Two rights, one impossible law: Chat control and child protection in the EU
By: Antonio Manuel Torres García
Reading time: 5 minutes
Image by Tumisu via Pixabay
Imagine every message you send being read by someone else. Would you accept that if it meant combating the spread of child sexual abuse material (CSAM)? This question, at the centre of a crossroads between child protection and your own privacy, has become increasingly relevant during July 2026. While this is not necessarily breaking news (given its long trajectory), the debate has been fiercely reignited for those who care about either cause and closely follow EU legislative developments. And not in vain.
On 9 July 2026, the European Parliament failed to reject, at second reading, a Council text commonly known as Chat Control 1.0. The Council has since given its final approval, confirming the text on 23 July 2026. In a nutshell, this means that until 3 April 2028, certain providers of number-independent interpersonal communication services (think webmail, messaging platforms, some apps) will be able to voluntarily scan content and traffic data in search of CSAM with the purpose of reporting it. This article will help you understand the context behind the law and the conundrum this question poses.
Chat Control, broken down
The first thing to keep in mind is that, as the name suggests, the series does not involve a single law, but two. These are widely known as Chat Control 1.0 and Chat Control 2.0.
For its part, Chat Control 1.0 lays down a temporary derogation from the ePrivacy Directive, more precisely from its Articles 5(1) and 6(1), which protect the confidentiality of communications and traffic data. This carve-out lets providers of number-independent interpersonal communication services (NI-ICS) voluntarily scan content and traffic data to detect and report CSAM to the relevant authorities without this breaching ePrivacy rules. For clarification, NI-ICS is the technical term for messaging or calling services that don’t rely on the traditional phone number system to connect people, like WhatsApp, Gmail, or Skype, as opposed to a regular phone call or SMS. Effectively, the derogation removes a legal barrier that would otherwise render such scanning illegal.
However, this is not a new phenomenon. Regulation (EU) 2021/1232 was the original piece of legislation introducing the derogation, later extended until April 2026 by Regulation (EU) 2024/1307. After it expired, and given disagreement between Parliament and Council on a second extension, the law was revived via an expedited procedure by the Council (11261/1/26, adopted 2 July 2026). Technically, this made it a "new" regulation, though its content was identical to the expired one. The Parliament was set to vote on rejecting it on 9 July 2026, but failed to gather the majority necessary to do so. As a result, the law was approved in second reading, with a new expiry date of 3 April 2028. The Council gave its final confirmation on 23 July 2026.
Chat Control 2.0, on the other hand, takes the same idea as Chat Control 1.0 but pushes it further, making it permanent (hence its formal name, the CSA Regulation). The Commission proposed it in May 2022, and as of the time of writing it remains stuck in trilogue negotiations. The two main points are whether scanning becomes mandatory, rather than voluntary, with sanctions for non-compliance, and whether it extends to end-to-end encrypted services (WhatsApp, Messenger, Telegram, etc.), which Chat Control 1.0 does not touch. Remarkably, the Council Legal Service was already flagging, in 2023, that this can amount to general and indiscriminate scanning that may seriously interfere with the rights to privacy and protection of personal data under Articles 7 and 8 of the EU Charter of Fundamental Rights. In practice, this means that no message would be presumptively private. The possibility of automated scanning could apply to any conversation, regardless of whether there is any suspicion of wrongdoing.
Chat Control 1.0’s approval
Rejecting a Council position at second reading under the ordinary legislative procedure requires an absolute majority of Parliament's component members, which currently is 360 MEPs, rather than a simple majority of those voting. In practice, this means that MEPs who are absent or abstain count in favour of the Council’s text, since only a “yes” vote to reject can stop it.
On 9 July 2026, a first rejection attempt got 314 votes in favour, 276 against, and 17 abstentions, short of the 360 threshold. A second rejection attempt, after Renew Europe’s end-to-end encryption carve-out amendment was included, got 276 in favour, 286 against, and 30 abstentions; not even a majority of votes cast. Thus, Parliament’s silence is treated as acceptance of the Council’s text, and the regulation is deemed adopted. It is worth noting that this mechanism is a long-standing feature of the ordinary legislative procedure (Article 294 TFEU, Rule 68 of Parliament’s Rules of Procedure). Still, it allows a law to pass even though more MEPs who voted opposed it than supported it. Strikingly, MEP Birgit Sippel, as rapporteur leading the file, voted against it.
On 23 July 2026, the Council confirmed the text via written procedure, a simplified process normally reserved for non-controversial files that lets member states register their vote without holding a formal meeting. The file was confirmed adopted with 25 member states in favour, one against, and one abstention. Chat Control 1.0’s revival is now fully law.
Some thoughts on the law
Chat Control 1.0 is a particularly divisive piece of legislation. This is, among other things, because it requires the balancing of two weighty rights. Both the protection from child sexual abuse (a serious, irreversible harm to a child) and the right to confidentiality of communications (a fundamental right, Art. 7 Charter) are deemed as carrying utmost importance in different legal traditions. Hence, it represents a “harm vs. harm” situation, unlike other privacy debates, which weigh rights against convenience. Think targeted advertising, which requires more data, but provides a more personalised online experience where no one’s particular safety is at stake.
Supporters of the measure point to the scale of the problem it addresses. Voluntary scanning under Chat Control 1.0 has led providers such as Microsoft and Google to flag thousands of detections of suspected CSAM in EU-linked content in a single year. Europol’s executive director, Catherine De Bolle, called this detection work “vital for the protection of children”.
However, and notably, the very efficacy of the measure is contested. There is disagreement on whether mass scanning is even the right tool: the Commission’s own implementation report acknowledges that data limitations make it impossible to establish a clear link between specific reports and convictions (though the report itself concludes there is no indication the measure is disproportionate), and, according to figures cited by former Commissioner Johansson, around 75% of flagged chats turn out not to be actionable, often resulting in suspended accounts or referrals potentially before a human reviews the case. As Patrick Breyer, a digital rights activist and former MEP, put it, mass surveillance carried out by Big Tech companies resembles, if anything, "the illusion of security.”
There is, also, the matter of precedent. Once scanning infrastructure exists and is normalised for one purpose, it becomes easier to extend it to others. A system designed to detect CSAM could, in principle, be repurposed, or required by a future law, to detect other categories of content, whether this be other crimes or copyrighted material, in the EU or in jurisdictions with weaker safeguards. The potential dual use of these technologies raises the stakes and presages potential expansion in the future.
On the privacy side, this can be regarded as generalised surveillance without suspicion. Rather than targeting specific individuals on the basis of a warrant, the derogation permits scanning the communications of every user, guilty or not. The picture is stark: companies without oversight prying, without a warrant, on an uncountable number of conversations. As MEP Ignazio Marino put it, “any scanning of the content of private communications must be limited to specific suspects.”
In general, all that is left is a controversial and divisive law that a majority of voting MEPs rejected and that was pushed through on a procedural technicality. In these circumstances, Chat Control 1.0 deserves scrutiny regardless of which side of the debate you're on. All things considered, if it were on your hands, do you value your privacy and fear for misuse, or would you relinquish part of it for the sake of protecting children?