UK ISPs forced to keep customer data by EU
An EU ruling comes into force which means that British ISPs will have to retain data by law, in order to aid police and intelligence agencies.
From this Sunday, internet service providers (ISPs) will be forced to store data from their customers for up to one year under the EU Data Retention Directive.
This data will include names, dates of birth, billing addresses and credit card information, in addition to IP addresses and session data.
The directive will represent a move from the current voluntary scheme that ISPs have with law enforcement, to one that meets minimum requirements across the EU.
Supporters claim that the directive is necessary as police, security and intelligence agencies all rely heavily on communications data to carry out their law enforcement and public safety functions efficiently.
It's believed that data will be available to support long running investigations such as terrorism, and will help build stronger prosecution cases.
However, opponents have criticised the proposals due to reasons like the cost of the operation - estimated at 46 million over a four year period - and low confidence about businesses' handling of data security.
Jamie Cowper of encryption firm PGP Corporation said that ISPs needed to take their obligations seriously.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
He said in a statement: "If privacy violation is to be avoided, and the huge cost of the operation is to be justified, then the security of public's data must be watertight."
-
The OpenAI and Anthropic containment breaches are a bit spooky, but also quite sillyOpinion An AI leaving notes to future versions of itself is pure sci-fi; forgetting to lock down an environment is prosaic
-
Bringing data to the heart of AISponsored AI is changing our approach to data, find out how HPE Alletra Storage can help your business
-
Startup founders lament 'regulatory friction' despite EU simplification effortsNews Entrepreneurs are spending a fortune on compliance, and it’s forcing some to consider relocating
-
AWS says cloud market gatekeeper designation risks ‘deterring European investment and innovation’ as EU regulators plot competition crackdownNews Gatekeeper designation under the legislation would force AWS and Microsoft to make concessions
-
‘This closes a gap that has caused real uncertainty in the market’: Changes to EU AI Act implementation deadlines welcomed by industryNews New implementation deadlines for the EU AI Act could help remove “genuine friction” for European companies
-
European Commission approves data flows with UK for another six yearsNews The European Commission says the UK can have seamless data flows for another six years despite recent rule changes
-
Three things you need to know about the EU Data Act ahead of this week's big compliance deadlineNews A host of key provisions in the EU Data Act will come into effect on 12 September, and there’s a lot for businesses to unpack.
-
The second enforcement deadline for the EU AI Act is approaching – here’s what businesses need to know about the General-Purpose AI Code of PracticeNews General-purpose AI model providers will face heightened scrutiny
-
Meta isn’t playing ball with the EU on the AI ActNews Europe is 'heading down the wrong path on AI', according to Meta, with the company accusing the EU of overreach
-
‘Confusing for developers and bad for users’: Apple launches appeal over ‘unprecedented’ EU fineNews Apple is pushing back against new app store rules imposed by the European Commission, suggesting a €500m fine is a step too far.