{"id":108123,"date":"2025-04-01T17:26:17","date_gmt":"2025-04-01T21:26:17","guid":{"rendered":"https:\/\/cdt.org\/?post_type=insight&#038;p=108123"},"modified":"2025-04-03T05:11:11","modified_gmt":"2025-04-03T09:11:11","slug":"eu-tech-policy-brief-april-2025","status":"publish","type":"insight","link":"https:\/\/cdt.org\/insights\/eu-tech-policy-brief-april-2025\/","title":{"rendered":"EU Tech Policy Brief: April 2025"},"content":{"rendered":"\n<p><em>Welcome back to the Centre for Democracy &amp; Technology Europe\u2018s Tech Policy Brief! This edition covers the most pressing technology and internet policy issues under debate in Europe and gives CDT\u2019s perspective on the impact to digital rights. To sign up for CDT Europe\u2019s AI newsletter, <\/em><a href=\"https:\/\/cdt.org\/email-signup\/\"><em>please visit our website<\/em><\/a><em>. Do not hesitate to contact <\/em><a href=\"https:\/\/cdt.org\/staff\/?staff-filter=cdt-europe\"><em>our team<\/em><\/a><em> in Brussels.<\/em><\/p>\n\n\n\n<p><strong>\ud83d\udc41\ufe0f Security, Surveillance &amp; Human Rights<\/strong><\/p>\n\n\n\n<p><strong>Citizen Lab Unveils Surveillance Abuses in Europe and Beyond&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;<\/strong><\/p>\n\n\n\n<p>\u200bThe recent <a href=\"https:\/\/citizenlab.ca\/2025\/03\/a-first-look-at-paragons-proliferating-spyware-operations\/\">Citizen Lab report<\/a> regarding deployment of Paragon spyware in EU Member States, particularly Italy and allegedly in Cyprus and Denmark, highlights a concerning trend of surveillance targeting journalists, government opponents, and human rights defenders. Invasive monitoring of journalist Francesco Cancellato, members of the NGO Mediterranea Saving Humans, and human rights activist Yambio raises serious concerns about press freedom, fundamental rights, and the broader implications for democracy and rule of law in the EU.&nbsp;<\/p>\n\n\n\n<p>The Italian government\u2019s denial that it authorised surveillance, while reports indicate otherwise, indicates a lack of transparency and accountability. Reportedly, the Undersecretary to the Presidency of the Council of Ministers <a href=\"https:\/\/www.repubblica.it\/politica\/2025\/03\/26\/news\/mantovano_servizi_usarono_paragon_spiare_mediterranea-424086192\/\">admitted<\/a> that Italian intelligence services used Paragon spyware against Mediterranean activists, citing national security justifications. This admission highlights the urgent need for transparent oversight mechanisms and robust legal frameworks to prevent misuse of surveillance technologies.&nbsp;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-medium is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"640\" height=\"367\" src=\"https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/CitizenLab-Report-640x367.png\" alt=\"Graphic for Citizen Lab report, which reads, &quot;Virtue or Vice? A First Look at Paragon's Proliferating Spyware Options&quot;. Graphic has a yellow background, and a grayscale hand reaching through great message bubbles.\" class=\"wp-image-108126\" style=\"width:640px;height:auto\" srcset=\"https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/CitizenLab-Report-640x367.png 640w, https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/CitizenLab-Report-768x440.png 768w, https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/CitizenLab-Report.png 904w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><figcaption class=\"wp-element-caption\"><em>Graphic for Citizen Lab report, which reads, &#8220;Virtue or Vice? A First Look at Paragon&#8217;s Proliferating Spyware Options&#8221;. Graphic has a yellow background, and a grayscale hand reaching through great message bubbles.<\/em><\/figcaption><\/figure><\/div>\n\n\n<p>Lack of decisive action at the European level in response to these findings is alarming. Efforts to initiate a plenary debate within the European Parliament have <a href=\"https:\/\/www.youtube.com\/watch?v=PAMgLhfik28\">stalled<\/a> due to insufficient political support, reflecting a broader pattern of inaction that threatens civic space and fundamental rights across the EU. This inertia is particularly concerning given parallel developments in <a href=\"https:\/\/www.globalencryption.org\/2025\/03\/global-encryption-coalition-steering-committee-statement-on-the-dangers-of-the-french-narcotrafic-legislation\/\">France<\/a>, <a href=\"https:\/\/netzpolitik.org\/2025\/koalitionsverhandlungen-gruselprogramm-fuer-grund-und-freiheitsrechte\/\">Germany<\/a>, and <a href=\"https:\/\/epicenter.works\/en\/content\/net-policy-analysis-government-programme-of-oevp-spoe-neos\">Austria<\/a>, where legislative measures are being considered to legalise use of surveillance technologies. In light of the European Parliament\u2019s PEGA Committee findings on Pegasus and equivalent spyware, it is imperative that EU institutions and Member States establish clear, rights-respecting policies governing the use of surveillance tools. Normalisation of intrusive surveillance without adequate safeguards poses a direct challenge to democratic principles and the protection of human rights within the EU.