<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Data protection law on ARPOKRAT</title>
    <link>https://arpokrat.com/blog/tags/data-protection/</link>
    <description>Recent content in Data protection law on ARPOKRAT</description>
    <generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Tue, 01 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://arpokrat.com/blog/tags/data-protection/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>SignalTrace: Europe Exports the Surveillance It Will Not Allow Itself</title>
      <link>https://arpokrat.com/blog/signaltrace-leonardo-bluetooth-surveillance/</link>
      <pubDate>Tue, 01 Sep 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/signaltrace-leonardo-bluetooth-surveillance/</guid>
      <description>&lt;p&gt;A grey saloon passes under a motorway gantry at 110 kph. The camera on the mast reads the plate, timestamps it, records it. Nothing new: this equipment has been around for twenty years, deployed in tens of thousands of units across North America and Europe alike.&lt;/p&gt;
&lt;p&gt;But if that gantry has been fitted with the unit the Italian group Leonardo has been selling since June 2026, it has just recorded something else. The driver&amp;rsquo;s iPhone. The passenger&amp;rsquo;s wireless earbuds. The smartwatch on the dashboard. The car stereo. The connected key fob in the glovebox. The pressure sensors in all four tyres. The access badge left in a jacket. And, if a dog is asleep in the back, its identification chip.&lt;/p&gt;
&lt;p&gt;A dozen identifiers, a plate, a position, a time. Repeat at every gantry on the network and you are no longer following a car: you are following people, and you know who they travel with.&lt;/p&gt;
&lt;h2 id=&#34;what-the-equipment-actually-does&#34;&gt;What the equipment actually does&lt;/h2&gt;
&lt;p&gt;The product is called &lt;strong&gt;SignalTrace&lt;/strong&gt;. Sold by Leonardo US Cyber and Security Solutions, it extends the &lt;strong&gt;ELSAG&lt;/strong&gt; range, one of the most widespread lines of automated licence plate readers on the American market. Its existence was revealed on 8 June 2026 by Joseph Cox in &lt;a href=&#34;https://www.404media.co/this-company-will-add-phone-airpod-and-smartwatch-trackers-to-license-plate-readers/&#34;&gt;404 Media&lt;/a&gt;, from a manufacturer&amp;rsquo;s product sheet.&lt;/p&gt;
&lt;p&gt;The decisive point fits in one sentence: &lt;strong&gt;these are not new cameras&lt;/strong&gt;. SignalTrace is a radio sensor added to plate readers that are already installed. The mast does not change, the location does not change, the silhouette of the roadside equipment does not change. What changes is what the equipment listens to.&lt;/p&gt;
&lt;p&gt;The sensor records the identifiers broadcast in the clear by the Bluetooth, Wi-Fi and RFID protocols of the devices inside the vehicle. A technical point that is often misunderstood: no device is hacked and no vulnerability is exploited. A Bluetooth or Wi-Fi device continuously emits discovery frames, because that is how the protocols were designed. Your earbuds announce their presence so your phone can find them, and the phone itself queries the surrounding air for the networks it knows. These emissions are public by construction, and any receiver within range hears them.&lt;/p&gt;
&lt;p&gt;Leonardo indeed states that the system works &lt;a href=&#34;https://www.leonardocompany-us.com/lpr/elsag-signaltrace&#34;&gt;with or without a plate reader&lt;/a&gt;, indoors included, and recognises a vehicle whose plate has been obscured or removed.&lt;/p&gt;
&lt;p&gt;The retrofit is the real political issue. Installing a new camera network triggers a vote, a public deliberation, sometimes litigation. Adding a circuit board inside a housing that has already been approved triggers nothing. The surveillance capability changes in nature without public debate, because there is materially nothing new to see.&lt;/p&gt;
&lt;h2 id=&#34;from-the-vehicle-to-the-person-and-from-the-person-to-the-group&#34;&gt;From the vehicle to the person, and from the person to the group&lt;/h2&gt;
&lt;p&gt;A plate reader answers one question: where was this vehicle. SignalTrace adds two more: who was in it, and with whom.&lt;/p&gt;
&lt;p&gt;Leonardo makes no secret of this, it is the sales pitch. The system builds what the documentation calls an &lt;strong&gt;electronic fingerprint&lt;/strong&gt;, a set of identifiers &amp;ldquo;frequently emitted together&amp;rdquo;. The manufacturer&amp;rsquo;s example is explicit: across an entire city, only one vehicle will pair an iPhone 13rev2, an Audi car stereo, a Bose headset, a Garmin watch, a key tracker and the plate ABC-1234.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The product does not merely track vehicles. It automatically produces a graph of relationships between people, without anyone having had to formulate the slightest suspicion.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This is where the qualitative leap happens. By correlating the devices that regularly travel together, the system mechanically builds a social graph. Two phones that end up in the same car every morning are a car share, or a relationship neither party wishes to make public. Fifty devices captured in the same place at the same time are a gathering: a protest, a religious service, a union meeting or a queue outside a clinic.&lt;/p&gt;
&lt;p&gt;None of these conclusions requires access to the content of a communication. They are deduced from a proximity table, by default, across the entire travelling population rather than on designated targets. This is guilt by association, produced industrially, upstream of any investigation. Tom Bowman, a lawyer at the &lt;a href=&#34;https://cdt.org/staff/tom-bowman/&#34;&gt;Center for Democracy &amp;amp; Technology&lt;/a&gt;, sums up the problem in &lt;a href=&#34;https://www.technewsworld.com/story/license-plate-reader-adds-device-snooping-feature-180421.html&#34;&gt;TechNewsWorld&lt;/a&gt;: what makes the tool useful for tracking a genuine suspect makes it just as capable of tracking every other motorist, none of whom consented to having their devices recorded.&lt;/p&gt;
&lt;p&gt;Leonardo offers two counter-arguments: the system neither decrypts nor reads the content of communications, and it does not identify people by itself. Both statements are accurate, and both miss the point. The intelligence sought was never the content, it lies in the location metadata, which is more revealing than a message. As for identification, the manufacturer itself acknowledges that an investigator can link an electronic signature to a plate, then work back to the registered keeper through vehicle registration records.&lt;/p&gt;
&lt;h2 id=&#34;american-law-written-for-something-else&#34;&gt;American law written for something else&lt;/h2&gt;
&lt;p&gt;In the United States, state laws governing plate readers do exist, and some are demanding about retention periods and access purposes. But all were drafted around one precise object: &lt;strong&gt;the image of a licence plate&lt;/strong&gt;. None anticipates the capture of personal device identifiers by the same equipment.&lt;/p&gt;
&lt;p&gt;This mismatch does not create illegality but a grey area, one more convenient for the vendor. A police department can maintain, without lying, that its plate reader programme is authorised and compliant, while now collecting under the same regime data of an entirely different nature. Leonardo also holds federal contracts, with Special Operations Command and the General Services Administration, a purchasing route that largely bypasses local approvals.&lt;/p&gt;
&lt;p&gt;The constitutional debate, for its part, has just shifted, and precision matters here because the state of the law changed this summer. In January 2026, a federal court in Virginia held, in &lt;em&gt;Schmidt v. City of Norfolk&lt;/em&gt;, that the city&amp;rsquo;s Flock camera network &lt;a href=&#34;https://www.courthousenews.com/judge-holds-norfolks-license-plate-reader-use-constitutional/&#34;&gt;did not constitute a search&lt;/a&gt; under the Fourth Amendment, because it did not cover the entirety of residents&amp;rsquo; movements. The decision is on appeal before the Fourth Circuit, where the &lt;a href=&#34;https://www.aclu.org/campaigns-initiatives/get-the-flock-out&#34;&gt;ACLU&lt;/a&gt; has intervened.&lt;/p&gt;
