Skip to content
393559

393559

www.hrw.org May 12, 2026

Increasing government use of commercial spyware and other types of surveillance technology poses a significant threat to human rights worldwide. Police and intelligence services in many countries use such technology to target activists, journalists, humanitarians, academics, and other critical voices, undermining democratic institutions, shrinking civic space, violating victims’ privacy and other rights and, in many cases, threatening their physical security.

The European Union (EU), whose member states are to many of the companies that develop and export such technologies worldwide, is part of the problem. Despite a regulatory framework designed in part to prevent abuses, the EU currently is doing too little to prevent sales and transfers from its member states to governments with a track record of using such technologies for crackdowns on dissent and other serious rights violations. Particularly for human rights defenders, journalists, and others whose work focuses on exposing abuse, corruption, and other crimes in both the public and private sectors, surveillance technology has been used to compromise their ability to work freely, safely and to protect their sources.

EU-produced surveillance technology is in use in dozens of countries worldwide as well as by countries in Europe, and the EU hosts many of the surveillance companies working worldwide: the majority of EU member states have at least one surveillance technology company operating inside their borders. In a 2024 report by Google’s Threat Analysis Group on the commercial surveillance industry, all but of the two companies mentioned are based in the EU.

In 2021 the EU passed a landmark recast of a law, the Dual-Use Regulation (also commonly referred to as “Recast”), intended in part to rein in the export of dual-use technology (technologies that may be used for both civilian and military purposes), including commercial surveillance technology. The new controls on surveillance technology had three key elements: an expanded harm-based definition of what products constitute surveillance technology and are subject to the regulation, including a catch-all clause requiring companies to seek licenses for the potential export of non-listed surveillance technology that meets the definition; a requirement that exporting countries consider the human rights record of destination countries and any potential for abuse; and a reporting and transparency requirement that EU member states collect data on their exports of cybersurveillance items and transmit it to the European Commission for inclusion in an annual public report. These provisions were intended to strengthen oversight and prevent the export of surveillance technologies to countries where they could be used to perpetrate or contribute to human rights violations.

This report assesses how these reforms are functioning in practice. Our analysis of European Commission public reports and data obtained via transparency (or Freedom of Information or Access to Documents) requests shows serious defects in the EU’s current approach. One problem is with the Recast itself: it does not go far enough. In particular, the requirement that EU member states to “consider” the human rights record of an export destination is insufficient to prevent exports to destinations where they are likely to be used to violate rights, as are human rights due diligence measures for surveillance companies. Another problem, the focus of this report, is that rights-protective features of the Recast, albeit with their limitations, have been undercut by guidelines developed by the European Commission to interpret the application of the regulation. These guidelines, published in January 2024, severely limit the value of the Recast’s reporting and transparency provisions. The result is that EU member states have continued to export dangerous surveillance technology to countries where it has likely contributed to abuses.

The majority of EU member states have at least one surveillance technology company operating inside their borders. The companies develop, sell and often export technology capable of eavesdropping on individuals, including journalists, activists, and other critical voices.

This report is divided into four sections. The first recounts the origins and objectives of the Recast, the latter notably including preventing exports of cyber-surveillance items that are likely to be used in ways that violate international humanitarian law (IHL) or human rights law. It details relevant provisions of the Recast and statements officials made the rights-protective provisions when the Recast was adopted. It also summarizes weaknesses of the Recast from a human rights perspective. This section draws in part on prior work by Human Rights Watch and others.

The second section focuses on the non-legally binding guidelines published in January 2024 by the European Commission to support the implementation of the Recast. It details how the interpretation has hollowed the rights-protective promise still contained in the Recast. A key conclusion is that the transparency requirements of the Recast, as put into practice through the January 2024 guidelines, are so weak that what is reported by the European Commission does not allow for meaningful assessment of whether, in practice, the regulatory framework is meeting its human rights objectives. As a result of that weakness Human Rights Watch had to resort to freedom of information requests at national level of EU states to try to identify exports of concern and assess whether abusive exports are happening.

The third section describes the results of Human Rights Watch efforts—through freedom of information requests to every EU member state—to flesh out the limited information publicly reported by the European Commission under the Recast. One finding is that EU member states routinely export surveillance technology to destinations with well-documented histories of human rights violations. We highlight two illustrative examples that identify such transfers: exports of surveillance technology from Bulgaria to Azerbaijan, and from Poland to Rwanda.

