On July 9, the European Parliament failed to block the extension of the temporary message scanning regime known as Chat Control. Although the majority of voting MEPs opposed it, procedural rules allowed the document to enter into force. Voluntary scanning of private messages on internet platforms is now legal until April 3, 2028.
Of the 607 MEPs, 314 voted against the extension, 276 voted in favor, and 17 abstained. Blocking required an absolute majority of the entire parliament — 361 votes out of 720 — which was not achieved. The reinstated regime is a temporary return to the ePrivacy rules, known as Chat Control 1.0. It allows platforms to voluntarily scan unencrypted or server-accessible messages for child sexual abuse material (CSAR).
Scanning is not mandatory: platforms decide whether to participate. When the regime was first adopted in 2021, Google, Meta, and Microsoft immediately joined. Services operating under this scheme include Gmail, Snapchat, Skype, Instagram, Facebook Messenger, Xbox, and Apple's mail services. However, WhatsApp and Signal remain outside the regime: end-to-end encryption makes server-side scanning technically impossible. MEPs separately adopted an amendment excluding end-to-end encrypted services, but it still needs to be reviewed by the EU Council within approximately three months.
Human rights advocate and former MEP Patrick Breyer called the situation a farce: "The fact that Chat Control is moving forward against the will of the majority of voting MEPs damages democracy. Our children are the real losers in this undemocratic process."
Public opinion and criticism of effectiveness
Critics debate not only privacy but also the effectiveness of mass scanning. According to official data, since 2022, the volume of reports of suspected abuse has decreased by 50% due to increased use of encryption. According to the European Commission, scanning private chats accounted for only 36% of all abuse reports in 2024 — the rest came from public posts and cloud storage. Germany's Federal Criminal Police Office believes that 48% of incoming signals have no criminal relevance, and 40% of investigations involve minors themselves. About 99% of reports from Meta relate to already known cases.
The position of abuse survivors deserves special attention. Alexander Hanff, a victim of abuse and privacy advocate, noted that confidential communications helped him report the incident and secure the conviction of the perpetrators. Marcel Schneider, who is suing Meta over voluntary Chat Control, believes that mass corporate surveillance does not prevent abuse, and real protection requires removing materials at the source, proactive police work on the dark web, and secure application architecture.
The latest vote concerns only the temporary version of the law. The main conflict shifts to the permanent CSAR regulation, which critics call Chat Control 2.0. The situation resembles a classic regulatory paradox: the attempt to protect children through mass scanning undermines the very privacy architecture that is often the only tool for victims to safely report a crime. The cryptocurrency and decentralized communications market should closely monitor this precedent — it could become a model for future attacks on encryption.