&lt;p&gt;Then, on 29 June 2026, the Supreme Court handed down &lt;a href=&#34;https://www.supremecourt.gov/opinions/25pdf/25-112_0am4.pdf&#34;&gt;&lt;em&gt;Chatrie v. United States&lt;/em&gt;&lt;/a&gt;. By five votes to four, in an opinion written by Justice Kagan, it held that police acquisition of a phone&amp;rsquo;s location data constituted a search, an individual retaining a reasonable expectation of privacy in that data even when held by a third party and over a short period. The ruling extends &lt;em&gt;Carpenter v. United States&lt;/em&gt; from 2018 and weakens the third-party doctrine, as the &lt;a href=&#34;https://cdt.org/insights/op-ed-scotuss-signals-in-chatrie-and-on-the-potential-limits-of-location-tracking/&#34;&gt;CDT&lt;/a&gt; noted.&lt;/p&gt;
&lt;p&gt;The precise reach of &lt;em&gt;Chatrie&lt;/em&gt; over SignalTrace is unsettled, and it would be careless to claim otherwise: the ruling concerns data demanded from Google, not direct capture by a police sensor in public space. But it establishes the reasoning that matters, namely that the sensitivity of location data does not depend on who holds it.&lt;/p&gt;
&lt;h2 id=&#34;the-european-question-which-is-the-real-question&#34;&gt;The European question, which is the real question&lt;/h2&gt;
&lt;p&gt;This is where the file becomes uncomfortable for Europe. Leonardo is not an American supplier but an Italian group listed in Milan whose leading shareholder is the Italian Ministry of Economy and Finance, holding around 30 % of the capital, with the power to appoint the majority of the board. The Italian state is not a passive shareholder in this product.&lt;/p&gt;
&lt;h3 id=&#34;the-technical-point-first&#34;&gt;The technical point, first&lt;/h3&gt;
&lt;p&gt;Under European law, a device identifier is personal data. This is not a doctrinal opinion but the settled position of the authorities. The CNIL explicitly treats the MAC address as such in its guidance on &lt;a href=&#34;https://www.cnil.fr/fr/dispositifs-de-mesure-daudience-et-de-frequentation-dans-des-espaces-accessibles-au-public-la-cnil&#34;&gt;footfall measurement systems&lt;/a&gt;, and permits their collection in public space only under narrow conditions: anonymisation within a few minutes with a high collision rate between individuals, or reliable pseudonymisation followed by destruction within twenty-four hours, failing which consent becomes mandatory. The same guidance specifies that inviting people to switch off their Wi-Fi is not an acceptable means of objecting.&lt;/p&gt;
&lt;p&gt;On 4 September 2025, in &lt;em&gt;EDPS v. SRB&lt;/em&gt; (C-413/23 P), the Court of Justice of the European Union clarified that whether pseudonymised data is personal is assessed against the means of re-identification that can reasonably be deployed. Here the holder is a police authority, which has access to vehicle registration records. The means of re-identification are not hypothetical, they are in the next office along.&lt;/p&gt;
&lt;h3 id=&#34;the-nuance-that-changes-everything&#34;&gt;The nuance that changes everything&lt;/h3&gt;
&lt;p&gt;It would be wrong to write that SignalTrace &amp;ldquo;would be illegal in Europe&amp;rdquo;, and a legally trained reader would spot it immediately. Processing carried out by a competent authority for the purposes of preventing and prosecuting criminal offences does not fall under the GDPR. It falls under &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/PDF/?uri=CELEX%3A32016L0680&#34;&gt;Directive (EU) 2016/680&lt;/a&gt;, known as the Law Enforcement Directive, transposed separately by each member state, in France under Title III of the Data Protection Act. The &lt;a href=&#34;https://www.cnil.fr/fr/directive-police-justice-de-quoi-parle-t&#34;&gt;CNIL&lt;/a&gt; points out that this regime is autonomous, with its own grounds for lawfulness and its own rights.&lt;/p&gt;
&lt;p&gt;The right question is therefore not one of abstract legality, but one of conditions. Under that regime, such a system would require an express national legal basis, defined purposes, demonstrated necessity, a bounded retention period, an impact assessment and independent oversight. In France, plate readers are governed on these terms: articles L233-1 and L233-1-1 of the internal security code set out an exhaustive list of offences that open the way to their use, and retention remains among the shortest in the Union, fifteen days in principle, even if a Senate bill seeks to extend it.&lt;/p&gt;
&lt;p&gt;That is the fundamental difference with the American situation. In the United States, the law governs an object, the plate, and silence on device identifiers amounts to permission. In Europe, the law governs purposes and categories of data, and that silence amounts rather to prohibition, for want of an express legal basis. The vacuum observed across the Atlantic does not exist here in the same form. Not that Europe is more virtuous: its legal technique is the reverse.&lt;/p&gt;
&lt;h3 id=&#34;what-the-protection-is-then-worth&#34;&gt;What the protection is then worth&lt;/h3&gt;
&lt;p&gt;That leaves the question this article is about. What is European regulatory protection worth when a European company, controlled by a member state, sells outside Europe a capability it could not deploy at home without new legislation?&lt;/p&gt;
&lt;p&gt;The objections deserve to be taken seriously. A manufacturer is not responsible for its customer&amp;rsquo;s legal framework: it is for the American authorities to decide what they permit at home. The product is not sold to a dictatorship but to a state under the rule of law with an active supreme court, as &lt;em&gt;Chatrie&lt;/em&gt; has just shown. And the industrial sovereignty argument is legitimate: if European groups shut themselves out of these markets, they will be taken by Israeli, American or Chinese suppliers, without surveillance receding by a single metre, and Europe will lose its technological base.&lt;/p&gt;
&lt;p&gt;These arguments are admissible. They do not answer the problem.&lt;/p&gt;
&lt;p&gt;First because the Union has already recognised that exporting surveillance capabilities is not trade like any other. &lt;a href=&#34;https://www.entreprises.gouv.fr/espace-entreprises/s-informer-sur-la-reglementation/le-reglement-europeen-sur-les-biens-double&#34;&gt;Regulation (EU) 2021/821&lt;/a&gt; on dual-use items introduced, in its article 5, a catch-all clause covering cyber-surveillance items, because the legislator accepted that a tool that is legal to manufacture may be illegitimate at its destination. Its limit is instructive: it is triggered by a risk of internal repression or serious human rights violations, categories designed for authoritarian regimes. A sale to an American municipal police force does not fall within them. The European grid examines the morality of the customer, never the nature of the capability being sold.&lt;/p&gt;
&lt;p&gt;Second because such a product is not a stock to be cleared, but a capability that is sustained: it funds research, trains engineers, accumulates know-how and creates an installed base. The day a major attack pushes a member state to demand this capability, the debate will no longer be about whether to build it. It will exist, it will be European, it will be mature, and its supplier will be partly public. The &amp;ldquo;we are only following the market&amp;rdquo; argument then becomes circular, since the domestic market will have been prepared by the export.&lt;/p&gt;
&lt;p&gt;That is what regulatory protection is worth in this scenario: it protects Europeans against uses, not against the existence of the means. It settles the question of who is entitled to press the button, and leaves industry to build it, sell it, improve it, then wait.&lt;/p&gt;
&lt;h2 id=&#34;what-can-be-done-without-kidding-ourselves&#34;&gt;What can be done, without kidding ourselves&lt;/h2&gt;
