EU Extends Controversial Voluntary Chat-Scanning Regime Until 2028

The Council of the European Union has given its final approval to a temporary regulation allowing online communications providers to resume voluntary detection of child sexual abuse material, reinstating a controversial exemption from European privacy rules until 3 April 2028.

The decision, announced on 23 July, completes the legislative process after the European Parliament adopted an amended position earlier in the month. The regulation will be published in the Official Journal of the European Union and will enter into force three days after publication, making it directly applicable throughout the bloc.

EU officials describe the measure as an interim child-protection instrument intended to close a legal gap while lawmakers negotiate permanent rules for preventing and combating online child sexual abuse. Critics refer to the arrangement as “chat control,” arguing that it permits private companies to examine communications that users reasonably expect to remain confidential.

The legislation does not impose a general obligation on companies to scan messages. Instead, it provides a legal exemption under which eligible providers may voluntarily use specified technologies to identify suspected child sexual abuse material, detect possible solicitation of children, report cases to law-enforcement authorities or recognised organisations, and remove illegal material from their services.

The exemption concerns provisions of the EU’s ePrivacy Directive that protect the confidentiality of electronic communications and associated traffic data. Messaging, webmail and internet-calling services were brought more clearly within those confidentiality rules in 2020 when the European Electronic Communications Code expanded the definition of electronic communications services.

Without a specific exemption, providers processing message content or traffic data for voluntary abuse-detection programmes could risk breaching those confidentiality obligations. The temporary regulation therefore allows narrowly defined processing for child-protection purposes, provided that companies comply with the General Data Protection Regulation and with additional safeguards written into the legislation.

The most politically significant safeguard is the exclusion of end-to-end encrypted communications. The final text states that the regulation does not apply to interpersonal communications to which end-to-end encryption “is, has been or will be applied.” It also says that nothing in the legislation should be interpreted as prohibiting or weakening end-to-end encryption.

The provision means that protected chats on services using genuine end-to-end encryption fall outside the temporary derogation. Services widely associated with encrypted private messaging, including Signal and encrypted WhatsApp conversations, were cited in reporting on the agreement. The precise treatment of individual platform functions may still depend on whether a particular communication is end-to-end encrypted.

Audio communications are also excluded. For services remaining within the framework, the regulation permits the processing of images, video, text and related traffic data only when the activity is strictly necessary for detecting and reporting online child sexual abuse or removing identified material.

Technologies described in the legislative text include hashing systems, which compare images or videos against non-reversible digital signatures linked to previously verified abuse material. Providers may also employ classifiers and artificial-intelligence systems to analyse relevant content or communication patterns.

Text-scanning technologies are subject to additional limitations. The regulation says they must not be capable of deducing the substance of communications and may be used only to identify patterns indicating possible child sexual abuse. Systems designed to detect grooming or solicitation must rely on relevant indicators and objectively identified risk factors, such as a significant age difference and the likely involvement of a child.

The legislation requires providers to use technologies that are considered state of the art and as minimally intrusive as reasonably possible. Companies must limit processing to the content and traffic data that are strictly necessary for the permitted purpose, conduct data-protection impact assessments and consult competent supervisory authorities where required under EU law.

Providers must also take steps to minimise false positives. The technologies used must be sufficiently reliable, errors must be limited as far as possible, and the consequences of mistaken detections must be corrected without delay. Material that has not previously been verified as child sexual abuse material, as well as suspected grooming cases, cannot be reported externally without human confirmation.

Human oversight is therefore a central condition of the derogation. Companies relying on the regulation must establish procedures to prevent unauthorised access, misuse or transfer of personal data. They must ensure human supervision of automated processing and provide intervention where necessary before consequential action is taken.

A smartphone displaying a messaging application near European Union symbols as lawmakers debate online child-protection and privacy rules.

Users must be informed clearly when a provider relies on the exemption. That notice must explain the logic of the detection measures, their effect on communications confidentiality and the possibility that personal data may be shared with law-enforcement agencies or organisations working against child sexual abuse.

Where content is removed, an account is blocked or access to a service is suspended, the affected user must receive information about available complaint and appeal procedures. Those options include internal redress with the provider, complaints to a data-protection supervisory authority and access to an effective judicial remedy.

Data-retention rules are also intended to limit the privacy impact. Information processed under the scheme must be deleted when it is no longer strictly necessary. When suspected abuse is detected, relevant data may be retained securely for reporting, investigation, legal proceedings, responding to user complaints or preventing repeated abuse, but the temporary framework sets limits on such storage.

The regulation introduces extensive transparency obligations. Within six months of its entry into force, and by 31 January each year thereafter, participating providers must publish and submit reports to the European Commission and the competent national supervisory authority.

Those reports must describe the types and volumes of data processed, the legal grounds used under the GDPR, any basis for transferring personal data outside the European Union and the number of suspected abuse cases identified. Providers must distinguish between child sexual abuse material and suspected solicitation of children.

Companies will also be required to disclose the number and proportion of false positives produced by each technology, the measures used to reduce errors, the outcomes of user complaints, applicable retention policies and the organisations with which data have been shared.

