Supreme Court on crypto-phone evidence: SkyECC and EncroChat in court
The Supreme Court has examined the admissibility of evidence from intercepted encrypted mobile phones in two rulings. The outcome varies depending on the source of the data.

Supreme Court examines admissibility of crypto-phone data in criminal proceedings
The Austrian Supreme Court (OGH) has investigated in two separate rulings whether evidence from encrypted mobile telephones – so-called crypto-phones – may be used in Austrian criminal proceedings when acquired by foreign authorities. As Mondaq reports, the senates reach partly contradictory conclusions, depending on whether the data stems from EU or non-EU sources.
Background: The "federal trojan" and its constitutional history
The covert installation of decryption software on mobile telephones – known in Austrian discourse as a "federal trojan" – has been legally contentious for years. The Constitutional Court declared such measures unconstitutional in December 2019, on the grounds that the serious interference with Article 8 ECHR was not offset by sufficient protective measures. Furthermore, there were no guarantees that monitoring would be limited to the prosecution of serious criminal offences. Since then, the question of a constitutionally compliant new regulation has been at issue.
Two Supreme Court senates, two cases with EU connection
In the rulings 14 Os 107/24b and 11 Os 129/24s, two separate senates dealt with cases in which EU member states installed decryption software without the knowledge of users on crypto-phones – including devices from the SkyECC and EncroChat platforms. The data obtained was subsequently made available to Austrian authorities for criminal proceedings.
The Supreme Court relied on the judgment of the European Court of Justice (CJEU, C-670/22, M.N. [EncroChat]). In it, the CJEU established that infiltrating end devices to collect traffic, location and communication data constitutes "telecommunications surveillance". Pursuant to Article 31 paragraph 1 of Directive 2014/41/EU, the executing foreign authority should have informed the Austrian public prosecutor's office of the measure.
Had such notification occurred, the public prosecutor's office could have informed the foreign authority within 96 hours that surveillance in Austrian territory was impermissible or should be discontinued – and that already collected data could not be used. This provision derives from § 55d paragraph 7 of the EU Judicial Cooperation Act (EU-JZG).
In Austrian law, a prohibition on the use of evidence leads to the nullity of a judgment, provided that the inadmissible evidence was used in the proceedings. However, Austrian law does not recognise a "ripple effect" – that is, the automatic inadmissibility of all subsequent evidence based on it, following the model of the American "fruit of the poisonous tree" doctrine.
The senates did not deliver a final judgment in these cases: it remained unclear whether the foreign authorities had obtained the data in a manner constituting an enforcement obstacle, and whether Austria had been informed of this. These questions are to be clarified in further procedural steps.
Third case: Non-EU authorities and a different outcome
Shortly before the ruling 11 Os 129/24s, another decision (14 Os 14/24a) was issued by the same senate that was responsible for 14 Os 107/24b. The factual situation appears comparable at first glance, but the outcome is fundamentally different.
In this case, foreign authorities – specifically from the United States and Australia – had introduced encrypted mobile telephones with pre-installed decryption capability into allegedly criminal organisations (so-called ANOM phones). In a further operation, the same authorities seized the server of a communications provider that had distributed devices with encryption software to its customers (SKY-ECC phones), thereby making communication conducted via them accessible. Austrian authorities were not involved in these operations but subsequently received the data and used it in a criminal proceeding that resulted in the conviction of a perpetrator.
The Supreme Court ruled that the evidence in this proceeding was admissible and could support the conviction. The decisive difference: the authorities that had instigated the introduction of the mobile phones originated from non-EU states. Accordingly, the provisions of Directive 2014/41/EU, the EU-JZG, and the CJEU case-law on the EncroChat proceeding simply do not apply. Relevant bilateral treaties between Austria and the United States or Australia likewise contain no comparable consequences.
The Supreme Court set out in detail that evidence obtained abroad without the involvement of Austrian authorities – even if it would not have been admissible under Austrian law – is not necessarily inadmissible. The requirement is that no fundamental procedural principle has been violated (for instance, a prohibition on the use of evidence obtained by torture) and that the accused was afforded a legal hearing.
Server seizure in France: distinction remains open
With regard to the seizure of the SKY-ECC server, which took place in France, the Supreme Court hinted at a possible differentiation between active surveillance measures and the securing of servers. A conclusive clarification of this issue is still pending.
Significance for practice
The rulings make clear that the admissibility of crypto-phone data in Austria depends substantially on which state conducted the acquisition measure and whether EU law applies in doing so. Proceedings in which foreign EU authorities have infiltrated encryption devices face significantly higher admissibility hurdles than those in which data stem from non-EU states. Criminal courts will have to assess these questions on a case-by-case basis in the forthcoming procedural rounds.
Source: Mondaq