An illustration of the EU anti-encryption proposal.

EU’s resolution on encryption foreshadows likely anti-encryption push

Share this page

On Dec. 14, 2020, the Council of the European Union, which is made up of government ministers from the 27 EU member countries, released a vague, five-page resolution that calls for new rules to govern the use of encryption in Europe.

The resolution, titled “The Council Resolution on Encryption(new window),” is non-binding and does not provide any specifics for new laws or regulations and, on the surface, seems fairly innocuous. But it represents a significant shift in tone and puts pressure on the European Commission to propose anti-encryption legislation in the near future.  

This resolution justifies the need for new rules on encryption by stating, “law enforcement is increasingly dependent on access to electronic evidence to effectively fight terrorism, organized crime, child sexual abuse (particularly its online aspects).” It calls on tech companies to find technical ways to bypass encryption so that police and security agencies can quickly access a suspect’s messages or device.

Something must be done to address the blight of pedophiles and terrorists coordinating online, but weakening encryption is not the solution. Pressuring widely used services, like WhatsApp or Proton Mail, to have a backdoor in their encryption would not prevent criminals from creating their own encryption services, as happened in 2019 when it was discovered that drug traffickers had started their own company(new window) adding aftermarket encryption to Android smartphones. Tackling these issues requires increased funding for law enforcement agencies and the adoption of more effective policing policies. 

Not only does weakening encryption fail to address these issues, it is counterproductive. The “technical solutions” this resolution calls for would instead put citizens’ private data at risk, reduce the overall security of the internet, and enable potential government mass surveillance.

What does the resolution say?

This resolution may be non-binding and diplomatically worded, but it is still an attack on encryption. This is not the first time the EU has considered anti-encryption legislation, but previous attempts in 2015(new window) and 2016(new window) floundered in the face of protests by tech companies, academics, and everyday people. This time, the Council of the EU appears to be taking a more subtle approach. There are no clear proposals for how encryption should be treated in this proposal. Instead, it calls for a new legal framework and technical solutions to allow competent authorities to access data in a lawful manner. 

While the resolution does not once mention the word “backdoor,” the “technical and operational solutions” it calls for to provide access to encrypted data are backdoors in all but name. According to the resolution, any technical solution would have to preserve encryption’s security and uphold fundamental human rights. Unfortunately, as appealing as it might sound in theory, there’s simply no way to have it both ways in practice. Once a vulnerability has been built into an encryption system, it is no longer secure. We have made this argument many times, but it continues to be true: There is no such thing as a backdoor that only lets the good guys in

This inconvenient fact also undermines the resolution’s promise that EU authorities will transparently cooperate with tech companies to develop these technical solutions. Security and privacy companies would never accept willingly weakening their technology; Proton certainly wouldn’t. Therefore, it seems more likely that cooperation will someday become coercion. 

If the EU does force tech companies to develop ways to break through their encryption, hackers will not rest until they have discovered and exploited these new vulnerabilities. This has already happened: a group known as the Shadow Brokers(new window) stole zero-day (previously undiscovered) hacks for Windows and the SWIFT international banking system from the NSA. More recently, the cybersecurity firm FireEye was breached(new window), and its tools have been used in hacks.

Therefore, if implemented, this resolution poses a substantial risk to privacy and security, endangers human rights around the world, sets a dangerous precedent, and fundamentally undermines many core European values. 

Does this resolution affect Proton?

This resolution is non-binding. On its own, it does not change the current EU framework but rather points the direction the EU may take in the future. Proton Mail is also protected by Swiss jurisdiction (Switzerland is not a member of the EU). Any request for us to develop a backdoor to Proton Mail under this hypothetical anti-encryption law would need to pass the scrutiny of Switzerland’s strict criminal procedure and data protection laws.

However, as an organization dedicated to protecting the fundamental human right of privacy, we condemn this resolution and the direction the EU seems to be taking. Encryption is a powerful tool to protect privacy, but for the right to privacy to be safe, it must be enshrined in strong privacy laws.

Encryption makes us all safer

The fact the EU seems likely to consider legislation that will backdoor end-to-end encryption is a distressing development for the global state of privacy. Until recently, the EU had been a leader in promoting services, tools, and legislation that protect the privacy of its citizens, but it now risks losing its reputation as a jurisdiction that takes privacy seriously. If the EU continues to go down the path laid out by this proposal, it will be the latest democratic institution to try to undermine its citizens’ privacy, joining Australia(new window), the UK(new window), and the US(new window).

After this past year, policymakers should be pushing for stronger encryption, not backdoors. The Covid-19 pandemic accelerated our society’s shift online, meaning billions of people worldwide now rely on the internet for work, entertainment, and communication. If the internet’s encryption is weakened, it will become easier for hackers to monitor private conversations or steal financial information, which could bring the internet — and the global economy — to a halt.

Encryption helps ordinary citizens preserve their right to privacy in the face of surveillance capitalism, governmental intrusion, and cybercrime. Given that privacy is a requirement for democratic self-government, strong encryption is also essential to a functioning democracy, especially in an age when so much business and communications are conducted online.

As the Council of the EU itself admits in this resolution, “Encryption is a necessary means of protecting fundamental rights and the digital security of governments, industry, and society.” We call on the EU to halt its move toward anti-encryption legislation and return to providing strong legal privacy protections. 

What you can do

If this resolution concerns you, you can sign up for a free email account(new window) with Proton Mail, which is outside the jurisdiction of any potential EU law. This account will also give you access to the free version of Proton VPN(new window), which you can use to encrypt your online browsing.

You can also help by sharing this article in order to raise awareness about this issue. If you are a European who is worried about your right to privacy, you should call or write to your MEP and tell them you are against the Council Resolution on Encryption. By voicing your support for strong encryption, you are fighting for an internet that is secure, private, and free.

UPDATE Jan. 27, 2021: We were not the only European-based end-to-end encrypted service that was alarmed by the EU’s sudden shift against privacy. Along with Threema, Tresorit, and Tutanota, we released a joint statement(new window) calling on the EU to rethink any attacks on end-to-end encryption.

Protect your privacy with Proton
Create a free account

Share this page

Richie Koch

Prior to joining Proton, Richie spent several years working on tech solutions in the developing world. He joined the Proton team to advance the rights of online privacy and freedom.

Related articles

In the public eye, Google presents itself as a champion of privacy. “Privacy is at the heart of everything we do,” its CEO said. But behind closed doors, Google is telling a different story to policymakers and actively fighting against privacy laws
The last thing you want when showing funny videos or holiday photos on your phone or tablet to friends and family is for them to see your sensitive and private photos. Although there are third-party apps dedicated to hiding your personal photos and
It can be slightly difficult to encrypt a zip file using the tools available on your Windows or Mac. Unlike encrypting a PDF or an Excel file, there’s no standardized software to use. You’ll need to rely on your device’s built-in encryption methods.
Last week, the Spanish Presidency of the European Council delayed a vote regarding the Council’s position on the controversial Child Sexual Abuse Regulation (CSAR) due to a lack of consensus over the issue of encryption, among others. This proposed r
At Proton, we’re always working on new and innovative ways to protect the privacy and data of the Proton community. Sometimes that means developing entirely new services, like our Proton Sentinel program, which combines AI and human security analysts
How to unsend an email in Gmail, Outlook, Proton Mail, and Apple Mail
“Undo Send” gives you a chance to stop an erroneous message you’ve just sent. We’ve all done it. You hit Send on an email only to spot you’ve misspelled someone’s name, forgotten an attachment, or accidentally sent a cringing joke to half your conta