the possibility of targeted retention of those data, particularly on the basis of a geographical criterion, for the purposes of pursuing the objective of combating serious crime, ( 24 ) and retention of the IP addresses assigned to the source of a connection in pursuit of that objective. ( 25 ) 57. By contrast, as regards data relating to the users’ identity, given that their retention involves a lesser degree of interference with fundamental rights, they can be retained for the purpose of combating crime in general. ( 26 ) 58. That approach is also the approach followed by the ECtHR. When examining whether a national measure providing for the retention of certain traffic and location data constitutes an infringement of Article 8 ECHR, the ECtHR makes the proportionality of that measure the central element of its analysis. Thus, in view of the seriousness of the interference under consideration with the applicants’ exercise of their rights coming within the scope of Article 8 ECHR, ( 27 ) it holds that national legislation providing for the general and indiscriminate retention of communications data infringes that article since it is insufficient to limit to what is necessary in a democratic society the interference which it entails with the right to respect for private life. ( 28 ) 3. The recent adaptation of the case-law on the interpretation of Article 15 (1) of Directive 2002/58 with regard to crime committed exclusively online 59. More recently, the Court has clarified the assessment of the proportionality of a measure for the retention of certain traffic and location data, where that measure is intended to detect and prosecute offences committed exclusively online. ( 29 ) In doing so, the Court has adjusted its interpretation of Article 15(1) of Directive 2002/58 in two respects. 60. In the first place, the Court has refined its examination of the seriousness of the interference which a measure for the retention of certain traffic and location data entails – in the present case, IP addresses assigned to the source of a connection. Thus, the Court has held that a measure, under Article 15(1) of Directive 2002/58, permitting the general and indiscriminate retention of IP addresses may, where appropriate, be justified by the objective of combating criminal offences in general, ( 30 ) where it is genuinely ruled out that that retention could give rise to serious interference with the private life of the person concerned due to the possibility of drawing precise conclusions about that person by, inter alia, linking those IP addresses with a set of traffic or location data which have also been retained by those providers. ( 31 ) 61. The Court has further specified that a Member State which intends to impose such an obligation on providers of electronic communications services must ensure that the arrangements for retaining those data are such as to guarantee that any combination of those IP addresses with other retained data, which would allow precise conclusions to be drawn about the private lives of the persons whose data is retained, is ruled out. ( 32 ) Accordingly, it is for that Member State to establish data retention arrangements which must relate to the very manner in which the retention is structured; in essence, that retention must be organised in such a way as to guarantee a genuinely watertight separation of the different categories of data retained. ( 33 ) 62. The judgment in La Quadrature du Net II thus develops the previous case-law on the interpretation of Article 15(1) of Directive 2002/58. Not only is it clearly stated that the seriousness of the interference depends on the conclusions that can be drawn regarding the private lives of the individuals whose data is retained, the Court also accepts that Member States have the possibility, by establishing specific arrangements for the retention of the data in question, of influencing the degree of seriousness of the interference. ( 34 ) 63. In the second place, the Court recalls that, as regards offences committed online, accessing certain data, including the IP address from which a connection originates, may be the only means of investigation enabling the person to whom that address was assigned at the time when the offence in question was committed to be effectively identified. ( 35 ) 64. According to the Court, that alone tends to show that the retention of the relevant data is – as regards combating criminal offences committed online – strictly necessary for the attainment of the objective pursued and therefore meets the requirement of proportionality imposed by Article 15(1) of Directive 2002/58. ( 36 ) Not allowing the retention of (and subsequent access to) such data carries a risk of systemic impunity for criminal offences committed online which cannot be ignored for the purposes of assessing, when balancing the various rights and interests in question, whether an interference with the rights guaranteed by Articles 7, 8 and 11 of the Charter is a proportionate measure in the light of the objective of combating criminal offences. ( 37 ) 65. As a result, the judgment in Quadrature du Net II seems to me to lead to a certain relaxation of the Court’s case-law on Article 15(1) of Directive 2002/58 or, at the very least, to a pragmatic application of its principles. 66. However, a reading of the directive as a whole reveals, in my view, certain limits. C. The pitfalls of the case-law on the interpretation of Article 15(1) of Directive 2002/58 as regards regimes for the retention of traffic and location data 67. The coexistence of a more flexible line of case-law, as regards the retention of data necessary for combating criminal offences committed online under Article 15(1) of Directive 2002/58, and the Court’s established case-law on the interpretation of that provision, seems to me to have two limits. 