Another finding is that freedom of information requests are able to fill in only a fraction of the gaps in current reporting. This is due in part to incomplete member state responses to such requests, but also significantly to overly sweeping European Commission and member state invocations of exemptions to transparency, such as trade secrets, national security and protecting international relations, as justifications for withholding information, limitations not supported by the language of the Recast itself.

The fourth section sets forth relevant international human rights standards.

The European Commission will launch an evaluation of the recast Dual-Use Regulation in September 2026. To show it is serious the purposes articulated when the Recast was adopted, the EU institutions—Commission, Parliament and Council—should use this opportunity to strengthen due diligence and transparency requirements to ensure the EU finally curbs its export of surveillance technology to abusive governments around the world.

Require exporters of surveillance technology to undertake a meaningful due diligence process that includes a thorough risk assessment of the possible use of their product in particular to facilitate or contribute to violations of international human rights and humanitarian law and require that the process and findings be published.

Require exporters to expressly notify member states of listed cybersurveillance items if they identify risk or find evidence of possible misuse through their due diligence process.

Clarify how the guidelines on dual-use licensing interact with the revised Corporate Sustainability Due Diligence Directive (CSDDD) which covers dual-use items until the export-licensing process.

Clarify state responsibilities if they chose to provide a license while red flags have been raised.

Revise sections of the Commission guidelines implementing the Dual-Use Regulation that relate to respecting human rights obligations in the context of dual-use licensing and due diligence so they align with due diligence standards as defined in the CSDDD (obligation of means). The revised guidelines should also define criteria to apply to all applications to export cybersurveillance technology, listed or not, from EU member states and clarify which are mandatory under either law.

Member states and/or companies should also establish mechanisms to provide an effective remedy for human rights violations committed using the transferred technology, and the use and impact of these mechanisms should be regularly reported to the relevant EU institutions.

Update guidelines on transparency reporting on exports of dual use surveillance technology with input from stakeholders. At a minimum the guidelines should:

Require member states to report the number of license applications for both listed and unlisted technology, with at least the following information per application: the exporter name, a description of the end user and destination, the value of the license, and whether the license was granted or denied and why.

Establish explicitly that the reported information described above is public and can be provided in response to transparency requests, and that the information is not subject to article 4 exemptions under EU Regulation 1049/2001.

Initiate the evaluation process mandated by article 26(4) of Regulation 2021/821 within the required timeline, and ensure that that process provides for meaningful participation of all relevant stakeholders, including human rights and other civil society organizations.

National export licensing authorities should take into account the human rights record of recipient countries and end-users (whether they be state or non-state actors) and act upon findings or red flags by withholding export licenses of cybersurveillance technology.

National authorities should report on the implementation activities with regard to due diligence responsibilities and obligations and encourage all companies to inform the public the scope, nature, and transferable findings of the human rights due diligence procedures they implemented.

National authorities should comply with transparency and access to documents laws regarding requests for export data, and not invoke sweeping exemptions to transparency, such as trade or defense secrets, national security, or protecting international relations.

This report is based on research conducted between November 2024 and February 2026. Human Rights Watch sent freedom of information requests to export license authorities in each of the 27 EU member states, as well as to the European Commission, asking for licensing data as reported by member states to the European Commission for the preparation of the annual report called for by article 26 of the recast Dual-Use Regulation. The language of these requests followed the language of the Recast, requesting information on export licensing of cybersurveillance items, including the number of applications received by item, destination, and the decision taken on those applications.

Depending on the country, freedom of information requests went to interior ministries, foreign ministries, or other institutions specifically responsible for dual-use export licensing. In most cases where export authorities initially denied access to the requested information, Human Rights Watch exhausted the available national appeals mechanisms for this data.

Human Rights Watch is publishing the raw data received online at github.com/HumanRightsWatch/EU-surveillance-export-data .

We also analyzed the parts of the 2021 Recast that relate to “cybersurveillance items,” as well as two sets of guidelines issued by the European Commission on transparency reporting and the definition of cybersurveillance items to assess how European institutions are implementing the elements of the regulation that pertain to human rights due diligence and transparency obligations of EU institutions and member states. Human Rights Watch also spoke at length with more than a dozen experts on export controls and the EU legislative process that led to the Recast, surveillance technology proliferation and the right to privacy.