&lt;p&gt;The first answer raised is always MAC address randomisation. It deserves an honest examination, neither promotion nor disparagement. It is real and it works.&lt;/p&gt;
&lt;p&gt;Android since version 10 and iOS since version 14 randomise by default the MAC address used over Wi-Fi, with a distinct address per network. In Bluetooth Low Energy, modern devices broadcast resolvable private addresses, which change periodically and can only be tied back to the real device by a counterpart holding the resolution key.&lt;/p&gt;
&lt;p&gt;Its limits are just as real.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Pairing reopens the door.&lt;/strong&gt; The resolution key is transmitted during pairing. A device already paired, or explicitly approved, recovers the stable identity behind the rotating address. The mechanism is designed for that.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Many objects randomise nothing.&lt;/strong&gt; Tyre pressure sensors, RFID badges, animal identification chips, car stereos and cheap peripherals emit fixed identifiers. Leonardo&amp;rsquo;s product sheet mentions exactly these categories, which is no accident.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Randomisation can be switched off.&lt;/strong&gt; It is disabled network by network, and often is, out of convenience, for MAC filtering on a home router or by corporate policy.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The group survives the rotation of identifiers.&lt;/strong&gt; This is the least intuitive and most important point. SignalTrace is not looking for an identifier, it is looking for a set of devices travelling together. If a single member of the group emits a stable identifier, the whole set remains attributable, whatever the discipline of the others.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The most effective measure remains the most tedious: do not emit. That means disabling Bluetooth and Wi-Fi at system level, in the settings, and not from the shortcut panel. The distinction is not cosmetic, we detailed it in our article on &lt;a href=&#34;https://arpokrat.com/blog/how-your-phone-tracks-your-location/&#34;&gt;how your phone tracks your location&lt;/a&gt;: on most consumer systems, the quick panel button cuts visible pairing but leaves the software stack alive, and proximity scanning continues. That article described Bluetooth scanning as a theoretical vector. SignalTrace is its commercial product, catalogued and deliverable.&lt;/p&gt;
&lt;p&gt;We have to stay honest about the outcome: these measures reduce the exposure surface, they do not eliminate it. A vehicle is still a plate, and a plate is still readable. The only way to emit nothing is to carry nothing, which is not a public policy.&lt;/p&gt;
&lt;h2 id=&#34;what-this-says-about-our-design-choices&#34;&gt;What this says about our design choices&lt;/h2&gt;
&lt;p&gt;At Arpokrat, it is this reasoning that led us to handle Bluetooth at the Core level of ArpokratOS rather than at the settings level. A switch in an interface is a user preference: an update, a system application or a location service can bypass or re-enable it, without the user knowing. A stack that is absent cannot be re-enabled.&lt;/p&gt;
&lt;p&gt;Faced with capture of the SignalTrace kind, this obviously does not make a device undetectable, and we do not claim it does: a phone remains on a mobile network, and the other objects in a vehicle emit on their own account. What it does guarantee is that one specific emission vector is absent by construction rather than disabled on trust. That is the argument we made about &lt;a href=&#34;https://arpokrat.com/blog/5g-location-data-privacy-law/&#34;&gt;5G and the law&amp;rsquo;s targeting error&lt;/a&gt;: legal protection concentrates on access to data when it should bear on the very existence of the infrastructure that produces it. SignalTrace illustrates the point, except that this infrastructure is built in Europe.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;The most striking thing in this file is not the technical capability, which researchers have been describing for years. It is the deployment method.&lt;/p&gt;
&lt;p&gt;There will be no new camera network to inaugurate, no municipal deliberation to challenge, no public contract identifiable as a change in nature. There will be units added to existing masts, under existing contracts, within programmes already authorised. By the time public debate opens, the infrastructure will be installed, written down and integrated into investigative procedures. The debate will then be about the conditions for accessing a database that exists, never about whether it should have been built.&lt;/p&gt;
&lt;p&gt;That is the usual order of things where surveillance is concerned, and it is not accidental. What remains to be seen is whether Europe considers it has anything to say when its own manufacturers, backed by its own states, build this infrastructure for others. European law has carefully organised the answer to the question of who may consult this data at home. It has never asked who is entitled to build the machine.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>5G, Location Data and the Law&#39;s Targeting Error</title>
      <link>https://arpokrat.com/blog/5g-location-data-privacy-law/</link>
      <pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/5g-location-data-privacy-law/</guid>
      <description>&lt;p&gt;In 2011, Detroit police asked a mobile operator for the cell site records of Timothy Carpenter&amp;rsquo;s phone. They obtained 12,898 location points spread over 127 days, around a hundred a day. Seven years later, the Supreme Court of the United States held that the request amounted to a search and required a warrant.&lt;/p&gt;
&lt;p&gt;Those 12,898 points came from fourth-generation towers, each covering a radius of several kilometres. The same request, addressed today to an urban 5G network, would not return a hundred points a day accurate to a few kilometres. It would return a far larger volume, accurate to a few dozen metres.&lt;/p&gt;
&lt;p&gt;The technology has changed scale. The legal reasoning has stayed at the same point in the chain.&lt;/p&gt;
&lt;h2 id=&#34;a-legal-interest-that-judges-recognise-on-both-sides-of-the-atlantic&#34;&gt;A legal interest that judges recognise on both sides of the Atlantic&lt;/h2&gt;
&lt;p&gt;There is an interest almost everyone accepts and almost no legal text protects effectively: the right to be somewhere without that fact being recorded.&lt;/p&gt;
&lt;p&gt;European case law established it unambiguously. In &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62012CJ0293&#34;&gt;Digital Rights Ireland&lt;/a&gt; (joined cases C-293/12 and C-594/12, 8 April 2014), and then in &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62015CJ0203&#34;&gt;Tele2 Sverige and Watson&lt;/a&gt; (joined cases C-203/15 and C-698/15, Grand Chamber, 21 December 2016), the Court of Justice of the European Union held that such data, taken as a whole, allow very precise conclusions to be drawn concerning people&amp;rsquo;s private lives: daily habits, places of residence, movements, activities carried out and social relationships.&lt;/p&gt;
&lt;p&gt;The Supreme Court of the United States reached a comparable conclusion in &lt;a href=&#34;https://www.supremecourt.gov/opinions/17pdf/16-402_h315.pdf&#34;&gt;Carpenter v. United States&lt;/a&gt;, 585 U.S. 296 (2018). It stressed a point American scholarship has commented on at length: the &lt;strong&gt;inescapable and automatic&lt;/strong&gt; nature of that collection. Nobody consents to being attached to a cell tower; you are attached because you own a phone that is switched on.&lt;/p&gt;
&lt;p&gt;The legal interest therefore exists, and it is recognised by the two courts that matter in this field. The problem lies elsewhere.&lt;/p&gt;
&lt;h2 id=&#34;what-5g-actually-changed&#34;&gt;What 5G actually changed&lt;/h2&gt;
&lt;p&gt;A common confusion treats location as data the phone transmits, in the same way as a message or a photograph. It is not. Location is a &lt;strong&gt;physical consequence of how the network works&lt;/strong&gt;. The operator knows which tower the device is attached to because it has to know in order to route a call. There is no key with which to encrypt that information, because it is not content but a property of the connection itself.&lt;/p&gt;
