Is this legal?
Yes — and here is the law that says so.
Privacy is a codified fundamental right under international and European law. Mass surveillance — indiscriminate bulk collection without individual suspicion — is not lawful under that framework. Targeted, warrant-based surveillance is lawful, and remains fully available to authorities with proper legal process. Sharp#Soft restores the warrant requirement; it does not disable law enforcement.
This page renders Appendix E of the whitepaper in full — the legal instruments and case law behind that claim.
What this means for authorities
Sharp#Soft is incorporated in Sweden and operates infrastructure in Switzerland — two jurisdictions with strong constitutional and statutory privacy protections, aligned with the EU's data-protection framework.
The product is built so that user content, user keys, and the cryptographic relationships between users are inaccessible to anyone — including Sharp#Soft — who does not hold a credential the user keeps for themselves. This is not a tool for evading justice. It is the restoration of a condition that governed private correspondence for centuries, before bulk technical collection became feasible.
What remains fully available to a law enforcement authority with valid legal process:
- Seize and forensically examine a specific device under a court-issued warrant.
- Compel production of data from any provider, to the extent that provider holds it — Sharp#Soft holds only sealed data, which is disclosed under lawful process like anything else we hold.
- Deploy targeted communications interception under judicial authorisation.
- Access backups of any other service the target uses independently of Sharp#Soft.
- Use financial records, informants, physical surveillance, and compel testimony within applicable legal limits.
What Sharp#Soft prevents is mass surveillance — collecting everyone's communications without individual suspicion. That prevention is itself lawful, and, in the language of European human-rights law, proportionate.
Privacy is a right, not a favour
Rooted in the post-war human-rights framework, and developed by courts continuously for more than seventy years.
The instruments
The UN Universal Declaration of Human Rights (1948) prohibits arbitrary interference with privacy, home, or correspondence. The International Covenant on Civil and Political Rights (1966) makes the same protection legally binding on states.
The European Convention on Human Rights, Article 8, guarantees the right to respect for private life and correspondence. Any government interference must clear a three-part test: it must be lawful (precise, accessible law), pursue a legitimate aim (national security, crime prevention, and so on), and be necessary in a democratic society — which courts read as proportionate: no more intrusion than the aim actually requires.
The EU Charter of Fundamental Rights and the GDPR add a data-protection layer: information must be collected for a specific purpose and limited to what is necessary. Bulk collection for possible future use fails that test on its own terms. The Council of Europe's Convention 108+ (2018), ratified by 55 states including Switzerland, adds the same proportionality requirement with independent oversight.
The court rulings
European courts have applied the proportionality test to bulk surveillance repeatedly, and the pattern is consistent: covert surveillance is only compatible with the law when it comes with real safeguards against abuse (Klass v. Germany, 1978); imprecise interception powers are a violation regardless of stated purpose (Malone v. UK, 1984); surveillance law must clearly define who can be watched, for what, and for how long (Kennedy v. UK, 2010).
Two Grand Chamber judgments from 2021 — Big Brother Watch v. UK and Centrum för Rättvisa v. Sweden — are the most authoritative current word on mass surveillance: bulk interception, as it was actually operated, violated the right to privacy because the safeguards on what gets selected and how metadata is used were inadequate.
The EU's top court has run a parallel line: blanket data-retention laws have been struck down as incompatible with fundamental rights (Digital Rights Ireland, 2014; Tele2 Sverige / Watson, 2016; La Quadrature du Net, 2020), and two data-transfer frameworks with the US were invalidated because of the mass- surveillance access they permitted (Schrems I and Schrems II).
This applies to organisations too. A common misconception is that privacy rights belong only to individuals. European courts have confirmed that companies, partnerships, and associations also hold a right to respect for their premises and correspondence (Société Colas Est v. France, 2002). For a business using Sharp#Soft to protect client confidentiality, legal-privilege material, or trade secrets, that isn't a technical nicety — it is the exercise of a recognised right. The GDPR goes further and names encryption as an example of the "appropriate technical measure" an organisation is obliged to use to protect the data it holds.
