EU Renews Chat Control 1.0: Message Scanning Returns

đź“… Aug 04, 2026

Quick Facts

  • Current Status: The legislation is officially renewed until April 3, 2028.
  • Effective Date: The renewal took effect on July 9, 2026, following a procedural threshold victory.
  • Scanning Type: Platforms may participate in the voluntary scanning of unencrypted communication data.
  • Target Platforms: Major services including Gmail, Instagram DMs, Discord, and Snapchat.
  • Safe Platforms: Signal, WhatsApp, and Proton remain exempt due to end-to-end encryption.
  • Vote Breakdown: A total of 314 against the measure was not enough to meet the 361 votes required for a block.

The EU renewed Chat Control 1.0 in July 2026 through a procedural maneuver, extending the technical ability for platforms to scan unencrypted messages for CSAM until 2028. While a majority of MEPs opposed it, the opposition failed to reach the absolute majority required to block the Council’s regulation, meaning voluntary scanning is now active for many mainstream apps. This current chat control status ensures that while end-to-end encrypted services remain secure, unencrypted communications are subject to automated monitoring under a temporary derogation of privacy laws.

The Procedural Zombie: Chat Control 1.0 vs 2.0

The legal journey of the chat control law feels like something out of a legislative thriller. In April 2026, the previous rules allowing tech companies to scan messages expired, leaving a temporary vacuum. Privacy advocates initially celebrated, but the victory was short-lived. By July, the European Council utilized a procedural maneuver to fast-track a renewal of Regulation 2021/1232. This regulation acts as a temporary derogation from the ePrivacy Directive, which normally guarantees the confidentiality of digital communications.

To understand the current landscape, one must recognize the difference between chat control 1.0 and 2.0. The version currently in effect, 1.0, is a voluntary framework. It allows service providers to choose whether they want to scan unencrypted messages for child sexual abuse material (CSAM). It does not force companies to break encryption. In contrast, the more controversial version 2.0 proposed mandatory scanning for all platforms, including those with end-to-end encryption, utilizing a technology called client-side scanning. While version 2.0 remains stalled due to intense political pressure from Germany and other member states, version 1.0 has been successfully resurrected as a "zombie law."

The political irony of this renewal is found in the voting numbers. When the European Parliament took the floor to discuss the chat control 2026 extension, a clear majority of those present, 314 against, expressed their disapproval. However, due to the specific procedural rules governing Council regulations of this type, an absolute majority of total seats—361 votes—was required to stop the renewal in its tracks. Because the opposition fell short of that absolute threshold, the regulation was extended by default.

Digital data stream and cybersecurity scanning interface showing code and binary elements.
The technological framework for 'Chat Control 1.0' enables providers to voluntarily scan unencrypted data streams for illegal content.

This legislative maneuver has extended the "Chat Control 1.0" regulation until April 3, 2028, providing a multi-year window for technology companies to continue their monitoring practices.

Safe vs. Scanned: Which Apps are Affected?

For the average user, the most pressing question is which services are actually looking at their data. Because the current regime is voluntary, the implementation is uneven and largely split between European and American tech firms. Most European-based providers, citing the Charter of Fundamental Rights and digital sovereignty, have declined to participate in the scanning programs. US-based tech giants, however, have historically been more willing to adopt these automated moderation tools.

If you are wondering which apps are exempt from eu chat control, the answer lies in their technical architecture. Services that use end-to-end encryption (E2EE) are currently safe because the service providers do not hold the decryption keys. Without those keys, they physically cannot scan the content of your messages. However, non-E2EE apps are a different story.

Platform Category Affected Apps Scanning Status
Unencrypted Services Gmail, Outlook, Instagram DMs, Snapchat, Discord Scanned (Voluntary)
Encrypted Services (E2EE) Signal, WhatsApp, Proton Mail, Threema Exempt (Technical Barrier)

Many users ask, does gmail scan private messages in eu? Under the renewed chat control law, the answer is yes, if Google opts to continue its voluntary reporting. Google, Meta (for Instagram), and Microsoft use automated content moderation tools to flag illegal files and known CSAM signatures. Because these services maintain access to the data on their servers, they can run detection algorithms before the data is delivered or while it is stored.

A smartphone screen displaying icons for Instagram, Gmail, Snapchat, and Discord.
Mainstream applications like Instagram and Gmail are among those where voluntary message scanning will be active through 2028.

The debate over signal vs whatsapp eu chat control often arises here. While both use the Signal Protocol for encryption, Signal has been more vocal about its refusal to ever implement scanning, even threatening to leave the EU market if version 2.0 becomes law. WhatsApp, owned by Meta, is currently exempt from 1.0 scanning due to its encryption, but privacy groups remain wary of Meta's long-term lobbying stance regarding future legislative versions.

