This contribution analyses how the automated surveillance of third-country nationals (TCNs) in the European Union creates second-class data subjects, revealing a rift within EU data protection law. Drawing on legislation establishing large-scale IT systems at the EU’s external borders (Entry/Exit System, European Travel Information and Authorisation System, Visa Information System and Eurodac), passenger name record (PNR) systems, and the relevant jurisprudence of the Court of Justice, this contribution examines how a data subject’s citizenship (EU or non-EU) determines the scope of lawful surveillance.
Empathy as a Method of Legal Interpretation
For the purposes of analysing surveillance legislation, this contribution relies on empathy as a means of legal interpretation. Empathy is understood as the ability to relate to others. The role of empathy in legal systems can be analysed from at least three perspectives: (i) empathy as a value in legal education, (ii) empathy as a value in the enforcement of law and (iii) empathy as a means of interpreting the law. It is the latter perspective that is advanced in this contribution.
More specifically, empathy as a method of analysing law makes it possible to map statutory law and case law along an inclusion/exclusion scale: whether they contribute to the inclusion or exclusion of an individual from the community of shared legal safeguards. In this context, the personal, material and temporal scope of surveillance legislation is scrutinised. The surveillance legislation is examined comparatively in relation to surveillance measures that are lawfully applicable to EU citizens.
Empathy as a method of legal interpretation differs from classical methods of legal interpretation: its objective is not to reconstruct the meaning of a legal norm. Rather, empathy allows analysing laws from the perspective of an external observer. Seeing laws as a reflection of values advanced in a given community makes empathy-driven interpretation a useful tool for legal analysis.
Citizenship as a Condition of Surveillance: Retention and Access, or The Two-Tier Structure of EU Surveillance Law
The basis for an empathy-driven analysis of surveillance legislation lies in the character of the fundamental right to data protection, which in the EU protects everyone, not just EU citizens (Art. 8 Charter, Art. 16 TFEU). While the CJEU repeatedly stated the fundamental right to data protection is not absolute and must be considered in relation to its function in society, this functional interpretation leads to a stratification of rights based on one’s citizenship. Accordingly, the objective of this contribution is to shed light on empathy deficits, not to question the validity or lawfulness of the surveillance legislation targeting TCNs. On the contrary, the fact that this legislation remains valid supports the finding that empathy deficits are embedded in its core.
At the same time, this contribution recognises that the distinction between citizens and non-citizens is embedded almost universally in modern legal systems, including the EU legal order. A distinction between citizens and non-citizens that determines their varying rights and responsibilities is a characteristic of the EU legal system. For example, the integration of the internal market was facilitated by individual rights granted to EU citizens, esp. through the free movement provisions.
What is characteristic, however, is the way in which the citizen/non-citizen distinction operates within surveillance law: citizenship does not merely allocate political membership, but also shapes the intensity, duration, and accessibility of state scrutiny. In the context of large-scale IT systems, this produces a regulatory architecture in which non-citizens are subjected to broader retention, wider access, and more durable traceability than citizens, even though the same fundamental right to data protection formally applies to both. The resulting legal order is therefore not one of equal surveillance, but of differentiated exposure, in which the status of TCNs is translated into a lower level of protection.
Identifying the empathy deficits
This contribution suggests using empathy to interpret laws related to surveillance of TCNs. Applying empathy exposes citizenship as a non-neutral category that conditions the scope of lawful surveillance. By identifying TCNs as second-class data subjects, this approach makes it possible to reveal the two-tier system of legal protection. The following questions allow the surveillance laws’ empathy deficits to be exposed:
- What is the personal scope of surveillance legislation (who is affected)?
- What is the material scope of surveillance legislation (what data is collected)?
- What is the temporal scope of surveillance legislation (what are the data retention periods)?
Answering the first question, the legislation establishing large-scale IT systems at EU borders (Entry/Exit System, European Travel Information and Authorisation System, Visa Information System and Eurodac) creates a regime of general and indiscriminate data retention of all TCNs entering the EU. Specifically, the large-scale IT systems complement each other in their personal scopes, creating a structure aimed at capturing data of all TCNs crossing the borders.
