It most certainly can. This was already a contentious issue in Germany, maybe with a slight majority in the government in favor of it or at least people who support it in the right places to implement it, but it was far from an uncontroversial issue, even inside the government (i.e. the coalition parties). Germany was already the last country not to have data retention. (Of course also because the constitutional court ruled against it, but political pressure against it was responsible, too.)
The government could ram it through when there were no court objections quite yet but with them the dissenting voices inside government certainly get amplified. Also, while violating the constitution has been quite a sport for the government in Germany in recent years, court decisions that ruled laws unconstitutional have been respected.
I’m quite optimistic, but there obviously remains a danger of this being implemented some years down the line.
I have no idea what this means on the European level and for other individual countries, though.
When it comes to security, don't live in hope that the bad actors (in this case, governments) won't do what's possible because of something that's fungible (law).
I’m quite willing to believe that there are bad actors within the government, I do not believe that the government as a whole could be characterised as a bad actor regarding security.
Also, while secret services may do all kinds of bullshit hidden in the dark something like the data retention law is out in the open and consequently comparably much easier to contain. It’s possible to have a proper discussion about it. (I think this also quite neatly illustrates the value of having those discussions out in the open, both when it comes to the courts that decide on it and to the political pressures. If it happens in secret it is much, much harder to control and contain. Policy that is decided on in secret – even if by elected representatives or people appointed by elected representatives – is just much more dangerous.)
At least in Germany it wasn't the government collecting the data, they simply forced the ISPs to do so. And when the court ruled the law invalid the ISPs were more than happy to stop the data retention because it cost them a lot of money.
ah so instead of properly security cleared people in one or two security services having access to it every ISP from DBP down to a mom and pop organization may have access.
Will the average ISP pay to put all its staff who have acess to those records with access through TS (DV clearance) clearance its not cheap. And what happens when some of the staff fail vetting - oops your now out of a job.
Oh and this woudl mean that ISP's would have to have judicial oversight.
Of course it can not. But making it illegal is a huge step towards the right direction. Now if the EU members abide to this ruling, it will make it very hard for government officials to get away with alleged privacy breaches.
While I'm not assuming Germany's system is perfect, it is very likely some governments operate more under the consent of the governed than the US government.