State trojans for criminal prosecution
So-called ‘state Trojans’ constitute a serious encroachment on fundamental rights and lead to state authorities handling IT security vulnerabilities in an irresponsible manner. In 2025, the Federal Constitutional Court ruled that law enforcement agencies may only use them to investigate particularly serious criminal offences.
In 2017, the German Bundestag created the legal basis for the mass use of so-called state Trojans by amending the Code of Criminal Procedure (StPO): the police were to be permitted to use Trojans in more than 30,000 cases per year. The amendments to the StPO allowed investigating authorities to install state surveillance software on the computers of suspects or, under certain conditions, also on those of uninvolved third parties.
State Trojans encroach more deeply on privacy than other investigative methods
These “state Trojans” enable online searches that go far beyond the acoustic surveillance of living spaces previously permitted. This means that suspects’ current and past communications can be analysed (source telecommunications interception), content stored on the devices can be viewed, and cameras can be accessed. Because computers and smartphones today contain a wealth of information, some of it highly private, online searches infringe upon the privacy of those affected more than any other investigative method.
Use violates the fundamental right to IT privacy
However, the relaxed rules on the use of so-called ‘state Trojans’ disregarded earlier guidelines set by the Federal Constitutional Court regarding the use of such surveillance tools. The amendment to the law violated the fundamental right to the confidentiality and integrity of information technology systems (the so-called ‘fundamental right of IT’) – a right established by the Federal Constitutional Court in a 2008 ruling – in several respects.
The use of state Trojans also infringes this fundamental right because it creates perverse incentives for the investigating authorities: in order to install Trojans on target devices, federal authorities are permitted to specifically exploit existing security vulnerabilities in software and hardware that are as yet unknown to the manufacturers. This creates an incentive not to close such known backdoors. However, it is not only the state that can use them to hack into mobile phones and computers, but also criminals. With such an incentive system, the Federal Government is breaching the state’s duty to protect under the fundamental right to IT security. The Federal Constitutional Court had already ruled in 2021 on our constitutional complaint against the Baden-Württemberg Police Act: the state is obliged to protect IT security. This also means that, under certain circumstances, it must report security vulnerabilities to manufacturers so that they can be closed.
State Trojans only for the investigation of particularly serious crimes
The GFF therefore lodged a constitutional complaint with the Federal Constitutional Court in Karlsruhe in August 2018 against the use of so-called state Trojans and the state’s irresponsible handling of IT security vulnerabilities, supported by the Humanist Union. The legal representative and author of the complaint was the Hamburg-based criminal defence lawyer Dr h.c. Gerhard Strate. The five complainants included the Turkish journalist Can Dündar, who lives in exile in Germany; ARD doping expert and investigative journalist Hajo Seppelt; and Green Party politician Konstantin von Notz. In the course of their work, they had already become victims of cyber-attacks on several occasions. The Federal Constitutional Court did not accept this constitutional complaint for adjudication in 2025.
The organisation Digitalcourage had also lodged a constitutional complaint against the new regulations. During the proceedings, the GFF submitted two statements as an expert third party. In August 2025, the Federal Constitutional Court partially upheld this complaint, echoing the GFF’s arguments: the court ruled that the police may only use state Trojans when investigating particularly serious criminal offences, as their use constitutes a very serious intrusion into privacy. In doing so, the court made it clear for the first time that the use of a state Trojan always constitutes a particularly serious infringement of the fundamental right to IT privacy, even if the investigators do not search the device but ‘merely’ record communication data.
Background information
- Article in the constitutional blog by Bijan Moini and Ulf Buermeyer: Good gaps, bad gaps? The objective-legal dimension of the IT fundamental right (8.9.2018) (in German).