//

EU Revives Controversial Chat Scanning Plan as Battle Over Privacy and Child Protection Returns

The European Parliament has backed extending voluntary message scanning until 2028, reopening a debate over digital surveillance, encrypted communications, and the future of online child protection.

4 mins read
A Representational Image

The European Union has once again thrust one of its most contentious digital policy debates back into the spotlight after lawmakers voted to revive plans allowing technology companies to voluntarily scan certain private communications for child sexual abuse material. The decision, which extends an existing exemption until 2028, marks a significant shift only months after the European Parliament had allowed the measure to expire, reigniting a dispute that has divided lawmakers, technology experts, civil rights organizations, and law enforcement authorities.

According to reporting by Die Zeit, the renewed debate centers on what has become widely known as “chat control,” an umbrella term describing proposals that would enable or require digital platforms to examine electronic communications for illegal child sexual abuse content and report suspected material to law enforcement agencies. Although the current proposal concerns only voluntary scanning of unencrypted communications, broader discussions over scanning encrypted messages continue to shape the political and public debate.

The issue has developed against the backdrop of the European Union’s efforts to prevent the online spread of images and videos depicting the sexual abuse of children. Because much of today’s digital communication passes through major technology companies such as Meta and Google, European policymakers have argued that these platforms play an essential role in identifying illegal material before it circulates further. The proposed system would allow companies to search digital messages for such content and alert authorities when suspected material is detected.

The legal framework surrounding these practices has shifted repeatedly in recent years. European privacy laws generally do not permit companies to monitor users’ private communications. To address concerns about detecting child sexual abuse material, the European Union introduced a temporary legal exemption in 2021 that allowed companies to voluntarily scan messages and share reports with law enforcement agencies. Technology firms operated under that exemption until early 2026.

That arrangement came to an end after the European Parliament decided in March 2026 not to continue supporting the temporary measure, allowing it to expire at the beginning of April. The latest parliamentary vote, however, reverses that course by approving an extension of the exemption through 2028. The legislative process has not yet concluded, but if the decision ultimately remains in place, messaging platforms will once again be permitted to carry out voluntary scans of eligible communications. Importantly, the measure does not require companies to perform such scans.

The renewed proposal also addresses one of the most sensitive aspects of the wider debate: end-to-end encryption. Popular messaging services including WhatsApp, Signal, and iMessage rely on end-to-end encryption, meaning messages can only be read on the sender’s and recipient’s devices. Even the companies operating those services cannot access the content while it is transmitted.

The European Parliament has explicitly stated that communications protected by end-to-end encryption should not fall within the scope of the current exemption. In its position, messages that use or have used end-to-end encryption are excluded from the voluntary scanning framework. As a result, encrypted WhatsApp conversations would not be automatically searched under the proposal now under consideration.

Despite that exclusion, the future of encrypted communications remains unresolved. Over the past several years, European institutions have repeatedly examined whether encrypted messages could be scanned before encryption occurs through a process known as client-side scanning. Under that approach, messages would be analyzed directly on a sender’s device before being encrypted and transmitted. Earlier proposals involving client-side scanning, sometimes referred to by critics as “Chat Control 2.0,” prompted widespread opposition from technical experts and privacy advocates before ultimately failing to secure approval. While those proposals were not adopted, discussions surrounding encrypted message scanning remain part of the broader legislative process and have not been permanently abandoned.

Under the current extension, only unencrypted digital communications would potentially be subject to voluntary scanning. These include services such as email as well as direct messages exchanged on platforms including Instagram and Discord, where end-to-end encryption is not universally applied.

The latest parliamentary vote has generated significant political controversy not only because of its substance but also because of the manner in which it returned to the legislative agenda. The European Union continues to negotiate a permanent legal framework governing chat scanning, a process expected to take considerable time. After lawmakers rejected extending the temporary exemption earlier in the year, many observers were surprised when the issue quickly resurfaced before Parliament’s summer recess.

The Council of the European Union supported extending the exemption but did not include the Parliament’s explicit exclusion for encrypted communications when forwarding its position. The European People’s Party, which includes Germany’s CDU and CSU parties, subsequently requested an expedited procedure to secure a parliamentary vote before lawmakers adjourned for the summer.

That procedural move drew criticism from several quarters. Konstantin Macher of the organization Digitale Gesellschaft argued in comments to netzpolitik.org that the Parliament’s previous position had effectively been overturned through what he described as a procedural maneuver ahead of the summer break. FDP Member of the European Parliament Moritz Körner also criticized the process, commenting that votes appeared to continue until the desired outcome was achieved.

Supporters of maintaining voluntary chat scanning point to its role in helping authorities investigate online child sexual abuse. Law enforcement agencies have repeatedly emphasized the value of reports submitted by major United States technology companies in identifying criminal cases involving abusive material. According to Germany’s Federal Criminal Police Office, the Bundeskriminalamt, more than 40,000 cases involving the production, distribution, acquisition, or possession of child sexual abuse material were recorded in 2024, highlighting the scale of the issue facing investigators.

Opponents, however, question both the effectiveness and necessity of the scanning system. Reporting by netzpolitik.org indicated that Germany’s Federal Criminal Police Office continued receiving around 500 reports each day even after the temporary exemption had expired. Meanwhile, hundreds of scientists warned in an open letter last autumn that current technology cannot identify child sexual abuse material with what they described as acceptable accuracy. Civil rights organizations have also argued that scanning all unencrypted communications represents an excessive intrusion into personal privacy by treating the entire population as potential suspects. They have expressed even stronger objections to proposals involving encrypted communications.

The legislative process is far from complete. Because the European Parliament rejected proposals that would have affected end-to-end encryption, the legislation now returns to the Council of the European Union. The Council has three months to consider Parliament’s amendments. It may either accept the revised position or proceed to negotiations through a conciliation committee, ensuring that the future of Europe’s chat scanning rules remains the subject of continued political and legislative debate.

Sri Lanka Guardian

The Sri Lanka Guardian is an online web portal founded in August 2007 by a group of concerned Sri Lankan citizens including journalists, activists, academics and retired civil servants. We are independent and non-profit. Email: editor@slguardian.org

Leave a Reply

Your email address will not be published.

Latest from Blog