68. In the first place, and from a practical point of view, I note that a combined reading of the judgments in Quadrature du Net II and previous judgments has the effect of requiring providers of electronic communications services to maintain multiple sets of retained data, each having to meet different technical characteristics, depending on the objective pursued by the retention. 69. Although such an issue might already have arisen prior to the judgment in La Quadrature du Net II on account of the different data retention regimes according to the objective pursued, it appears to have become even more pronounced. 70. The Court’s case-law now requires Member States, when they impose, for the pursuit of an objective of lesser importance than the defence of national security, the retention of traffic and location data which in principle allow precise conclusions to be drawn about private lives of users, to establish retention arrangements which ensure that the various categories of data are kept entirely separate. ( 38 ) 71. According to the Court’s case-law, those retention arrangements must ensure that, from a technical point of view, the separation of the various categories of data retained is genuinely watertight, by means of a secure and reliable computer system . ( 39 ) In addition, the various data thus retained must be linked through the use of an effective technical process which does not undermine the effectiveness of the watertight separation of those categories of data. ( 40 ) Furthermore, the reliability of that watertight separation must be subject to regular review by a public authority other than that which seeks to obtain access to the personal data retained by the providers of electronic communications services. ( 41 ) 72. Thus, the retention of traffic and location data necessary for the detection and prosecution of offences committed exclusively online requires, in order to be carried out in accordance with Article 15(1) of Directive 2002/58, a number of technical adjustments on the part of providers of electronic communications services. 73. However, no such requirement exists in respect of traffic and location data retained for the purpose of addressing a serious threat to national security. In such a situation, those data may be retained in a single dataset, thereby facilitating cross-referencing between them, without that calling into question the compatibility of such a mechanism with Article 15(1) of that directive. 74. It follows that the requirements arising from the Court’s case-law on the interpretation of that provision appear to me to lead to a proliferation of separate datasets for the retention of traffic and location data, which must, moreover, meet different requirements. 75. In my view, such a solution carries a not insignificant risk to the security of the traffic and location data to be retained in a dataset ensuring their watertight separation so that no precise conclusions can be drawn about users’ lives. As the same data are subject to two different retention methods, it cannot be ruled out that the less secure dataset might be used – at the very least inadvertently – to obtain data unconnected to a serious threat to national security. 76. In addition, as the Ligue des droits humains pointed out at the hearing, it seems to me that the proliferation of datasets for the retention of identical data also carries the risk that the Court’s most recent case-law will not be effectively implemented. In so far as all traffic and location data are already collected in a single file for the purposes of safeguarding national security, there is an appreciable likelihood that providers of electronic communications services will ultimately refrain from structuring the data at all where they are retained in pursuit of the other objectives set out in Article 15(1) of Directive 2002/58. 77. In the second place, a reading of the Court’s case-law on the interpretation of Article 15(1) of Directive 2002/58 as a whole leads me to question the very logic of that provision. 78. It is clear from that case-law that the seriousness of the interference that the retention of traffic and location data involves relates to the conclusions that can be drawn from those data as to the private lives of users. Moreover, the Court accepts that the interference may be limited by technical measures specifically intended to ensure that such conclusions cannot be drawn. 79. It follows, in my view, from those considerations – which lie at the heart of the proportionality test set out in Article 15(1) of Directive 2002/58 – that determining the level of interference with fundamental rights essentially depends on the subsequent use that may be made of the data in question. 80. It is true that the Court has consistently held that the retention of traffic and location data constitutes an interference with fundamental rights, irrespective of whether the information in question relating to private life is sensitive or whether the persons concerned have been inconvenienced in any way on account of that interference. ( 42 ) Similarly, whether or not the retained data have been used subsequently is irrelevant, since access to such data is a separate interference with the fundamental rights, irrespective of the subsequent use made of them. ( 43 ) 81. Therefore, the issue here is not one of disputing the idea that the mere retention of traffic and location data constitutes, in itself, an interference with fundamental rights. 