On July 9, 2024, the European Parliament made a decision that many experts have already called a "procedural knockout" for privacy. The temporary regime for scanning private messages, known as Chat Control 1.0, was extended until April 3, 2028. The irony is that 314 of the 607 deputies present voted against the extension, 276 voted in favor, and 17 abstained. However, blocking the document required an absolute majority of the entire parliament — 361 votes out of 720. Thus, the formal "no" from the majority of those present did not become a legal "no."

The reinstated regime returns us to the ePrivacy rules, which allow internet platforms to voluntarily scan unencrypted messages for material related to child sexual abuse (CSAR). This is not a mandatory measure: platforms decide for themselves whether to participate in the program. It is worth recalling that back in 2021, Google, Meta, and Microsoft joined this scheme, targeting Gmail, Snapchat, Skype, Instagram, Facebook Messenger, Xbox, and Apple's mail services. WhatsApp and Signal, thanks to end-to-end encryption, remain out of reach — server-side scanning is technically impossible for them. Deputies even adopted an amendment excluding services with end-to-end encryption, but the EU Council must approve it within three months.

Crisis of Effectiveness and Trust

Critics of the regime, including former MEP Patrick Breyer, call what is happening a "farce damaging democracy." And their arguments deserve attention. Official data shows that since 2022, the volume of reports on alleged abuse has decreased by 50% — a direct consequence of the increased use of encryption. According to the European Commission, scanning private chats accounted for only 36% of all abuse reports in 2024. The rest came from public posts and cloud storage. Germany's Federal Criminal Police Office adds that 48% of incoming signals have no criminal relevance, and 40% of investigations involve minors themselves. Meanwhile, 99% of reports from Meta concern already known cases.

The voice of abuse victims is particularly telling. Alexander Hanff, a survivor of sexualized violence, emphasizes that confidential communications allowed him to report what happened and secure the conviction of the perpetrators. Marcel Schneider, who is suing Meta over voluntary Chat Control, argues that mass corporate surveillance does not prevent violence. Real protection, in his view, requires removing materials at the source, proactive police work on the darknet, and secure application architecture.

My analysis: The current vote is only a temporary measure. The main conflict is shifting to the permanent CSAR regulation, already dubbed "Chat Control 2.0." The real threat to privacy is not voluntary scanning, but the creation of a precedent where procedural tricks allow the will of elected representatives to be ignored. If Europe wants to protect children, it needs not mass surveillance, but targeted, cryptographically sound methods that do not undermine the very architecture of privacy. Otherwise, we risk getting a law that does not catch criminals but erodes trust in the EU's digital infrastructure.