Member states will separately be expected to publish statistics on reports submitted to national law-enforcement authorities, children identified through action under the regulation and perpetrators convicted. The European Commission must use those figures in an implementation assessment examining the proportionality, effectiveness and technological development of the temporary system.

The restored framework follows an unusually contentious legislative sequence. The original temporary derogation was adopted in 2021, when changes to EU telecommunications law created uncertainty over whether providers could continue voluntary detection programmes that had previously operated under the GDPR.

That legislation was presented as a short-term bridge pending adoption of a permanent EU regulation. It was later prolonged through 3 April 2026, but negotiations over the permanent framework remained unresolved as the expiry date approached.

The European Commission proposed another two-year extension in December 2025. Parliament declined in March 2026 to prolong the interim arrangement, allowing it to expire on 3 April. The lapse left providers without the EU-level ePrivacy exemption that had underpinned voluntary detection programmes.

Child-safety organisations and major technology companies warned that the interruption could sharply reduce the number of reports sent to investigators and organisations specialising in the identification of victims. Supporters of reinstatement said voluntary systems had helped rescue children, prevent repeated circulation of abuse material and identify offenders operating across national borders.

Privacy advocates maintained that those objectives did not justify scanning communications belonging to millions of people who were not suspected of an offence. They also questioned the accuracy of automated tools, particularly technologies seeking to interpret text or detect grooming patterns rather than matching known illegal images.

The file returned to Parliament before the summer recess following renewed political pressure to restore the exemption. Lawmakers reconsidered it under an accelerated procedure, limiting the time normally available for committee examination and amendment negotiations.

Although a large number of members opposed the measure, opponents did not secure the absolute majority required to block it under the procedure used. Parliament consequently adopted its position on 9 July, including the amendment excluding end-to-end encrypted communications.

A smartphone displaying a messaging application near European Union symbols as lawmakers debate online child-protection and privacy rules.

Political divisions crossed traditional parliamentary group lines. Supporters emphasised the immediate protection of children and the need to prevent an extended regulatory vacuum. Opponents argued that the process and the substance of the measure weakened privacy rights and risked future challenges before the Court of Justice of the European Union.

The Council accepted Parliament’s amendments rather than reopening interinstitutional negotiations. According to Euronews, 25 EU governments supported adoption through a written procedure, while one government opposed the text and another abstained.

The Council said its acceptance of the encryption exclusion was based on the specific purpose and limited duration of the interim measure. It explicitly cautioned that this decision should not be interpreted as committing member states to an identical position in negotiations over the permanent child-sexual-abuse regulation.

That distinction is important because the long-term proposal is broader than the voluntary derogation approved on Thursday. The permanent framework, originally proposed by the Commission in May 2022, has generated prolonged disagreement over detection orders, risk assessments, age-verification requirements and the treatment of encrypted services.

Member states and Parliament have struggled to reconcile child-protection objectives with the EU Charter of Fundamental Rights, which protects privacy, personal data and the confidentiality of communications. Security researchers and encrypted-service providers have repeatedly warned that systems designed to inspect content before or after encryption could create exploitable weaknesses, even when formally described as preserving encryption.

Child-protection advocates argue that excluding encrypted environments leaves a significant blind spot because offenders may deliberately migrate to services where automated detection is unavailable. Privacy and cybersecurity groups respond that weakening secure communications would expose children, journalists, businesses, public officials and abuse survivors to additional risks from criminals and hostile governments.

The temporary regulation acknowledges both sides of that debate. Its recitals describe end-to-end encryption as an important mechanism for protecting users, including children, and warn that any weakening could be exploited by malicious actors. The text also recognises that private communications may connect victims with lawyers, trusted adults or support organisations.

At the same time, the legislation states that voluntary provider activity can contribute to identifying and rescuing victims, reducing repeated distribution of abuse imagery and assisting investigations and prosecutions. The policy is therefore framed as a limited and supervised exception rather than a general change to Europe’s confidentiality rules.

For technology companies, the immediate consequence is the restoration of an EU-wide legal route for qualifying voluntary programmes once the regulation enters into force. Participation will remain optional, but companies choosing to scan eligible services must demonstrate compliance with the regulation’s necessity, proportionality, transparency and data-protection requirements.

National data-protection authorities will monitor processing under the framework using their GDPR powers. The Commission is expected to request guidance from the European Data Protection Board to help authorities evaluate whether existing and new technologies have an adequate legal basis and meet the required standards of accuracy and privacy protection.

The regulation will cease to apply on 3 April 2028. It could effectively be superseded earlier if the EU adopts and implements the permanent child-sexual-abuse framework before that date.

The renewed deadline gives the Council, Parliament and Commission less than two years to settle questions that have already resisted agreement for several legislative cycles. Failure to do so could produce another debate over temporary extension, while adoption of a permanent system would shift the dispute from voluntary detection to binding and potentially more expansive obligations.

Thursday’s decision consequently resolves the immediate legal gap but not the underlying conflict. The European Union has restored voluntary detection powers under tighter encryption protections, while postponing the final determination of how far digital communications may be monitored in the name of combating child sexual abuse.

Leave a Reply

Your email address will not be published. Required fields are marked *

The Swedish Post

The Swedish Post is Sweden’s independent voice for international readers, offering clear analysis and trusted news on Nordic affairs.