EU PEGA Committee
The PEGA Committee (Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware) was established by the European Parliament in April 2022 to investigate the use of commercial spyware in EU member states and to make recommendations for regulation.
- 01The PEGA Committee was established by the European Parliament in April 2022
- 02It investigated the use of Pegasus and equivalent spyware in EU member states
- 03The committee found that spyware was used against journalists, politicians, and activists in multiple EU countries
- 04Key recommendations included a moratorium on spyware use and stronger oversight
- 05The committee's work has led to proposed EU legislation on spyware regulation
Establishment
On April 14, 2022, the European Parliament established the Committee of Inquiry to investigate the use of Pegasus and equivalent surveillance spyware (PEGA Committee). The committee was created in response to revelations from the Pegasus Project (July 2021) and subsequent reporting that Pegasus had been used against individuals in multiple EU member states, including journalists, politicians, and political activists.
The PEGA Committee had 38 members and was tasked with:
- Investigating the use of Pegasus and equivalent spyware in EU member states
- Examining the impact on fundamental rights, press freedom, and democracy
- Assessing the adequacy of existing EU and national legal frameworks
- Making recommendations for future regulation and oversight
Key Findings
The PEGA Committee's final report, adopted in 2023, found that:
- Spyware was used in multiple EU member states: Including Poland, Hungary, Spain, Greece, and others
- Journalists and politicians were targeted: Multiple cases of journalists, opposition politicians, and activists being targeted were confirmed
- National legal frameworks were inadequate: Existing laws did not provide sufficient safeguards against misuse of spyware
- Oversight was insufficient: National oversight mechanisms were often weak or non-existent
- Export controls were inadequate: EU-level export controls for surveillance technology were insufficient
- NSO Group and other vendors operated with insufficient accountability: Commercial spyware vendors faced little legal accountability for misuse of their products
Country-Specific Findings
Poland
The committee found that Pegasus was used against multiple government critics and opposition figures in Poland, including politicians, prosecutors, and journalists. The use was attributed to Polish government agencies, raising serious concerns about democratic backsliding and the rule of law.
Hungary
The committee found that Pegasus was used against journalists, media owners, and political figures in Hungary. The Hungarian government did not fully cooperate with the committee's investigation.
Spain
The committee found that Pegasus was used against politicians and activists involved in Catalonia's independence movement, including members of the European Parliament. The use was attributed to Spanish government agencies.
Greece
The committee found that Predator (Intellexa's spyware, not Pegasus) was used against a journalist in Greece (Thanasis Koukakis). The Greek government faced significant domestic and international pressure following this revelation.
Key Recommendations
- Moratorium: A moratorium on the use of commercial spyware in EU member states until robust safeguards are in place
- Strict oversight: Mandatory prior judicial authorization for any use of spyware, with independent oversight
- Transparency: Annual public reporting on the use of spyware by national authorities
- Export controls: Stronger EU-level export controls for surveillance technology, including dual-use regulation
- Vendor accountability: Legal liability for spyware vendors whose products are used to violate human rights
- Victim support: Support and redress mechanisms for victims of unlawful surveillance
- Journalist protection: Enhanced protections for journalists and media freedom, including a ban on targeting journalists with spyware
- EU-level regulation: A comprehensive EU regulatory framework for commercial spyware
Impact
The PEGA Committee's work has had significant impact:
- EU legislation: The committee's recommendations have informed proposed EU legislation on spyware regulation and the AI Act's surveillance provisions
- National inquiries: Several EU member states launched their own national investigations following the PEGA Committee's findings
- Public awareness: The committee's hearings and report increased public awareness of spyware use in Europe
- Political pressure: The committee put political pressure on governments and spyware vendors
- Export control reform: The committee's work contributed to discussions about reforming EU dual-use export controls
Criticisms
- Non-binding recommendations: The committee's recommendations are not legally binding — implementation depends on the European Commission and member states
- Member state resistance: Some member states (notably Hungary and Poland) did not fully cooperate with the investigation
- Scope limitations: The committee focused on EU member states and could not fully investigate use outside the EU
- Time constraints: The committee had a limited mandate period to complete its work
- Access to classified information: The committee faced challenges accessing classified national security information
Legacy
The PEGA Committee represents one of the most significant parliamentary investigations into commercial spyware. Its work has contributed to the growing international consensus that commercial spyware requires robust regulation, oversight, and accountability. The committee's recommendations continue to inform EU policy discussions and proposed legislation as of 2026.
