What the Council Just Adopted and Why
On Thursday, July 23, the Council of the European Union gave its final, definitive approval to a measure that keeps a temporary exemption to electronic communications confidentiality rules alive. The exemption, widely known as "Chat Control," allows certain online platforms to voluntarily scan private messages in search of child sexual abuse material (CSAM). The stated goal, as with earlier iterations of this policy, is to strengthen the fight against online child sexual abuse while carving out exclusions for specific types of communications.
This is not a brand-new law. It's the latest extension of a derogation that has been renewed multiple times since it first appeared, each time reigniting the same fundamental question: how far should platforms be allowed to go in analyzing the content of private conversations, even with good intentions, before it becomes a privacy problem for everyone?
The Council's move follows a pattern that readers who have tracked this issue will recognize. The European Parliament previously voted to limit Chat Control scanning until 2027, and before that, lawmakers pushed through a version that revived scanning through 2028. The July 23 Council adoption is the next chapter in a legislative saga that has stretched across several years without a permanent resolution.
How Chat Control's Scanning Mechanism Actually Works
Under the current derogation, participation by platforms remains voluntary rather than mandatory. Companies that choose to opt in can use automated detection tools to flag suspected CSAM in messages, images, or files shared through their services. Because the underlying EU rules on the confidentiality of electronic communications would normally prohibit this kind of content analysis, the derogation exists specifically to create a legal window for it.
Importantly, the framework has consistently included exclusions for certain categories of communications, a detail that has shaped much of the political negotiation around each renewal. The exact boundaries of what counts as excluded, and how platforms are expected to apply detection tools without undermining the security of encrypted services, remain the most contested technical and legal questions in this debate. It's worth remembering that an earlier version of this framework was adopted as "Chat Control 1.0" even after facing pushback from members of the European Parliament, as covered in our look at how Chat Control 1.0 passed despite MEP rejection.
Child Safety Versus Mass Surveillance: The Core Trade-off
The policy sits at the intersection of two legitimate priorities that are difficult to reconcile. On one side, child protection advocates and many lawmakers argue that voluntary scanning gives platforms a critical tool to detect and report abuse material that would otherwise circulate undetected. On the other side, digital rights groups and privacy-focused technologists warn that any mechanism capable of analyzing private message content, even under narrow, voluntary conditions, sets a precedent that could expand over time or be technically difficult to contain once built.
This is the same tension that has defined every round of the Chat Control debate. Each renewal has attempted to thread the needle by adding exclusions or narrowing scope, but the underlying architecture, giving platforms legal cover to scan private communications, remains largely intact. That's why this issue keeps resurfacing rather than reaching a settled endpoint.
What This Means for Encrypted Messaging and VPN Users
For everyday users of encrypted messaging apps and VPN services in Europe, the July 23 adoption doesn't immediately change how their favorite apps function. Participation remains voluntary, and platforms that rely on strong end-to-end encryption have generally resisted building in scanning capabilities that could weaken that encryption. But the persistence of this derogation keeps the broader policy question alive: could future versions of Chat Control shift from voluntary to mandatory scanning, and could that eventually require weakening encryption itself?
That concern isn't hypothetical. It's the same one raised in our earlier coverage of how the Chat Control debate threatens encryption more broadly. A VPN can protect the privacy of your internet traffic and hide your browsing activity from your network provider, but it can't shield the content of a message once it reaches a platform that has opted into scanning. Encryption at the app level, not just at the network level, is what's actually being debated here.
What This Means For You
If you use encrypted messaging apps in the EU, your day-to-day experience isn't changing overnight because of this vote. Scanning remains voluntary, and major encrypted platforms have largely held firm against building in content-scanning tools. That said, this is a policy area worth watching closely, especially if you rely on private messaging for sensitive conversations, professional communications, or simply value your right to a confidential conversation.
Actionable Takeaways
- Stick with messaging apps that use verified end-to-end encryption and have publicly committed to resisting mandatory scanning requirements.
- Follow the legislative timeline, since Chat Control has been renewed repeatedly rather than resolved, and future versions could shift from voluntary to mandatory participation.
- Understand the difference between what a VPN protects (your network traffic and location) and what it doesn't (message content once it reaches an app's servers).
- Stay informed through ongoing coverage of the EU Chat Control message scanning debate, since each renewal reshapes the practical stakes for private communication in Europe.