<\/p>\n\n\n\n<p><strong><em>Recommended read: <\/em><\/strong>Amnesty International, <a href=\"https:\/\/www.amnesty.org\/en\/documents\/eur70\/9186\/2025\/en\/\">Serbia: Technical Briefing: Journalists targeted with Pegasus spyware<\/a><\/p>\n\n\n\n<p><strong>&nbsp;\ud83d\udcac Online Expression &amp; Civic Space<\/strong><\/p>\n\n\n\n<p><strong>DSA Civil Society Coordination Group Publishes Analysis on DSA Risk Assessment Reports<\/strong><\/p>\n\n\n\n<p>Key elements of the Digital Services Act\u2019s (DSA) due diligence obligations for Very Large Online Platforms and Search Engines (VLOPs\/VLOSEs) are the provisions on risk assessment and mitigation. Last November, VLOPs and VLOSEs published their first risk assessment reports, which the DSA Civil Society Coordination Group, convened and coordinated by CDT Europe, took the opportunity to jointly assess. We identified both <a href=\"https:\/\/cdt.org\/wp-content\/uploads\/2025\/03\/RA-Report-Assessment-Report.pdf\">promising practices to adopt and critical gaps to address<\/a> in order to improve future iterations of these reports and ensure meaningful DSA compliance.<\/p>\n\n\n\n<p>Our analysis zooms in on key topics like online protection of minors, media pluralism, electoral integrity, and online gender-based violence. Importantly, we found that platforms have overwhelmingly focused on identifying and mitigating user-generated risks, as a result focusing less on risks stemming from the design of their services. In addition, platforms do not provide sufficient metrics and data to assess the effectiveness of the mitigation measures they employ. In our analysis, we describe what data and metrics future reports could reasonably include to achieve more meaningful transparency.&nbsp;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-medium\"><img loading=\"lazy\" decoding=\"async\" width=\"640\" height=\"360\" src=\"https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/DSA-RA-Report-blog-banner-640x360.png\" alt=\"Graphic with a blue background, with logo for the DSA Civil Society Coordination Group featuring members' logos. In black text, graphic reads, &quot;Initial Analysis on the First Round of Risk Assessments Reports under the EU Digital Services Act&quot;.\" class=\"wp-image-108127\" srcset=\"https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/DSA-RA-Report-blog-banner-640x360.png 640w, https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/DSA-RA-Report-blog-banner-1024x576.png 1024w, https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/DSA-RA-Report-blog-banner-768x432.png 768w, https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/DSA-RA-Report-blog-banner-1536x864.png 1536w, https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/DSA-RA-Report-blog-banner-2048x1152.png 2048w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><figcaption class=\"wp-element-caption\"><em>Graphic with a blue background, with logo for the DSA Civil Society Coordination Group featuring members&#8217; logos. In black text, graphic reads, &#8220;Initial Analysis on the First Round of Risk Assessments Reports under the EU Digital Services Act&#8221;.<\/em><\/figcaption><\/figure><\/div>\n\n\n<p>CDT Europe\u2019s <a href=\"https:\/\/cdt.org\/staff\/david-klotsonis\/\">David Klotsonis,<\/a> lead author of the analysis, commented, \u201cAs the first attempt at DSA Risk Assessments, we didn\u2019t expect perfection \u2014 but we did expect substance. Instead, these reports fall short as transparency tools, offering little new data on mitigation effectiveness or meaningful engagement with experts and affected communities. This is a chance for platforms to prove they take user safety seriously. To meet the DSA\u2019s promise, they must provide real transparency and make civil society a key part of the risk assessment process. We are committed to providing constructive feedback and to fostering an ongoing dialogue.