Adversaries

The adversaries here are not the hooded figures of popular imagination. Most of them have offices, legal mandates, oversight committees of varying rigour, and annual budgets that appear in parliamentary documents. The entities doing the harvesting are, in many cases, the same entities responsible for the legal framework that permits it.

Domestic intelligence agencies

Every EU member state maintains at least one civilian intelligence agency with domestic remit. Examples include the AIVD in the Netherlands, the DGSI in France, the BfV in Germany, the ABW in Poland, and the BVT (now DSN) in Austria. These agencies operate under national legislation that grants surveillance powers for purposes including counter-terrorism, counter-espionage, protection of constitutional order, and, in some cases, broader national security mandates that are defined generously.

They are subject to oversight, but the quality of that oversight varies considerably. In some member states, parliamentary oversight committees have meaningful access and investigative power. In others, oversight is largely formal. Judicial authorisation requirements also vary: some states require prior judicial or independent authorisation for intrusive surveillance; others require only internal approval.

The domestic intelligence agency is the adversary with the most legal access and the deepest structural embeddedness. It is also the adversary that is most constrained by domestic law, at least in theory.

Foreign intelligence agencies

Foreign agencies operate under entirely different legal constraints in the target country, which is to say they operate under none enforceable there. Allied foreign agencies (GCHQ, NSA, and others) may have formal or informal access agreements with domestic counterparts, share collected data, and conduct their own collection on infrastructure that passes through or is hosted in EU jurisdictions.

Adversarial foreign agencies (Russian SVR/FSB, Chinese MSS, Iranian MOIS, and others) conduct surveillance and espionage operations against EU citizens, civil society, companies, and government institutions through a range of technical and human means. Much of the most capable technical tooling, however, belongs to no single state. It is bought.

The foreign agency adversary is the one with the fewest domestic legal constraints and the most varied technical capability.

The mercenary spyware industry

The most intrusive surveillance capability of the past decade has been a product, not a state secret. Firms develop spyware that can compromise a fully updated phone and read everything on it, and licence it to government clients. The Israeli NSO Group’s Pegasus is the best known; its use against politicians, journalists and lawyers across several EU member states prompted the European Parliament’s PEGA inquiry. It is not alone. Intellexa’s Predator surfaced in scandals in Greece and beyond, and in 2025 Paragon’s Graphite was forensically confirmed on the phones of European journalists and activists. Italy’s own oversight committee acknowledged the state had used the tool against two migrant-rescue activists, while leaving open who had targeted a journalist infected in the same period. The Paragon case is the current instance of a recurring pattern: the capability is an industry, and it is available to any government that will pay.

Law enforcement

Law enforcement agencies are distinct from intelligence agencies in most EU jurisdictions and operate under stricter legal frameworks with clearer judicial oversight requirements. However, they are relevant for two reasons.

First, data collected by intelligence agencies can be and in some cases is passed to law enforcement for use in prosecutions, often through the mechanism of parallel construction. The legal threshold for collection and the legal threshold for use in prosecution are handled separately.

Second, law enforcement agencies have expanded their own data collection capabilities, including through data retention mandates applied to telecommunications providers, through access to commercial databases, and through the use of technical surveillance tools that were previously the exclusive domain of intelligence agencies.

Border and data agencies

Surveillance at EU level increasingly runs through shared institutions rather than any one national agency. eu-LISA operates the large-scale databases at the border, the Entry/Exit System, Eurodac, the Schengen and Visa Information Systems, now being wired together under the interoperability programme described in the legal landscape. Frontex conducts its own data collection at the frontier, and Europol pools and analyses data from member states, an accumulation that its own supervisor has at points found to outrun its legal basis. Alongside them, police forces in several member states have adopted commercial data-mining platforms, Palantir among them, that merge disparate databases into a single searchable picture. None of these is a spy agency. Each expands the reach and joinability of state-held data.

The commercial data layer

This is the adversary that appears on no intelligence community organogram, and the one that is barely an adversary at all. The trade itself collects and sells at scale for reasons that have nothing to do with intelligence. What puts it here is the second sale: agencies buy the product, and platform data reaches them through legal instruments or informal cooperation, so the commercial layer extends state visibility into domains that would otherwise need an intrusive operation and a legal authorisation.

The broker intends no harm. It qualifies as an adversary by being a structural participant in a system that produces harm anyway.

Regulatory bodies

Regulatory bodies with access to corporate and financial data (tax authorities, financial regulators, competition authorities, sector regulators) hold detailed information about companies and in some cases individuals. In most EU jurisdictions, intelligence and law enforcement agencies can request access to regulatory data under appropriate legal thresholds. Regulatory compliance requirements can also be structured to create data collection obligations that serve a surveillance function.

This is the adversary that does not look like one. It looks like bureaucracy. The data flows it generates are a byproduct of legitimate regulatory function, but byproducts can be collected and repurposed.

Last reviewed: 2026-07-17.