Policy & Regulation
Ireland moves to modernize surveillance laws amid spyware concerns
Ireland has introduced the Communications (Interception and Lawful Access) Bill to regulate surveillance technology and modernize laws governing encrypted communications.
The Irish government announced this week the introduction of the Communications (Interception and Lawful Access) Bill, a legislative effort to regulate surveillance technology and update the country’s legal framework. The existing law, which dates back to 1993, predates modern communication methods such as end-to-end encrypted applications. Because these older rules do not account for modern digital security, the proposed bill will cover all forms of communications, whether encrypted or not. This includes regulating “lawful interception”—the industry term for surveillance technology—and “spyware,” which refers to covert surveillance software used to gain access to electronic devices.
Jim O’Callaghan, Ireland’s minister for justice, home affairs, and migration, emphasized that a new legal framework is urgently needed to confront serious crime and security threats. To address privacy concerns, O’Callaghan asserted that the framework will balance state powers with civil liberties. “The new legislation will also include robust legal safeguards to provide continued assurance that the use of such powers is necessary and proportionate,” O’Callaghan said.
The legislative push in Ireland comes as government spyware continues to proliferate across Europe. While spyware has been “used to violate human rights” and remains subject to the “abuse of spyware,” the technology has steadily normalized over the last two decades. Historically, high-profile spyware scandals were primarily associated with countries in the Middle East and South America, but recent cases of abuse have emerged within Europe, including in Greece, Hungary, Italy, and Poland.
The normalization of these tools in Europe has deep roots. In 2004, the Italian cybercrime unit Polizia Postale signed a contract with Hacking Team, a defunct cybersecurity startup, marking the first documented government spyware sale. By 2007, the head of the BundesKriminalamt, Germany’s federal criminal police office, confirmed the agency was using computer spyware. In 2008, WikiLeaks revealed that German authorities were purchasing spyware from a company called DigiTask. By 2011, the Chaos Computer Club, a hacker group, discovered police spyware on a businessman’s computer. Over the following years, researchers documented the abuse of European-made spyware in countries such as Egypt, Ethiopia, Mexico, Morocco, and the United Arab Emirates, making spyware a relatively normalized technology.
Why it matters
The Irish government is proposing a new law to modernize surveillance capabilities, specifically targeting encrypted communications, which currently fall outside the scope of the 1993 legislation. As European states seek to regulate or adopt these tools, the bill highlights the ongoing tension between state security demands and digital privacy protections.