Politics

EU extends private message scanning rules until 2028

EU private message scanning rules will remain in place until 3 April 2028, allowing technology companies to voluntarily examine certain messages and emails for material linked to child sexual abuse. The European Parliament allowed the temporary exemption from EU communications privacy law to proceed despite more lawmakers supporting its rejection than its continuation.

The regulation, often described by critics as Chat Control 1.0, permits providers of online communication services to use automated technologies to detect, report and remove child sexual abuse material.

The rules cover services operated by companies such as Meta, Google and Microsoft. Communications protected by end-to-end encryption, including encrypted conversations on services such as Signal and WhatsApp, remain outside the scope of the temporary measure.

Why the EU extended private message scanning

The measure creates a temporary exemption from parts of the ePrivacy Directive, which normally protects the confidentiality of electronic communications.

EU institutions argue that the exemption allows platforms to continue identifying images, videos and other content connected to the sexual abuse of children. Providers may report suspected material to law enforcement authorities and remove it from their services.

The Council of the European Union said voluntary detection can help identify victims, investigate offenders and limit the circulation of abuse material.

The original temporary regulation entered into force in 2021. It was extended in 2024 but expired on 3 April 2026 after the European Parliament and the Council failed to agree on another extension.

The new measure is intended to close that legal gap while negotiations continue over a permanent European framework.

More MEPs opposed the measure than supported it

The outcome has attracted criticism because 314 members of the European Parliament voted to reject the Council’s position, while 276 voted against rejection and 17 abstained.

However, rejecting or amending a Council position during the second reading of the EU legislative process requires an absolute majority of all members of Parliament, rather than a majority of those taking part in the vote.

Opponents therefore failed to reach the required threshold. According to Parliament’s briefing for the plenary session, the absolute-majority requirement stood at 360 MEPs under its current composition.

The Council had adopted its position on 2 July, triggering the second-reading procedure. Without the required absolute majority to block or substantially change the text, the temporary framework was allowed to proceed.

End-to-end encrypted messages remain excluded

The temporary rules do not apply to communications that use end-to-end encryption, a system in which only the sender and recipient can access the content.

This protection is used by several messaging services, including Signal and encrypted WhatsApp conversations. It prevents the platform itself from reading messages while they are being transmitted.

Encryption remains one of the central issues in the wider EU debate. Privacy advocates argue that scanning encrypted conversations would require providers to weaken their security systems or examine content before encryption takes place.

Jannike Tillå of the Swedish Internet Foundation (Internetstiftelsen) told SVT that requiring companies to disclose information without a concrete suspicion of a crime could threaten digital privacy.

Critics also warn that allowing the systematic examination of private communications could create a precedent for surveillance in other areas.

Supporters maintain that platforms need effective tools to detect abuse material and identify children who may still be at risk.

Chat Control 1.0 and the permanent EU proposal

The extended exemption is separate from the proposed permanent legislation commonly known as “Chat Control 2.0”.

The European Commission presented the permanent framework in 2022. The proposal would establish long-term obligations for technology companies to prevent and address child sexual abuse online.

Negotiations between the European Parliament, the Council and the Commission have continued for several years. Disagreements have focused on the possible scanning of encrypted communications, age-verification requirements and the risk of indiscriminate monitoring.

Parliament adopted its negotiating position on the permanent regulation in November 2023. The Council reached its position in November 2025, allowing interinstitutional negotiations to begin.

The temporary exemption will apply until 3 April 2028, unless the permanent legislation enters into force earlier. The debate will therefore continue to centre on how the EU can protect children online without weakening encryption and the confidentiality of private communications.

Shares:

Related Posts