&lt;p&gt;That is precisely what makes 5G significant in legal terms rather than technical ones.&lt;/p&gt;
&lt;p&gt;Earlier architectures relied on wide cells. A 4G tower commonly serves a radius of several kilometres, and the position inferred from attachment alone was measured in hundreds of metres in cities, sometimes in tens of kilometres in rural areas. 5G rests on massive densification: urban cells typically cover a few hundred metres, and the engineering literature works with densities on the order of forty to fifty base stations per square kilometre, against four or five in the 3G era.&lt;/p&gt;
&lt;p&gt;The consequence is mechanical. According to &lt;a href=&#34;https://www.ericsson.com/en/reports-and-papers/white-papers/5g-positioning&#34;&gt;Ericsson&amp;rsquo;s white paper on 5G positioning&lt;/a&gt;, infrastructure deployed for connectivity alone reaches an accuracy of twenty to fifty metres outdoors and one to three metres indoors, dropping below a metre in favourable urban conditions. This is not a location feature switched on somewhere, but what the network knows by construction, with no application installed and no permission granted. We set out all of these mechanisms, along with the countermeasures that actually work, in our article on &lt;a href=&#34;https://arpokrat.com/blog/how-your-phone-tracks-your-location/&#34;&gt;how your phone tracks your location&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The intrusion has therefore grown by several orders of magnitude. The applicable legal framework remains the one designed for 2G and 3G. No normative adjustment has accompanied that change of scale.&lt;/p&gt;
&lt;h2 id=&#34;the-law-protects-access-not-generation&#34;&gt;The law protects access, not generation&lt;/h2&gt;
&lt;p&gt;European law carefully regulates who may access location data, on what conditions and under what supervision. Directive 2002/58/EC lays down the principle of confidentiality of communications, and the Court of Justice held, in &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62018CJ0511&#34;&gt;La Quadrature du Net&lt;/a&gt; (joined cases C-511/18, C-512/18 and C-520/18, Grand Chamber, 6 October 2020), that Article 15(1) of that directive, read in the light of Articles 7, 8, 11 and 52(1) of the Charter, precludes the &lt;strong&gt;general and indiscriminate retention&lt;/strong&gt; of traffic and location data on a preventive basis. The Court nonetheless allowed framed derogations where a Member State faces a serious threat to national security that is genuine and present or foreseeable, subject to effective review.&lt;/p&gt;
&lt;p&gt;These are real protections, and it would be absurd to play them down. But they all come into play after the fact. They presuppose that the data exists and is retained, and then organise the conditions of its use.&lt;/p&gt;
&lt;p&gt;Yet if location is an unavoidable by-product of how the network operates, the relevant point of intervention is not confidentiality. It is &lt;strong&gt;persistence&lt;/strong&gt;.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;An instantaneous position, needed to route a communication and erased immediately afterwards, is not an instrument of surveillance. A history of positions kept for months is one, whatever access safeguards surround it.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The difference between the two is not legal, it is architectural. And the European timetable makes the question urgent rather than theoretical. The Commission &lt;a href=&#34;https://edri.org/our-work/the-eprivacy-regulation-proposal-has-been-withdrawn-but-the-fight-for-your-privacy-is-far-from-over/&#34;&gt;withdrew the proposed ePrivacy Regulation&lt;/a&gt; in 2025, for lack of agreement between the co-legislators. It has since been working on a separate instrument on data retention for criminal purposes, &lt;a href=&#34;https://www.heise.de/en/news/Data-Retention-Commission-to-present-proposal-by-mid-2026-11101430.html&#34;&gt;announced for 2026&lt;/a&gt; and intended to harmonise national regimes that have grown disparate since the 2006 directive was annulled. In other words, the text that will set the regime for location metadata for a decade is being written right now, on the basis of reasoning conceived in the era of kilometre-wide cells.&lt;/p&gt;
&lt;h2 id=&#34;the-precedent-5g-created-for-itself&#34;&gt;The precedent 5G created for itself&lt;/h2&gt;
&lt;p&gt;The most interesting aspect of the file is that the right answer is already in the technical standard, but applied to a different object.&lt;/p&gt;
&lt;p&gt;Up to 4G, the subscriber&amp;rsquo;s permanent identifier, the &lt;strong&gt;IMSI&lt;/strong&gt;, travelled in the clear over the radio interface during attachment. That is what made &lt;strong&gt;IMSI catchers&lt;/strong&gt; possible, those fake base stations which, according to the &lt;a href=&#34;https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks&#34;&gt;Electronic Frontier Foundation&amp;rsquo;s reference description&lt;/a&gt;, transmit more strongly than legitimate towers in order to attract handsets and capture their identifier.&lt;/p&gt;
&lt;p&gt;Since Release 15 of the 3GPP specifications, published in 2019, 5G has offered an elegant answer. The permanent identifier, now called the &lt;strong&gt;SUPI&lt;/strong&gt;, can be replaced on the radio interface by the &lt;strong&gt;SUCI&lt;/strong&gt;, a concealed identifier obtained by encrypting the subscriber-specific part using elliptic curve cryptography, with the home operator&amp;rsquo;s public key. Only the home network, which holds the corresponding private key, can decrypt it. The result is unique on each computation, which prevents correlation from one session to the next.&lt;/p&gt;
&lt;p&gt;The logic adopted deserves to be underlined, because it is exactly the logic that should guide lawmakers: you do not encrypt the position, which would be technically impossible, you encrypt the identity. A position with no attachable identity has very limited value for individualised surveillance.&lt;/p&gt;
&lt;h3 id=&#34;the-flaw-an-optional-protection&#34;&gt;The flaw: an optional protection&lt;/h3&gt;
&lt;p&gt;There is, however, a considerable caveat, and in our view it is the most concrete point of intervention in the whole file.&lt;/p&gt;
&lt;p&gt;The &lt;a href=&#34;https://doi.org/10.6028/NIST.CSWP.36A&#34;&gt;NIST CSWP 36A white paper&lt;/a&gt;, published in March 2026 by the National Institute of Standards and Technology, states it bluntly. Handsets and network functions compliant with Release 15 or later are required to &lt;strong&gt;support&lt;/strong&gt; the SUCI, but enabling it remains &lt;strong&gt;optional for the operator&lt;/strong&gt;. Three conditions must be met: the equipment vendor must support it, the operator must enable it on its network, and the SIM card must carry the elements needed for the computation.&lt;/p&gt;
&lt;p&gt;A configuration trap comes on top of that. The standard provides for a &lt;strong&gt;null protection scheme&lt;/strong&gt;, in which the SUCI format is formally used but without effective encryption, so that the identifier travels in the clear. NIST writes that operators need to configure their networks with a non-null protection scheme, and recalls that a report by CSRIC, the advisory body of the Federal Communications Commission, recommended as early as 2021 that the null scheme be reserved for emergency calls placed by a handset unknown to the network.&lt;/p&gt;
&lt;p&gt;The formulation is worth stating plainly. The best available protection against mobile device tracking has existed in the technical standard since 2019. It rests on a configuration choice left to the operator&amp;rsquo;s discretion. An American federal agency finds it useful to publish a document in 2026 to remind everyone that it ought to be switched on. And no European legal instrument requires it.&lt;/p&gt;
