After Pegasus Scandal, Poland Still Lacks Rules for Spyware Use, Report Finds
Translated from Polish and summarized by DistantNews. Read the original for the full story.
At a glance
- A report by Fundacja Panoptykon highlights insufficient regulation of spyware, including Pegasus, in Poland despite the "Pegasus scandal."
- The report argues that spyware allows access to all data on a device, including remote microphone and camera control, and is used by both authoritarian and democratic governments for surveillance.
- Panoptykon asserts that spyware, by enabling evidence fabrication and accessing historical data beyond legal limits, does not fit the definition of "operational control" under Polish law.
The aftermath of the Pegasus scandal continues to reveal a disturbing lack of robust regulation surrounding the use of spyware in Poland. A new report by the Panoptykon Foundation, titled "Democracy Under Surveillance: Poland and Pegasus Spyware," paints a stark picture: despite public outcry and government promises, the framework for utilizing such powerful surveillance tools remains dangerously underdeveloped.
Governments, both in authoritarian and democratic countries, reach for spyware. The states themselves often deny using such tools or only admit to it after evidence is revealed. We don't know if Polish services are using such software after the loud 'Pegasus affair,' but it is potentially possible.
This comprehensive assessment by Panoptykon, a respected non-governmental organization, scrutinizes the actions of the Polish government, parliament, and law enforcement agencies. It concludes that too little has been done to "civilize" the rules governing operational control, particularly concerning spyware like Pegasus. The report emphasizes that these tools, capable of breaching device security and accessing all data, as well as remotely controlling microphones and cameras, are a significant threat not only to democracy and human rights but also to cybersecurity globally.
Panoptykon's findings are particularly concerning given the history of Pegasus's misuse in Poland. The report notes that the spyware was allegedly used against Krzysztof Brejza, then-campaign manager for the Civic Coalition, with his phone reportedly being infiltrated over 33 times during the 2019 election campaign, leading to the theft of tens of thousands of SMS messages. This history underscores the urgent need for clear legal boundaries and strict oversight, which, according to the report, are still lacking.
Using Pegasus and other spyware involves breaching device security and modifying its operation. Neither the CBA Act nor any other law gives services the right to breach the security of devices belonging to individuals for whom operational control has been ordered.
The foundation argues forcefully that spyware like Pegasus fundamentally differs from traditional "operational control." By allowing for the modification of device functions and the potential fabrication of evidence, and by enabling the retrieval of historical data beyond the court-ordered three-month limit, its use falls outside existing legal definitions. This legal ambiguity, the report suggests, leaves Polish citizens vulnerable and undermines the rule of law. The international community, including other NGOs across Europe, rightly identifies spyware as a paramount threat, and Poland's continued struggle to implement effective safeguards is a cause for serious concern.
Therefore, in our opinion, there is currently no legal basis provided for in the regulations to consider Pegasus or other spyware as a tool for implementing operational control.
Originally published by Rzeczpospolita in Polish. Translated, summarized, and contextualized automatically by DistantNews, with a note on how the source frames the story. Not individually reviewed before publishing. How this works.