Civil Society Common Statement: United Against Spyware Abuse in the EU and Beyond

Spyware isn’t just a privacy issue — it’s a threat to the very foundations of our democratic values. By undermining independent decision-making, restricting public debate, and silencing journalists and activists, spyware erodes the pillars of a healthy civic space.

As new European Union institutions prepare to take office following the EU elections, the growing threat of spyware has become a pressing global concern that demands immediate attention.

On Tuesday 3/9, Homo Digitalis joined Center for Democracy and Technology Europe (CDT Europe), alongside 30 civil society and journalists' organisations in publishing a joint statement urging the incoming EU institutions to prioritise action against the misuse of spyware in the new legislative term.

Some of our coalition’s key recommendations include:

  • A ban on the production, sale, and use of spyware that disproportionately harms fundamental rights.
  • Stronger export controls to prevent the misuse of these technologies beyond the EU.
  • Transparency and accountability in government contracts involving spyware.

As Silvia Lorenzo Perez, Director of CDT Europe’s Security, Surveillance & Human Rights Programme, puts it: "The incoming EU institutions have the opportunity to correct the failures of the last legislature by taking concrete and decisive action against the abuse of spyware surveillance."

The new EU institutions must seize this moment to restore public trust, protect our fundamental rights, and uphold the values that define the Union.

You can read the EN version of the letter here, and the EL version of the letter here.

Homo Digitalis has also addressed related concerns, before the Council of Europe’s Commissioner for Human Rights in a recent Open Letter submitted in August. You can read more about this here.


New Book: #FakeYou – Don’t blame the people; don’t blame the Internet. Blame the power

Our friends from the digital rights civil society organization Xnet published recently the book “#FakeYou – Don’t blame the people; don’t blame the Internet. Blame the power”.

The book’s lead author is Simona Levi, while it is the activist’s guide to defeating fake news and blocking policies that use disinformation to curtail civil rights and freedoms.

You can freely read and download the book here.


Homo Digitalis Submits Urgent Letter to the Council of Europe’s Commissioner for Human Rights

Homo Digitalis submitted today a letter to the Council of Europe’s Commissioner for Human Rights.

We this letter, the Greek CSO aims to draw the Commissioner’s attention to the following three issues:
A. The imminent adoption of a Presidential Decree in Greece permitting state authorities to procure spyware.
B. The deteriorating condition of independent supervisory authorities in Greece, plagued by power struggles, understaffing, and financial constraints.
C. The latest developments in the ongoing PREDATOR scandal in Greece, which leaves critical questions unanswered regarding the surveillance of journalists, politicians, and lawyers through illegal means.

Moreover, with this letter Homo Digitalis urges the Commissioner:

  • To give full and close attention to the situation in Greece,
  • To take into account the facts presented above and urgently request further information and clarifications from Greek authorities,
  • To examine the situation in Greece and take necessary steps to identify any shortcomings in the law and practices concerning human rights abuses, and
  • To assist in strengthening the activities of national supervisory institutions and other human rights structures in Greece.

You can read the letter (EN) here.


Homo Digitalis is immediately informed by the Hellenic DPA & the Hellenic Authority for Communication Security and Privacy for their intervention re the Draft Presidential Decree on Spyware

On Tuesday July 30th  η Homo Digitalis filed a request before the President of the Hellenic Data Protection Authority (HDPA), Mr.Menoudakos (no.6277/30-07-2024), and the President of the Hellenic Authority for Communication Security and Privacy (ADAE), Mr. Rammou (no. 2755/30-07-2024), in order for the two Independent Authorities to exercise their advisory powers and issue a joint Opinion regarding the Draft Presidential Decree of Articles 13 & 47 of Law 5002 /2022 on the procurement of contracts on behalf of governmental structures for the supply of spyware or surveillance devices.

In response to our request, the response of the HDPA and ADAE has been lightning fast. Specifically, the Directorate of Supervisory Work of the HDPA informed us on the same day, 30 July 2024, that the HDPA has requested the draft presidential decree from the Ministry of Citizen Protection from 19 July 2024 in order to give its opinion on the matter, while the President of ADAE, Mr. Rammos, in a letter addressed to Homo Digitalis on August 1, 2024, informed us that ADAE, as it always does, within the framework of its constitutional and statutory competence, it goes without saying that it will exercise its advisory competence (provided for by Article 6 paragraph 1 point i of Law 3115 /2003) and on the specific draft presidential decree in the context of an institutional dialogue with all the state bodies involved in its adoption.

