Go back to the Europarl portal

Choisissez la langue de votre document :

  • bg - български
  • es - español
  • cs - čeština
  • da - dansk
  • de - Deutsch
  • et - eesti keel
  • el - ελληνικά
  • en - English (Selected)
  • fr - français
  • ga - Gaeilge
  • hr - hrvatski
  • it - italiano
  • lv - latviešu valoda
  • lt - lietuvių kalba
  • hu - magyar
  • mt - Malti
  • nl - Nederlands
  • pl - polski
  • pt - português
  • ro - română
  • sk - slovenčina
  • sl - slovenščina
  • fi - suomi
  • sv - svenska
Parliamentary questions
PDF 43kWORD 9k
21 October 2021
E-004790/2021
Question for written answer  E-004790/2021
to the Commission
Rule 138
Patrick Breyer (Verts/ALE)
 Answer in writing 
 Subject: Use of unsafe encryption standards in criminal law and police matters

1. Where EU public bodies such as Europol exchange DNA, fingerprint, and other biometric data (such as facial biometrics), what encryption and hashing algorithms are currently used to protect the confidentiality and integrity of this data in transit, and with what key lengths?

2. Council Decision 2008/616/JHA stipulates, with regard to the exchange of DNA data, that ‘the encryption algorithm AES (Advanced Encryption Standard) with 256‑bit key length and RSA with 1 024‑bit key length’ and ‘the hash algorithm SHA‑1 shall be applied.’ However, the SHA‑1 hash algorithm has effectively been broken since 2017, while 1 024‑bit RSA encryption is vulnerable to brute force attacks by more powerful modern computers. When will the legal provisions stipulated in that decision be updated to ensure that cryptographic protection for cross-border transfers is based on up-to-date technical guidance?

3. More generally, where there is cross-border cooperation on criminal or police matters, is there an obligation to apply cryptographic mechanisms for data confidentiality and data integrity to personal data exchanged? If so, where are the appropriate levels of protection specified, and on the basis of what technical advice?

Last updated: 29 October 2021Legal notice - Privacy policy