\u201d<\/p>\n\n\n\n<p><strong><em>Recommended read<\/em><\/strong>: Tech Policy Press, <a href=\"https:\/\/www.techpolicy.press\/a-new-framework-for-understanding-algorithmic-feeds-and-how-to-fix-them\/\">A New Framework for Understanding Algorithmic Feeds and How to Fix Them<\/a>&nbsp;<\/p>\n\n\n\n<p><strong>\u2696\ufe0f Equity and Data<\/strong><\/p>\n\n\n\n<p><strong>Code of Practice on General-Purpose AI Final Draft Falls Short<\/strong><\/p>\n\n\n\n<p>Following CDT Europe\u2019s <a href=\"https:\/\/cdt.org\/insights\/cdt-europe-statement-on-the-third-general-purpose-ai-code-of-practice-draft\/\">initial reaction<\/a> to the release of the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/third-draft-general-purpose-ai-code-practice-published-written-independent-experts\">third Draft Code of Practice on General-Purpose AI<\/a> (GPAI), we published a <a href=\"https:\/\/cdt.org\/insights\/third-draft-of-the-general-purpose-ai-code-of-practice-misses-the-mark-on-fundamental-rights\/\">full analysis<\/a> highlighting key concerns. One major issue is the Code\u2019s narrow interpretation of the AI Act, which excludes fundamental rights risks from the list of selected risks that GPAI model providers must assess. Instead, assessing these risks is left as an option, and is only required if such risks are created by a model\u2019s high-impact capabilities.<\/p>\n\n\n\n<p>This approach stands in contrast to the growing international consensus, including the <a href=\"https:\/\/assets.publishing.service.gov.uk\/media\/679a0c48a77d250007d313ee\/International_AI_Safety_Report_2025_accessible_f.pdf\">2025 International AI Safety Report<\/a>, which acknowledges the fundamental rights risks posed by GPAI. The Code also argues that existing legislation can better address these risks, but we push back on this claim. Laws like the General Data Protection Regulation, the Digital Services Act, and the Digital Markets Act lack the necessary tools to fully tackle these challenges.<\/p>\n\n\n\n<p>Moreover, by making it optional to assess fundamental rights risks, the Code weakens some of its more promising provisions, such as requirements for external risk assessments and clear definitions of unacceptable risk tiers.&nbsp;<\/p>\n\n\n\n<p>In response to these concerns, we joined a coalition of civil society organisations in <a href=\"https:\/\/cdt.org\/insights\/joint-civil-society-letter-urging-the-eu-institutions-to-protect-fundamental-rights-in-the-code-of-practice-for-general-purpose-ai-final-draft\/\">calling for a revised draft<\/a> that explicitly includes fundamental rights risks in its risk taxonomy.<\/p>\n\n\n\n<p><strong>Global AI Standards Hub Summit&nbsp;<\/strong><\/p>\n\n\n\n<p>At the inaugural <a href=\"https:\/\/aistandardshub.org\/global-summit\/#summit-tabs%7C0\">global AI Standards Hub Summit, <\/a>co-organised by the Alan Turing Institute, CDT Europe\u2019s Laura Lazaro Cabrera spoke at a session exploring the role of fundamental rights in the development of international AI standards. Laura highlighted the importance of integrating sociotechnical expertise and meaningfully involving civil society actors to strengthen AI standards from a fundamental rights perspective. Laura emphasised the need to create dedicated spaces for civil society to participate in standards processes, tailored to the diversity of their contributions and resource limitations.&nbsp;&nbsp;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-medium\"><img loading=\"lazy\" decoding=\"async\" width=\"640\" height=\"317\" src=\"https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/Laura-Lazaro-Cabrera-at-Global-AI-Standards-Hub-Summit-640x317.png\" alt=\"Image featuring Programme Director for Equity and Data Laura Lazaro Cabrera speaking at a panel with three other panelists on the role of fundamental rights in standardisation, at the Global AI Standard Hub Summit\" class=\"wp-image-108128\" srcset=\"https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/Laura-Lazaro-Cabrera-at-Global-AI-Standards-Hub-Summit-640x317.png 640w, https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/Laura-Lazaro-Cabrera-at-Global-AI-Standards-Hub-Summit-1024x508.png 1024w, https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/Laura-Lazaro-Cabrera-at-Global-AI-Standards-Hub-Summit-768x381.png 768w, https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/Laura-Lazaro-Cabrera-at-Global-AI-Standards-Hub-Summit-1536x762.png 