Human Rights Watch wrote to the European Commission, export license authorities and relevant ministries in Bulgaria, Poland and Sweden, state security services and relevant ministries in Azerbaijan, India and Rwanda, as well as to the companies Circles and MSAB on April 13th and 15th. We received written responses from the European Commission and from the ministries of Economy and Industry and of Economic Development and Technology in Bulgaria and Poland, respectively, as well as from the Inspectorate of Strategic Products (ISP), the Swedish authority responsible for export controls of most dual use items and have reflected relevant parts of those responses in the report. The responses are available in full in Annex I, Annex II, Annex III and Annex IV.

This is an ongoing piece of research: Human Rights Watch, alongside partner organizations, is developing a civil society monitoring mechanism to continue requesting this data from EU member states and the European Commission and to continue carrying out local research in countries that receive EU-developed surveillance technology.

EU countries have a long history of exporting surveillance technology to governments that use it to violate rights. [1] In the early 2010s, security researchers began documenting cases of European-developed spyware being used in countries with poor human rights records.

In 2013, researchers found evidence that Gamma International’s surveillance software, FinFisher, which can target mobile phones to obtain contacts, text messages, emails, locations, photos and other data, and to record calls, ended up being used by governments in Egypt, Bahrain, Turkmenistan, and Myanmar, among other countries. [2] Gamma International at the time denied that the identified products were from the FinFisher line. [3] In 2014, Human Rights Watch documented the Ethiopian government’s use of both FinFisher and Italy-based company Hacking Team’s Remote Control System (RCS) spyware, which provides access to computers and smart phones in real time, against opposition group members and journalists overseas. [4] In 2012, security researchers also found that the United Arab Emirates (UAE) used both companies’ software to target the high-profile Emirati activist Ahmed Mansoor, who is serving an abusive 15-year sentence. [5] Four executives from the French firm then known as Amesys, which later became Nexa Technologies, were indicted in 2021 by a Paris court for “complicity in acts of torture” related to their spyware’s role in facilitating human rights abuses in Libya and Egypt in the late 2000s and early 2010s. [6] These cases are still ongoing, and the executives have denied the charges.

At the time, the EU framework for controlling the trade in dual-use items was the 2009 EU Dual-Use Regulation (428/2009), which incorporated the control list of the Wassenaar Arrangement, an international export control regime regulating the export and transfer of weapons and dual-use items. [7] At the time, the Wassenaar list of regulated items did not include specific categories of cybersurveillance technology.

One of the first attempts at regulating global surveillance industries was a 2013 update to the Wassenaar Arrangement to cover “intrusion software” and “network surveillance systems.” [8] This came after revelations of the use and misuse of EU-exported surveillance technology by security forces in countries in North Africa, [9] and a pressure campaign by a coalition of privacy and human rights organizations, including Human Rights Watch. [10]

The change to the Wassenaar control list meant that exporters of intrusion software and network surveillance systems would need to apply for licenses from participating national governments in order to sell or transfer them. While an important first step, this classification has had limited ability to actually restrict the sale and transfer of surveillance technology. The Wassenaar Arrangement is not legally binding and is limited to the 42 participating governments. It is up to each national regulator to decide if and how to enforce it, and laws governing surveillance exports vary substantially from country to country.

In 2011, the EU began the process of updating its export control regime, as mandated by the 2009 Dual-Use Regulation. This change became increasingly important as more cases became known of surveillance technology developed in EU countries being used to violate rights.

The European Parliament has also pushing for these changes. A 2012 report by the Parliament’s Committee on Foreign Affairs called on the Commission to submit a proposal for a new regulation:

requiring increased transparency and accountability on the part of EU-based companies, as well as the disclosure of human rights impact assessment policies, with a view to improving the monitoring of exports of ICTs, products and services aimed at blocking websites, mass surveillance, tracking and monitoring of individuals, [and] breaking into private (email) conversations or the filtering of results… [11]

A 2015 European Parliament resolution noted that EU-based companies at the time made up an important of the global market in exports of “surveillance, tracking, intrusion and monitoring technology.” [12] The resolution called on the European Commission to propose new policies to limit and regulate dual-use technology.