Answering the second question, the analysed legislation covers biometric and travel data of the TCNs. The sensitivity of the collected data, including fingerprints and facial images, and the centralised character of the large-scale IT systems pose significant risks to privacy and data protection. The centralised large-scale of biometric data paired with law enforcement access to stored data that lacks judicial oversight, puts the underlying legislation on a collision course with the CJEU case law on Arts. 7-8 and 52 of the Charter.
Answering the third question, the temporal scope of the analysed legislation also reveals a marked imbalance in the protection afforded to third-country nationals. The maximum retention periods vary considerably across the systems, ranging from 3 to 10 years depending on the database and the factual circumstances of the case. This duration of storage is not a neutral technical feature: it extends the effects of surveillance far beyond the moment of border crossing, normalising long-term data availability and amplifying the impact of purpose transgression.
As a result, two areas of discrepancies between EU citizens (first-class data subjects) and TCNs (second-class data subjects) are identified. First, TCNs are subject to general and indiscriminate long-term retention of biometric and travel data for the purposes of fight against serious crime and terrorism. Second, retained data are available to law enforcement authorities without independent oversight. For EU citizens, neither one can be reconciled with the Charter, as interpreted by the CJEU. As this contribution argues, these discrepancies between the standards of lawful surveillance of EU citizens and TCNs are indicative of empathy deficits in the underlying legislation.
General and indiscriminate retention of TCNs’ biometric and travel data for the purposes of fight against serious crime and terrorism is carried out through infrastructure designed primarily for the purposes of border management and immigration control (Eurodac, VIS, ETIAS, EES). For EU citizens, the CJEU repeatedly struck down EU and national legislation permitting general and indiscriminate retention of non-law-enforcement data for law enforcement purposes (Digital Rights Ireland, Tele2 Sverige). While the basis for the annulment of the Data Retention Directive was found in Art. 8 Charter, it was interpreted with EU citizens in mind.
The distinction between EU citizens and TCNs is also visible in the CJEU judgment on the validity of the PNR Directive Ligue des droits humains (C-817/19). The CJEU differentiated between lawful and unlawful general retention of PNR data based on one’s citizenship. That distinction is achieved indirectly, by referring to Art. 45 Charter and Art. 3(2) TEU, which enshrine EU citizens’ right to move and reside freely across the EU (paras 274-276). Accordingly, general and indiscriminate retention of PNR data of all intra-EU flights is considered by the CJEU as infringing EU primary law, unless justified by specific and concrete security needs and narrowly applied to specific routes – making it an exception from the rule (para 291). At the same time, general and indiscriminate retention of PNR data on all extra-EU flights is permitted (para 228).
The second differentiation between EU citizens and TCNs concerns law enforcement access to retained data. The CJEU requires external authorisation for law enforcement access to retained data (see Digital Rights Ireland, Tele2 Sverige, SpaceNet). The established standard is that law enforcement may only access retained non-law enforcement data with a prior authorisation by a court or an independent administrative body. In case of the large-scale IT systems (Eurodac, VIS, ETIAS, EES) independent control of law enforcement access is not foreseen. The verification of access requests is explicitly put in the hands of law enforcement authorities, which may be part of the same organisation as the requesting entity. This does not meet the strict independence test outlined by the CJEU in An Garda Siochana (C-140/20, paras 107-110).
Taken together, these legislative choices show that EU surveillance law does not apply uniformly across all persons within the Union’s legal order. Instead, it distinguishes between those whose data protection is constrained by citizenship-linked mobility rights and those whose data may be retained and accessed under broader conditions. This asymmetry is precisely what an empathy-based reading seeks to expose: not a defect in legality, but a structural difference in the intensity of legal protection. In that sense, empathy is not used here as a moral embellishment, but as an analytical tool for identifying where the law draws and normalises lines of exclusion.

Antoni Napieralski
Assistant Professor at the Department of European Economic Law, Faculty of Management, University of Warsaw. He works on data protection law, competition law and regulation of online platforms.