We await with interest the relevant developments in the near future, since, as Homo Digitalis has pointed out in its letter to the two independent authorities, the provisions of the draft presidential decree may cause irreparable risks for democracy, the rule of law and the protection of fundamental rights and freedoms in Greece.


Learn more about the Council of Europe's Framework Convention on Artificial Intelligence, in the drafting of which Homo Digitalis was actively involved.

The Council of Europe has published an important overview of the “Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law,” the first international legally binding instrument for AI.

The AI Treaty “aims to ensure that activities within the lifecycle of artificial intelligence systems are fully consistent with human rights, democracy and the rule of law, while being conducive to technological progress and innovation.”

For more than 4 years, since July 2020, Homo Digitalis has been actively involved in the relevant processes of the Council of Europe, initially participating in the CAHAI (Ad Hoc Committee on Artificial Intelligence) in the Policy Development and Legal Frameworks Working Groups, and subsequently in the Council of Europe’s Committee on Artificial Intelligence (CAI). Throughout this period, we had the honor of closely collaborating with civil society organizations, academic experts, member delegations, the Presidents of the Committees and Working Groups, and the Secretariat of the Council of Europe’s Committee on Artificial Intelligence in the development of the AI Convention.

Our co-founder and Executive Director, Eleftherios Chelioudakis, has represented Homo Digitalis in the relevant processes for the past 4 years.

Despite the limitations in the text of the Convention, which we have discussed in detail, we eagerly anticipate its adoption and implementation by the Member States of the Council of Europe. The treaty will be open for signature on September 5, 2024.

You can read the related overview here.


We submitted an Open Letter to the Special Secretary of Foresight Strategy about the National AI Strategy and the enforcement of the AI Act

Today, 1/8/2024, on the occasion of the entry into force of the AI Act, Homo Digitalis sent a letter to the Special Secretary of Foresight Strategy of the Hellenic Government, Mr. Giannis Mastrogiorgiou, regarding the National Strategy for AI and the incorporation of the AI Act into national law! In addition, we communicated our concerns to the Prime Minister’s Office and the Ministry of Digital Governance.

Among other things, we raise critical questions about the national governance and oversight model, the creation of regulatory sandboxes (No. 57) and how the Greek public will be informed when subjected to the use of AI systems that create profiles or make decisions about them in the provision of public services.

At Homo Digitalis, we believe that the next steps of the Greek government will be crucial for the effective or not defence of digital rights in Greece, at a time when AI is a reality in our daily lives. The proper incorporation of such a technical and legally complex legislation into national law and the solutions adopted to address the ethical and social issues that arise are crucial for all of us.

You can see the full text of our letter here.


We requested from the Hellenic DPA and the Hellenic Authority for Communication Security and Privacy to issue an Opinion on the Draft Presidential Decree for the procurement of spyware by Greek authorities

Today, 30.7.2024, Homo Digitalis filed a request before the President of the Hellenic Data Protection Authority (HDPA), Mr.Menoudakos (no.6277/30-07-2024), and the President of the Hellenic Authority for Communication Security and Privacy (ADAE), Mr. Rammou (no. 2755/30-07-2024), in order for the two Independent Authorities to exercise their advisory powers and issue a joint Opinion regarding the Draft Presidential Decree of Articles 13 & 47 of Law 5002 /2022 on the procurement of contracts on behalf of governmental structures for the supply of spyware or surveillance devices.

The lack of transparency and openness regarding the whole process of drafting the text of the draft Presidential Decree, as well as the absence of an informed dialogue with the independent authorities of the country and with the advisory bodies of the state , combined with its late preparation, which contradicts the explicit provision of the legislator in Articles 13 and 47 of Law 5002 /2022, create additional concerns in the public sphere, as well as in certain professional circles, such as politicians, journalists, and lawyers, whose preservation of the confidentiality of communications is vital for democracy.

