Chat Control 1.0 Clears the European Parliament Through a Procedural Back Door

Chat Control 1.0 Clears the European Parliament Through a Procedural Back Door
Chat Control 1.0 Clears the European Parliament Through a Procedural Back Door

A gap in parliamentary procedure has allowed MEPs to extend the mass scanning of private communications without ever holding a direct vote on the substance of the law.

Chat Control 1.0, a temporary carve-out from ePrivacy rules designed to detect online child sexual abuse, was adopted by the European Parliament on Thursday. The regulation will stay in force until 3 April 2028, giving lawmakers a sizeable window to negotiate an agreement on the updated framework known as Chat Control 2.0.

How the file resurfaced

In March, MEPs rejected extending Chat Control 1.0 after follow-up talks broke down. In late June, European Parliament President Roberta Metsola reopened the file and sent it to the Council, warning that the lapsed rules had left a dangerous gap in online child protection.

The Council then returned the file to Parliament at the start of the holiday season, a point at which it proved difficult to assemble the majority needed to dismiss it again.

What happened in the Parliament

At first, a simple majority backed rejecting the position, with 314 MEPs in favour, 276 against and 17 abstentions. But because there was no absolute majority, currently set at 360 MEPs, to reject the amended EP position, the vote fell short, with 276 in favour, 286 against and 30 abstentions. The second reading was closed, and the amended package has now gone to the Council for approval within three months.

The amended EP position adopts a positive but largely cosmetic change put forward by the liberal RENEW group. It would exclude from the law’s scope any communications to which end-to-end encryption is, has been, or will be applied.

Some MEPs have called this a glimmer of hope, and it was likely one reason the full text was not rejected in the second hearing. Even so, it remains unclear how broad the list of such communication channels might turn out to be. Because the amendment may run against the core idea of mass scanning of private communications, the Council is likely to reject it.

Earlier Council positions on Chat Control 2.0 have also included brief mentions of protecting privacy and end-to-end encryption, but without any technical debate on how the goals of Chat Control and encryption could be reconciled in practice.

While social media is buzzing with criticism of both proposals, discussion at the member state level remains thin. In most countries, the files for both Chat Control proposals are led by representatives from the interior ministries. Only a small number of governments are currently engaged in active debate, weighing the proposal not just as a law enforcement matter but also through the lens of data protection, private communication and cybersecurity.

Broad-based opposition

Both proposals for the mass scanning of European private communications have drawn wide opposition, cutting across left-wing, liberal and right-wing politicians, privacy advocates such as former MEP Patrick Breyer, cybersecurity specialists and human rights campaigners with extensive experience in freedom of expression and information issues beyond the EU.

Svenja Hahn, the recently re-elected ALDE Party President and German MEP, was openly critical of the vote in a comment for EUTechLoop. She called it a disgrace that the Chat Control instrument had passed, arguing that it opens the door to mass surveillance of all private communication of European citizens rather than the targeted fight against child sexual abuse that the Parliament had proposed. The surveillance of private chats pushed by EU states, she added, is a threat to freedom and democracy, and the fight against Chat Control must continue.

Lyudmyla Kozlovska, President of the Open Dialogue Foundation, told EUTechLoop that the vote on Chat Control 1.0 should be seen in the wider context of eroding privacy across the EU. She described it as the same pattern of normalising the loss of privacy seen before, first with financial privacy, then travellers’ data and now communications: a sweeping power justified by an urgent-sounding purpose and then quietly made routine.

The result, she argued, is that financial, security and cybersecurity laws are now heavily weaponised by the EU’s adversaries against its own citizens and entities, in the service of transnational repression. The real fight for encryption and the privacy of communication, she said, comes in September over Chat Control 2.0, and between now and then the resistance has to be strong enough that no procedural trick can carry it.

Harriet Caldwell

Experienced News Reporter with a demonstrated history of working in the broadcast media industry. Skilled in News Writing, Editing, Journalism, Creative Writing, and English.

Latest from Blog