MOZOM-analyse
Hack first, get permission later? German draft bill opens phones and computers to intelligence services

- Source
- German draft law NDRefG, Tagesschau, Federal Constitutional Court, Deutscher Anwaltverein, Reporter ohne Grenzen, AG KRITIS and European Commission
- MOZOM headline
- Hack first, get permission later? German draft bill opens phones and computers to intelligence services
- Original headline
- More powers for intelligence services: necessary reform or 'historical taboo breaking'?
- Author
- Ron Caroselli
- Date
- 12 augustus 2026 om 12:25
- Subject
- MOZOM examines what the German draft intelligence law reform actually allows: covert access to telephones and computers, technical interventions before final consent, dormant access, zero-days, active cyber operations and the limits of independent supervision.
Summary of the original report
Tagesschau reported on August 12 that the German cabinet wanted to approve the reform that day. The public draft of July 5 consists of 691 pages and rewrites large parts of the rules for the Bundesamt fuer Verfassungsschutz (BfV), the domestic security service, and the Bundesnachrichtendienst (BND), the foreign intelligence service. Paragraph 23 gives the BfV the authority, under certain conditions, to secretly access IT devices and read stored personal data. Sections 25 and 26 regulate deeper or limited interventions in private systems. For the BND, paragraphs 36 to 39 contain similar options, including changing or deleting data, redirecting or blocking traffic and disabling systems in the event of an immediately threatening situation in which another agency cannot act in a timely manner. According to the explanation, smartphones, laptops, servers and cloud environments fall under such IT systems. The owner is not asked for permission in advance; secrecy is actually part of the method.
What is allowed, who controls and where is the risk?
The table summarizes provisions from the draft. 'Risk' here means a legal or technical risk of abuse; it is not a claim that the abuse described has already occurred.
| Power | Legal threshold | Control | Residual risk |
|---|---|---|---|
| Read stored data on an IT device | At least a significant observable threat; the system must be identified as accurately as possible. | Internal command. Independent prior assessment applies to the more serious cases from paragraph 23, paragraphs 2 and 3, not visible for every normal reading from paragraph 1. | The service that wants to intrude first carries out the legal assessment itself for the lighter variant. The person concerned cannot defend himself in advance. |
| Prepare technical access before the authorization is finalized | Only when otherwise success is jeopardized; no substantive collection of personal data yet. | Final consent and verification follow before data may be processed. | System integrity may be compromised before the remote check is complete. This means that the technical intrusion comes earlier than the moment of consent. |
| Complete intervention in a private system | A concrete danger to particularly important legal assets, a very serious threat and no timely equivalent police route. | Prior assessment by the Unabhaengiger Kontrollrat; for home surveillance, the Federal Administrative Court decides. | A complete device intervention potentially provides an exceptionally complete picture of a person's life. Unavoidably involved third parties can also be affected. |
| Allowing technical access to exist dormant | Only if there are concrete indications that the change is necessary again in the foreseeable future. | Necessity and proportionality must continue to exist and subsequent data processing requires a valid basis. | 'Within the foreseeable future' is not clearly limited to a fixed number of days. Meanwhile, hidden access itself remains a security risk. |
| Inform the person concerned afterwards | In principle, notification after termination applies to the listed severe measures. | Postponement, non-reporting and final withdrawal after five years are possible under certain conditions; some decisions require permission from the Kontrollrat. | Those who never hear that their device has been invaded will find it difficult to have the legitimacy tested independently. For notification, the legal action against order and execution is excluded. |
| Actively influence systems and data | An immediately threatening situation, necessity and the lack of timely action by another competent authority. | Internal orders, independent review of appropriate measures, proportionality and parliamentary oversight. | The boundary between collecting information and operational intervention is becoming thinner. A wrong target or hijacked system from an innocent third party can cause collateral damage. |
| Take advantage of zero days before a repair is available | The explanation describes that the BND can use the short period for a software patch for intelligence work. | No general backdoor in every device, but targeted exploitation of a leak that has not yet been repaired. | As long as the leak remains open, criminals or foreign services can also find the same vulnerability. Offensive advantage then conflicts with protection of all users. |
| Automated profiles and predictions | Analysis must fall within the legal task, purpose limitation and data rules. | Supervision and control of the data and applications used remain required. | Automation increases scale and speed, but also the reach of incorrect connections, biases and difficult-to-explain risk scores. |
Own source research: four passages that change the debate