82. However, it seems to me that that interference results primarily from the fact that those data are capable of being used in such a way as to enable conclusions to be drawn about users’ private lives. As the Court has also made clear, data are retained only for the purpose, when necessary, of making those data accessible to the competent national authorities. ( 44 ) Where there is no retention of traffic and location data, the question of the interference which accessing such data entails does not arise. ( 45 ) 83. Simply put, in my view the retention of traffic and location data constitutes an interference with fundamental rights because it constitutes the requirement for subsequent access to them, irrespective of whether or not such access actually takes place. 84. As a result, I am of the view, like the Commission, that a regime providing for the general and indiscriminate retention of traffic and location data should not, as a matter of principle, be ruled out merely because it does not pursue the objective of safeguarding national security. In so far as such a regime remains subject to arrangements governing the structuring of the retention of those data, such as those developed by the Court in the judgment in La Quadrature du Net II , and to strict temporal limits, it seems to me that the resulting interference with fundamental rights remains proportionate. 85. That is all the more so since the Court’s case-law, even before the judgment in La Quadrature du Net II , seems to me to lay the foundations for such a solution. By accepting the possibility of data retention on the basis of a geographical criterion, for reasons other than those relating to the safeguarding of national security, ( 46 ) the Court implicitly recognises that general and indiscriminate data retention may, subject to certain conditions, be permitted under Article 15(1) of Directive 2002/58. 86. On the other hand, the acknowledgement that such a traffic and location data retention regime is compatible with Article 15(1) of that directive must necessarily go hand-in-hand with a significant strengthening of the conditions governing access to such data, in particular where such access is requested in the pursuit of objectives of lesser importance within the hierarchy of that provision. 87. In particular, and broadly speaking, access to data thus retained should be refused where it is justified by an objective under Article 15(1) of that directive of lesser importance, even where the resulting interference with fundamental rights is of a serious nature. In other words, the requirement that the seriousness of the interference with fundamental rights corresponds to the importance of the objective pursued does not disappear, but is focused on the stage of assessing the interference with fundamental rights resulting from such access. 88. In my view, such an approach would, first of all, help to mitigate the risk of systemic impunity for offences committed exclusively online or the commission or preparation of which is facilitated by the specific characteristics of the internet. It would ensure that the data required to prosecute such offences exist, even as the development and growing importance of the internet lead at the same time to a rise in cybercrime. ( 47 ) 89. Next, when combined with strengthened conditions for access to the relevant data, that approach would at the same time ensure that the interference with fundamental rights entailed by such retention is limited. 90. Lastly, by avoiding the proliferation of different techniques for retaining such data, that approach also makes it possible to prevent the Court’s case-law from being circumvented in the Member States – whether inadvertently or otherwise – through access, on grounds unrelated to the safeguarding of national security, to data retained in a general, unstructured dataset in pursuit of that objective, or through the failure of electronic communications service providers to implement it effectively. 91. I therefore take the view that it is possible, and indeed desirable, to extend the solution developed by the Court in the judgment in La Quadrature du Net II to all traffic and location data retention regimes adopted on the basis of Article 15(1) of Directive 2002/58. ( 48 ) D. A proposal for systematisation 92. Article 15(1) of Directive 2002/58 should thus be interpreted as not precluding national legislation which, for the pursuit of the objectives set out in that provision, provides for the general and indiscriminate retention of traffic and location data, provided that, under that legislation, those data are retained in conditions and in accordance with technical arrangements which ensure that the possibility that that retention might allow precise conclusions to be drawn about the private life of users is ruled out, which may be accomplished, in particular, by imposing on providers of electronic communications services an obligation to retain the various categories of personal data in such a way as to ensure a genuinely watertight separation of those different categories of data, thereby preventing, at the retention stage, any combined use of those different categories of data – and for a period not exceeding what is strictly necessary. 