Homo Digitalis considers that, in the absence of immediate intervention by the two supervisory authorities, there is a serious risk that the provisions of the Draft Presidential Decree may not meet the requirements set out in Union law and the case law of the CJEU, may contravene the values enshrined in Article 2 TEU and the Fundamental Rights enshrined in the Charter and, in particular Articles 7, 8, 11, 11, 17, 21 and 47 thereof, fail to comply with the requirements laid down in Council of Europe law, in particular the values enshrined in the ECHR and Convention 108 and the case-law of the ECtHR, and infringe Articles 9A, 14 and 19 of the Greek Constitution.

Furthermore, Homo Digitalis considers that there is a serious possibility that the provisions of the said Draft Presidential Decree will create a lower level of protection in Greece than in other EU Member States, thus hindering the exchange of data and information between Greece and other Member States and leading to the impossibility of fighting serious crime and terrorism at a cross-border level whenever the use of spyware by the Greek authorities has taken place.

You can read our request in detail here.


We published an article on Nomiki Bibliothiki's website about CSAR

This is a crucial period for the proposed European Regulation on preventing and combating child sexual abuse online (Child Sexual Abuse Regulation -CSAR).

In the context of these important developments, our co-founding members Elefterios Chelioudakis and Stefanos Vitoratos prepared a detailed article for the NB Daily website in order to highlight the relevant issues.

We would like to thank the editorial team of Nomiki Bibliothiki for their cooperation.

You can read the article here.


The European Union must keep funding free software

Open Letter to the European Commission.

Since 2020, Next Generation Internet (NGI) programmes, part of European Commission’s Horizon programme, fund free software in Europe using a cascade funding mechanism (see for example NLnet’s calls). This year, according to the Horizon Europe working draft detailing funding programmes for 2025, we notice that Next Generation Internet is not mentioned any more as part of Cluster 4.

NGI programmes have shown their strength and importance to supporting the European software infrastructure, as a generic funding instrument to fund digital commons and ensure their long-term sustainability. We find this transformation incomprehensible, moreover when NGI has proven efficient and economical to support free software as a whole, from the smallest to the most established initiatives. This ecosystem diversity backs the strength of European technological innovation, and maintaining the NGI initiative to provide structural support to software projects at the heart of worldwide innovation is key to enforce the sovereignty of a European infrastructure.
Contrary to common perception, technical innovations often originate from European rather than North American programming communities, and are mostly initiated by small-scaled organizations.

Previous Cluster 4 allocated 27 million euros to:

  • “Human centric Internet aligned with values and principles commonly shared in Europe” ;
  • “A flourishing internet, based on common building blocks created within NGI, that enables better control of our digital life” ;
  • “A structured ecosystem of talented contributors driving the creation of new internet commons and the evolution of existing internet commons”.

In the name of these challenges, more than 500 projects received NGI funding in the first 5 years, backed by 18 organisations managing these European funding consortia.

NGI contributes to a vast ecosystem, as most of its budget is allocated to fund third parties by the means of open calls, to structure commons that cover the whole Internet scope – from hardware to application, operating systems, digital identities or data traffic supervision. This third-party funding is not renewed in the current program, leaving many projects short on resources for research and innovation in Europe.

Moreover, NGI allows exchanges and collaborations across all the Euro zone countries as well as “widening countries” [1:1], currently both a success and an ongoing progress, likewise the Erasmus programme before us. NGI also contributes to opening and supporting longer relationships than strict project funding does. It encourages implementing projects funded as pilots, backing collaboration, identification and reuse of common elements across projects, interoperability in identification systems and beyond, and setting up development models that mix diverse scales and types of European funding schemes.

While the USA, China or Russia deploy huge public and private resources to develop software and infrastructure that massively capture private consumer data, the EU can’t afford this renunciation.
Free and open source software, as supported by NGI since 2020, is by design the opposite of potential vectors for foreign interference. It lets us keep our data local and favors a community-wide economy and know-how, while allowing an international collaboration.
This is all the more essential in the current geopolitical context: the challenge of technological sovereignty is central, and free software allows addressing it while acting for peace and sovereignty in the digital world as a whole.