Europe wrote the rules for surveillance exports, then left its own member states to enforce them-236
May 12, 2026
A new Human Rights Watch report has identified a specific and uncomfortable failure point in how the European Union governs its own surveillance technology industry: the 2021 export rules meant to prevent EU-based spyware makers from selling to authoritarian regimes were never actually centralized, leaving the decision of who gets access to intrusion tools sitting with the same 27 member states whose companies profit from selling them.
The report's documentary evidence, built from trade records obtained through freedom of information requests, names six countries — Bulgaria, Poland, Finland, Denmark, Estonia, and the Czech Republic — whose companies collectively sold surveillance technology to more than two dozen nations with documented human rights records. Bulgaria emerges as the most significant single exporter, having sold surveillance tools to more than twenty countries including the United Arab Emirates and Azerbaijan, both governments with well-documented records of using such technology against domestic dissidents. Poland's contribution to the pattern is narrower but no less pointed: the sale of phone-call interception systems to Rwanda, a state with its own long history of surveillance-enabled repression. Five other known exporting countries — France, Greece, Spain, Germany, and Italy — either declined to share their trade records with Human Rights Watch or ignored the request entirely, meaning the report's documented cases likely represent a floor rather than the full scope of the practice.
The regulatory mechanism at the center of this failure was designed with real ambition. The EU's 2021 export control update expanded the legal definition of what counts as surveillance technology, required exporting states to weigh the human rights record of destination countries before approving a sale, and created a reporting regime intended to give the European Commission oversight visibility. What it did not do is centralize the actual licensing decision. A European Commission spokesperson defended the framework's rigor, noting that surveillance items cannot legally leave EU territory without an export authorization issued by the competent authority of the relevant member state — but that same statement makes the structural gap explicit: the authorization comes from the member state, not from Brussels, and the Commission's own oversight role is limited to reviewing a reporting regime built on data that several exporting countries apparently feel free to withhold. The Commission has scheduled a review of the rules for September, and Human Rights Watch's central demand is that this review actually strengthen due diligence and transparency requirements rather than simply reaffirm the existing framework.
The scale of what's at stake extends well beyond the six countries named in this specific report. A majority of EU member states host at least one surveillance technology vendor, and separately, a 2024 Google Threat Analysis Group report on the commercial spyware industry found that all but two of the companies it identified globally are headquartered inside the European Union. That concentration means the EU is not a peripheral actor in the global surveillance-technology trade but very nearly its center of gravity — which makes the enforcement gap this report documents less a regional compliance failure and more a structural loophole sitting at the heart of the industry's global supply chain, one that individual member states have shown little appetite to close on their own.