1536w, https:\/\/cdt.org\/wp-content\/uploads\/2025\/04\/Laura-Lazaro-Cabrera-at-Global-AI-Standards-Hub-Summit-2048x1015.png 2048w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><figcaption class=\"wp-element-caption\"><em>Image featuring Programme Director for Equity and Data Laura Lazaro Cabrera speaking at a panel with three other panelists on the role of fundamental rights in standardisation, at the Global AI Standard Hub Summit<\/em><\/figcaption><\/figure><\/div>\n\n\n<p><strong><em>Recommended read<\/em><\/strong>: Tech Policy Press, <a href=\"https:\/\/www.techpolicy.press\/human-rights-are-universal-not-optional-dont-undermine-the-eu-ai-act-with-a-faulty-code-of-practice\/\">Human Rights are Universal, Not Optional: Don\u2019t Undermine the EU AI Act with a Faulty Code of Practice<\/a><\/p>\n\n\n\n<p><strong>\ud83c\udd95 Job Opportunities in Brussels: Join Our EU Team<\/strong><\/p>\n\n\n\n<p>We&#8217;re looking for two motivated individuals to join our Brussels office and support our mission to promote human rights in the digital age.&nbsp;<\/p>\n\n\n\n<p>The Operations &amp; Finance Officer will play a key role in keeping our EU office running smoothly\u2014managing budgets, coordinating logistics, and ensuring strong operational foundations for our advocacy work.&nbsp;<\/p>\n\n\n\n<p>We&#8217;re also seeking an EU Advocacy Intern to support our policy and advocacy efforts, with hands-on experience in research, event planning, and stakeholder engagement.&nbsp;<\/p>\n\n\n\n<p>Apply before 23 April 2025 by sending your cover letter and CV to <a href=\"mailto:hr@cdt.org\">hr@cdt.org<\/a>. <a href=\"https:\/\/cdt.org\/careers\/\">For more information, visit our website<\/a>.&nbsp;<\/p>\n\n\n\n<p><strong>\ud83d\uddde\ufe0f In the Press<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Euronews, <a href=\"https:\/\/www.euronews.com\/next\/2025\/03\/17\/online-platforms-fail-to-assess-risks-in-annual-reports-study-says\">Online platforms fail to assess risks in annual reports, study says<\/a><\/li>\n\n\n\n<li>Mlex, <a href=\"https:\/\/www.mlex.com\/mlex\/technology\/articles\/2312770\/big-tech-s-eu-digital-services-act-risk-reporting-needs-work-monitor-group-says\">Big Tech&#8217;s EU Digital Services Act risk reporting needs work, monitor group says<\/a><\/li>\n\n\n\n<li>Euractiv, <a href=\"https:\/\/www.euractiv.com\/section\/tech\/news\/paragon-scandal-denmark-and-cyprus-potential-spyware-customers-alongside-italy\/\">Paragon scandal: Denmark and Cyprus potential spyware customers alongside Italy<\/a><\/li>\n\n\n\n<li>Euractiv, \u200b\u200b<a href=\"https:\/\/www.euractiv.com\/section\/tech\/news\/gpai-code-of-practice-the-thankless-quest-to-please-1000-lobbyists\/\">GPAI Code of Practice: The impossible task of pleasing 1,000 lobbyists<\/a><\/li>\n<\/ul>\n\n\n\n<p><strong>\u23eb Upcoming Event<\/strong><\/p>\n\n\n\n<p><strong>Pall Mall Process Conference: <\/strong>On 3 and 4 April, our Director for Security and Surveillance Silvia Lorenzo Perez will participate in the annual Pall Mall Process Conference in Paris.&nbsp;<\/p>\n","protected":false},"featured_media":108133,"template":"","content_type":[],"area-of-focus":[834,652,7257,77,806,7252],"class_list":["post-108123","insight","type-insight","status-publish","has-post-thumbnail","hentry","area-of-focus-ai-policy-governance","area-of-focus-european-policy","area-of-focus-european-surveillance","area-of-focus-free-expression","area-of-focus-government-surveillance","area-of-focus-transparency-accountability"],"acf":[],"_links":{"self":[{"href":"https:\/\/cdt.org\/wp-json\/wp\/v2\/insight\/108123","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cdt.org\/wp-json\/wp\/v2\/insight"}],"about":[{"href":"https:\/\/cdt.org\/wp-json\/wp\/v2\/types\/insight"}],"version-history":[{"count":4,"href":"https:\/\/cdt.org\/wp-json\/wp\/v2\/insight\/108123\/revisions"}],"predecessor-version":[{"id":108131,"href":"https:\/\/cdt.org\/wp-json\/wp\/v2\/insight\/108123\/revisions\/108131"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cdt.org\/wp-json\/wp\/v2\/media\/108133"}],"wp:attachment":[{"href":"https:\/\/cdt.org\/wp-json\/wp\/v2\/media?parent=108123"}],"wp:term":[{"taxonomy":"content_type","embeddable":true,"href":"https:\/\/cdt.org\/wp-json\/wp\/v2\/content_type?post=108123"},{"taxonomy":"area-of-focus","embeddable":true,"href":"https:\/\/cdt.org\/wp-json\/wp\/v2\/area-of-focus?post=108123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}