In 2016, the European Commission issued a legislative proposal for what would eventually become the recast Dual-Use Regulation. [13] The proposal noted that European surveillance technology had been exported to repressive governments and conflict areas where it was used to target dissidents and human rights activists, and for other forms of internal repression. The proposal emphasized that

the export of cyber-surveillance technology under such conditions poses a risk to the security of those persons and to the protection of fundamental human rights, such as the right to privacy and the protection of personal data, freedom of expression, freedom of association, as well as, indirectly, freedom from arbitrary arrest and detention, or the right to life.

The Commission’s legislative proposal also included a plan to provide transparency on export controls through the publication of annual reports, which would, according to the document, “enable civil society organizations to fully contribute to the formulation and implementation of export control policy.” The role of transparency in increasing public awareness and facilitating work by civil society organizations was framed by the document as an important mechanism for public accountability surrounding these exports.

Following years of negotiations between the European Commission, Council, and Parliament, in May 2021 the EU passed landmark new legislation further regulating EU member states’ export of dual use items, and, in particular, certain especially harmful types of surveillance technology. The new regulation came as news began to break in July 2021 that Pegasus spyware, developed and sold by the Israel-based company NSO Group, had been used to surveil dozens of journalists, human rights activists and others around the globe. In response, the EU institutions formed a committee to investigate the use of Pegasus and other types of surveillance technology, and began working with journalists and civil society organizations to further document cases of harm.

This regulation, Regulation 2021/821, better known as the 2021 recast Dual-Use Regulation (“Recast”), entered into force on September 9, 2021. [14] According to the implementation schedule included in the regulation, the Commission is due to begin evaluating the Recast in September 2026, although in a written response to Human Rights Watch the Commission said that they would be starting the process as early as May 2026.

At the time the Recast was adopted, civil society organizations raised concerns that it did not go far enough in preventing EU member states from exporting surveillance technology to countries where they were likely to be abused.

The Recast established three important regulatory and transparency norms in the EU specific to these export licenses:

The Recast, using a definition that centers a technology’s potential for harm, expanded what types of cybersurveillance exports are regulated, including through a provision known as the “catch-all” clause [15] for surveillance technologies not included in the Wassenaar control list. In the past, export regulations only applied to the specific surveillance technologies included in the control list of the Wassenaar Arrangement. [16] This meant that cutting-edge technologies could be left unregulated until they were added to the Wassenaar control list.

The Recast also created a public reporting responsibility for the European Commission. It requires the Commission to collect data from EU member states on the exports of certain types of surveillance technologies, and annually publish a report to the Parliament and Council outlining specific elements of that data, including the number of license applications received, the type of technology concerned, and the destination for export, as well as the final decision taken on each application. The Recast also specifies that the report be public.

The Recast makes explicit the need for exporting countries to consider the human rights record of recipient countries when considering an export license application, based on criteria included in the EU Common Position. The latter is a set of common rules among EU member states that seeks to limit the export of European weapons and dual-use technology to places where they might be used for “internal repression or international aggression or contribute to regional instability.” [17]

A stated aim of the Recast is “maintaining robust legal requirements with regard to dual-use items, as well as … strengthening the exchange of relevant information and greater transparency.” It also notes the specific importance of controlling the export of surveillance technologies given “the risk of them being used in connection with internal repression or the commission of serious violations of human rights and international humanitarian law.” [18]

Throughout the legislative process, greater transparency on surveillance and other dual-use exports was highlighted as an important mechanism for public accountability. In a 2018 Parliamentary debate on the legislation, MEP Bernd Lange noted that providing public transparency on exports was a priority for the new regulation:

Nowadays, hardly anyone knows which applications are submitted, which exports are approved, and which are prohibited. Sometimes you can find this out through parliamentary inquiries – sometimes there are leaks. We want this information to be made public on a mandatory quarterly basis. That will already have an impact on practice. [19]

Similarly, MEP Markéta Gregorová noted in a 2021 Parliamentary debate, two months before the Recast was passed: “The new rules for cyber-surveillance exports, paired with companies’ new due diligence requirements and meaningful transparency, will together mean that powerful European cyber-surveillance technology does not end up in the hands of dictators and authoritarians.” [20]