&lt;p&gt;It should be added that the SUCI does not close the subject. The work presented under the title &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3448300.3467826&#34;&gt;5G SUCI-catchers: still catching them all?&lt;/a&gt; documents linkability attacks that allow sessions to be recorrelated despite the encryption, and the protection falls entirely if the attacker forces the handset to downgrade to an earlier generation. A legal obligation would therefore not settle everything. It would nonetheless remove a gap with no defensible justification: the one between what the standard allows and what commercial networks do.&lt;/p&gt;
&lt;h2 id=&#34;three-coherent-interventions&#34;&gt;Three coherent interventions&lt;/h2&gt;
&lt;p&gt;If we take seriously the idea that location should be minimised by design rather than protected after the fact, three measures follow logically.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Make effective concealment of the identifier mandatory.&lt;/strong&gt; Require the SUCI to be enabled and prohibit null protection schemes on commercial networks, apart from the residual case of emergency calls. This is not about prescribing a new technology, or funding a rollout, but about requiring the activation of a function standardised seven years ago and already present in the equipment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Treat retention as the exception, not the default.&lt;/strong&gt; The position needed to route a communication should be erased as soon as that function is fulfilled. Building a history should call for specific justification. That is the difference between a network that knows where you are and a network that remembers where you have been.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Make custody of the key the relevant connecting factor.&lt;/strong&gt; Locating servers in the Union does not mean much if the keys that make the data intelligible are held elsewhere. The legally significant criterion should be effective control of the means of decryption, a question we examined in detail in relation to the &lt;a href=&#34;https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/&#34;&gt;conflict between the Data Act and the CLOUD Act&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;the-angle-arpokrat-follows&#34;&gt;The angle Arpokrat follows&lt;/h2&gt;
&lt;p&gt;This reasoning is not specific to telecommunications law. It is the one we apply to our own architectural choices, and it fits in a sentence: what has not been produced does not need to be protected.&lt;/p&gt;
&lt;p&gt;That is why &lt;a href=&#34;https://arpokrat.com/os/&#34;&gt;ArpokratOS&lt;/a&gt; removes GPS, Bluetooth and NFC at kernel level rather than disabling them in a menu. A switch is a policy: it can be bypassed by a privileged component, re-enabled by an update, ignored by a compromised system. Removing the code path removes the question. It is the transposition, at device scale, of the same shift we are calling for at the scale of the law: intervening on generation rather than on access.&lt;/p&gt;
&lt;p&gt;It must be said straight away what this does not do. No operating system removes a handset from the geometry of the network. As long as a SIM card is active, the operator knows the serving cell, and routing all traffic through Tor changes nothing, since it protects content and destination, not the radio layer. That is precisely why the subject is a legal one. There is a category of risks that no individual configuration reduces, and for which the only available variable is the rule applicable to the operator.&lt;/p&gt;
&lt;p&gt;The same concern governs the rest of our work. Data that does not exist cannot be requisitioned, resold, exfiltrated, or decrypted ten years from now by a machine nobody has today, a question we addressed from the angle of &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;encryption harvested now and broken later&lt;/a&gt;.&lt;/p&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;Public debate on mobile surveillance focuses almost exclusively on access: who can consult the data, on what basis, with what authorisation. That debate is legitimate, and the rulings handed down by the Court of Justice since 2014 have had tangible effects. But it comes too late in the chain.&lt;/p&gt;
&lt;p&gt;The prior and more decisive question is whether the history should exist at all. A database built today for a legitimate purpose remains available tomorrow for another, and the safeguards around it depend on later political decisions that nobody controls at the moment of collection. It is a bet on the stability of institutions, made for a period nobody sets.&lt;/p&gt;
&lt;p&gt;5G has multiplied the resolution of this information without any normative adjustment. It has simultaneously shown, through the SUCI mechanism, that the workable path is to dissociate position from identity rather than attempt to encrypt a physical property of the network. The technical standard supplied the answer seven years before the law asked the question.&lt;/p&gt;
&lt;p&gt;The European text on data retention is being written now. It will deal with metadata, therefore with location, therefore with what 5G now produces at a granularity its drafters never knew. Whether it will settle for organising access to a history taken for granted, or dare to question the necessity of that history, is probably the most important privacy question of the coming years in Europe. And it is a question the technical sector, for once, has already settled the right way.&lt;/p&gt;
&lt;h2 id=&#34;sources&#34;&gt;Sources&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Court of Justice of the European Union, &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62012CJ0293&#34;&gt;Digital Rights Ireland&lt;/a&gt;, joined cases C-293/12 and C-594/12, 8 April 2014&lt;/li&gt;
&lt;li&gt;Court of Justice of the European Union, &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62015CJ0203&#34;&gt;Tele2 Sverige and Watson&lt;/a&gt;, joined cases C-203/15 and C-698/15, Grand Chamber, 21 December 2016&lt;/li&gt;
&lt;li&gt;Court of Justice of the European Union, &lt;a href=&#34;https://eur-lex.europa.eu/legal-content/FR/TXT/?uri=CELEX:62018CJ0511&#34;&gt;La Quadrature du Net and Others&lt;/a&gt;, joined cases C-511/18, C-512/18 and C-520/18, Grand Chamber, 6 October 2020&lt;/li&gt;
&lt;li&gt;Supreme Court of the United States, &lt;a href=&#34;https://www.supremecourt.gov/opinions/17pdf/16-402_h315.pdf&#34;&gt;Carpenter v. United States&lt;/a&gt;, 585 U.S. 296, 2018&lt;/li&gt;
&lt;li&gt;National Institute of Standards and Technology, &lt;a href=&#34;https://doi.org/10.6028/NIST.CSWP.36A&#34;&gt;Protecting Subscriber Identifiers with Subscription Concealed Identifier (SUCI)&lt;/a&gt;, NIST CSWP 36A, March 2026&lt;/li&gt;
&lt;li&gt;Ericsson, &lt;a href=&#34;https://www.ericsson.com/en/reports-and-papers/white-papers/5g-positioning&#34;&gt;5G positioning: Locating devices anywhere&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Merlin Chlosta et al., &lt;a href=&#34;https://dl.acm.org/doi/10.1145/3448300.3467826&#34;&gt;5G SUCI-catchers: still catching them all?&lt;/a&gt;, ACM WiSec, 2021&lt;/li&gt;
&lt;li&gt;Electronic Frontier Foundation, &lt;a href=&#34;https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networks&#34;&gt;Gotta Catch &amp;lsquo;Em All: Understanding How IMSI-Catchers Exploit Cell Networks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;European Digital Rights, &lt;a href=&#34;https://edri.org/our-work/the-eprivacy-regulation-proposal-has-been-withdrawn-but-the-fight-for-your-privacy-is-far-from-over/&#34;&gt;The ePrivacy Regulation proposal has been withdrawn, but the fight for your privacy is far from over&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;heise online, &lt;a href=&#34;https://www.heise.de/en/news/Data-Retention-Commission-to-present-proposal-by-mid-2026-11101430.html&#34;&gt;Data Retention: Commission to present proposal by mid-2026&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</description>
    </item>
    <item>
      <title>Data Act vs CLOUD Act: who really controls your data in the cloud?</title>
      <link>https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/</link>