93. Such legislation must also lay down clear and precise rules governing the scope and application of the measure in question and imposing minimum safeguards, so that the persons whose personal data are affected have sufficient guarantees that those data will be effectively protected against the risk of abuse. That legislation must be legally binding under domestic law and, in particular, must indicate in what circumstances and under which conditions a measure providing for the processing of such data may be adopted, thereby ensuring that the interference is limited to what is strictly necessary. 94. It is on the basis of those principles that I shall analyse the questions referred for a preliminary ruling. E. Answers to the questions referred 1. The first question referred 95. By its first question, the referring court asks, in essence, whether Article 15(1) of Directive 2002/58, read in the light of Articles 7 and 8, and Article 52(1) of the Charter, precludes legislation which: – lays down an obligation for providers of electronic communications services to retain and process the traffic data referred to in that legislation for a period of 4 or 1 2 months, as the case may be, in order to enable those providers to take appropriate, proportionate, preventive and remedial measures to prevent fraud and misuse of their networks and to prevent end users suffering harm or inconvenience, as well as to establish fraud or malicious use of the network or service or enable the perpetrators or origin thereof to be identified; – allows providers of electronic communications services to retain and process the traffic data concerned beyond the abovementioned time limits, in the case of an identified specific instance of fraud or malicious use of the network, for the time required for its analysis and resolution or the time necessary to process that malicious use; – allows providers of electronic communications services, without laying down an obligation to request a prior opinion or to notify an independent authority, to retain and process data other than those referred to in that directive, with a view to making it possible to establish fraud or malicious use of the network or service, or to identify its perpetrator and origin; – allows providers of electronic communications services, without laying down an obligation to request a prior opinion or to notify an independent authority, to retain and process for a period of 12 months the traffic data which they consider necessary to ensure the security and proper functioning of their electronic communications networks and services, and in particular for the detection and analysis of a potential or actual breach of that security, including identifying the origin of that breach and, in the event of a specific breach of that security, to retain those data for the period necessary to process that breach. 96. The first question therefore concerns Article 122(4) and (4/1) of the Law of 13 June 2005. That provision sets out both an obligation and an option requiring providers of electronic communications services to retain certain traffic and location data for the purpose of detecting or identifying the perpetrator of fraud or malicious use of the network or service. 97. The Belgian Government argues that such legislation is justified by the objective set out in Article 15(1) of Directive 2002/58, namely the prevention, investigation, detection and prosecution of unauthorised uses of the electronic communications system, and that, furthermore, it is strictly proportionate to that objective. 98. This does not appear to me to be the case. 99. I would begin by noting that the data covered by Article 122(4) and (4/1) of the Law of 13 June 2005 constitute a particularly broad range of data. That provision covers: the identifiers of the origin and destination of the communication, the precise dates and times of the start and end of the communication, the location of the terminal equipment of the parties to the communication, the telephone number from which the incoming communication originated, the IP address at the source of the incoming communication, the time stamp and the port used, the precise dates and times of the incoming communication, and all the data necessary to ensure the security and proper functioning of their electronic communications services. As a result, the data which providers of electronic communications services retain make it possible to trace and identify the source of a communication and its destination, and to determine the date, time, duration of the communication and the location of the users. ( 49 ) There is therefore no doubt that those data allow precise conclusions to be drawn about the private life of users. 100. Although, according to my interpretation of the Court’s case-law on Article 15(1) of Directive 2002/58, the existence of such an interference with fundamental rights may nevertheless be justified on the basis of that provision, that is only on condition that the legislation at issue imposes, in respect of the retention of that set of data, a precise method of retention in such a way as to limit the interference resulting from the retention of that set of data. 101. However, it is in no way apparent from the national legislation that the data at issue are retained in conditions and in accordance with technical arrangements which ensure that that can be ruled out. It does not in any way impose arrangements for the retention of those data in such a way as to ensure a genuinely watertight separation of the different categories of data, thereby preventing, at the retention stage, any combined use of those different categories of data. 102. Therefore, the interference which the retention of the data referred to in Article 122(4) and (4/1) of the Law of 13 June 2005 involves is not, in my view, proportionate to the objective pursued. 