MEP Gregorová, rapporteur for the European Parliament committee responsible for drafting the Recast, described the role envisioned by civil society and journalists in monitoring for misuse. “In this regard, I also cannot omit the current and future role of civil society…. Watchdogs and non-governmental organizations and journalists always had a crucial role in the identification of problematic companies and areas. We now free their hands with the new transparency provisions to access necessary information.” [21]

Article 26 of the Recast also states that the European Commission and Council are responsible for developing guidelines for member states to use in their data gathering under the article. [22] In January-February 2023, the European Commission held a public consultation related to the development of these guidelines. In the webpage announcing the consultation, the Commission noted that the Dual Use Regulation mandates the collection of certain export data “for reasons of effectiveness, consistency and transparency.” [23] The results of that consultation, whose respondents were largely from industry, civil society and academic institutions, noted the importance of providing transparency on dual-use exports, particularly cybersurveillance items, in particular as relates to the type of item to be exported and the end-user and its end-use. [24] At no point does the document summarizing responses to the consultation mention concerns over commercial secrecy or otherwise relating to the public nature of this information. Rather, the Commission notes this input from civil society respondents:

… reporting detailed information exports of dual-use items and technologies can enable stakeholders get better oversight of how the controls that Member States have in place are being implemented. Reporting on enforcement measures can also offer a better picture of the way in which export control violations are being detected, investigated, and prosecuted in the EU.

Promoting transparency in the trade of cyber-surveillance technologies and applying relevant exceptions to disclosure strictly - is considered critical to ensure these items are not being used in third countries in connection with internal repression or the commission of serious violations of international human rights and humanitarian law. [25]

As detailed below, these guidelines were published in January 2024 in a non-legally binding document that also includes example spreadsheet forms that EU member states were to use for their reporting of cybersurveillance export data. [26] Between the Recast coming into effect and publication of this report, the Commission has published three reports assessing its implementation and one “statistical update” document with additional export data. While all the reports contain aggregated EU export data relating to cybersurveillance items, only two of them were published after the European Commission issued its guidelines in January 2024.

The Recast specifically regulates six categories of cybersurveillance technology, transposed from the Wassenaar Arrangement control list, and included the “catch all” clause for non-listed technology. In October 2024 the European Commission released a second set of guidelines related to exports for cybersurveillance items, which sought to define the specific types of surveillance technology that are categorized and controlled by the Recast, as well as to explain to companies the criteria under which the catch-all clause would apply to a possible export. [27]

The Recast defines cybersurveillance technology as “dual-use items specially designed to enable the covert surveillance of natural persons by monitoring, extracting, collecting or analyzing data from information and telecommunication systems.” [28] Cybersurveillance guidelines issued in October 2024 clarify this definition and define listed export controls for six types of surveillance technology: telecommunication interception systems, internet surveillance systems, intrusion software (and related controls), communication monitoring software, items to perform cryptanalysis and forensic or investigative tools. [29]

The six categories of technology included in the October 2024 European Commission guidelines are:

Internet surveillance systems: equipment that allows an operator to analyze, extract and index large amounts of Internet traffic (content and metadata) on the networks of a telecommunications carrier. These tools allow users to in the indexed data for personal identifiers or map relational networks of a person or group of people.

Intrusion software: software that allows operators to covertly and remotely access electronic devices, in order to obtain data, track users or eavesdrop using a device's built-in microphone or cameras.

Communication monitoring software : software designed for monitoring and analysis by authorized law enforcement authorities of data collected in targeted interceptions from telecommunications providers. This software uses data collected by telecommunication interception systems and allows for searches of communication content and metadata.

Items to perform cryptanalysis : software or equipment used to bypass or defeat device locking and/or encryption. [30]

Forensic or investigative tools : equipment or software used to extract (and often analyze) raw data from electronic devices by bypassing its security controls, in many cases via a physical, cabled, connection to the device.

The October 2024 European Commission cybersurveillance guidelines also set forth criteria for assessing whether technologies not specifically listed in the Recast nonetheless fall within the scope of its catch-all clause and require an export license from a national authority. One important consideration is whether the technology in question can be used “in connection with internal repression and/or the commission of serious violations of human rights and international humanitarian law.” The guidelines include examples of potential non-listed technology that would fall under this category and, per the document, “may warrant potential vigilance” under the Recast. Examples of potential non-listed technology are facial and emotion recognition technology, location tracking devices, and video surveillance systems.

