Berlin Pride attack reignites calls to pass controversial IP retention bill in Germany
“A mass surveillance law.”

Image by Omer Messinger via Getty Images
- Berlin Pride attack revived calls to pass Germany’s IP retention bill.
- The bill would require internet providers to keep IP addresses and some port numbers for 3 months.
- Supporters say retained data would help criminal investigations, especially as Germany faces heightened terrorism concerns.
- Critics warn the proposal risks mass surveillance, weakens privacy protections, and could breach European court standards.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Lawmakers have called for a security bill that would oblige internet service providers to retain IP addresses for 3 months so the data could be used in criminal investigations.
A terrorist attack during Berlin Pride on July 25th, 2026, when an Islamist extremist rammed a van into a crowd and went on a knife rampage, killing a woman and leaving 29 injured, sent shockwaves across the world.
In Germany, the incident also reignited discussions about security, not least because the attacker was known to the police due to his failed attempt to join the Islamic State (ISIS), a terrorist organization.
CDU lawmaker Alexander Throm urged lawmakers to pass pending security legislation, which, among other things, would introduce retention of IP addresses for criminal investigations, Deutsche Welle reports.
A draft bill for an Act to Introduce IP Address Retention and Expand Data Collection Powers in Criminal Proceedings was introduced on December 22nd, 2025, by Germany’s Federal Ministry of Justice and Consumer Protection.
If passed, the bill would compel internet access providers to retain IP data and, in some cases, accompanying port numbers for a period of 3 months if authorities have a reasonable suspicion of an offense and the data is necessary for investigation.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Target IP addresses, content data, location data, and other traffic data would be excluded, according to analysis by the law firm Gleiss Lutz.
The lawyers explain that the bill wouldn’t extend law enforcement’s access to IP addresses, as authorities can already request this information from internet access providers.
“What is new, however, is that internet access providers will be required to actually retain the relevant data in the future. Law enforcement authorities will therefore continue to access such data on the basis of their existing legal powers,” the firm’s website reads.
The bill would also introduce preservation orders for additional traffic data that would otherwise be deleted.
In addition, the proposal foresees changes to cell tower dumps, allowing authorities to determine that mobile phones were connected to a cell tower near a crime scene.
Critics warn of mass surveillance potential
Germany is facing heightened security concerns following a string of terrorist attacks in recent years, which have played a role in pushing the IP address retention bill. However, critics say the new rules would endanger citizens’ privacy.
The Association of the Internet Industry (eco), a tech lobby group, issued a warning in February 2026 that the bill would violate European Court of Justice case law.
The EU’s Court of Justice scrapped the Data Retention Directive in 2014, citing privacy concerns. The directive, however, encompassed a broader scope of data than the current German proposal.
The group argues that the bill would reduce judicial control and impose considerable financial burdens on the sector, as they will have to invest heavily in infrastructure “that is highly likely to be legally vulnerable.”
“The draft law once again fails to meet the requirements of the European Court of Justice and creates a system of indiscriminate surveillance without proven benefits for law enforcement,” eco’s Board Member Klaus Landefeld said.
Constanze Kurz, spokeswoman for the Berlin-based hacker association Chaos Computer Club, called the proposal “a mass surveillance law” that doesn’t take into account high security risks.
“Instead of putting all people under general suspicion and introducing a disproportionate and unjustified forced storage of all IP addresses and other accompanying data, we need evidence-based policies that pursue differentiated solutions,” Kurz said.
The analysis by the law firm Bird & Bird points out the bill’s loose wording, as it would require providers to retain “information required to identify an IP connection,” leaving “considerable room for interpretation.”
The firm argues that this could encompass more data than IP addresses and timestamps, depending on the technical implementation.