The European Parliament building in Strasbourg, France, with rows of EU member state flags flying in the evening light
Photo via Unsplash

TL;DR: On March 26, the European Parliament voted 311-228 to reject extending the Chat Control 1.0 ePrivacy derogation, the legal loophole that let Google, Meta, Microsoft, and TikTok voluntarily scan your private messages for child abuse material. That derogation expires April 3, 2026. Tomorrow. Without it, platforms have no legal basis to scan unencrypted messages under EU law. But don't celebrate too hard: the permanent CSAR regulation (which would mandate scanning, including on encrypted platforms) is still alive. Trilogue negotiations resume May 4, with a target deal by July 2026.

What the Parliament Actually Killed

Quick background. Since 2021, EU Regulation 2021/1232 gave tech companies a temporary pass: they could voluntarily scan private messages for known child sexual abuse material (CSAM), new CSAM, and grooming behavior, even though this scanning technically violates the EU's ePrivacy Directive.[1]

That regulation was always meant to be temporary. A bridge until the permanent CSAR rules got sorted out.

The permanent rules never got sorted out.

So the Commission asked for an extension to April 2028. Two more years of voluntary scanning. Parliament said no.

Here's the timeline of how it fell apart:

  • March 11, 2026: Parliament votes 458 in favor of a compromise: extend scanning, but with strict conditions. Judicial authorization required. Only targeted scanning, not mass surveillance. Member states in the Council rejected these restrictions.
  • March 26, 2026: After the Council refused the compromise, Parliament gets a second vote on the Commission's original clean extension. Votes 311-228-92 to reject it outright.[2]
  • March 27, 2026: EU governments scramble. Leaked documents show discussion of pushing a political deal through a Council meeting of fisheries ministers, "an unusual but procedurally possible route," according to internal cables.[3]

That fisheries minister gambit didn't work. The derogation dies tomorrow.

What Actually Changes on April 3

Three types of scanning lose their legal basis:

  • Hash scanning: Matching known CSAM images against a database (PhotoDNA-style)
  • Automated image assessment: AI classifying new images as potential CSAM
  • Text analysis: Algorithms flagging conversations as potential grooming

The platforms doing this voluntarily: Google (Gmail, Google Chat), Meta (Facebook Messenger, Instagram DMs), Microsoft (Outlook, Xbox), and TikTok. Apple had its own client-side scanning plan for iCloud but famously scrapped it after backlash.

What this means in practice: these companies can no longer scan your unencrypted messages for CSAM under EU jurisdiction without violating ePrivacy rules. They'll either have to stop, find a different legal basis (the Digital Services Act's general monitoring prohibition makes this tricky), or face regulatory action.[4]

End-to-end encrypted platforms like Signal and WhatsApp were never doing this scanning anyway. Nothing changes for them today.

The Scanning They're Losing Was Terrible Anyway

Here's what the "voluntary" scanning actually looked like, according to the European Commission's own evaluation:[5]

  • 13-20% false positive rate on automated image assessment
  • 0.0000027% of billions of scanned messages contained actual illegal content
  • Germany's federal police (BKA): nearly 50% of reports were criminally irrelevant
  • Among German suspects flagged: roughly 40% were minors, often acting without criminal intent

Reports from voluntary scanning dropped 50% since 2022. Only 36% of CSAM reports now originate from chat scanning at all.[5]

Patrick Breyer, the Pirate Party MEP who's been the loudest voice against Chat Control, put it bluntly: "Indiscriminate Chat Control is like trying to mop up water while the faucet is still running."[6]

The actual victims agree. Survivors Alexander Hanff and Dorothee Hahne publicly opposed mass scanning, saying it destroys the safe spaces abuse survivors need to communicate about their experiences.

The Political Battle Behind the Vote

The March votes were a mess. Here's what happened behind the scenes.

On March 11, Parliament passed a compromise position with 458 votes: extend voluntary scanning, but add judicial authorization requirements and limit it to targeted cases. A reasonable middle ground.

EU member states (through the Council) said no. They wanted broader powers. Mass scanning, not targeted scanning. No judicial gatekeeping.

