Skip to main content
Does Your Metadata Retention Program Pass the Separation Test?Privacy Regulations
4 min readFor Privacy Officers

Does Your Metadata Retention Program Pass the Separation Test?

A recent opinion from CJEU Advocate-General Maciej Szpunar signals a potential shift in how European courts evaluate bulk metadata collection. The key question is no longer whether you collect metadata indiscriminately, but whether your separation controls are "effectively watertight." If the Court of Justice follows this recommendation, your retention architecture needs an immediate audit.

What This Checklist Covers

This checklist helps you assess whether your metadata retention program could withstand scrutiny under emerging EU standards. It focuses on separation controls, oversight mechanisms, and access governance. You'll identify gaps between your current setup and the Technical and Organisational Measures required to demonstrate proportionate interference with privacy rights.

Prerequisites

Before using this checklist, ensure you have:

  • Documentation of all metadata categories you collect (identification, traffic, location, IP addresses, timestamps, terminal information)
  • Current retention periods for each category, mapped to specific legal bases
  • Access logs showing who retrieved metadata and under what authority
  • Your data architecture diagrams showing where each metadata type is stored

If you lack any of these, stop. You can't assess separation controls without knowing what you're separating.

Checklist Items

1. Metadata categories are stored in separate logical or physical systems

Check that identification data (subscriber names, account details), traffic data (who contacted whom, when), and location data (cell tower logs, GPS coordinates) can't be queried together without explicit authorization. A query against your traffic database should return session identifiers, not customer names. Linking requires a second query against a separate identity store, logged and authorized independently.

2. Recombination requires documented legal basis before execution

Verify that your systems enforce authorization checks before joining metadata categories. A legitimate interests assessment or court order must exist in your records before the join operation executes. Your access control system should block cross-category queries unless the requesting user presents a case reference number tied to a documented legal basis in your compliance database.

3. Retention periods are category-specific and precisely defined

Confirm you've set explicit retention periods for each metadata type, not blanket timelines. Your policy must specify exactly which data elements fall under which period. For example: "IP address and timestamp: 12 months. Subscriber identity linked to IP: stored separately, 12 months. Location data: 6 months."

4. Access requests trigger supervisory notification or oversight

Check whether every metadata access event generates a notification to your Supervisory Authority or an independent oversight body. At minimum, your internal audit function must receive real-time alerts. Your system should send an automated notification to your Chief Privacy Officer and log the request in a tamper-evident audit trail within 60 seconds of the query execution.

5. Your separation architecture has been independently validated

Verify that an external auditor or your Supervisory Authority has reviewed your separation controls within the past 12 months. Self-assessment is insufficient. You should hold a third-party attestation report confirming that your metadata stores are logically isolated, that join operations require multi-party authorization, and that your access logs are immutable.

6. You maintain a register of every metadata recombination event

Confirm you log not just access, but specifically the joining of previously separated metadata categories. Each entry must record the legal basis, the requesting party, the categories combined, and the supervisory notification timestamp. Your breach register should show: case ID, legal basis document reference, categories joined, timestamp, authorized by whom, oversight notification sent (yes/no).

7. Communications providers are not left to interpret retention scope

If you're a service provider subject to retention obligations, verify that the applicable law or regulation specifies exactly which data elements you must retain. If it says "traffic data" without enumeration, you have a compliance gap. Your retention matrix should list every field name in your database alongside the specific statutory or regulatory provision requiring its retention.

8. High-risk processing activities have Prior Consultation records

If your data protection impact assessment identified high risks that your Technical and Organisational Measures do not sufficiently mitigate, confirm you consulted your Supervisory Authority before deploying the retention system. You should have a dated response letter from your Supervisory Authority acknowledging your consultation and either approving your approach or requiring specific additional controls.

Common Mistakes

Treating separation as a policy, not a technical control. Writing "we keep metadata types separate" in your privacy notice doesn't satisfy the watertight standard. Separation must be enforced by access control systems, not by staff training.

Logging access but not recombination. You might track every database query, but if you don't specifically flag and audit the moment when identification data gets joined to traffic data, you can't demonstrate oversight of the privacy-invasive event.

Retaining "for law enforcement purposes" without category-specific justification. Blanket retention doesn't pass proportionality review. Each metadata type needs its own necessity justification.

Assuming your current architecture is adequate because it predates recent rulings. The 2024 CJEU ruling on French copyright enforcement and Szpunar's opinion represent an evolution in the court's thinking. Your 2020-era retention design may not meet 2026 standards.

Next Steps

If you checked fewer than six items, your metadata retention program carries significant legal risk under emerging EU standards. Prioritize items 1, 2, and 6 immediately; they form the core of the separation-and-oversight framework.

If you checked all eight, schedule your next independent validation. The standard is "effectively watertight," and that requires ongoing verification, not a one-time design review.

Finally, monitor the Court of Justice's final ruling on the Belgian law. If the court follows Szpunar's recommendation, expect the European Commission to incorporate these separation principles into any replacement for the defunct Data Retention Directive. Your current architecture will become your compliance baseline.

You Might Also Like