Editorial illustration of an EU policy chamber debating message scanning on a smartphone

EU Chat Control update

EU Chat Control update: Is message scanning back until 2028?

EU lawmakers moved closer to restoring temporary rules that let some messaging and webmail providers voluntarily scan for child sexual abuse material. They have not finished the job. As of July 19, 2026, the official EU procedure still says the file is awaiting a Council decision.

Several headlines nevertheless say "Chat Control has been extended to 2028." The European Parliament did adopt an amended position on July 9, and the European Commission endorsed it on July 15. The Council must now accept all of Parliament's amendments or the institutions will enter conciliation.

This is a follow-up to our November 2025 Chat Control and VPN privacy analysis. That article explains the permanent Child Sexual Abuse Regulation and the wider ProtectEU debate. This update focuses on the separate temporary measure often called Chat Control 1.0.

Current status: message scanning is not back in force

The European Parliament's Legislative Observatory lists the file as "Awaiting Council decision, 2nd reading." The previous temporary derogation lapsed on April 3, which created a legal gap at EU level.

Claim Verified position
Chat Control runs until 2028 Not yet. April 3, 2028 is the proposed end date if the reinstatement becomes law.
Parliament rejected the plan A simple majority backed rejection, but it fell short of the absolute majority required at this stage.
Encrypted chats are included Parliament amended the text to exclude end-to-end encrypted communications. That wording still needs Council acceptance.
A VPN can block the scanning No. A VPN protects the network path, not content processed by a communications service.

What happened between April and July 2026

April 3: the previous derogation expired

Regulation (EU) 2021/1232 had provided a temporary exception to parts of the ePrivacy Directive. The exception allowed certain providers to use specific technologies voluntarily, subject to safeguards, to detect and report online child sexual abuse and remove related material. Lawmakers failed to agree on another extension before its April 3 expiry date.

July 2: the Council adopted a reinstatement position

The Council of the EU adopted its position on July 2. It wants the temporary measure restored as soon as possible and applied until April 3, 2028, while work continues on a permanent law.

The Council text says providers may scan content such as images and text, or traffic data, using tools that can include hashing, classifiers and artificial intelligence. It also sets conditions and safeguards. For example, it says the least privacy-intrusive technology should be used and that text should not be systematically filtered unless it is used to detect patterns pointing to concrete reasons for suspicion.

July 9: Parliament amended the Council position

At second reading, rejecting or amending the Council position required support from an absolute majority of all MEPs. A majority of the votes cast was insufficient. According to the Parliament's official account, 314 MEPs initially supported rejection, with 276 against and 17 abstentions. That was a simple majority, but it was short of the required 360 votes.

Parliament then adopted three amendments that exclude "communications to which end-to-end encryption is, has been or will be applied." The amended position went back to the Council.

Critics described the urgent second-reading route as a procedural manoeuvre or a "back door" because more MEPs supported rejection than opposed it. Under the rules for a second reading, the rejection motion failed because it did not receive an absolute majority of all MEPs.

July 15: the Commission supported Parliament's changes

The European Commission issued a positive opinion on Parliament's amendments. It said the exclusion for end-to-end encrypted communications could use more precision and clarity, but considered the changes acceptable.

The opinion also confirms that any reinstatement would have no retroactive effect. It would not turn provider activity during the legal gap into activity covered by the EU derogation after the fact.

What the temporary measure would actually allow

"Chat Control 1.0" is a political nickname, not the title of the regulation. The legal file concerns a temporary derogation from the confidentiality rules in the ePrivacy Directive for certain number-independent interpersonal communications services. That category includes messaging, voice-over-internet and webmail services.

The measure is voluntary. It does not order every provider to scan every message, and it is not a general warrant for governments to read private chats. It creates an EU-level exception that qualifying providers can rely on if they choose to use detection technologies and meet the regulation's conditions.

The Council's own text acknowledges that such processing interferes with the rights to private life and data protection. Critics argue that provider-led scanning can examine communications of people who are not suspected of a crime, produce false reports and shift law-enforcement functions to private companies. Supporters argue that voluntary detection helps identify victims, remove abuse material and investigate offenders.

What changed for end-to-end encryption

Parliament's July amendments are more protective of encryption than the Council position. If the Council accepts them, communications protected by end-to-end encryption would sit outside the temporary derogation.

That does not settle the permanent Chat Control 2.0 debate. The Commission said its support for the temporary amendments does not prejudge its position on the longer-term regulation. The European Data Protection Board has previously warned that discouraging end-to-end encryption could weaken confidentiality, fundamental rights and trust in digital services.

What the July vote means for VPN users

The July text does not impose a new logging obligation on VPN providers. It concerns interpersonal communications services. Claims that this vote directly forces VPNs to log users or weaken their tunnels go beyond the legislation.

A VPN also cannot stop an email or messaging provider from processing content within its own service. The VPN encrypts traffic from your device to the VPN server and replaces your public IP address. Once traffic reaches the communications provider, that provider still handles the message, account and associated metadata. For a fuller explanation, read our guide to what a VPN does and does not protect.