When the Council rejected Parliament's conditions, conservative MEPs in the EPP group tried to force a re-vote on the Commission's original proposal, a clean extension with no restrictions. "We cannot let predators hide in a legal vacuum," they argued.[3]

European Digital Rights (EDRi) shot back: "In democracy we cannot re-vote until we reach the outcome that power players want."[3]

Green MEP Marketa Gregorova added: "A broad democratic majority of the Parliament does not want indiscriminate scanning."[3]

The re-vote happened March 26. Parliament rejected the clean extension 311-228, with 92 abstentions. Game over for Chat Control 1.0.

The Permanent Regulation Is the Real Danger

Here's why you shouldn't relax.

The voluntary scanning was always the opening act. The main event is CSAR (the Child Sexual Abuse Regulation) which would make scanning mandatory and extend it to encrypted platforms. We've covered the details.

Where CSAR stands now:

  • May 4, 2026: Next trilogue negotiation round (Parliament, Council, Commission)
  • June 29, 2026: Second trilogue session
  • July 2026: Target date for a political deal

The Council, representing member state governments, still wants broad scanning powers. The Commission is on their side. Four EU Commissioners signed a statement insisting "the protection of children, not that of perpetrators, must remain the guiding principle of the EU's actions."[7]

Parliament is the only institution pushing back. Their November 2023 position favored targeted surveillance with judicial warrants, not mass scanning. But the Council's own legal service warned in 2023 that the Commission's proposed permanent regulation risks violating Charter Articles 7 and 8 on privacy and data protection through "generalised automated and systemic screening surveillance."[5]

Even the European Data Protection Supervisor (EDPS) said any detection must be targeted, not indiscriminate.

Signal Already Told You What Happens

If CSAR passes in anything close to its current form, encrypted messaging platforms face three options:

  1. Implement client-side scanning (breaking encryption's security model)
  2. Exit the EU market
  3. Remove encryption entirely

Signal president Meredith Whittaker has been crystal clear: they'll leave Europe before compromising encryption. That threat hasn't changed.

The tech lobby is divided. Companies like Meta, Google, Microsoft, and TikTok that were doing voluntary scanning have their own lobbying operations pushing for continued scanning authority. Meanwhile, Thorn (an anti-CSAM software vendor) invests hundreds of thousands annually in EU lobbying, and the ECLAG coalition, backed by non-European foundations, pushes the pro-scanning position.[5]

What to Watch Next

May 4: Trilogue Round 2

The next formal negotiation between Parliament, Council, and Commission on permanent CSAR rules. This is where the real battle lines get drawn.

Platform Responses

Watch what Google, Meta, and Microsoft actually do starting April 3. Do they stop scanning EU messages? Quietly continue and dare regulators to act?

Council's Next Move

Member states failed with the fisheries minister gambit. They'll try something else. The Cyprus presidency has the rotating chair.

July 2026 Target

If a political deal lands by July, expect the full mandatory scanning regulation to move toward adoption. Every privacy group in Europe will be watching.

What You Can Do

If you're in the EU: Contact your MEPs before the May 4 trilogue. Tell them you support Parliament's position of targeted surveillance with judicial warrants, not mass scanning. The EDRi campaign page makes this easy.

If you're anywhere: Use end-to-end encrypted messaging. Signal, not Messenger. The more people depend on real encryption, the harder it becomes for any government to break it.

Today's a win. Voluntary scanning dies tomorrow. But the permanent regulation that could mandate scanning, including on encrypted platforms, is three months from a potential deal. The fight isn't over. It's just entering the final round.

References

  1. EUR-Lex: Regulation 2021/1232 (temporary ePrivacy derogation for voluntary CSAM detection)
  2. Computer Weekly: EU Parliament rejects Chat Control message scanning (March 2026)
  3. EU Perspectives: EU Scrambles to Save Chat Control (March 2026)
  4. CyberInsider: EU votes to block extension of rules allowing private message scanning
  5. Patrick Breyer MEP: The Battle Over Chat Control: Comprehensive Fact Check
  6. Patrick Breyer MEP: Chat Control Tracker
  7. Heise Online: Chat Control: EU Parliament rejects extension again