- Blog >
- News >
- Chat Control Returned Through the Back Door — Here's What the EU Parliament Did About It
Chat Control Returned Through the Back Door — Here's What the EU Parliament Did About It
Key Takeaways
- The European Parliament voted for the third time in four months on the "Chat Control 1.0" ePrivacy derogation — a temporary law allowing Big Tech to mass-scan users' private messages for child abuse material — and it passed, applying from August 3, 2026 until April 2028.
- The derogation returned through a rarely-used procedural maneuver by European People's Party president Roberta Metsola, who suggested the Council ignore the Parliament's earlier rejection and force a second reading.
- Despite the derogation passing, MEPs successfully amended it to protect end-to-end encrypted communications against client-side scanning — a meaningful win for encryption that the European Commission and Council both accepted.
- The vote sends a clear signal to negotiators on the permanent "Chat Control 2.0" (CSAR) framework: there is no majority for mass surveillance, and only a balanced approach without mass scanning can conclude negotiations.
The European Parliament has passed a renewed version of the ePrivacy derogation known as "Chat Control 1.0" — a temporary law that allows companies like Microsoft and Meta to mass scan users' private messages to search for child abuse material — according to analysis published by European Digital Rights (EDRi). The new derogation applies from August 3, 2026 until April 2028.
This was the third vote on the same measure in four months, and it happened through a maneuver that bypassed the normal democratic process. The Parliament had already rejected an extension of the derogation on March 26, 2026, rendering it politically dead. Then Roberta Metsola, president of the European Parliament and a member of the conservative EPP group, suggested the Council ignore that rejection and force the Parliament into a rarely-used "second reading" procedure. The Council agreed.
In second readings, a text is automatically adopted unless actively rejected — and rejection requires an absolute majority of all MEPs, not just those present. With the vote timed to the last plenary before summer break, when more than 100 MEPs were absent, the threshold was structurally stacked against opposition. Over a seventh of the votes "in favor" came from MEPs who didn't actually vote at all.
The derogation passed. But so did two amendments that matter.
The Encryption Protections MEPs Managed to Pass
Despite the procedural disadvantage, MEPs passed two amendments — AM30 and PC3 — that explicitly protect end-to-end encrypted interpersonal communications, including against client-side scanning. Client-side scanning is the mechanism that would scan messages on a user's device before they're encrypted — a technique that privacy advocates have consistently described as functionally equivalent to breaking encryption, since it undermines the security guarantee at its source.
The European Commission gave a green light to the amended text. The Council accepted it. The encryption protections are now part of the law.
EDRi frames this as a meaningful win: not because the derogation was stopped, but because the Parliament's position on encryption was reinforced rather than undermined. The concern going into the vote was that passing Chat Control 1.0 without amendments would signal to negotiators on the permanent framework — the CSA Regulation, sometimes called "Chat Control 2.0" — that mass surveillance and client-side scanning were politically viable. Instead, the opposite signal was sent: more than half of present MEPs voted to reject or amend the proposal, and the amendments protecting encryption passed.
What This Means for Chat Control 2.0
The CSA Regulation — the permanent framework being negotiated in parallel — is where the real stakes lie. Chat Control 1.0 is a temporary derogation. Chat Control 2.0 would be permanent legislation, with the potential to mandate mass scanning of private communications across the EU indefinitely.
According to EDRi, negotiators on the CSAR have already agreed to protect encryption and remove age verification provisions from the text. The remaining question is what kind of content detection the final law will require: mandatory and/or voluntary, targeted or mass scanning. The next trilogue is scheduled for September 29.
The Parliament's vote — and particularly the encryption amendments that passed — tells negotiators something concrete: there's no majority for mass surveillance or mass scanning of private messages. A deal is only possible if it's proportionate, targeted, and doesn't compromise end-to-end encryption. EDRi credits that signal in part to the thousands of citizens who contacted their elected representatives during this process.
The Pattern This Fits
I want to zoom out for a moment, because this story sits alongside several others we've been tracking this week. The UK government demanding a backdoor into Apple's encrypted iCloud data. The US Senate Commerce Committee considering KOSA and the SCREEN Act, both of which push platforms toward expanded data collection. The EU's own Technology Roadmap on Encryption, an expert report expected in 2027 that EDRi and 68 civil society organizations have already warned is focused on identifying ways to weaken or circumvent encryption.
Each of these is a separate story. Together, they're a coherent picture: governments on both sides of the Atlantic are looking for ways to access the contents of encrypted communications, using child safety as the primary justification in each case. The EU Parliament's encryption amendments are a pushback within that pattern — imperfect, achieved through a structurally compromised process, but real. Courts and legislatures occasionally get these calls right. It's worth saying so when they do.
The fight over Chat Control 2.0 continues. The signal from this vote is that it can't be won by the surveillance advocates — not if they're trying to win it through democratic process. Whether they keep trying to win it through procedural maneuvers is a different question.
Be part of the resistance, quietly.
Get Mysterium VPN

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.
