EU encryption and surveillance policy

Brussels Extends Voluntary CSAM Scanning to 2028 on a Procedural Technicality, Not a Majority

An absolute-majority quirk let absent MEPs outvote the 314 lawmakers who opposed renewing Chat Control 1.0, extending it to April 2028.

Chat Control 1.0: Renewed by Absence, Not Consent People of Internet Research · EU 314 MEPs voted to reject it More lawmakers opposed the extensi… 361 Votes needed to block Absolute majority of all 720 MEPs … 2028 New expiry date Derogation extended to April 3, 20… 2021 Scanning regime running since Voluntary CSAM-scanning derogation… peopleofinternet.com
Chat Control 1.0: Renewed by Absence, … People of Internet Research · EU 314 MEPs voted to reject it 361 Votes needed to block 2028 New expiry date 2021 Scanning regime running since peopleofinternet.com

Key Takeaways

A Vote Parliament Lost by Winning

On July 9, 2026, the European Parliament held a vote that, on its face, went against mass message scanning: 314 MEPs voted to reject the Council's position reinstating the ePrivacy derogation known as Chat Control 1.0, versus 276 who voted to keep it alive. Opponents won the room. They lost the law. Under the ordinary legislative procedure set out in Article 294 of the Treaty on the Functioning of the European Union, a second-reading Parliament can only reject a Council position with an absolute majority of the chamber's full membership — 361 votes out of 720 seats, regardless of who shows up. Absent members are not neutral; they function as automatic yes votes for the status quo. Opponents fell roughly 47 votes short, and the derogation survived by default (The Register; The Record).

The result: Regulation (EU) 2021/1232, which lets messaging and webmail providers voluntarily scan for known child sexual abuse material (CSAM) and report it, now runs until April 3, 2028 — a two-year extension the European Commission formally proposed on December 19, 2025 (EUR-Lex, COM(2025)797). The underlying regime dates to August 2021 and has already been extended once before, to April 2026, before lapsing that April when Parliament couldn't agree on renewal terms (EUR-Lex, Regulation 2021/1232).

The Case the EU Isn't Wrong to Make

It's worth stating the strongest version of the case for renewal, because it's not frivolous. The derogation is voluntary, not a mandate: platforms that already run hash-matching and classifier-based CSAM detection — a practice that predates this regulation and generates the referrals that feed NCMEC and EU law enforcement — needed a clear legal basis to keep doing so without falling foul of the ePrivacy Directive's confidentiality-of-communications rules. When the law lapsed in April, providers reportedly kept scanning anyway, but without the legal cover Brussels itself had told them they needed, creating exactly the kind of ambiguity that chills good-faith compliance (The Record). A bridge measure that keeps existing, voluntary detection running while the EU finishes negotiating a permanent CSAM Regulation is a defensible stopgap, not obviously an assault on privacy.

Crucially, this is not the mandatory-scanning, encryption-breaking "Chat Control 2.0" that privacy advocates have spent years fighting. Recital 25 of the original 2021 regulation states plainly that nothing in it should be read as "prohibiting or weakening end-to-end encryption," and reporting on the July 9 vote confirms encrypted services like Signal remain outside its scope (The Record; EUR-Lex). Companies choose whether to scan; users who want unscanned communications can and do choose E2EE platforms instead. That's a meaningfully different proposition than a backdoor mandate.

Where the Real Damage Was Done

What should worry a pro-innovation, pro-speech publication is not primarily the substance of this extension — it's the method. Parliament had already rejected essentially the same extension once, by normal majority vote, in March 2026. Rather than accept that outcome, proponents brought the identical policy back on the eve of summer recess and ran it through a procedural channel where a losing coalition on the floor still wins if enough colleagues are simply absent. Critics, including in a blog post cited by The Record, called the maneuver an "unprecedented" and "highly politicised procedural" tactic, pushed by European Parliament President Roberta Metsola's office to get the measure over the line before the chamber emptied out for the summer (The Record).

That precedent cuts both ways, and that's the problem. A mechanism that can resurrect a policy MEPs voted down by exploiting absenteeism is a mechanism that works regardless of whether the underlying policy is sympathetic. CSAM detection is About as sympathetic a use case as EU tech policy offers — which is exactly why it's a dangerous test case for the tactic. The next use of an absolute-majority override to steamroll a floor majority may not come wrapped in child-protection framing, and the institutional habit, once normalized, doesn't self-limit to good causes.

What to Watch Next

The encryption fight isn't over — it's deferred. The permanent CSAM Regulation, the successor framework this derogation is bridging toward, is still being negotiated in Council and Parliament, and earlier drafts of that proposal have included detection orders that could reach encrypted services. This July vote extended the voluntary, non-encrypted status quo; it did not resolve whether Brussels will eventually mandate scanning that reaches Signal and WhatsApp. Publications and platforms that care about encryption should treat this extension as a procedural warning shot, not a verdict on the bigger fight still to come.

"Highly politicised procedural efforts" — the characterization of the maneuver by critics cited in reporting on the vote.

For now, the operative fact is narrower and more mundane than headlines suggest: a voluntary, encryption-excluded scanning regime got a two-year renewal nobody on the floor actually voted for in the affirmative majority sense — because under EU procedural rules, showing up to abstain and staying home produce the same result.

Sources & Citations

  1. EUR-Lex — Regulation (EU) 2021/1232
  2. EUR-Lex — Commission proposal COM(2025)797
  3. The Record: Europe revives law allowing big tech to scan for CSAM
  4. The Register: MEPs fail to prevent Chat Control snoopfest revival