The “Chat Control 1.0” saga: Big Tech can scan our private messages again – but Parliament sent a strong signal against mass surveillance
Members of the European Parliament (MEPs) voted on a derogation of the EU’s ePrivacy Directive for the third time in 4 months. While the proposal passed, the vote nonetheless remains a triumph because it reinforces the Parliament’s position against mass surveillance on the more dangerous CSA Rregulation, and because it enshrines the protection of encryption.
Big Tech scanning users’ private messages will likely be back soon – here’s why
On 26 March 2026, the European Parliament voted to reject an extension of the 2021 ‘temporary’ interim ePrivacy derogation – the law sometimes referred to as “Chat Control 1.0”. This law allowed Big Tech companies like Microsoft and Meta to mass scan their users’ private messages to search for child abuse material. After the Parliament’s valid rejection of the extension, this temporary derogation expired on 4 April 2026. Because of the rarity of such rejections, the legislative proposal was considered politically dead, or so everyone thought.
Enter: Roberta Metsola, president of the European Parliament and a member of the European People’s Party (EPP), which is rapidly gaining infamy for undermining democratic processes.
Roberta Metsola surprised everyone by suggesting to the European Council to ignore the position of the Parliament she represents. The EU governments swiftly agreed to push the text again, forcing the Parliament through a rarely-used procedure: a third vote, this time for a “second reading” of the file.
The bad news is that the European Parliament failed to stop the return of the temporary derogation.
The good news is that they still managed to send a clear signal that mass surveillance would not be accepted in the CSA Regulation, sometimes known as “Chat Control 2.0”, the permanent framework which is being negotiated in parallel and which has the potential to be much more dangerous for our right to private and secure communications online.
What happened, concretely
The conservative EPP group used a combination of the second reading procedure with an urgency procedure to its advantage. In second readings, the proposed text is automatically adopted unless it is rejected. Further, in second readings the threshold for amendments to be adopted is an “absolute majority” (50% +1 of the total number of MEPs, i.e. 360 votes) instead of the usual “simple majority” (more ‘yes’ than ‘no’ in the votes cast). This means that MEPs who are absent or do not vote are counted as being in favour of the text, and against all amendments. EPP then requested an urgency procedure to bypass the competent Parliament committee (Committee on Civil Liberties, Justice and Home Affairs – LIBE), and directly add this vote to the agenda of the last plenary before the summer break. Many MEPs tend to be absent at this plenary – in this case, 100+ MEPs were absent, meaning that more than 1/7 of the ‘votes’ against amendments and against rejection were from MEPs who did not actually vote. Essentially, anyone in the European Parliament who wanted to oppose this last-minute surprise move was at a disadvantage from the outset.
Beside the risk of normalising harmful and disproportionate practices, and undermining the Parliament’s democratic process by forcing another reading, the real risk with this vote was that it could have undermined the Parliament’s strong position on the CSA Regulation. The European Parliament had, so far, opposed mass surveillance and the undermining of end-to-end encryption.
Fortunately, instead of undermining the Parliament’s position, this vote reinforced it, with more than half of the present MEPs voting to reject and amend the proposal for the temporary derogation. A bigger-than-normal majority was needed this time, but that won’t be the case for the CSAR negotiations, signalling to the negotiators that they can’t get support for a deal which allows for mass surveillance.
Despite the temporary derogation being voted through, MEPs managed to pass two amendments (AM30 and PC3) protecting end-to-end encrypted interpersonal communications, including against client-side scanning. These changes to the proposal are an important success for safeguarding the principle that communications should be safe and secure.
These changes also meant that the proposal was not automatically adopted: first the Commission had to issue an opinion on the text as amended (it gave a green light on the protection of encryption), then the Council had to accept it too, before the measure could be made into law.
The new derogation applies from 3 August 2026 until 3 April 2028.
Upcoming files: the European Parliament still stands against mass surveillance
Now, the institutions are expected to focus on the long-term legislation, that is, the CSA Regulation again, where the negotiators already agreed to protect encryption and to remove the provisions on age verification. The only provisions they still need to negotiate concern the kind of detection that will be used: mandatory and/or voluntary, targeted or mass scanning. The next CSAR trilogue is scheduled for 29 September. At least negotiators now know for sure: there is no majority for mass surveillance or “Chat Control”. Only a balanced and proportionate approach without the mass scanning of private communications can finally conclude discussions on this file with an agreement. A part of the credit for this goes to the thousands of people who emailed or called their elected representatives and/or government!
Moreover, the Parliament’s broad support for the protection of encryption also sends a strong signal to the Council and to the Commission for other files, such as any potential legislative proposals from the Commission based on the “Technology Roadmap on Encryption”, an expert report expected in 2027 which aims to assess technical solutions that enable law enforcement access to encrypted data. Together with 68 civil society groups, industry and professional associations, EDRi already warned against the Commission’s continued focus on identifying ways to weaken or circumvent encryption, which would inevitably undermine both our ability to communicate safely online and the EU’s own cybersecurity objectives.
Contribution by: Simeon de Brouwer, Policy Advisor, EDRi & Konstantin Macher, Board Member of EDRi member Digitale Gesellschaft
- The amendments to reject the text got 314 votes in favour (=52% of the actual ballots), and 276 against (=45%). 112 MEPs didn’t vote. If this had been the usual procedure, this whole proposal would have been rejected (once more), but 360 votes were required due to the ‘absolute majority’ threshold.
- Amendments aligning the Chat Control 1.0 text onto the Parliament’s position on Chat Control 2.0 (the CSAR) similarly received the backing of a ‘mere’ simple majority, sending a clear signal that although voluntary scanning is now temporarily allowed again, that doesn’t mean a weakening of the Parliament’s mandate on the CSAR file:
- AM5 would have limited the scanning to specific suspects. It got 322 in favour (=53%), 255 against (=42%).
- PC1 would have forbidden the scanning for unknown CSAM. It got 345 in favour (=57%), 237 against (=40%).
- PC2 would have forbidden the scanning for grooming. It got 346 in favour (=57%), 254 against (=42%). With 15 additional votes in support, this would have gone through.
