More Security, Less Freedom? The Debate Over New Powers

  • New powers for the police and intelligence services are usually justified on the grounds of greater security—which initially sounds hard to argue with. At the same time, experience shows that what is intended as an exception today can become a standard tool surprisingly quickly tomorrow. And then someone, somewhere, explains that it was all “within the legal framework.”

    Where do you think the line should be drawn? Is increased surveillance and data retention justified if they can prevent terrorist attacks or serious crimes—or do the long-term risks to privacy and freedom outweigh the benefits? For me, clear time limits and independent oversight would be especially important. What do you think?

    This post has been automatically translated.

  • It’s always a balancing act. Let’s simply take chat control as an example:

    Chat control refers to planned or temporary EU rules intended to scan digital messages in messaging services and emails for depictions of child sexual abuse.

    At first, that sounds like a very worthwhile goal. However, the way to achieve it is less noble. Here, all internet users are initially placed under general suspicion and their means of communication are searched. This creates the technical foundation for complete surveillance. All it takes is for someone to .... and we’re in deep trouble. Spin it a little further, and we’ve arrived at social scoring.

    I also have security concerns here. If someone snoops around in my data through a backdoor, others will try to use that door as well.

    This post has been automatically translated.

    Ich kaufe ein "F" und möchte lösen: 🔳uck A🔳D!

  • It feels like with every new crisis, the calls for more surveillance, stricter rules, and additional powers grow louder. Understandable—security really is no luxury. At the same time, you often only realize later what remains of the exceptions on a permanent basis—and suddenly the friendly observer is actually standing rather close to the garden gate in everyday life.

    Where do you draw the line between sensible precaution and unnecessary restriction? Should the state, when in doubt, prefer to risk more freedom or create more security, even if that means personal liberties become more limited?

    This post has been automatically translated.

  • For me, the decisive point is not “security or freedom,” but whether a measure demonstrably achieves something and is proportionate. So far, I’m not convinced that chat control meets that standard: A blanket screening of private communications affects millions of people who are not suspected of anything, while criminals can switch to other services. That means a major intrusion for questionable benefits. Targeted measures against specific suspects would make more sense—with judicial authorization rather than a presumption of guilt against everyone.

    And a “legal framework” alone is not sufficient oversight. There needs to be independent supervision, public figures on effectiveness, clear deletion deadlines, and a genuine sunset clause. If authorities can demonstrate that a power prevents hardly anything, it must disappear again. Otherwise, an exception will simply become a permanent foundation for surveillance.

    This post has been automatically translated.

  • Exactly, “demonstrably making a difference” is the sticking point for me too. When new powers are introduced, the potential success is often emphasized, but hardly anyone is honest later about whether the measure achieved little. Public figures, independent reviews, and genuine sunset clauses would be the bare minimum—not just a checkmark in the legislative process.

    And with chat control, the problem of treating everyone as a suspect remains, even if the goal itself is entirely undisputed. Perhaps we should focus much more on well-equipped investigative authorities and targeted proceedings instead of immediately planning a sweeping digital crackdown every time. Otherwise, “only against serious offenders” will eventually turn into “preemptively against everyone” again—the usual story.

    This post has been automatically translated.

  • That “something else…” is precisely the critical point: Once a measure is technically and legally possible, it is rarely rolled back. That is why powers should not merely be time-limited but should automatically expire if the government and authorities cannot substantiate their effectiveness with transparent figures. This also includes error rates: How many hits were actually relevant, and how many completely innocent people were affected?

    I know this from my day-to-day work with IT systems: At first, they say that new logging is only for security, and a few months later it is being used for completely different analyses—because the data is there now. With private communications, this is an entirely different order of magnitude. So why not first better equip the existing investigative and youth welfare structures and take targeted action against known offenders, instead of wanting to technically scrutinize everyone’s communications?

    This post has been automatically translated.

  • …because the data is there, after all. That’s exactly where the supposed exception can quickly turn into a convenient tool for all sorts of things. I think that with powers like these, the burden of proof really ought to lie with the state: not just to explain in advance why they might be necessary, but also to regularly disclose what they have actually achieved and what harm they have caused.

    At our club, a simple access list was introduced once, “just in case of an emergency.” A year later, it was suddenly being used to monitor attendance—small-scale, but the pattern is the same. Automatic expiration, judicial oversight, and clear reports would therefore not be bureaucracy to me, but the safety mechanisms. Who would actually evaluate such powers independently—the agency itself can hardly write its own report card.

    This post has been automatically translated.

  • …and a clear limitation of purpose that must not be weakened afterward through a back door. Especially when it comes to data, “we’ll delete it later” is often not a sufficient guarantee—who actually checks whether it was really deleted? That would require independent oversight bodies with their own resources, not just internal data protection officers who ultimately depend on the same authority.

    I would also make a strict distinction between acute situations involving danger and permanent surveillance instruments. An intervention may be plausible for a specific suspect, but not for millions of people without cause. Which metrics would be binding enough for you to ensure that a power automatically expires—for example, only solved cases, or would the benefit also have to be assessed in relation to false alarms and innocent people affected?

    This post has been automatically translated.

  • When it comes to metrics, I wouldn’t look only at the number of crimes prevented—that can be difficult to prove in case of doubt. The hit rate, number of false alarms, uninvolved people affected, costs, and whether less intrusive means would have been available would also matter. And the audit reports would have to be public, if necessary in an easy-to-understand summary rather than as a 300-page bureaucratic oracle.

    The independent body should also actually be able to verify whether data was deleted and purpose limitations were observed, including sanctions. With our association’s list, it was already difficult enough to get rid of an old Excel file; when it comes to government data, I don’t want to rely on someone eventually finding the right trash can. Perhaps this exact combination would make sense: narrowly defined powers for specific dangers, but a general ban on blanket collection without cause.

    This post has been automatically translated.

  • I don't even want to know how difficult that will be in practice. That's why an audit report alone isn't enough: Those affected should subsequently be able to find out that they were recorded, provided this does not jeopardize ongoing investigations. And violations must have tangible consequences—not just a reprimand in the annual report.

    When it comes to metrics, it would also be important to me that the government not simply claim that it has “prevented attacks” without providing the countervailing figures. If a measure generates thousands of false alarms and is still deemed a success, that's political number-crunching. In my professional experience, I've seen a system with a miserable hit rate continue operating because no one wanted to be responsible for shutting it down. That's exactly why it needs a firm sunset date and a genuine obligation to reassess it—otherwise “temporary” will eventually become permanent.

    This post has been automatically translated.

Participate now!

Don’t have an account yet? Register yourself now and be a part of our community!