A vote that passed by falling short
On July 9, 2026, the European Parliament held a second-reading vote on reinstating the EU's temporary "ePrivacy derogation" — the rule that lets email, messaging, and social platforms voluntarily scan private communications for child sexual abuse material (CSAM). A motion to reject the Council's text got 314 votes to keep rejecting it, against 276 to let it stand. That looks like a win for the rejectionists — until you note the procedure required an absolute majority of all 720 MEPs, 361 votes, to actually block it. Falling 47 votes short with over 100 members absent for a summer plenary, the rejection failed, and the voluntary-scanning regime lives on (EDRi). The derogation, first adopted in 2021 and repeatedly extended since, now runs until April 3, 2028.
In the same session, MEPs adopted a separate amendment, proposed by the liberal Renew group, excluding "communications to which end-to-end encryption is, has been, or will be applied" from the scope of the voluntary-scanning law (European Parliament plenary agenda; Euronews). WhatsApp, Signal, and iMessage are now formally out of reach of this particular scanning power.
Why the carve-out is closer to a formality
Here's the steelman for treating this as a genuine win: giving providers explicit legal cover to scan for known CSAM hashes, and explicitly telling them not to touch encrypted traffic, is a coherent, targeted design. It matches what Parliament itself argued back in March 2026, when it backed extending the derogation on the condition that "voluntary measures need to remain proportional and targeted and should not apply to end-to-end encrypted communications" (European Parliament, March 11, 2026). Codifying that limit in the operative text, rather than leaving it to a press release, closes a door that a future Commission or a more permissive court reading could otherwise reopen.
But the practical stakes are close to zero, because the door was barely ajar. End-to-end encrypted services cannot voluntarily scan message content without breaking the encryption in the first place — nothing in the pre-amendment derogation was forcing WhatsApp or Signal to scan anything, since scanning under E2EE requires client-side scanning, a different and far more contested technical approach. The amendment mostly formalizes a status quo where encrypted platforms already weren't participating. It is a meaningful signal about Parliament's mood — a majority now visibly distrusts scanning mandates that reach encrypted traffic — but it changes very little about what any provider can or must do today.
The regulation that actually decides this
The real fight is the permanent CSA Regulation, commonly called "Chat Control 2.0" — in trilogue negotiations since November 2023, with a sixth substantive session now scheduled for September 29, 2026 under the incoming Irish Council presidency (EDRi). Negotiators reportedly agree on protecting encryption in principle and have dropped mandatory age-verification provisions. What remains open is the design of "detection orders" — the mechanism by which a court or administrative authority could compel a specific provider to scan specific communications. Earlier Commission and Council drafts of CSAR would let such an order reach an end-to-end encrypted service by requiring client-side scanning: software on the user's own device that inspects content before encryption is applied, then reports matches externally.
That is the design point where the child-safety case is genuinely strong and the security case against it is also genuinely strong, and neither should be waved away. CSAM does circulate on encrypted platforms, and law enforcement's most persuasive argument is that a total blind spot for the largest messaging apps in the world is itself a policy choice with victims. But client-side scanning is not a scalpel; it is infrastructure. Once a device runs software that flags content and reports it before the user ever sends a message, the same architecture can be redirected — by a change in law, a court order, or a more authoritarian future government — to flag anything else a state decides to look for. Europe's own cryptographers, and civil liberties groups across the political spectrum, have made this point since the Commission's original 2022 proposal, and it's why the European Data Protection Supervisor has repeatedly urged the EU to drop mandatory client-side scanning obligations in favor of targeted, judicially authorized measures against specific suspects.
What to watch
The July vote is worth tracking as a barometer, not a resolution. It shows the Parliament that will negotiate CSAR in September no longer has an appetite for scanning mandates that reach encrypted traffic wholesale — but the vote's own arithmetic, a rejection that failed despite a majority backing it, shows how fragile that appetite is against a Council and Commission that have not abandoned client-side scanning as an option. The proportionate outcome for September's trilogue is a permanent law that funds better reporting infrastructure and targeted, court-authorized detection orders against identified suspects, while formally excluding general client-side scanning obligations for encrypted services — not just for the temporary regime nobody was using anyway, but for the permanent one that will govern EU messaging for the next decade.