EU Chat Control update
EU Chat Control update: Is message scanning back until 2028?
EU lawmakers moved closer to restoring temporary rules that let some messaging and webmail providers voluntarily scan for child sexual abuse material. They have not finished the job. As of July 19, 2026, the official EU procedure still says the file is awaiting a Council decision.
Several headlines nevertheless say "Chat Control has been extended to 2028." The European Parliament did adopt an amended position on July 9, and the European Commission endorsed it on July 15. The Council must now accept all of Parliament's amendments or the institutions will enter conciliation.
This is a follow-up to our November 2025 Chat Control and VPN privacy analysis. That article explains the permanent Child Sexual Abuse Regulation and the wider ProtectEU debate. This update focuses on the separate temporary measure often called Chat Control 1.0.
Current status: message scanning is not back in force
The European Parliament's Legislative Observatory lists the file as "Awaiting Council decision, 2nd reading." The previous temporary derogation lapsed on April 3, which created a legal gap at EU level.
| Claim | Verified position |
|---|---|
| Chat Control runs until 2028 | Not yet. April 3, 2028 is the proposed end date if the reinstatement becomes law. |
| Parliament rejected the plan | A simple majority backed rejection, but it fell short of the absolute majority required at this stage. |
| Encrypted chats are included | Parliament amended the text to exclude end-to-end encrypted communications. That wording still needs Council acceptance. |
| A VPN can block the scanning | No. A VPN protects the network path, not content processed by a communications service. |
What happened between April and July 2026
April 3: the previous derogation expired
Regulation (EU) 2021/1232 had provided a temporary exception to parts of the ePrivacy Directive. The exception allowed certain providers to use specific technologies voluntarily, subject to safeguards, to detect and report online child sexual abuse and remove related material. Lawmakers failed to agree on another extension before its April 3 expiry date.
July 2: the Council adopted a reinstatement position
The Council of the EU adopted its position on July 2. It wants the temporary measure restored as soon as possible and applied until April 3, 2028, while work continues on a permanent law.
The Council text says providers may scan content such as images and text, or traffic data, using tools that can include hashing, classifiers and artificial intelligence. It also sets conditions and safeguards. For example, it says the least privacy-intrusive technology should be used and that text should not be systematically filtered unless it is used to detect patterns pointing to concrete reasons for suspicion.
July 9: Parliament amended the Council position
At second reading, rejecting or amending the Council position required support from an absolute majority of all MEPs. A majority of the votes cast was insufficient. According to the Parliament's official account, 314 MEPs initially supported rejection, with 276 against and 17 abstentions. That was a simple majority, but it was short of the required 360 votes.
Parliament then adopted three amendments that exclude "communications to which end-to-end encryption is, has been or will be applied." The amended position went back to the Council.
Critics described the urgent second-reading route as a procedural manoeuvre or a "back door" because more MEPs supported rejection than opposed it. Under the rules for a second reading, the rejection motion failed because it did not receive an absolute majority of all MEPs.
July 15: the Commission supported Parliament's changes
The European Commission issued a positive opinion on Parliament's amendments. It said the exclusion for end-to-end encrypted communications could use more precision and clarity, but considered the changes acceptable.
The opinion also confirms that any reinstatement would have no retroactive effect. It would not turn provider activity during the legal gap into activity covered by the EU derogation after the fact.
What the temporary measure would actually allow
"Chat Control 1.0" is a political nickname, not the title of the regulation. The legal file concerns a temporary derogation from the confidentiality rules in the ePrivacy Directive for certain number-independent interpersonal communications services. That category includes messaging, voice-over-internet and webmail services.
The measure is voluntary. It does not order every provider to scan every message, and it is not a general warrant for governments to read private chats. It creates an EU-level exception that qualifying providers can rely on if they choose to use detection technologies and meet the regulation's conditions.
The Council's own text acknowledges that such processing interferes with the rights to private life and data protection. Critics argue that provider-led scanning can examine communications of people who are not suspected of a crime, produce false reports and shift law-enforcement functions to private companies. Supporters argue that voluntary detection helps identify victims, remove abuse material and investigate offenders.