What's lawful, and what isn't
The line the courts draw is not between "surveillance" and "no surveillance" — it is between targeted and indiscriminate.
Lawful
Targeted, warrant-based surveillance
Standard in every democratic legal system, and fully available to authorities today. It follows a structured process: evidence accumulates from ordinary investigative work; a judge or independent authority assesses whether the legal threshold is met; specific authority is granted for a named person and a defined, limited period; the process is documented and can be challenged.
This is not a theoretical alternative. A major transatlantic bombing plot was disrupted in 2006 using informant networks and targeted surveillance of named suspects — no bulk collection involved. A 2021 international operation identified criminal networks first, then collected against them — over 800 arrests across 16 countries, every target a known member of a criminal network before collection began. Several European democracies, including Germany under its constitutional telecommunications-secrecy protections, run effective security services under strict targeted-warrant limits, with results comparable to peer services that use broader powers.
Not lawful
Mass surveillance and mandated backdoors
Indiscriminate bulk collection without individual suspicion fails the proportionality test on every dimension the courts examine: the ECHR's Article 8 case law, the EU's Charter of Fundamental Rights, and the GDPR's own data-minimisation principle. A regulatory requirement to weaken encryption for everyone would be mass-surveillance infrastructure by another name — a backdoor accessible under defined legal conditions is, by the nature of cryptography, accessible to anyone who obtains or discovers it, not only the intended authority.
The empirical record backs the legal one. The US oversight board that reviewed bulk telephone-metadata collection after its disclosure found it had not made a concrete difference in the outcome of any terrorism investigation. An independent study of 225 US terrorism cases found bulk surveillance contributed meaningfully in fewer than 2% of them, and was never the deciding factor. In documented attacks that were not prevented, the recurring pattern is that the perpetrator was already known to services — the failure was resourcing and coordination, not a lack of data.
The objections people raise, answered
The arguments that come up most often when a product enables real privacy — and the short, evidence-backed answer to each.
"What about child safety?"
The majority of CSAM is found on open, unencrypted web infrastructure — not inside end-to-end encrypted apps. Breaking encryption pushes offenders to platforms that are harder to monitor, not easier.
"What about terrorism?"
The most authoritative government review of bulk surveillance found it had not concretely contributed to any terrorism-investigation outcome. Documented failures were operational — known suspects, insufficient follow-through — not informational.
"What about organised crime?"
The largest network disruptions in recent memory — including operations yielding hundreds of arrests across dozens of countries — were achieved through targeted infiltration, not mass collection.
"Nothing to hide, nothing to fear"
The right to privacy doesn't depend on innocence, any more than the right to a fair trial depends on guilt. Requiring people to justify their privacy reverses the presumption of innocence.
"Encryption means law enforcement goes dark"
A government agency once significantly overstated how many devices it couldn't access; an independent audit found the real number was a small fraction. Metadata, device forensics, backups, and informants remain extensive alternative paths.
"Organisations shouldn't get privacy tools"
Organisations hold their own right to privacy of correspondence and premises under European law. Disclosure obligations must still be proportionate and prescribed by law — they don't justify blanket access to all business communications.
Five principles run underneath every one of these answers — the standards European courts actually apply when they weigh a surveillance measure:
- Individual suspicion — grounds to suspect a specific person, not a statistical pattern across a whole population.
- Judicial authorisation — an independent authority approves each target; administrative convenience isn't a substitute.
- Proportionality — the least intrusive means available must be used. Mass collection where targeted collection would do is disproportionate by definition.
- Accountability — every act of surveillance must be documented, reviewable, and challengeable.
- Effectiveness — the evidence available shows mass surveillance does not outperform properly resourced targeted methods.
Want the short version? This chapter is the legal case in full. For the plain-English answer to "doesn't this just help criminals?" — read Privacy Is a Fundamental Right — Not an Optional Privilege, our direct answer built on the same foundation.
Want the deeper technical detail?
This web edition covers the openly-published parts of the whitepaper. Evaluators, auditors, and partners can request the full technical brief under agreement.