Concept illustration showing app-level message processing above a VPN-encrypted network tunnel
A VPN protects the network path. It does not control what a messaging service processes inside the app or on its servers.

A reliable VPN still hides your destination IP from your internet provider, protects traffic on untrusted local networks and reduces some forms of network-level tracking. You can verify the network side with our IP, DNS and WebRTC leak test and check drop protection with the VPN kill switch test.

VPN jurisdiction and logging policies remain worth examining, but for different reasons. Our reports on Swiss VPN surveillance proposals and the Windscribe server seizure in the Netherlands deal with laws, infrastructure and evidence that affect VPN providers directly. The temporary Chat Control file does not.

What EU users should do now

  1. Use end-to-end encrypted services for sensitive conversations. Under Parliament's current amendments, those communications would be excluded from the temporary measure. The Council decision and permanent regulation still need watching.
  2. Keep a VPN in its proper role. Use it to protect the network path and your public IP address. Do not treat it as a shield against processing performed by an app or account provider.
  3. Secure the endpoint. Install operating-system and app updates, use a strong device lock and review cloud backups. Message confidentiality depends on the device and service as well as the connection.
  4. Read privacy policies for the services that hold your messages. Check whether content is end-to-end encrypted, whether backups retain that protection and what metadata the service keeps.
  5. Check the official procedure again after the Council votes. That decision will determine whether Parliament's encryption exclusion becomes law or whether the file moves to conciliation.

What happens next

The Council has three months to approve or reject Parliament's amendments. If it accepts all three, the regulation can be adopted with the end-to-end encryption exclusion. If it does not, Parliament and the Council move to conciliation and try to agree on a joint text.

Meanwhile, negotiations on the permanent Child Sexual Abuse Regulation continue. The current Council text says the temporary measure would apply until April 3, 2028. The Council's next decision will say more about the practical outcome than that proposed end date.

Primary sources

EU Chat Control and VPNs: FAQ

Not yet. The European Parliament adopted an amended position on 9 July 2026, and the European Commission supported those amendments on 15 July. The official procedure was still awaiting a Council decision on 19 July 2026. The earlier temporary derogation expired on 3 April 2026.

Chat Control 1.0 is the name critics use for a temporary exception to EU ePrivacy rules. It allowed certain messaging and webmail providers to use technologies voluntarily, subject to conditions, to detect, report and remove online child sexual abuse material and detect solicitation of children.

The Parliament amendments exclude communications to which end-to-end encryption is, has been or will be applied. The Commission gave those amendments a positive opinion, but the Council must still accept them for that wording to become law.

No. A VPN encrypts traffic between your device and the VPN server. It cannot stop a messaging or email service from processing content inside its own app, on your device or on its servers. A VPN still helps protect your IP address and traffic from your internet provider.

No. This temporary legislative file concerns certain interpersonal communications services, such as messaging and webmail. It does not create a new VPN logging duty. VPN jurisdiction and logging policies matter in other legal contexts, but they do not solve app-level scanning.

No. Chat Control 2.0 is the nickname for the separate, permanent Child Sexual Abuse Regulation proposed in 2022. Negotiations on that longer-term framework continue. The temporary 2026 file is intended to cover the period until a permanent law is agreed and applied.

Compare VPNs for the privacy protections they can provide

A VPN cannot prevent app-level message scanning. It can still protect your network traffic and public IP address. Compare providers on audits, logging policies, leak protection and app maintenance.

Proton VPN Logo
4.6

Proton VPN

70% OFF
$2.99 /month
Was $9.99/mo

Proton VPN is a Swiss-based service with open-source apps, Secure Core multi-hop routes and a published no-logs policy. The paid plan supports up to 10 devices and suits readers who put transparency and privacy controls ahead of the lowest price.

  • 20,000+ servers in 140+ countries
  • 10 simultaneous connections
Get Proton VPN deal →

Includes at least a 30‑day money‑back guarantee – test it on your own network and cancel if it does not fit your needs.

NordVPN Logo
4.7

NordVPN

77% OFF +3 Months Free
$3.49 /month
Was $14.99/mo

NordVPN combines broad server coverage with NordLynx, independently reviewed no-logs controls and extra privacy tools such as Double VPN. It is a strong all-round option for streaming, travel and everyday privacy across up to 10 devices.

  • 8,400+ servers in 126 countries
  • NordLynx (WireGuard) protocol
Get NordVPN deal →

Includes at least a 30‑day money‑back guarantee – test it on your own network and cancel if it does not fit your needs.

Surfshark Logo
4.6

Surfshark

85% OFF +3 Months Free
$2.49 /month
Was $16.45/mo

Surfshark covers unlimited simultaneous devices and includes WireGuard, MultiHop and CleanWeb. Its low introductory price makes it useful for households that want one subscription across phones, computers and streaming devices.

  • 4,500+ RAM-only servers in 100 countries
  • Unlimited simultaneous connections
Get Surfshark deal →

Includes at least a 30‑day money‑back guarantee – test it on your own network and cancel if it does not fit your needs.