What changed for end-to-end encryption
Parliament's July amendments are more protective of encryption than the Council position. If the Council accepts them, communications protected by end-to-end encryption would sit outside the temporary derogation.
That does not settle the permanent Chat Control 2.0 debate. The Commission said its support for the temporary amendments does not prejudge its position on the longer-term regulation. The European Data Protection Board has previously warned that discouraging end-to-end encryption could weaken confidentiality, fundamental rights and trust in digital services.
What the July vote means for VPN users
The July text does not impose a new logging obligation on VPN providers. It concerns interpersonal communications services. Claims that this vote directly forces VPNs to log users or weaken their tunnels go beyond the legislation.
A VPN also cannot stop an email or messaging provider from processing content within its own service. The VPN encrypts traffic from your device to the VPN server and replaces your public IP address. Once traffic reaches the communications provider, that provider still handles the message, account and associated metadata. For a fuller explanation, read our guide to what a VPN does and does not protect.
A reliable VPN still hides your destination IP from your internet provider, protects traffic on untrusted local networks and reduces some forms of network-level tracking. You can verify the network side with our IP, DNS and WebRTC leak test and check drop protection with the VPN kill switch test.
VPN jurisdiction and logging policies remain worth examining, but for different reasons. Our reports on Swiss VPN surveillance proposals and the Windscribe server seizure in the Netherlands deal with laws, infrastructure and evidence that affect VPN providers directly. The temporary Chat Control file does not.
What EU users should do now
- Use end-to-end encrypted services for sensitive conversations. Under Parliament's current amendments, those communications would be excluded from the temporary measure. The Council decision and permanent regulation still need watching.
- Keep a VPN in its proper role. Use it to protect the network path and your public IP address. Do not treat it as a shield against processing performed by an app or account provider.
- Secure the endpoint. Install operating-system and app updates, use a strong device lock and review cloud backups. Message confidentiality depends on the device and service as well as the connection.
- Read privacy policies for the services that hold your messages. Check whether content is end-to-end encrypted, whether backups retain that protection and what metadata the service keeps.
- Check the official procedure again after the Council votes. That decision will determine whether Parliament's encryption exclusion becomes law or whether the file moves to conciliation.
What happens next
The Council has three months to approve or reject Parliament's amendments. If it accepts all three, the regulation can be adopted with the end-to-end encryption exclusion. If it does not, Parliament and the Council move to conciliation and try to agree on a joint text.
Meanwhile, negotiations on the permanent Child Sexual Abuse Regulation continue. The current Council text says the temporary measure would apply until April 3, 2028. The Council's next decision will say more about the practical outcome than that proposed end date.
Primary sources
- European Parliament: July 9 vote, amendments and next steps
- Legislative Observatory: current procedure status
- Council position at first reading, document 11261/1/26 REV 1
- European Commission: July 15 opinion on Parliament's amendments
EU Chat Control and VPNs: FAQ
Not yet. The European Parliament adopted an amended position on 9 July 2026, and the European Commission supported those amendments on 15 July. The official procedure was still awaiting a Council decision on 19 July 2026. The earlier temporary derogation expired on 3 April 2026.
Chat Control 1.0 is the name critics use for a temporary exception to EU ePrivacy rules. It allowed certain messaging and webmail providers to use technologies voluntarily, subject to conditions, to detect, report and remove online child sexual abuse material and detect solicitation of children.
The Parliament amendments exclude communications to which end-to-end encryption is, has been or will be applied. The Commission gave those amendments a positive opinion, but the Council must still accept them for that wording to become law.
No. A VPN encrypts traffic between your device and the VPN server. It cannot stop a messaging or email service from processing content inside its own app, on your device or on its servers. A VPN still helps protect your IP address and traffic from your internet provider.
No. This temporary legislative file concerns certain interpersonal communications services, such as messaging and webmail. It does not create a new VPN logging duty. VPN jurisdiction and logging policies matter in other legal contexts, but they do not solve app-level scanning.
No. Chat Control 2.0 is the nickname for the separate, permanent Child Sexual Abuse Regulation proposed in 2022. Negotiations on that longer-term framework continue. The temporary 2026 file is intended to cover the period until a permanent law is agreed and applied.