CDT Europe’s Response to the European Parliament Rejection of the Chat Control 1.0’s Extension
On Thursday, 26 March, the European Parliament voted not to extend the temporary derogation from the ePrivacy Directive, also referred to as Chat Control 1.0 (EU 2021/1232), thereby permitting the current legal basis to expire on 4 April 2026. Despite last-minute procedural efforts to extend the derogation, we welcome the expiration which will end the voluntary, indiscriminate mass scanning of private communications, including the detection of known Child Sexual Abuse Material (CSAM), new CSAM, and the solicitation of children. While this is a positive step forward, CDT Europe has previously voiced pressing fundamental rights concerns, and negotiations for a permanent CSAM Regulation (Chat Control 2.0) are still ongoing, with the next expected trilogue on 16 April focusing on injunctions to detect content and encryption.
The expiration of this derogation presents a window of opportunity. Moving forward, negotiators can now focus on measures that truly protect children online and uphold fundamental rights, while avoiding a return to indiscriminate mass scanning of private communications. This would be in line with both the Parliament and Council’s move away from the original broad-detection model.
Procedural maneuvers and opportunities
The rejection of the temporary derogation resulted from a series of procedural maneuvers intended to reopen negotiations and voting on a position previously agreed upon by Parliament. Prior to the vote, four European Commissioners argued that the expiration of the derogation would result in immediate and severe consequences by creating a regulatory void for online platforms. The final vote to amend and extend the temporary derogation failed to achieve the requisite majority, thereby terminating the voluntary indiscriminate scanning of online communication. This outcome presents an opportunity to pursue an alternative, narrowly tailored, and proportionate regulatory pathway that champions fundamental rights, protecting against indiscriminate mass scanning models and the implementation of expansive risk mitigation measures, in line with international human rights standards and jurisprudence of the European Court of Human Rights. The expiration of the derogation does not create a legal loophole for investigating online child sexual abuse, as the derogation was always meant to be an exceptional carve out, although legally questionable, and not the legal basis for online child sexual abuse investigations as such.
Even without Chat Control 1.0, targeted telecommunications surveillance based on concrete suspicion and permitted by judicial authority remains permissible, as well as production and preservation orders for electronic evidence in criminal proceedings under the EU e-evidence framework. Even after the derogation expires, authorities can still take action against content hosted on online platforms as existing channels remain available to identify and act on CSAM in those environments. These include legal orders to remove content expeditiously when it is clearly illegal – CSAM being a clear example – as well as notice-and-action mechanisms, and notices from trusted flaggers, of which several are dedicated for flagging CSAM content under the Digital Services Act (DSA). For known and previously verified CSAM, established tools such as hash-matching also remain available to identify matching material for hosted environments. This process relies on specific indicators, or hashes, to identify and flag content for human review within narrowly defined parameters.
The forthcoming CSAM Regulation (Chat Control 2.0) is now an opportunity to protect against both a reintroduction of indiscriminate mass scanning and other mechanisms which undermine online anonymity and privacy. Lastly, the Regulation ought to strike a balance to ensure that mitigation measures do not unintentionally infringe upon the rights of those who are meant to be protected by the legislation. Age assurance mechanisms, including obligations for age verification, raise significant concerns for user privacy and freedom of expression by requiring users to prove their age to access services. In doing so, all users, not just children, must share sensitive personal information and forfeit their own anonymity online. There is limited evidence demonstrating that such verification methods have been effective, with reporting and research suggesting that users find workarounds when faced with age-related restrictions and at times do so with their parents’ permission or even help.
This vote should serve as an important opportunity to reset the direction of the CSAM trilogues. Moving forward, co-legislators should aim to deliver a rights-respecting framework that protects children online and upholds privacy, anonymity, encryption and fundamental rights.
British Public Oppose Secret Surveillance Powers and Want Strong Protections for Encrypted Communications
CDT released nationally representative polling data revealing that a the British public are broadly concerned about the security, privacy, and free speech consequences of allowing law enforcement to access encrypted communications.
Responding to the EU-US Negotiations on Reciprocal Data Exchanges for Border Procedures
CDT Europe, together with 29 other civil society organisations and academics, sent an open joint letter to the Council of the EU regarding the worrying direction taken by the European Commission in the EU-US border negotiations with the U.S. government.
Open Joint Letter on a Public Reassessment of the EU-US Adequacy Decision
On 29 June, the US Supreme Court ruled that US President Trump can remove the leaders of independent agencies and commissions, overturning nearly 90 years of precedent limiting executive power. This decision raises serious questions about one of the key safeguards underpinning the EU-US Data Privacy Framework adopted in 2023: independent supervision.
Return of Mass Scanning of Private Communications through Undemocratic Procedure
CDT Europe responds to the European Parliament's vote to revive the interim derogation from the ePrivacy Directive, commonly known as “Chat Control 1.0”, which provides the legal basis for the voluntary, indiscriminate scanning of private communications for known and new Child Sexual Abuse Material (CSAM), and for the solicitation of children.