Key facts
- The European Parliament voted to extend "chat control" legislation until April 3, 2028.
- End-to-end encrypted messages are excluded from the scanning regime.
- A procedural loophole allowed the extension without a direct vote on the law's substance.
- The amended legislation has been sent to the Council for approval.
- Critics label the law "chat control" and warn of mass surveillance.
The European Parliament has voted to extend "Chat Control 1.0," a temporary derogation from ePrivacy rules designed to detect online child sexual abuse material, until April 3, 2028. This extension was facilitated by a procedural loophole that allowed the legislation to pass without a direct vote on its substance.
Initially, a majority of MEPs voted to reject the extension, but a subsequent vote failed to achieve the necessary absolute majority to dismiss the amended position. The amended text includes a proposal from the liberal RENEW group to exclude end-to-end encrypted communications from the scanning regime, a move some MEPs view as a "glimmer of hope" for privacy, though its practical implementation and acceptance by the Council remain uncertain.
Critics, including MEP Svenja Hahn and privacy advocates, have condemned the vote, labeling it "disgraceful" and a step towards mass surveillance. They argue that the law undermines freedom and democracy by enabling the scanning of all private communications rather than focusing on targeted investigations. Lyudmyla Kozlovska of the Open Dialogue Foundation views this as part of a broader erosion of privacy in the EU, warning that the "real fight for encryption and the privacy of communication is in September, over Chat Control 2.0."
The legislation, which aims to provide a buffer while lawmakers negotiate an updated framework (Chat Control 2.0), has now been sent to the Council of the EU for approval within three months. The debate has ignited widespread opposition from various political factions, privacy advocates, and cybersecurity specialists.