      <pubDate>Fri, 19 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/data-act-vs-cloud-act-digital-sovereignty/</guid>
      <description>&lt;p&gt;For years, the world operated on a simple assumption: data has a physical place of residence. If it was stored on a server in Dublin, it fell under Irish and European law. That assumption collapsed in 2018, when the United States enacted the CLOUD Act — a law that grants American authorities access to data controlled by US companies, regardless of where that data is physically stored in the world. Several years later, Brussels responded with its own protective framework: the Data Act, now fully applicable, which attempts to limit the extraterritorial access of third-country authorities to data held within the European Union.&lt;/p&gt;
&lt;p&gt;Here is what these two texts actually provide, where they collide, and why the only truly robust protection against this conflict remains technical impossibility of access.&lt;/p&gt;
&lt;h2 id=&#34;the-american-cloud-act-access-based-on-control-not-location&#34;&gt;The American CLOUD Act: access based on control, not location&lt;/h2&gt;
&lt;p&gt;The &lt;strong&gt;CLOUD Act&lt;/strong&gt; (&lt;em&gt;Clarifying Lawful Overseas Use of Data Act&lt;/em&gt;), enacted in March 2018, amended US law by adding &lt;strong&gt;18 U.S. Code § 2713&lt;/strong&gt;. This provision requires any provider of electronic communication services or remote computing services to preserve, back up, or disclose the contents of a communication or any record pertaining to it, whenever that data is in the provider&amp;rsquo;s possession, custody, or control, &lt;strong&gt;regardless of whether the data is located inside or outside the United States&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;It is precisely this final clause that changes everything. The criterion is no longer the physical location of the server, but the control exercised by the parent company over its subsidiaries. A US company operating data centres in Europe therefore remains subject to American legal demands, even for data stored entirely on European soil.&lt;/p&gt;
&lt;h2 id=&#34;the-european-data-act-a-legal-barrier-to-extraterritorial-access&#34;&gt;The European Data Act: a legal barrier to extraterritorial access&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Regulation (EU) 2023/2854&lt;/strong&gt;, known as the Data Act, entered into force on 11 January 2024 and has been fully applicable since 12 September 2025, with certain provisions phased in through 2026 and 2027. Its &lt;strong&gt;Article 32&lt;/strong&gt; directly addresses the question of international governmental access to data.&lt;/p&gt;
&lt;p&gt;The text establishes a clear rule: any decision or judgment of a court or administrative authority of a third country requiring a data processing service provider to transfer or give access to non-personal data held in the European Union &lt;strong&gt;is recognised and enforceable only if it is based on an international agreement&lt;/strong&gt;, such as a mutual legal assistance treaty (MLAT), in force between the requesting country and the Union, or between that country and the relevant Member State.&lt;/p&gt;
&lt;p&gt;In the absence of such an agreement, Article 32 provides a second avenue, but one that is strictly circumscribed: the foreign decision may only be enforced if the legal system of the third country requires that the request be reasoned, proportionate, and sufficiently specific — for example, by establishing a clear link to specific individuals or offences — and if the recipient&amp;rsquo;s reasoned objection can be submitted to the review of a competent court in that third country.&lt;/p&gt;
&lt;h2 id=&#34;a-direct-legal-collision&#34;&gt;A direct legal collision&lt;/h2&gt;
&lt;p&gt;The problem is immediate: the CLOUD Act requires disclosure based on the control exercised by the parent company, without a proportionality requirement comparable to that demanded by European law. The Data Act, conversely, conditions recognition of such a request on the existence of an international agreement or specific procedural safeguards. A US company operating in Europe, ordered by an American authority to hand over data hosted within the Union, thus finds itself caught between two contradictory legal obligations: comply with the American mandate and violate Union law, or respect the Data Act and face the consequences of refusal in the United States.&lt;/p&gt;
&lt;p&gt;This tension is not theoretical. It has already been documented by the Court of Justice of the European Union (CJEU) in two landmark rulings, &lt;strong&gt;Schrems I&lt;/strong&gt; (2015) and &lt;strong&gt;Schrems II&lt;/strong&gt; (2020). In the Schrems II judgment, the CJEU held that American surveillance conducted under &lt;strong&gt;Section 702 of FISA&lt;/strong&gt; (&lt;em&gt;Foreign Intelligence Surveillance Act&lt;/em&gt;) and &lt;strong&gt;Executive Order 12333&lt;/strong&gt; does not respect the minimum safeguards required by Union law under the principle of proportionality, and therefore cannot be regarded as limited to what is strictly necessary. The Court also noted the absence of an effective judicial remedy for Union data subjects, in violation of Article 47 of the Charter of Fundamental Rights. This ruling invalidated the Privacy Shield framework, which had until then governed data transfers between the EU and the United States.&lt;/p&gt;
&lt;h2 id=&#34;the-structural-risk-harvest-now-decrypt-later&#34;&gt;The structural risk: Harvest Now, Decrypt Later&lt;/h2&gt;
&lt;p&gt;Beyond the jurisdictional conflict, a more insidious threat looms over data hosted in infrastructures subject to US law: the so-called &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;&lt;strong&gt;Harvest Now, Decrypt Later&lt;/strong&gt;&lt;/a&gt; (HNDL) strategy. The principle involves an intelligence service or hostile state actor intercepting and storing encrypted data today, in anticipation of sufficient quantum computing capabilities to decrypt it in the future.&lt;/p&gt;
&lt;p&gt;This strategy transforms any prolonged dependence on American cloud infrastructure into a deferred security liability: what is confidential today may become readable in ten or fifteen years, without any further action required on the part of the attacker — only time and patience.&lt;/p&gt;
&lt;h2 id=&#34;why-only-technical-impossibility-constitutes-a-genuine-guarantee&#34;&gt;Why only technical impossibility constitutes a genuine guarantee&lt;/h2&gt;
&lt;p&gt;Legal analysis converges on a finding shared by many compliance experts: however solid the Data Act&amp;rsquo;s legal framework may be, it remains a text that geopolitical power dynamics and diplomatic pressures can circumvent, delay, or reinterpret. The only protection that depends on no future negotiation is &lt;strong&gt;technical impossibility of enforcement&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;A &lt;strong&gt;zero knowledge&lt;/strong&gt; architecture, in which the service provider never holds possession or custody of the decryption keys, renders a legal demand materially inoperable. One cannot be compelled to hand over what one never possesses.&lt;/p&gt;
&lt;p&gt;This is the logic that underpins ecosystems such as &lt;strong&gt;Arpokrat&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Jurisdictional neutralisation&lt;/strong&gt;: the infrastructure is hosted in Switzerland, under the Swiss Federal Act on Data Protection (FADP/LPD), outside the direct scope of the CLOUD Act&amp;rsquo;s extraterritoriality&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No custody&lt;/strong&gt;: the zero knowledge architecture deprives the service provider of any ability to hand over keys or content it never holds&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reduced identity footprint&lt;/strong&gt;: by eliminating the requirement to register with a phone number or email address — identifiers that FISA Section 702-based surveillance can easily track — the user ceases to be an identifiable subscriber and becomes an anonymous cryptographic key&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&#34;the-chain-of-custody-does-not-stop-at-message-encryption&#34;&gt;The chain of custody does not stop at message encryption&lt;/h2&gt;
