Double encryption is insufficient for re-randomization: Colluding source and destination can re-link incoming and outgoing ciphertexts since the original incoming ciphertext can be reconstructed from the re-encrypted one.
Possible solutions:
- symmetric proxy-reencryption
- fallback to ElGamal