Although, the preamble of the Recast explicitly refers to the need for exporting countries to consider the human rights record of recipient countries when assessing an export license application, the operative text itself lacks a reference to the internationally established framework of “human rights due diligence”. Nor does it establish any reporting mechanism to monitor how national export licensing authorities operationalize the Recast’s due diligence obligations and the standards that exporting companies were expected to apply.

The Recast does however reference the 2008 EU Common Position, a set of common rules among EU member states that sought to limit the export of European weapons and dual-use technology to places where they would be used for “internal repression or international aggression or contribute to regional instability.” [31]

The Common Position, for the first time in the European Union, sought to ensure military and dual-use export controls prevented use of exported technologies by recipient countries to commit human rights violations, and the text of the Recast makes reference to these same human rights obligations. The Common Position requires that EU member states deny an export license if there is a “clear risk” that the item to be exported might be used in violation of IHL or for internal repression, and that member states “exercise special caution and vigilance” in issuing licenses to countries where UN or European institutions have documented serious violations of human rights. [32]

The Recast provides in the preamble that EU institutions and member states are to “fully take into account all relevant considerations,” including the Common Position and other international obligations when determining whether or not to issue an export license.

Specifically regarding cyber-surveillance items, the preamble states that member state authorities “should consider in particular the risk of them being used in connection with internal repression and the commission of serious violations of human rights and international human rights law”. [33]

Article 15 of the recast Dual-Use Regulation also explicitly references the Common position imposing a legal obligation on member states “in deciding whether or not to grant an authorization or to prohibit a transit" to “take into account all relevant considerations” including international obligations and commitments, national foreign and security policy covered by the Common Position and intended end use and risk of diversion.

As noted above, article 5 also includes a so-called “catch-all clause,” requiring export authorizations for cybersurveillance items even if the technology is not specifically listed as requiring regulation if they “are or may be intended, in their entirety or in part, for use in connection with internal repression and/or the commission of serious violations of human rights and international humanitarian law.” [34] Article 5 puts much of the burden on the exporter to notify the competent authority of the human rights risk based on their own human rights due diligence and request a license, which is not in their interest to do.

This catch-all clause relies on exporting companies to carry out due diligence limited to “transaction-screening measures,” which are defined and elaborated on in the October 2024 cybersurveillance guidelines. [35] The cybersurveillance guidelines call on, but do not require, exporters to review how end-users intend to use the products, and assess whether or not their products could be used, or form a part of system used to

commit internal repression, violate or abuse human rights, including the right to life, freedom from torture, inhuman and degrading treatment, the right to privacy, right to freedom of speech, the right to association and assembly, the right to freedom of thought, conscience and religion, the right to equal treatment or prohibition of discrimination or the right to free, equal and secret elections.

This section of the cybersurveillance guidelines outlines a series of example red flags that exporters should, but are not required to look for, and if encountered, should inform national authorities, mostly related to the potential or past use in connection with serious violations of human rights, IHL, or in violation of national laws. These red flags, which, according to the cybersurveillance guidelines, “indicate that the export may be destined for an inappropriate end-use, end-user, or destination.”

While the recast does not compel exporters to for risks, some national authorities recommend that they do so. An informational leaflet on article 5 of the Dual-Use Regulation printed by the German export authority, the Federal Office for Economic Affairs and Export Control (BAFA), states that “exporters should not deliberately ignore apparent indications; it is improper and may be tantamount to awareness to willfully look away and intentionally pass up a seemingly obvious opportunity to take note of something which any other in such position would have perceived. The complete failure to perform due diligence is improper (" passivity does not protect ").”

It is a positive that the Recast text and both the January and October 2024 European Commission guidelines contain language mentioning human rights and due diligence considerations for exports, but as the Commission annual reports and member state export data reveal, the due diligence requirements are not strong enough to prevent the export of surveillance technology to governments who are likely to abuse it.

The European Commission has reinterpreted the recast Dual-Use Regulation’s transparency obligations in a manner that has undermined the purpose of the regulation, and transparency reports to date do not provide sufficient detail to facilitate the scrutiny necessary to assess whether the regulation is having its intended effect.

