EU Chat Control: Data Protection Authorities Demand End to Mass Surveillance

Brussels – A potential turning point in the debate over online privacy and security is emerging from the European Union. Lawmakers are reportedly poised to abandon plans for widespread “chat control” measures, a proposal that sparked significant controversy and raised concerns about fundamental rights. The shift comes following sustained pressure from digital rights advocates and data protection authorities who argued the measures would represent a dangerous overreach of surveillance and undermine encryption.

At the heart of the debate is a proposed regulation aimed at combating online child sexual abuse material (CSAM). Whereas the goal enjoys broad support, the methods proposed – specifically, the scanning of private messages – proved deeply divisive. The initial proposal, part of the broader CSA regulation, would have required online platforms, including messaging apps like WhatsApp and Signal, to proactively scan user content for illegal material. This sparked fears that such a system would necessitate breaking conclude-to-end encryption, a cornerstone of secure communication.

The debate centers on the balance between protecting children and safeguarding privacy. Critics argued that mandating the scanning of encrypted messages would create a backdoor for surveillance, potentially accessible to malicious actors and eroding trust in online communication. They likewise pointed to the potential for false positives and the chilling effect such surveillance could have on legitimate expression. The German data protection conference, along with other independent authorities, has been particularly vocal in its opposition, urging negotiators to fully abandon the chat control measures.

Encrypted messaging apps like Signal and WhatsApp were key targets of the proposed chat control measures. – Alle Rechte vorbehalten IMAGO / photothek

The Evolving Debate Over Chat Control

The European Commission initially proposed the chat control measures as part of a broader effort to tackle online abuse and illegal content. The plan envisioned requiring platforms to use technologies to detect and remove CSAM, even if it meant scanning encrypted communications. Although, this approach quickly faced pushback from privacy advocates, security experts, and some member states. The core argument against the proposal centered on the inherent conflict between mass surveillance and the fundamental right to privacy, as enshrined in the EU Charter of Fundamental Rights.

Signal, a messaging app known for its strong emphasis on privacy and end-to-end encryption, has been one of the most vocal opponents of the chat control measures. In October 2025, Signal President Meredith Whittaker warned that the company would be forced to leave the European Union if the proposal became mandatory, stating, “If we were faced with the choice of undermining the integrity of our encryption and data protection guarantees or leaving Europe, we would unfortunately make the decision to leave the market.” As reported by Signal, this stance reflects a broader concern within the security community that weakening encryption would create vulnerabilities that could be exploited by malicious actors.

The Electronic Frontier Foundation (EFF) has also been a leading voice against the proposals, highlighting the dangers of mass scanning and the potential for abuse. According to the EFF, the most controversial aspect of the plan – the forced scanning of encrypted messages – has been removed from the latest iteration of the legislation. However, the EFF cautions that other aspects of the proposal, such as allowing for “voluntary” detection of illicit content, still pose a threat to privacy.

What Remains: Voluntary Scanning and Client-Side Scanning

While the mandatory scanning of encrypted messages appears to be off the table, the current proposal still allows for platforms to voluntarily scan non-encrypted messages. This raises concerns that companies may be incentivized to move away from end-to-end encryption to facilitate such scanning. The proposal includes provisions for “client-side scanning,” a technology that would allow platforms to scan content on users’ devices before it is encrypted. This approach, while not directly breaking end-to-end encryption, is seen by many as a significant compromise that could still undermine privacy.

Client-side scanning involves deploying software on users’ devices that analyzes content for illegal material before it is encrypted and sent to the platform. Critics argue that this effectively creates a backdoor for surveillance, as the platform would have access to the content before it is protected by encryption. The EFF points out that, unlike the United States, where there is no comprehensive federal privacy law, voluntary scanning is not technically legal in the EU, although it has been permitted through a temporary derogation set to expire in 2026.

The debate over chat control also highlights the broader tension between law enforcement’s desire for access to data and the fundamental right to privacy. Proponents of the measures argue that they are necessary to protect children and combat serious crime. However, opponents contend that the potential harms to privacy and security outweigh the benefits, and that there are alternative approaches that can be used to address these issues without compromising fundamental rights.

The Trilog Negotiations and Next Steps

The current state of the chat control proposal is the result of ongoing negotiations between the European Commission, the European Parliament, and the Council of the EU – a process known as the “trilog.” These negotiations are often complex and opaque, with compromises being made on all sides. According to Tagesspiegel Background Digitalisierung, preliminary agreements have been reached on some issues, but the details remain vague. The focus of recent discussions has been on the establishment of an EU Center for Child Sexual Abuse, rather than directly on the chat control measures themselves.

The third political trilog meeting is scheduled for May 11, 2026. This meeting will be a crucial moment in the negotiations, as lawmakers will attempt to finalize the text of the CSA regulation. The outcome of these negotiations will have significant implications for the future of online privacy and security in the European Union. The trilog process is known for being intransparent, making it difficult to predict the final outcome.

The German data protection conference has issued a statement appealing to negotiators to abandon the mass surveillance of private chats, the blanket scanning of messages, and any attempt to break end-to-end encryption. They emphasize that backdoors in encryption jeopardize the security of all citizens and could be exploited by criminals. The conference argues that surveillance should only be targeted and based on concrete suspicion, and that preventing child sexual abuse should not justify a general suspicion against millions of citizens.

The future of online privacy in the EU hangs in the balance. While the removal of mandatory encrypted message scanning represents a significant victory for privacy advocates, the potential for voluntary scanning and client-side scanning remains a cause for concern. The upcoming trilog negotiations will be critical in determining whether the final CSA regulation strikes a reasonable balance between protecting children and safeguarding fundamental rights. The outcome will undoubtedly be closely watched by privacy advocates, tech companies, and citizens across Europe and beyond.

Leave a Comment