&lt;p&gt;A point often underestimated in compliance analyses: encrypting the content of a communication is not enough if the underlying operating system — whether Android or iOS — continues to capture metadata or kernel-level telemetry destined for servers under US jurisdiction. Protecting confidentiality requires a complete closure of the chain of custody, from content all the way down to the hardware infrastructure itself.&lt;/p&gt;
&lt;p&gt;This is why digital sovereignty also requires reflection on the operating system in use, not just on messaging applications. De-Googled systems, in which modules such as Bluetooth or GNSS geolocation can be disabled directly at the kernel level, eliminate physical attack vectors that no application-layer encryption can compensate for.&lt;/p&gt;
&lt;h2 id=&#34;post-quantum-cryptography-an-already-engaged-horizon&#34;&gt;Post-quantum cryptography: an already-engaged horizon&lt;/h2&gt;
&lt;p&gt;In the face of the threat posed by the HNDL strategy, adopting post-quantum cryptography (PQC) standards becomes a necessity for anyone wishing to guarantee the confidentiality of sensitive data over the long term — whether that involves trade secrets, professional correspondence, or health data. Encryption considered robust today under classical standards does not guarantee that it will withstand the quantum computing capabilities expected within the next fifteen years.&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;The conflict between the Data Act and the CLOUD Act illustrates a broader reality: digital sovereignty can no longer be built on legislation alone, however solid that legislation may be. It requires closing the chain of custody at every level — from the encryption protocol to the hosting jurisdiction, and including the operating system itself. It is this layered approach, rather than trust placed in a single regulatory framework, that defines genuine digital sovereignty by design today.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>The End of Privacy? Backdoors, the Online Safety Act, and the Response of Sovereign Ecosystems</title>
      <link>https://arpokrat.com/blog/ipa-osa-backdoors/</link>
      <pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/ipa-osa-backdoors/</guid>
      <description>&lt;p&gt;London has become the epicenter of a global battle for the future of digital privacy. With the adoption of the &lt;em&gt;Online Safety Act&lt;/em&gt; 2023 (OSA) and recent proposals to revise the &lt;em&gt;Investigatory Powers Act&lt;/em&gt; (IPA) — dubbed the &amp;ldquo;Snoopers&amp;rsquo; Charter&amp;rdquo; by its critics —, the British government is claiming the right to impose surveillance obligations at the very heart of private communications. The breaking point is the power granted to the regulator OFCOM to require platforms to deploy &amp;ldquo;accredited technology&amp;rdquo; to detect child sexual exploitation and abuse (CSEA) material or terrorism, including within &lt;a href=&#34;https://arpokrat.com/messenger&#34;&gt;end-to-end encrypted communications&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For major digital platforms, Westminster&amp;rsquo;s message is unambiguous: either they facilitate state access to their infrastructures, or they face fines of up to 10% of their global revenue. The response was immediate: services like Signal and WhatsApp publicly threatened to withdraw from the UK market, refusing to compromise the security of their users to satisfy a single jurisdiction. The technical argument is hard to dispute: there is no master key reserved solely for legitimate actors. An open door for law enforcement is, by design, an open door for cybercriminals and foreign intelligence services.&lt;/p&gt;
&lt;h2 id=&#34;the-business-model-of-major-platforms-a-structural-obstacle-to-zero-knowledge&#34;&gt;The business model of major platforms: a structural obstacle to Zero-Knowledge&lt;/h2&gt;
&lt;p&gt;The resistance of major platforms to adopting Zero-Knowledge encryption is not explained by technical inability, but by a fundamental economic incompatibility. Companies like Alphabet and Meta rely on monetization models based on the systematic collection of behavioral data. This model is, incidentally, implicitly recognized by the European Union&amp;rsquo;s Digital Markets Act (DMA), which classifies these &amp;ldquo;gatekeepers&amp;rdquo; as entities whose dominant position is precisely fueled by the accumulation of data on an unparalleled scale. For these actors, adopting a Zero-Knowledge architecture would mean depriving their advertising systems of the continuous identification of users that constitutes its fuel. It is therefore not a technical choice, but a trade-off between user privacy and the viability of their business model.&lt;/p&gt;
&lt;h2 id=&#34;the-strategic-risk-the-harvest-now-decrypt-later-threat&#34;&gt;The strategic risk: the &amp;ldquo;Harvest Now, Decrypt Later&amp;rdquo; threat&lt;/h2&gt;
&lt;p&gt;Beyond the debate on privacy, the weakening of encryption raises a national security issue of a completely different scope. The strategy known as &lt;a href=&#34;https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/&#34;&gt;&lt;em&gt;Harvest Now, Decrypt Later&lt;/em&gt; (HNDL)&lt;/a&gt; involves state adversaries intercepting and storing massive volumes of encrypted communications today, in anticipation of future quantum decryption capabilities. By weakening current encryption standards, the British legislative framework objectively facilitates this type of operations against government, diplomatic, or industrial communications.&lt;/p&gt;
&lt;p&gt;It is precisely in this context of a trust deficit that ecosystems like Arpokrat&amp;rsquo;s acquire operational relevance. By operating under the regime of the Swiss Federal Act on Data Protection (FADP), with an architecture that collects no civil identifiers, Arpokrat offers a technical break from infrastructures subject to British jurisdiction — guaranteeing that the system remains deaf to the injunctions foreseen by the OSA.&lt;/p&gt;
&lt;h2 id=&#34;the-conflict-of-norms-osa-and-ipa-against-european-law&#34;&gt;The conflict of norms: OSA and IPA against European law&lt;/h2&gt;
&lt;p&gt;The legal analysis of the new British state prerogatives reveals a direct collision with the foundations of European law regarding data protection and the confidentiality of communications.&lt;/p&gt;
&lt;h3 id=&#34;osa-against-the-prohibition-of-generalized-surveillance&#34;&gt;OSA against the prohibition of generalized surveillance&lt;/h3&gt;
&lt;p&gt;Article 121 of the OSA introduces the possibility for OFCOM to issue notices forcing platforms to implement client-side scanning. This measure directly contravenes the principle, derived from European law and included in the jurisprudence of the CJEU, prohibiting general surveillance obligations. By imposing a &amp;ldquo;vulnerability by design&amp;rdquo;, it also places companies in a double bind situation: by weakening their security to comply with a state mandate, they fail in their obligation to guarantee a level of security appropriate to the processing, as enshrined in Article 32 of the GDPR.&lt;/p&gt;
&lt;h3 id=&#34;the-eprivacy-directive-and-the-confidentiality-of-communications&#34;&gt;The ePrivacy Directive and the confidentiality of communications&lt;/h3&gt;
&lt;p&gt;The scanning of private messages is in direct contradiction with Article 5, paragraph 1, of Directive 2002/58/EC (&lt;em&gt;ePrivacy&lt;/em&gt;), which obliges Member States to guarantee the confidentiality of electronic communications and prohibits any form of interception or surveillance without the explicit consent of the users concerned.&lt;/p&gt;
&lt;h3 id=&#34;technical-capability-notices-and-blocking-security-updates&#34;&gt;&lt;em&gt;Technical Capability Notices&lt;/em&gt; and blocking security updates&lt;/h3&gt;
