So in their infinite wisdom, they replaced it with "Mindestspeicherfristen" / "minimum storage limit" / data retention.
So in their infinite wisdom, they replaced it with "Mindestspeicherfristen" / "minimum storage limit" / data retention.
Here is some reporting on it:
http://translate.google.com/translate?sl=de&tl=en&u=http%3A%...
http://netzpolitik.org/2013/spiegel-online-ente-union-gibt-v... (German)
"But for this change of course to be more than just an election ploy, the government should however advocate a change in the EU Directive in Brussels. Which prescribes a six-month storage of traffic data - and the Union confirms in other parts of its election manifesto that it holds onto the fundamental goal to implement the Directive. "Minimum retention period" is spoken in the Union for two years already - and means nothing but data retention."
https://en.wikipedia.org/wiki/Data_Retention_Directive
This has been in force since 2006. The storage is required by law.
"member states will have to store citizens' telecommunications data for six to 24 months stipulating a maximum time period. Under the directive the police and security agencies will be able to request access to details such as IP address and time of use of every email, phone call and text message sent or received. A permission to access the information will be granted only by a court."
To explain this further, one needs to know how EU legislation works. As it is a supranational state conglomerate, a lot of its legislation is not immediately binding. This is how "EU Directives" differ from "EU Regulations". The latter are directly applicable, binding law. But the Directives need to be realized by EU member states doing legislation of their own. They have some degree of freedom for doing so.
Arguably, Germany didn't have the freedom to not push forward with its own realization of that Directive. However, it is disputed that the Data Retention Directive is actually conforming to EU law - and that was not checked in court yet to its full extent. So the matter is highly political in its nature. The EU Commission, which watches over the implementation of the Directives, is currently in a legal battle over sanctions regarding the non-implementation.
Germany is not alone here, however. Other EU member states postponed an implementation, too.
Though I think, again, the biggest difference is that it did not happen in secrecy but in a open and more democratic manner.
And you have all the usual data protection rights like requesting a full copy of all stored data from each company. In theory you should also always be informed afterwards when your data was retrieved due to a warrant.
That said, I'm still very much against this kind of data collection. Data protection starts at data parsimony. And you never know who'll have access and who watches the watchers etc.
The primary concern is not that data retention will directly lead to law enforcement going on big data harvesting operations, but that the chilling effect from having that data stored outweighs the practical benefits that law enforcement would derive from it.
A particular concern in Germany is the interaction with §98a+b of the Code of Criminal Procedure [1] and similar laws enacted by the states, which allow for not just particularized warrants, but dragnet searches ("Rasterfahndung"). While such a search still requires a (non-secret) court order and is allowed only under a limited set of circumstances, there is an undeniable chilling effect associated with it.
[1] http://www.gesetze-im-internet.de/englisch_stpo/englisch_stp...