103. In any event, I note that the legislation at issue in the main proceedings is, in my view, characterised by considerable uncertainty both as regards the data actually retained by providers of electronic communications services and the duration of such retention. 104. First, I note that, in addition to the data expressly listed, Article 122(4/1) of the Law of 13 June 2005 allows providers of electronic communications services to retain ‘the traffic data necessary to ensure the security and proper functioning of their networks’ and that it also provides that the data expressly listed may be supplemented by a decree of the King. 105. Second, Article 122(4) and (4/1) of that law authorises providers of electronic communications services to retain the data at issue for the period necessary to deal with an identified instance of fraud or malicious use of the network, beyond the period expressly provided for by the legislature. 106. Consequently, it is ultimately left to the providers of electronic communications services to decide whether to retain data and to determine the extent of the data concerned and the period of retention. 107. Therefore, in the absence of clear and precise rules on both to the extent of the data retained and the duration of their retention, thus leaving open the possibility of unlimited retention solely at the initiative of providers of electronic communications service, the national legislation at issue in the main proceedings cannot be considered to be proportionate to the objective pursued. 108. Similarly, such legislation appears to me to be clearly contrary to the requirement that any limitation on the exercise of fundamental rights must be provided for by law, which implies that the legal basis which permits interference with those rights must itself define the scope of the limitation on the exercise of the right concerned. ( 50 ) 109. Therefore, I am of the view that Article 15(1) of Directive 2002/58, read in the light of Articles 7 and 8 and Article 52(1) of the Charter, must be interpreted as precluding national legislation such as that referred to by the referring court in its first question. 2. The second question referred 110. By its second question, the referring court asks, in essence, whether Article 15(1) of Directive 2002/58, read in the light of Articles 7 and 8 and Article 52(1) of the Charter, precludes legislation which: – allows providers of electronic communication s services to retain and process location data, without the legislation describing precisely which data are covered, in the context of the provision of a network or service, for a period of 4 or 12 months, as the case may be, where necessary for the proper functioning and security of that network or service, or to detect or analyse fraud or malicious use of the network; – allows providers of electronic communications services to retain and process location data beyond the abovementioned time limits, in the event of a specific breach or instance of fraud or malicious use. 111. The second question therefore concerns Article 123 of the Law of 13 June 2005, which sets out the obligation on providers of electronic communications services to retain location data for a period of 4 or 12 months, as the case may be, and the option of extending those retention periods. 112. That question relates to the retention of location data other than traffic data. In that regard, I would point out, as is stated in recital 35 of Directive 2002/58, that location data giving the geographic position of the terminal equipment of the mobile user constitutes traffic data covered by Article 6 of that directive where they are processed to enable the transmission of communications. However, in addition, digital mobile networks may have the capacity to process location data which are more precise than is necessary for the transmission of communications and which are used for the provision of value added services such as services providing individualised traffic information and guidance to drivers. This type of data comes within the scope of Article 9 of that directive, which provides that such data may only be processed anonymously or with the consent of users or subscribers. ( 51 ) 113. In so far as the national legislation at issue in the main proceedings limits the scope of the rights and obligations laid down in that provision, it must comply with the requirements laid down in Article 15(1) of that directive, as interpreted by the case-law of the Court. 114. I note that the legislation which is the subject of the second question referred displays, in my view, the same characteristics as that referred to in the first question and which led me to consider it contrary to Article 15(1) of Directive 2002/58. 115. First, it does not lay down any requirement to structure data and, second, it lacks precision as regards both the data retained and the period of their retention since those two elements are left to the discretion of providers of electronic communications services. 116. Therefore, for the same reasons as those identified in my answer to the first question, ( 52 )Article 15(1) of Directive 2002/58, read in the light of Articles 7, 8 and Article 52(1) of the Charter, must be interpreted as precluding national legislation such as that referred to by the referring court in its second question. 