EU Extends Controversial Chat-Scanning Regime Until 2028

 

The European Union has temporarily extended its controversial chat-scanning regime until April 2028, allowing messaging platforms to voluntarily detect child sexual abuse material (CSAM) while exempting end-to-end encrypted apps like WhatsApp and Signal. This decision, approved by 25 EU member states, continues a contentious debate over balancing child protection with fundamental privacy rights in digital communications. 
Modus operandi of extension under EU law 
The temporary framework operates as a derogation from the EU's ePrivacy Directive, permitting tech companies including Meta, Google, and Microsoft to scan unencrypted messages and emails for known CSAM without requiring judicial authorization. Originally introduced in 2021 as Regulation 2021/1232, the measure was designed as a stopgap until permanent legislation could be finalized, but ongoing negotiations have delayed comprehensive reform. The European Parliament initially rejected the extension in March 2026 before reviving it in July through a procedural vote where opponents failed to secure the absolute majority needed to block the Council's position. 

Under the extended rules, scanning remains voluntary for platforms and applies only to unencrypted communications, explicitly excluding end-to-end encrypted messaging services.  MEPs successfully amended the text to narrow the scope, limiting detection to previously known CSAM or content reported by trusted flaggers rather than enabling proactive, algorithmic scanning of all messages. Privacy advocates argue this carve-out protects encrypted apps but warn the voluntary regime still creates a dangerous precedent for mass surveillance of private digital conversations. 
Digital rights organizations including EDRi have condemned the extension as "Chat Control," arguing it permits companies to deny citizens' right to confidential digital conversations by reading every message, email, and image shared on their platforms. Several MEPs, particularly from the Greens/EFA and radical left groups, voted against the measure, contending that child protection should not come at the expense of violating the right to secret communications under EU fundamental rights law. Critics also warn the temporary regime could be annulled by the European Court of Justice, potentially undermining both privacy protections and child safety efforts. 
What comes next for EU digital privacy policy 
The temporary extension runs alongside ongoing trilogue negotiations for a permanent "Chat Control 2.0" regulation, which would introduce mandatory risk assessments, detection orders, and potentially binding scanning obligations for platforms. Discussions are set to resume in September 2026, with the European Commission pushing for stronger enforcement mechanisms while Parliament and civil society groups demand stricter judicial oversight and narrower scope. The outcome will determine whether the EU adopts a comprehensive child safety framework or continues relying on voluntary, time-limited derogations from privacy law.

This article has been indexed from CySecurity News – Latest Information Security and Hacking Incidents

Read the original article: