Ground truth¶
Nation-state surveillance is not a conspiracy. It is a legal regime with documented practitioners, published standards, and court judgments that confirm it happens and argue about its limits rather than its existence.
What the GDPR does not cover¶
The General Data Protection Regulation is the most prominent data protection law in the world and it explicitly does not apply to national security activities. Article 2(2)(a) places national security outside its scope entirely. This is a deliberate boundary, written into the text, reflecting the settled position that states reserve the right to surveil in the name of security and that European data protection law was not designed to constrain that right.
Everything GDPR achieves for individual privacy stops at the national security fence.
What member states are permitted to do¶
No EU member state has a blanket legal prohibition on surveilling its own citizens. Every member state has intelligence legislation that permits surveillance of individuals and groups under conditions that include national security, counter-terrorism, serious crime, and in many cases broad public order provisions. The European Court of Human Rights, which operates separately from the EU, allows surveillance under Article 8 of the European Convention on Human Rights subject to requirements of legality, proportionality, and necessity. The court has found violations and states have responded by rewriting their laws rather than abandoning the practice.
The real constraints are: proportionality (contested), legal authorisation (often available on request), and oversight (which varies from rigorous to nominal across EU member states and is rarely truly independent).
The intelligence-sharing dimension¶
The Five Eyes alliance (United States, United Kingdom, Canada, Australia, New Zealand) is the most discussed, but several EU member states participate in expanded sharing arrangements under the Nine Eyes and Fourteen Eyes frameworks. These include the Netherlands, Denmark, France, Germany, Belgium, Italy, Spain, and Sweden, along with Norway, which sits outside the EU but inside the same arrangements.
The mechanism is more structural than agencies spying on each other’s citizens to order: each agency collects intelligence that it categorises as “foreign” (meaning communications flowing through or associated with non-domestic targets), and agencies share what they have collected. Since “foreign” collection captures vast amounts of data about citizens of other partner states, the practical effect is that each agency’s domestic legal constraints on surveilling its own citizens can be navigated by receiving data about those citizens from a partner who collected it under different rules.
The Snowden disclosures of 2013 documented this at scale. GCHQ collected data on EU citizens from undersea cable access points and shared it with NSA. The NSA monitored the German Chancellor’s communications. These are facts of record.
The commercial layer¶
The state does not have to collect what it can buy. Agencies in the United States have purchased location data from brokers; in Europe the Databroker Files investigation of 2025 found the same feeds carrying the movements of officials inside the EU’s own institutions. Nothing in that market was built for the state: it runs on advertising identifiers, real-time bidding and broker enrichment, and sells to whoever pays.
This is not interception. It is procurement. And it is largely unregulated in the national security context precisely because GDPR does not apply there.
The system working as built¶
Most of this is either legal, contested only at the margins, or structured to be difficult to challenge. The system was designed to permit observation. It optimises for visibility under plausible deniability.
This is not a malfunction. It is the system working as built, under conditions of political stress that reveal what it was always capable of.
Last reviewed: 2026-07-17.