3. The third question referred 117. By its third question, the referring court asks, in essence, whether, if the first two questions are answered in the affirmative, it may maintain on a temporary basis the effects of the provisions of the Law of 20 July 2022 that are incompatible with EU law, in order to avoid a situation of legal uncertainty and to enable data previously collected and retained to continue to be used for the objectives pursued by that law. 118. In that regard, I would point out that the Court has answered in the negative a similar question, specifically in the case which gave rise to the judgment in La Quadrature du Net I . ( 53 ) In my view, it is not possible to reach any other conclusion. 119. Thus, it has recalled that the principle of the primacy of EU law establishes the pre-eminence of EU law over the law of the Member States and therefore requires all Member State bodies to give full effect to the various EU provisions, and the law of the Member States may not undermine the effect accorded to those various provisions in the territory of those States. ( 54 ) In the light of the primacy principle, where it is unable to interpret national law in compliance with the requirements of EU law, the national court which is called upon within the exercise of its jurisdiction to apply provisions of EU law is under a duty to give full effect to those provisions, if necessary refusing of its own motion to apply any conflicting provision of national legislation, even if adopted subsequently, and it is not necessary for that court to request or await the prior setting aside of such provision by legislative or other constitutional means. ( 55 ) 120. Only the Court may, in exceptional cases, on the basis of overriding considerations of legal certainty, allow the temporary suspension of the ousting effect of a rule of EU law with respect to national law that is contrary thereto. Such a restriction on the temporal effects of the interpretation of that law, made by the Court, may be granted only in the actual judgment ruling upon that interpretation. The primacy and uniform application of EU law would be undermined if national courts had the power to give provisions of national law primacy in relation to EU law contravened by those provisions, even temporarily. ( 56 ) 121. In addition, according to settled case-law, the interpretation that the Court gives to a rule of EU law, in the exercise of the jurisdiction conferred upon it by Article 267 TFEU, clarifies and defines the meaning and scope of that rule as it must be, or ought to have been, understood and applied from the time of its coming into force. It follows that the rule as thus interpreted may and must be applied by the courts to legal relationships arising and established before the judgment ruling on the request for interpretation, provided that in other respects the conditions for bringing an action relating to the application of that rule before the courts having jurisdiction are satisfied. ( 57 ) 122. In that regard, it should also be stated that a temporal limitation of the effects of the interpretation given was not imposed in the judgments in Tele2 Sverige and Watson and Others , ( 58 ) in La Quadrature du Net I , or in Commissioner of An Garda Síochána and Others , ( 59 ) with the result that it cannot be imposed in a judgment of the Court subsequent to them. 123. In those circumstances, I am of the view that the answer to the third question referred for a preliminary ruling should be that EU law precludes a national court from applying a provision of national law which limits the temporal effects of a declaration of invalidity which that court is required to make pursuant to EU law as regards national legislation imposing on providers of electronic communications services an obligation to retain, generally and indiscriminately, traffic and location data that is incompatible with Article 15(1) of Directive 2002/58, read in the light of Articles 7, 8 and 11, and Article 52(1) of the Charter. V. Conclusion 124. In the light of all the foregoing considerations, I propose that the Court should answer the questions for a preliminary ruling referred by the Cour constitutionnelle (Constitutional Court, Belgium) as follows: (1) Article 15(1) of Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications), as amended by Directive 2009/136/EC of the European Parliament and of the Council of 25 November 2009, read in the light of Articles 7, 8 and 11, and Article 52(1) of the Charter of Fundamental Rights of the European Union, must be interpreted as precluding national legislation which: – lays down an obligation for providers of electronic communications services to retain and process the traffic data referred to in that legislation for a period of 4 or 1 2 months, as the case may be, in order to enable those providers to take appropriate, proportionate, preventive and remedial measures to prevent fraud and malicious use of their networks and to prevent end users suffering harm or inconvenience, as well as to establish fraud or malicious use of the network or service or enable the perpetrators or origin thereof to be identified; – allows providers of electronic communications services to retain and process the traffic data concerned beyond the abovementioned time limits, where a specific instance of fraud or malicious use of the network has been identified, for the time required for its analysis and resolution or the time necessary to process that malicious use; – allows providers of electronic communications services, without laying down an obligation to request a prior opinion or to notify an independent authority, to retain and process data