The Data Paradox: Privacy Risks vs. Child Safety

The tension at the heart of this legislation is the balance between human rights and the urgent need to stop child exploitation. Proponents of the law argue that scanning is a vital tool for law enforcement. According to official reports, Europol processed about 1.1 million "CyberTips" in a single year, the vast majority of which were generated by the voluntary scanning of private communications by major technology platforms. Without these automated flags, proponents argue, thousands of crimes would go undetected.

However, the efficacy of these tools is under heavy fire from the scientific community. An evaluation by the European Union found that automated detection algorithms used for scanning digital communications produce a false positive rate of approximately 48 percent. This means nearly half of the flags sent to law enforcement may involve legal, albeit perhaps sensitive or misidentified, private content.

A stylized blue digital eye overlaid with data patterns representing digital surveillance.
Privacy advocates argue that automated scanning tools represent a significant shift toward mass surveillance in the digital age.

European Digital Rights (EDRi) and other advocacy groups describe this as a shift toward mass surveillance. They argue that once the infrastructure for scanning is built, it can easily be repurposed for political monitoring or other forms of social control. The high false positive rate also puts a massive strain on police resources, forcing investigators to manualy review thousands of private photos and messages that turn out to be harmless.

A young child interacting with a tablet device in a home setting.
The primary legislative goal cited by the EU is the protection of minors and the detection of child sexual abuse material online.

The debate is further complicated by historical data. In late 2020, there was a brief period where scanning lapsed due to legislative changes. During that time, there was a reported 58% drop in abuse reports, which law enforcement cited as proof that voluntary scanning is indispensable for the protection of minors.

User Guide: How to Protect Your Privacy

Given the chat control 2026 status, users who value their privacy should take proactive steps to audit their digital communication habits. Since the current law relies on the ability of the provider to read the content, the solution is purely technical.

  1. Transition to End-to-End Encryption: The most effective way to protect your messages is to stop using unencrypted DMs and legacy email providers for sensitive conversations. Moving chats to Signal or Threema ensures that no one, not even the service provider, can scan the content.
  2. Understand the Limits of VPNs: Many people believe a VPN will solve this issue. In reality, while a VPN hides your location and IP address from your ISP, it does nothing to stop the application itself (like Instagram or Gmail) from scanning your messages at the point of origin or on the server.
  3. Audit Your Workplace Tools: For professionals, ensuring that your company uses E2EE for internal communication is vital for compliance with general data protection regulations and for maintaining trade secrets. Ensure your provider offers a clear DPIA (Data Protection Impact Assessment) that addresses the risks of automated scanning.
  4. Stay Informed on 2.0: While 1.0 is the current reality, the struggle over version 2.0 continues. This is the version that could mandate client-side scanning on every device in Europe. Supporting digital rights organizations is one way to keep the debate active in the public sphere.
Close-up of a smartphone with a padlock icon representing encrypted messaging and digital privacy.
Switching to services that utilize end-to-end encryption (E2EE) remains the most effective way for users to protect their private communications.

Learning how to protect messages from eu scanning is not just about hiding; it is about reclaiming the digital sovereignty that the ePrivacy Directive was originally designed to protect. As long as you use platforms that hold the keys to your data, your privacy depends entirely on their voluntary choices.

FAQ

Did chat control get passed?

Yes, a form of it did. While the more aggressive version 2.0 is still under debate, the renewal of Chat Control 1.0 was officially passed in July 2026. This happened because the European Parliament failed to reach the absolute majority of 361 votes required to block the Council’s fast-tracked regulation, extending the existing voluntary scanning framework.

Is chat control active now?

Yes, the regulation is currently active and will remain in effect until April 3, 2028. This means that platform providers are currently authorized to voluntarily scan unencrypted emails, messages, and files for illegal content using automated detection algorithms.

What apps would chat control affect?

Currently, it affects non-end-to-end encrypted services. This includes major platforms like Gmail, Outlook, Instagram DMs, Facebook Messenger (non-encrypted chats), Discord, and Snapchat. These providers have the technical ability to scan content because they manage the data on their own servers.

What will happen with chat control?

The current voluntary scanning regime is locked in until 2028. Meanwhile, the debate over Chat Control 2.0 continues in the European Council. If 2.0 passes in the future, it could move scanning from a voluntary choice for unencrypted apps to a mandatory requirement for every messaging app, potentially forcing the implementation of client-side scanning on all devices within the EU.

The extension of the chat control law until 2028 marks a significant moment for European digital rights. While the protection of children remains a universal priority, the methods used to achieve it continue to divide the tech world and the political sphere. As users navigate this landscape, the distinction between unencrypted "public-private" spaces and truly encrypted private communication remains the most important boundary to understand. The coming years will determine if the "zombie law" of 1.0 becomes the foundation for a much more permanent and pervasive monitoring system.

Tags