MOZOM has not only read the media summary, but the complete design and explanation. Four passages stand out. Firstly, paragraph 33 states that preparatory technical measures that affect the integrity of an IT system are permitted before the order is issued if otherwise their success is jeopardized, as long as no personal data is collected. The explanatory notes to the BND explicitly state that even an emergency procedure can sometimes take too long. Secondly, paragraph 23(4) stipulates that system changes do not always have to be reversed if there are concrete indications that they will soon be needed again. The explanation describes such access as 'dormant' and can be reactivated later. Third, notification under paragraph 35 can be postponed as long as the research purpose or important state interests are threatened; After five years, reporting can be definitively waived if the reasons are expected to continue to exist. Fourth, the explanation describes that information about a zero-day from the BSI can be temporarily used by the BND before a manufacturer provides a patch. That is not a hidden obligation to build a state backdoor in every telephone. It is a visible conflict between offensive intelligence interests and the task of quickly making citizens, companies and vital infrastructure safer. The explanatory memorandum is more concrete still. On page 292 it says that, for surveillance inside a home, the BfV may not only introduce its own sensors but also use existing sensors belonging to the resident, explicitly giving a smart speaker as an example; if this requires interference with an IT system, the conditions governing such interference also apply. The memorandum also mentions mobile devices, cloud services and IoT devices, while the bill provides for requests for vehicle telemetry such as location, speed, mileage, usage profiles and even seat-occupancy sensor data. No brands are named in the law, but technical categories can include Google Nest/Home, Amazon Echo with Alexa, Meta Quest 3, PCs, laptops, iPads and other tablets, smartphones with cameras and microphones, Ring doorbells, home cameras, smart televisions, wearables and connected electric cars. This is not automatic permission to listen continuously through every online device: the purpose, statutory threshold, specific power and required oversight remain decisive for each measure. It is precisely the combination of microphones, cameras, sensors, accounts and cloud data that makes the potential reach so intrusive.
The reassuring word 'control'
The design includes internal orders, documentation, proportionality, the Unabhaengiger Kontrollrat, parliamentary supervision and an administrative judge for home surveillance. Therefore, "uncontrolled hacking" as a general description is incorrect. But the word 'control' can also be too reassuring. Not every reading is independently assessed in advance, emergency exceptions exist, extensions to additional persons can be submitted later and the target person does not participate in an adversarial procedure. Good control not only requires that a supervisor exists somewhere, but that he or she can decide on the intervention in a timely, concrete manner and with sufficient information.
No Chat Control law, but the same European direction
The German draft bill and Chat Control are legally separate dossiers. The first regulates the powers of German intelligence services; the second concerns providers, detection and reporting of online child sexual abuse material. The temporary EU arrangement re-adopted in July 2026 excludes end-to-end encrypted communications, while the permanent framework is still under negotiation. The German draft bill does not reveal a direct joint system with the BND or BfV. The similarity lies in the technical direction. When encryption makes interception on the go difficult, the focus shifts to the end device, the cloud or the provider. The European Commission is also officially working on data retention, cross-border interception, digital forensic tools, access to encrypted data and new decryption capacity for Europol. In the Netherlands, the AIVD and MIVD are already allowed to hack, but this special power requires ministerial permission and a binding judgment from the TIB. Europe is therefore building an increasingly broader infrastructure for digital state access not through a single secret law, but through several separate regulations.
Possible message behind the news
The visible message is that Germany needs modern means against modern threats. The critical MOZOM message is that a democracy should not design powers only for the current well-intentioned user, but also for an incorrect system, a broadly interpretive service and the worst possible future government.
Neutral conclusion
The conclusion: the German draft contains more guarantees than the slogan 'the state can hack into just any phone' suggests, but it goes much further than technical maintenance of outdated legislation. The services are given access to private systems, are allowed to secure technical access under conditions prior to final approval, can leave access dormant and are given opportunities to actively influence digital systems. At the same time, notification may be omitted for a long time or permanently. That's a real power shift. The most defensible limit is therefore clear: any covert intervention in a private device must be independently and concretely assessed in advance, exceptions must be kept short and demonstrable, backdoors must be removed, vulnerabilities must be reported quickly and they must be notified afterwards unless a judge decides otherwise with reasons. Otherwise, 'trust us' will slowly become the most important lock on the secret service's power.
Source:
- German Ministry of the Interior: complete draft NDRefG
- Tagesschau: necessary reform or historical taboo breaking?
- Federal Constitutional Court: existing BND surveillance partly unconstitutional
- Deutscher Anwaltverein: more powers, less control?
- Reporter ohne Grenzen: criticism of source protection
- AG KRITIS: criticism of zero-days and cyber resilience
- European Commission: roadmap for lawful access to data
- Council of the EU: temporary CSAM scheme and end-to-end encryption
- National government: hacking powers of the AIVD and MIVD
- Previously at MOZOM: threat as a gateway to more power