&lt;p&gt;Under the IPA 2016 regime, the British government now intends to use &lt;em&gt;Technical Capability Notices&lt;/em&gt; (TCN) to block security updates before they are deployed. This mechanism creates an unsolvable conflict with the obligation, set by Article 32 of the GDPR, to ensure the continuous security of processing systems — an obligation that precisely requires the ability to apply patches without delay or external interference.&lt;/p&gt;
&lt;h2 id=&#34;compliance-risks-for-companies-operating-in-europe&#34;&gt;Compliance risks for companies operating in Europe&lt;/h2&gt;
&lt;p&gt;The revisions to the IPA aim to force companies to notify the British government of any technical modification affecting security, prior to its implementation, thereby granting it a veto right over product development. This interference creates considerable legal insecurity for suppliers operating in the European market: British adequacy to European law — already fragile — could be called into question if the UK no longer guarantees protection substantially equivalent to that of the GDPR. Data transfers to the UK under this new framework would therefore likely expose companies to sanctions under the GDPR.&lt;/p&gt;
&lt;h2 id=&#34;defense-through-technical-impossibility-the-zero-knowledge-principle-as-a-legal-shield&#34;&gt;Defense through technical impossibility: the Zero-Knowledge principle as a legal shield&lt;/h2&gt;
&lt;p&gt;International jurisprudence, consolidated by the &lt;em&gt;Schrems I&lt;/em&gt; and &lt;em&gt;Schrems II&lt;/em&gt; rulings of the CJEU, has established a defining principle: the only robust safeguard against disproportionate surveillance is the technical impossibility of accessing it. Zero-Knowledge architectures apply this principle in three layers of protection:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;&lt;strong&gt;Absence of custody:&lt;/strong&gt; since the platform does not hold the decryption keys, any injunction to scan messages is technically inoperative;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Sovereignty of the operating system:&lt;/strong&gt; the control of &lt;a href=&#34;https://arpokrat.com/os&#34;&gt;ArpokratOS&lt;/a&gt; eliminates telemetry that feeds intelligence collection at the device level;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Swiss jurisdictional anchoring:&lt;/strong&gt; by hosting its infrastructure in Switzerland, Arpokrat operates under a legal regime requiring individualized and reasoned mutual legal assistance requests, neutralizing the automated execution of mass scans foreseen by the OSA.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&#34;conclusion&#34;&gt;Conclusion&lt;/h2&gt;
&lt;p&gt;The provisions of the OSA and the revisions of the IPA are not only a threat to the privacy of individuals: they represent a breach of legal certainty for all European data passing through infrastructures subject to British jurisdiction. By legitimizing the weakening of encryption in the name of public safety, London paradoxically exposes its allies and trading partners to risks of industrial and state espionage that Zero-Knowledge architectures are precisely designed to prevent.&lt;/p&gt;
&lt;p&gt;The integrity of professional and institutional communications now requires a structural response: the migration towards decentralized ecosystems guaranteeing digital sovereignty, from the code level up to the jurisdictional anchoring.&lt;/p&gt;
</description>
    </item>
    <item>
      <title>The Time Bomb: Harvest Now, Decrypt Later and the Zero-Knowledge Imperative</title>
      <link>https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/</link>
      <pubDate>Tue, 26 May 2026 00:00:00 +0000</pubDate>
      <guid>https://arpokrat.com/blog/harvest-now-decrypt-later-hndl-zero-knowledge/</guid>
      <description>&lt;p&gt;The dependence of European governments on American cloud infrastructure poses more than just an immediate interception problem. The great revelation, the most devastating threat for decades to come, is what intelligence specialists call the &lt;strong&gt;&lt;a href=&#34;https://en.wikipedia.org/wiki/Harvest_now,_decrypt_later&#34;&gt;HNDL: &amp;ldquo;Harvest Now, Decrypt Later&amp;rdquo;&lt;/a&gt;&lt;/strong&gt; strategy.&lt;/p&gt;
&lt;p&gt;This is not a frontal intrusion, but a silent theft. Intelligence agencies and state adversaries are intercepting and storing immense amounts of encrypted data today, simply because the cost of storage has become negligible.&lt;/p&gt;
&lt;p&gt;They wait patiently for the moment when technological leaps and the unpredictable evolution of computing power will render current cryptographic keys obsolete. What constitutes a protected state secret in 2026 could become an open book in fifteen or twenty years.&lt;/p&gt;
&lt;h2 id=&#34;retroactive-liability-and-temporal-risk&#34;&gt;Retroactive Liability and Temporal Risk&lt;/h2&gt;
&lt;p&gt;The HNDL model introduces a novel concept: delayed legal harm. Traditionally, a breach of secrecy is a static event. With the massive collection of data for future decryption, confidentiality becomes a time-dependent variable.&lt;/p&gt;
&lt;p&gt;To quantify this risk, the HNDL scientific model defines that confidentiality inevitably fails when the required lifespan of the secret exceeds the adversary&amp;rsquo;s decryption horizon. Sectors of critical exposure are currently in a state of latent vulnerability.&lt;/p&gt;
&lt;p&gt;If a state or an organization does not guarantee the absolute sovereignty of its hardware infrastructure, it is practically signing a waiver of long-term confidentiality for its citizens and institutions.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Today&amp;rsquo;s interception is tomorrow&amp;rsquo;s compromise. Turning cloud dependence into a national security debt is a gamble impossible to repay.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id=&#34;the-arpokrat-antithesis-legal-impossibility-by-code&#34;&gt;The Arpokrat Antithesis: Legal Impossibility by Code&lt;/h2&gt;
&lt;p&gt;Faced with this vulnerability, the industry is responding by creating &lt;a href=&#34;https://arpokrat.com/&#34;&gt;radical digital sovereignty ecosystems&lt;/a&gt;. The Arpokrat model emerges as the perfect antithesis to centralized messaging: this architecture operates on a decentralized network, protected by the very strict &lt;a href=&#34;https://www.edoeb.admin.ch/en/basic-knowledge&#34;&gt;Federal Act on Data Protection (FADP) in Switzerland&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;The core logic is one of absolute &lt;em&gt;Privacy by Design&lt;/em&gt;. By removing the need to provide a phone number, the user becomes a simple cryptographic key, devoid of physical identity.&lt;/p&gt;
&lt;p&gt;Legally, this drastically changes the rules of the game. If the &lt;a href=&#34;https://arpokrat.com/infrastructure&#34;&gt;architecture is fundamentally Zero-Knowledge&lt;/a&gt; and non-custodial, the company faces a technical impossibility to comply with foreign warrants.&lt;/p&gt;
&lt;p&gt;This is not civil disobedience against extraterritorial laws, but an unstoppable mathematical and legal safeguard: &lt;strong&gt;what you do not hold cannot be disclosed.&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id=&#34;beyond-encryption-devaluing-the-target-data&#34;&gt;Beyond Encryption: Devaluing the Target Data&lt;/h2&gt;
&lt;p&gt;The true response, natively integrated into the &lt;a href=&#34;https://arpokrat.com/messenger&#34;&gt;Arpokrat messaging app&lt;/a&gt;, is not to bet on eternal mathematics, but to &lt;strong&gt;devalue the data itself&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Without central metadata, without phone numbers, and without IP logs to link a message to a physical individual, the encrypted content loses its strategic value because it becomes unattributable.&lt;/p&gt;
&lt;p&gt;However, software alone can do nothing if the hardware betrays it upstream.&lt;/p&gt;
&lt;p&gt;Ultimately, security in the 21st century requires the independence of the machine itself. Deploying a &lt;a href=&#34;https://arpokrat.com/os&#34;&gt;sovereign de-Googled OS&lt;/a&gt; has become an absolute survival requirement for anyone handling state secrets.&lt;/p&gt;
</description>
    </item>
  </channel>
</rss>