The cabinet wants to significantly expand the powers of the Dutch intelligence services. This includes less screening, a special status for designated 'opponents', and expanding emergency law. What do these changes mean? And what are the long-term risks?
Under what conditions are things like wiretapping, hacking and data collection permitted? The Wet op de inlichtingen- en veiligheidsdiensten (Wiv, or Intelligence and Security Services Act) governs what the Dutch intelligence services - the AIVD (General Intelligence and Security Service) and the MIVD (Military Intelligence and Security Service) - are allowed to do and when. The current bill represents a major revision of the 2017 Wiv. That law is now considered outdated due to new threats, such as Russian cyberattacks, the invasion of Ukraine, and Chinese cyber espionage and criminal subversion.
With the new bill, the services are calling for more capacity to counter these hybrid threats. Oversight bodies are being merged, and less screening will be required before granting permission for action. Finally, the proposal provides for increased cooperation and data sharing between the services, the police, the armed forces and other security agencies.
What risks does the bill pose?
During a debate on the intelligence services last week, questions were raised about the risks associated with the new law. Doubts were also expressed about the additions to emergency law, which would grant the government extra authority in certain crisis situations. A significant change lies in how permission is granted. Under the current Wiv, approval must be requested for each separate hacked server or tapped phone, leading to delays and administrative burdens. The new law introduces an 'opponent regime': once ministers have designated an organisation as an opponent and this has been approved, the oversight body will no longer review each individual operation in advance. Instead, in many cases, the director of the service can grant permission themselves.
In the podcast Schaduwoorlog (Shadow War), Jan-Jaap Oerlemans, assistant professor of Criminal Law, explained the changes: 'This law includes many new regulations, is broader in scope, and is therefore truly different from the 2017 Wiv. There are several aspects where I see tensions arising. For example, with the opponent regime, the question is whether you should require independent oversight for the use of certain powers.'
A change in the law is necessary
Oerlemans does see the need for a revision of current procedures. 'The services see a need for the rapid, effective deployment of powers given the current threats. In the past, there were many problems with the use of certain powers, such as hacking and bulk interception, which this law attempts to address.'
'This law also assigns a much more prominent role to the MIVD,' Oerlemans explains. 'That's not surprising, given the Russian threat and the operational environment in which the service now operates. The AIVD is also being given a more explicit role in combating criminal subversion. I find the interface with criminal law particularly interesting,' he says. And there are also important improvements regarding oversight and the protection of fundamental rights: 'In particular, the fact that oversight bodies within the College will soon be able to consult with each other more effectively and, in some cases, make binding decisions.'
Hacking in three phases
Under the new regulations, hacking is organised into three phases: the first two can take place without prior approval from the independent oversight body. Only in the third phase - actually extracting information - permission is required. 'In the first two phases of hacking, it's not just about preliminary exploration but also about actual intrusion. That's where things get tricky. I think the oversight body will have something to say about that. We need to better define how that oversight will work: is there a well-developed plan in place beforehand, and is it being executed carefully?'
Meanwhile, the oversight bodies have responded, expressing strong criticism of the new regulations for hacking powers and the opponent regime. 'Still, I find the oversight bodies' response on a total of 173 points quite substantial. And I miss the necessary reflection on what went wrong in the past and what this bill is specifically trying to address,' says Oerlemans, who previously worked at the CTIVD (Review Committee on the Intelligence and Security Services).
Data requests
Another new development is that the AIVD and MIVD will have 'compulsory disclosure powers' for financial institutions, communication services, and online platforms. These entities can be required to hand over data (such as banking information), under penalty of imprisonment for refusal. 'This is also established in criminal law. It's not unusual to regulate this for intelligence and security services as well, but I do think more consideration needs to be given to a correction mechanism, such as a special complaints procedure for the companies involved or reports to the oversight body.'
Who oversees this, and how?
Finally, the bill proposes increased cooperation and data sharing between the services, the police, the armed forces, and other security agencies. 'Who will oversee this? And how far does that oversight extend? Especially when it comes to joint operations and data processing. Does the oversight body lose sight of things if state-secret data ends up with the police, the Ministry of Defence, or a private party?'
Oerlemans reserves final judgment: 'It's still too early to conclude whether the balance is ultimately correct. The draft bill will still be amended, and even small changes can have major consequences. Only after it has been debated in the House of Representatives and the Senate can you truly answer that question.'