other than those referred to in that directive, with a view to making it possible to establish fraud or malicious use of the network or service, or to identify its perpetrator and origin; – allows providers of electronic communications services, without laying down an obligation to request a prior opinion or to notify an independent authority, to retain and process for a period of 12 months the traffic data which they consider necessary to ensure the security and proper functioning of their electronic communications networks and services, and in particular for the detection and analysis of a potential or actual breach of that security, including identifying the origin of that breach and, in the event of a specific breach of that security, to retain those data for the period necessary to process that breach. (2) Article 15(1) of Directive 2002/58, read in the light of Articles 7, 8 and 11, and Article 52(1) of the Charter of Fundamental Rights of the European Union, must be interpreted as precluding national legislation which: – allows providers of electronic communication s services to retain and process location data, without the legislation describing precisely which data are covered, in the context of the provision of a network or service, for a period of 4 or 12 months, as the case may be, where necessary for the proper functioning and security of the network or service, or to detect or analyse fraud or malicious use of the network; – allows providers of electronic communications services to retain and process location data beyond the abovementioned time limits, in the event of a specific breach or instance of fraud or malicious use. (3) EU law must be interpreted as precluding a national court from applying a provision of national law which limits the temporal effects of a declaration of invalidity which that court is required to make pursuant to EU law as regards national legislation imposing on providers of electronic communications services an obligation to retain, generally and indiscriminately, traffic and location data that is incompatible with Article 15(1) of that directive, read in the light of Articles 7, 8 and 11, and Article 52(1) of the Charter of Fundamental Rights of the European Union. 1 Original language: French. 2 Judgment No 57/2021 of 22 April 2021 (ECLI:BE:GHCC:2021:AR.057). 3 Judgment of 6 October 2020 (C‑511/18, C‑512/18 and C‑520/18, ‘the judgment in La Quadrature du Net I ’, EU:C:2020:791). 4 Directive of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications) (OJ 2002 L 201, p. 37), as amended by Directive 2009/136/EC of the European Parliament and of the Council of 25 November 2009 (OJ 2009 L 337, p. 11) (‘Directive 2002/58’). 5 Judgment of 30 April 2024 (C‑470/21, ‘the judgment in La Quadrature du Net II ’, EU:C:2024:370). 6 Directive of the European Parliament and of the Council of 24 October 1995 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (OJ 1995 L 281, p. 31). 7 [OJ 2002 L 108], p. 33. 8 Regulation of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ 2016 L 119, p. 1, ‘the GDPR’). 9 Directive of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA (OJ 2016 L 119, p. 89). 10 The judgment in La Quadrature du Net I (paragraph 107); and judgments of 5 April 2022, Commissioner of An Garda Síochána and Others (C‑140/20, EU:C:2022:258, paragraph 35); and of 20 September 2022, SpaceNet and Telekom Deutschland (C‑793/19 and C‑794/19, EU:C:2022:702, paragraph 52). 11 Judgment of 21 December 2016, Tele2 Sverige and Watson and Others (C‑203/15 and C‑698/15, EU:C:2016:970, paragraph 86); the judgment in La Quadrature du Net I (paragraph 108); and judgments of 5 April 2022, Commissioner of An Garda Síochána and Others (C‑140/20, EU:C:2022:258, paragraph 38); and of 20 September 2022, SpaceNet and Telekom Deutschland (C‑793/19 and C‑794/19, EU:C:2022:702, paragraph 55). 12 Judgment of 21 December 2016, Tele2 Sverige and Watson and Others (C‑203/15 and C‑698/15, EU:C:2016:970, paragraph 86); the judgment in La Quadrature du Net I (paragraph 108); and judgments of 5 April 2022, Commissioner of An Garda Síochána and Others (C‑140/20, EU:C:2022:258, paragraph 38); and of 20 September 2022, SpaceNet and Telekom Deutschland (C‑793/19 and C‑794/19, EU:C:2022:702, paragraph 55). 13 Judgments of 5 April 2022, Commissioner of An Garda Síochána and Others (C‑140/20, EU:C:2022:258, paragraph 39) and of 20 September 2022, SpaceNet and Telekom Deutschland (C‑793/19 and C‑794/19, EU:C:2022:702, paragraph 56). 14 The judgment in La Quadrature du Net I (paragraph 112); and judgments of 5 April 2022, Commissioner of An Garda Síochána and Others (C‑140/20, EU:C:2022:258, paragraph 41); of 20 September 2022, SpaceNet and Telekom Deutschland (C‑793/19 and C‑794/19, EU:C:2022:702, paragraph 58); and the judgment in La Quadrature du Net II (paragraph 67). 15 The judgment in La Quadrature du Net I (paragraphs 110 and 111); and judgments of 5 April 2022, Commissioner of An Garda Síochána and Others (C‑140/20, EU:C:2022:258, paragraph 40); and of 20 September 2022, SpaceNet and Telekom Deutschland (C‑793/19 and C‑794/19, EU:C:2022:702, paragraph 57). 16 The judgment in La Quadrature du Net I (paragraphs 120 to 122); and judgments of 5 April 2022, Commissioner of An Garda Síochána and Others (C‑140/20, EU:C:2022:258, paragraphs 48 and 49); and of 20 September 2022, SpaceNet and Telekom Deutschland (C‑793/19 and C‑794/19, EU:C:2022:702, paragraphs 63 and 64). 