1
Yesterday, the sixth round of trilogue negotiations on the final “Chat Control 2.0” regulation, intended to replace the current interim mechanism, took place in Brussels.
2
Since July 24, a regulation known as “Chat Control 1.0” has been in force, allowing email and messaging service providers to voluntarily scan users’ correspondence for child sexual abuse material (CSAM).
3
The regulation does not cover communications protected by “end-to-end” encryption (e.g., via Signal or WhatsApp) or voice communications.
4
The Ordo Iuris analysis of the Chat Control 1.0 regulation now in force points to a questionable basis for processing personal data under the GDPR, resulting from the inconsistent practices of individual providers.
5
Ordo Iuris draws attention to the mechanism’s lack of proportionality: the correspondence of an enormous number of users who have no connection whatsoever to any crime is subjected to scanning.

EU negotiations
On September 29, Brussels hosted the sixth round of trilogue negotiations between the Council of the EU, the European Parliament and the European Commission on the final shape of EU rules on combating online child sexual abuse material. These talks concern only the planned final regulation, commonly referred to as “Chat Control 2.0.” Meanwhile, Regulation (EU) 2026/1881, adopted on July 24, 2026, and known as “Chat Control 1.0,” has already been in force for more than two months.
It is yet another temporary derogation from the rules protecting the confidentiality of electronic communications, introduced in place of the previous arrangement, which expired on April 3, 2026, after the EU institutions failed to agree in time either on its extension or on the adoption of the aforementioned permanent legal framework. Regulation (EU) 2026/1881 maintains, with certain changes, the mechanism in place since 2021, which allows email and online messaging service providers to voluntarily scan users’ correspondence for child sexual abuse material.
How does the scanning mechanism work?
The regulation allows providers of number-independent interpersonal communications services, such as email and online messaging providers, to voluntarily use technologies that process personal data in order to detect and report child sexual abuse material (CSAM), as well as cases of solicitation of children. The key word is “voluntarily”: the regulation does not impose on providers any obligation to deploy such a mechanism; it merely removes, for a limited period, a legal obstacle – namely the prohibition, under EU law, on violating the confidentiality of correspondence.
The regulation also provides for two significant exclusions. First, it does not cover communications secured by full encryption in transit, i.e., “end-to-end” encryption, which is used by default for text conversations by, among others, Signal and WhatsApp. Second, it does not cover voice communications at all, regardless of the encryption used. In practice, this means that the mechanism continues to apply primarily to widely used services that are not “end-to-end” encrypted, such as Gmail and Outlook, as well as to standard, unencrypted text chats on Telegram.
Ordo Iuris’s concerns
The Ordo Iuris Institute’s analysis of Chat Control 1.0 points to serious legal doubts surrounding this mechanism. First, the analysis calls into question the basis for processing personal data under the GDPR. The regulation expressly stipulates that it does not itself constitute a legal basis for such processing, and providers must demonstrate their own basis under Article 6 of the GDPR. As the transparency reports submitted by providers under the previous, analogous mechanism showed, the largest of them relied on different, mutually inconsistent legal bases for their activities, which makes it even harder to assess whether the mechanism as a whole complies with data protection law.
Second, the available data on how the mechanism has operated so far raise doubts as to its proportionality. The analysis notes that the volume of data processed is enormous, while the proportion of content actually containing illegal material remains negligible – which clearly illustrates how wide a circle of ordinary users, with no connection whatsoever to this crime, is covered by the mechanism.
Arguments in favor of the regulation
Ordo Iuris does not overlook the arguments in favor of the solution adopted. Protecting children from sexual abuse is an indisputable, legitimate aim, deeply rooted in the EU Charter of Fundamental Rights and the UN Convention on the Rights of the Child. The European Court of Human Rights has emphasized that a state’s passivity in the face of the absence of mechanisms for identifying the perpetrators of online crimes against children may in itself constitute a violation of the European Convention on Human Rights.
“Protecting children and minors from sexual exploitation and solicitation online is a fully legitimate aim that deserves the legislator’s firm support. However, this aim cannot be pursued at the expense of fundamental safeguards, namely the proportionality of the measures applied and respect for the privacy of millions of users who have no connection whatsoever to the crime in question. In this context, a mechanism based on the mass – albeit voluntary – scanning of correspondence, lacking independent judicial oversight, raises justified doubts. This makes a thorough, balanced assessment of the solutions already in force all the more important before decisions are taken on the shape of the final regulation, which is still being negotiated in Brussels,” says Patryk Ignaszczak, an analyst at the International Law Center of the Ordo Iuris Institute.
See also:
- Ordo Iuris to the UN: Family Takes Priority in Protecting Children Online
- Who Will Check Social Media? Answer: Those on the European Commission’s List of “Trusted Flaggers”
- Is Surveillance the Price for Protecting Children? Council of the EU Agreement on Chat Regulation
- Limiting civil liberties under the guise of combating child abuse
Source of cover photo: iStock
