On July 9, the European Parliament formally extended the temporary regime for scanning private messages, known as Chat Control 1.0. Despite the majority of voting MEPs opposing it, the document was adopted due to procedural rules. This decision legalizes voluntary scanning of unencrypted messages on internet platforms until April 3, 2028.
Of the 607 MEPs present, 314 voted against the extension, 276 in favor, and 17 abstained. Blocking the document required an absolute majority of the entire parliament — 361 votes out of 720. A simple majority among those present proved insufficient, allowing the initiative to pass.
What is Chat Control 1.0?
The renewed regime is a temporary return to the ePrivacy rules, which allow platforms to voluntarily scan unencrypted or server-accessible messages for child sexual abuse material (CSAR). The regime was first adopted in 2021, and Google, Meta, and Microsoft immediately joined. Services operating under this scheme include Gmail, Snapchat, Skype, Instagram, Facebook Messenger, Xbox, and Apple's mail services.
WhatsApp and Signal remain outside the regime: end-to-end encryption makes server-side scanning technically impossible. MEPs adopted an amendment explicitly excluding services with end-to-end encryption from the provisions, but it must still be reviewed by the EU Council within approximately three months.
Criticism and Effectiveness
Critics debate not only privacy but also the effectiveness of mass scanning. According to data, since 2022, the volume of reports on alleged abuse has decreased by 50% due to the increased use of encryption. According to the European Commission, scanning of private chats accounted for only 36% of all abuse reports in 2024 — the rest came from public posts and cloud storage. Germany's Federal Criminal Police Office believes that 48% of incoming signals have no criminal relevance, and 99% of reports from Meta concern already known cases.
Notably, the position of survivors of abuse stands out. Alexander Hanff, a victim of abuse and privacy advocate, stated that confidential communications helped him report the incident and secure convictions of several perpetrators. Marcel Schneider, who is suing Meta over voluntary Chat Control, believes that mass corporate surveillance does not prevent abuse, and real protection requires removing materials at the source, proactive police work on the dark web, and secure application architecture.
The latest vote concerns only the temporary version of the law. The main conflict shifts to the permanent CSAR regulation, which critics call Chat Control 2.0. The fight for privacy and security in the digital space is expected to intensify.
Expert Opinion: The extension of Chat Control 1.0 is a clear example of how procedural loopholes can outweigh democratic will. While encryption becomes a security standard, regulators' attempts to implement mass scanning undermine trust in digital platforms. Real child protection requires not surveillance of everyone, but targeted actions against criminals.