17 The judgment in La Quadrature du Net I (paragraphs 127 to 129); and judgments of 5 April 2022, Commissioner of An Garda Síochána and Others (C‑140/20, EU:C:2022:258, paragraphs 50 and 51); and of 20 September 2022, SpaceNet and Telekom Deutschland (C‑793/19 and C‑794/19, EU:C:2022:702, paragraphs 65 and 66). 18 C‑470/21, EU:C:2023:711, points 42 and 43. 19 The judgment in La Quadrature du Net I (paragraph 132). 20 The judgment in La Quadrature du Net I (paragraph 131); and judgments of 5 April 2022, Commissioner of An Garda Síochána and Others (C‑140/20, EU:C:2022:258, paragraph 53); and of 20 September 2022, SpaceNet and Telekom Deutschland (C‑793/19 and C‑794/19, EU:C:2022:702, paragraph 68). 21 Judgment of 20 September 2022, SpaceNet and Telekom Deutschland (C‑793/19 and C‑794/19, EU:C:2022:702, paragraph 71). 22 The judgment in La Quadrature du Net I (paragraph 168). 23 Judgment of 21 December 2016, Tele2 Sverige and Watson and Others (C‑203/15 and C‑698/15, EU:C:2016:970, paragraph 112). 24 Judgments of 8 April 2014, Digital Rights Ireland and Others (C‑293/12 and C‑594/12, EU:C:2014:238, paragraph 59); of 21 December 2016, Tele2 Sverige and Watson and Others (C‑203/15 and C‑698/15, EU:C:2016:970, paragraph 108); and the judgment in La Quadrature du Net I (paragraph 168). 25 The judgment in La Quadrature du Net I (paragraph 168). 26 The judgment in La Quadrature du Net I (paragraph 168). 27 ECtHR, 28 May 2024, Pietrzak and Bychawska-Siniardska and Others v. Poland, CE:ECHR:2024:0528JUD007203817, paragraph 259. 28 ECtHR, 28 May 2024, Pietrzak and Bychawska-Siniardska and Others v. Poland, CE:ECHR:2024:0528JUD007203817, paragraph 264. 29 The judgment in La Quadrature du Net II . 30 And not only serious crime, as held in the judgment in La Quadrature du Net I . 31 The judgment in La Quadrature du Net II (paragra ph 83). 32 The judgment in La Quadrature du Net II (paragraph 84). 33 The judgment in La Quadrature du Net II (paragraph 85). 34 The Court sets out a number of conditions appropriate for ensuring the genuinely watertight separation of the different categories of data retained. See, in that regard, the judgment in La Quadrature du Net II (paragraphs 86 to 89). In that respect, see also point 71 of the present Opinion. 35 The judgments in La Quadrature du Net I (paragraph 154) and in La Quadrature du Net II (paragraph 117). 36 The judgment in La Quadrature du Net II (paragraph 118). 37 See, to that effect, the judgment in La Quadrature du Net II (paragraph 119). 38 The judgment in La Quadrature du Net II (paragraph 86). 39 The judgment in La Quadrature du Net II (paragraph 87). 40 The judgment in La Quadrature du Net II ( paragraph 88). 41 The judgment in La Quadrature du Net II (paragraph 89). 42 The judgments in La Quadrature du Net I (paragraph 115) and in La Quadrature du Net II (paragraph 69). 43 The judgments in La Quadrature du Net I (paragraph 116) and in La Quadrature du Net II (paragraph 69). 44 Judgment of 21 December 2016, Tele2 Sverige and Watson and Others (C‑203/15 and C‑698/15, EU:C:2016:970, paragraph 79). 45 On the need to retain traffic and location data from the perspective of subsequent access to them, see Eurojust and Europol, Common Challenges in Cybercrime – 2024 Review by Eurojust and Europol , Publication Office of the European Union, Luxembourg, 2025, p. 7. 46 Judgments of 8 April 2014, Digital Rights Ireland and Others (C‑293/12 and C‑594/12, EU:C:2014:238, paragraph 59); of 21 December 2016, Tele2 Sverige and Watson and Others (C‑203/15 and C‑698/15, EU:C:2016:970, paragraph 108); and the judgment in La Quadrature du Net I (paragraph 168). 47 See, on that point, Joint Declaration of the European Police Chiefs of March 2023 (website: EDOC-#1384205-v1-Joint_Declaration_of_the_European_Police_Chiefs.PDF). 48 In addition, such a solution appears to me to be in line with the case-law of the ECtHR which, by placing the proportionality of a data retention measure at the heart of its analysis, specifically allows account to be taken of any safeguards put in place to limit the interference with users’ rights that such a measure entails. See, in particular, on the need to put in place appropriate safeguards, ECtHR, 28 May 2024, Pietrzak and Bychawska-Siniarska and Others v. Poland, CE:ECHR:2024:0528JUD007203817, paragraphs 250 and 251. 49 Judgment of 21 December 2016, Tele2 Sverige and Watson and Others (C‑203/15 and C‑698/15, EU:C:2016:970, paragraph 98). 50 Judgments of 6 October 2020, Privacy International (C‑623/17, EU:C:2020:790, paragraph 65), and of 21 June 2022, Ligue des droits humains (C‑817/19, EU:C:2022:491, paragraph 114). 51 Judgment of 21 December 2016, Tele2 Sverige and Watson and Others (C‑203/15 and C‑698/15, EU:C:2016:970, paragraph 86). 52 See, in particular, point 99 et seq. of the present Opinion. 53 Paragraphs 214 to 220. 54 The judgment in La Quadrature du Net I (paragraph 214). See also judgment of 5 April 2022, Commissioner of An Garda Síochána and Others (C‑140/20, EU:C:2022:258, paragraph 118). 55 Judgment of 22 June 2010, Melki and Abdeli (C‑188/10 and C‑189/10, EU:C:2010:363, paragraph 43); the judgment in La Quadrature du Net I (paragraph 215); and judgment of 5 April 2022, Commissioner of An Garda Síochána and Others (C‑140/20, EU:C:2022:258, paragraph 118). 56 The judgment in La Quadrature du Net I (paragraphs 216 and 217) and judgment of 5 April 2022, Commissioner of An Garda Síochána and Others (C‑140/20, EU:C:2022:258, paragraph 119). 57 Judgment of 5 April 2022, Commissioner of An Garda Síochána and Others (C‑140/20, EU:C:2022:258, paragraph 125). 58 Judgment of 21 December 2016 (C‑203/15 and C‑698/15, EU:C:2016:970). 59 Judgment of 5 April 2022 (C‑140/20, EU:C:2022:258).