The European Union has once again extended a temporary derogation to its ePrivacy rules, the legal mechanism that lets messaging platforms scan private communications for child sexual abuse material (CSAM) without running afoul of confidentiality protections. On paper, this looks like routine housekeeping. In practice, it keeps alive the legal foundation for client-side scanning, a technique that privacy advocates warn could quietly dismantle the end-to-end encryption protecting apps like Signal and WhatsApp. Understanding what changed, and what didn't, matters for anyone who relies on encrypted messaging in Europe or anywhere else.

What the ePrivacy Extension Actually Changes

The ePrivacy Directive normally requires that communications remain confidential, meaning platforms cannot inspect the content of private messages without a specific legal exception. Since 2021, the EU has repeatedly granted a derogation, a temporary carve-out, that allows companies to voluntarily scan messages and images for CSAM. This derogation was never meant to be permanent, but it keeps getting renewed rather than replaced with a final legislative framework.

This pattern isn't new. The European Parliament extended Chat Control 1.0 past its April lapse earlier this year, and when that expired again, lawmakers scrambled to bring it back in a surprise July vote that revived Chat Control 1.0. The most recent renewal, which passed on July 9, effectively continued the scanning regime not through a decisive vote in favor, but because opponents couldn't gather enough support to block it. That episode is covered in detail in our reporting on how the EU Parliament renewed Chat Control scanning law on July 9.

The latest ePrivacy extension follows the same script: a stopgap measure, passed amid procedural wrangling, that avoids a permanent decision while keeping the scanning door open. Critics argue this approach lets the EU sidestep a full public debate on whether mass message scanning is compatible with fundamental privacy rights.

How Client-Side Scanning Breaks End-to-End Encryption

The technical detail that gets lost in policy debates is exactly how client-side scanning works, and why it undermines encryption even though the encryption itself remains technically intact.

End-to-end encryption, the system used by Signal and WhatsApp, ensures that only the sender and recipient can read a message. Not even the app provider can see the content in transit. Client-side scanning changes this by inserting an analysis step before encryption happens, directly on the user's device. Every photo, file, or message gets checked against a database or algorithm before it's locked with encryption and sent.

The encryption itself isn't broken in a cryptographic sense. But the privacy guarantee it's supposed to provide, that no third party can inspect your communications, is defeated. If a device is scanning content before it's sent, then a third party (the scanning system, and by extension whoever controls it) effectively has visibility into your private communications regardless of what happens to the data afterward. This is the core objection raised by security researchers, messaging providers, and digital rights groups: client-side scanning doesn't coexist peacefully with end-to-end encryption, it hollows it out from the inside.

Our explainer on Chat Control 2.0 and the EU's CSAM scanning plan walks through how this proposal has evolved and why messaging providers have pushed back so hard against mandatory scanning requirements.

Why a VPN Can't Protect You From On-Device Scanning

This is the point that often gets confused in public discussion, so it's worth stating plainly: a VPN does nothing to prevent client-side scanning. A VPN encrypts your internet traffic between your device and a remote server, protecting your connection from network-level surveillance, your internet provider, or someone snooping on public Wi-Fi. It has no visibility into, and no control over, what happens on your device before that traffic is sent.

Client-side scanning happens locally, on the phone or computer itself, before a message is encrypted and transmitted. A VPN operates entirely downstream of that process. If an app is required to scan a photo before sending it, no VPN, no matter how strong its encryption or how strict its no-logs policy, can intervene in that scan. This is a fundamental architectural distinction that every privacy-conscious user should understand: VPNs protect data in transit, not data at the point of creation.

Where the Chat Control 2.0 Debate Goes Next

The broader Chat Control 2.0 proposal, the formal legislative effort to mandate rather than merely permit scanning, remains unresolved. Each ePrivacy extension buys time without settling the underlying question of whether the EU will require platforms to scan encrypted messages by law. Messaging providers, security researchers, and civil liberties organizations continue to warn that any mandatory scanning requirement would set a precedent affecting encrypted communications far beyond Europe's borders, since global apps often apply the same architecture everywhere.

For a fuller picture of the legislative timeline, our coverage of what users can do now following the July 9 Chat Control renewal lays out the practical steps available to people concerned about where this is headed.

What This Means For You

If you use Signal, WhatsApp, or any encrypted messaging app in the EU, nothing has changed in your day-to-day experience yet. Client-side scanning is not currently mandatory. But the legal groundwork for it keeps being extended rather than resolved, which means the possibility remains live. Users should understand that encryption strength alone doesn't guarantee privacy if scanning is inserted before encryption occurs, and that no VPN, firewall, or network tool can substitute for that guarantee once it's compromised.

Actionable Takeaways

Stay informed on the legislative timeline rather than assuming the issue is settled, since these extensions happen quietly and repeatedly. Understand the difference between network-level privacy tools like VPNs and on-device protections like end-to-end encryption, they solve different problems. Follow statements from the messaging providers you use directly, as companies like Signal have historically been vocal about threats to their encryption model. And if you want to weigh in, EU citizens can contact their representatives in the European Parliament, since public pressure has previously shaped how quickly and how far these proposals advance.