Article 26(2) of the Recast states:

The Commission shall, in consultation with the Dual-Use Coordination Group, submit an annual report to the European Parliament and the Council on the implementation of this Regulation, and on the activities, examinations and consultations of the Dual-Use Coordination Group. That annual report shall be public.

The annual report shall include information on authorisations (in particular number and value by types of items and by destinations at Union and Member State levels), denials and prohibitions under this Regulation. The annual report shall also include information on the administration (in particular staffing, compliance and outreach activities, dedicated licensing or classification tools), and enforcement of controls (in particular the number of infringements and penalties)

With regard to cyber-surveillance items, the annual report shall include dedicated information on authorisations, in particular on the number of applications received by item, the issuing Member State and the destinations concerned by those applications, and on the decisions taken on those applications…

The Recast defines transparency on cybersurveillance exports as providing information regarding the types of technology EU member states are exporting and the countries to which that technology has been sold. This is consistent with the type and degree of transparency called for in the legislative proposal as well as statements by key legislators involved in drafting the regulation. The Recast does not require divulging the company selling the technology or the name of the product that was sold.

Article 26(2) also states that details on implementation of the transparency section of the Recast are to be developed by the European Commission and Council: “The Commission and the Council shall make available guidelines on the methodology for data gathering and processing of the annual report, including the determination of the types of items and the availability of enforcement data.”

In January 2024, the European Commission published guidelines doing just that, detailing the information to be included in the annual report called for by article 26, and the methodology for collecting it. [36] These guidelines are not legally binding on member states, but provide authoritative guidance to states in carrying out their reporting responsibilities under article 26. The guidelines, however, define transparency requirements in ways that undercut the Recast’s objective of ensuring exported dual-use technologies are not used to commit rights violations.

A seemingly small but significant difference, one that applies to all dual-use exports and not simply cybersurveillance technologies, is that the guidelines direct member states to separately list the technologies and the countries to which they were exported, making it often impossible to determine which technologies went to which countries.

The relevant provision of the guidelines reads as follows: “The wording ‘by types of items and by destinations’ in article 26(2) para. 2 … has to be read as requiring [member states] to report authorisations by destinations and, separately, by times of items...” [37]

The Recast itself includes no indication that identification of the technologies and countries to which they were exported are to be listed separately, rather calling on the Commission to include in its report “information on authorisations (in particular number and value by types of items and by destinations at Union and Member State levels)…”

A second difference is that the January 2024 guidelines interpret the transparency requirement of the Recast applicable specifically to cyber-surveillance items in a way that also defeats the aim of shedding light on sales to potential rights abusers. The text of the Recast states: “With regard to cyber-surveillance items, the annual report shall include dedicated information on authorisations, in particular on the number of applications received by item, the issuing Member State and the destinations concerned by those applications, and on the decisions taken on those applications.”

A plain reading of this provision of the Recast, and the reading most consistent with its aims and with statements legislators made its purposes when it was adopted, is that this information should be presented together such that readers of annual reports know what technologies were transmitted to which countries.

The January 2024 guidelines, however, call for member states to provide only separately listed and aggregated data that would not allow readers to connect specific technology sales to specific recipient countries. The guidelines state that the annual report will include a dedicated section with information on cyber-surveillance items that “will include the number of applications received by Member States as well as the list of all destinations concerned by those applications and the Member States concerned. The wording ‘decisions taken on those applications’ is interpreted as either authorization or denial/prohibition, and this information will be expressed as EU total figure for all the relevant cyber-surveillance items.”

The January 2024 European Commission guidelines thus redefine the type of transparency required by the Recast, separating reporting on what type of technology was exported from the countries to which it was sent, despite explicit indication to the contrary in the text of the Recast that this was not the intended outcome.

In the January 2024 guidelines, the European Commission justifies this reinterpretation of the Recast text, writing that “[t]his interpretation is considered consistent with the need to protect sensitive information under article 26(3) and the need to avoid the risk of undercutting restrictive licensing decisions in the Union.” [38]

A footnote to that paragraph also reads: “Combining data on authorisations by destination and by types of items in one table would very likely lead to significant violations of exporters confidentiality or could undercut restrictive licensing decisions in the EU.” [39]

Extracted Entities