EU Extends Chat Control Opt-In Derogation to 2028
On July 9, 2026, the European Parliament voted to extend a specific piece of EU legislation known informally as "Chat Control" through 2028. If you saw alarming social media posts suggesting the EU had just imposed mandatory mass surveillance on private messages, it's worth slowing down and looking at what actually happened. The vote did not create a new binding scanning regime. It extended an existing, voluntary derogation that allows messaging platforms to opt in to detecting child sexual abuse material (CSAM) if they choose to. The separate, permanent regulation often referred to as CSAR, which would set binding rules for all providers, is still being negotiated and was not the subject of this vote.
This distinction matters enormously for how the public understands the state of privacy law in Europe. French politician Jean-Luc Mรฉlenchon posted on X claiming the EU had just instituted sweeping surveillance measures, a characterization that conflates two very different legislative tracks. Understanding the difference between an extended opt-in derogation and a binding, EU-wide scanning mandate is essential for anyone trying to assess what protections currently exist for their digital communications.
What Actually Changed on July 9
The legislative history here goes back several years. In 2021, the EU adopted a temporary derogation from its own ePrivacy rules, allowing electronic communication providers such as messaging and email services to voluntarily scan user content for CSAM without running afoul of privacy law that would otherwise prohibit such scanning. This derogation was designed as a stopgap measure while lawmakers worked toward a permanent, comprehensive framework, the CSAR regulation (Child Sexual Abuse Regulation), which has been debated and revised multiple times since it was first proposed.
The July 9, 2026 vote extended that temporary, voluntary derogation until 2028. Nothing changed for users of platforms that have not opted into voluntary scanning. No new mandatory scanning obligation was created. The binding version of Chat Control, the one that has drawn the most sustained criticism from privacy advocates, encryption experts, and civil liberties organizations across Europe, remains stuck in negotiation between the European Parliament, the Council of the EU, and the European Commission. Disagreements over encrypted messaging, the scope of scanning obligations, and safeguards against false positives have kept the final text unresolved for years.
Why the Confusion Matters
Misreporting or oversimplifying legislative votes like this one has real consequences. When a public figure with a large following announces that the EU has "just instituted" mass surveillance, it can spread faster and further than the more nuanced, accurate account of what a procedural extension vote actually does. This kind of confusion can erode public trust in EU institutions on both sides: those who genuinely oppose expanded scanning powers may feel a false sense of urgency or defeat, while those monitoring EU privacy policy closely may dismiss legitimate future concerns as exaggerated, based on this earlier confusion.
The underlying debate is real and unresolved. Privacy advocates have long argued that any mandatory scanning of private communications, even when framed as protecting children, risks undermining end-to-end encryption and creating tools that could be repurposed for broader surveillance. Those concerns remain squarely tied to the still-pending CSAR regulation, not to the derogation extension that passed in July 2026. Anyone tracking this issue should watch the CSAR negotiations closely, since that is where the binding rules affecting encrypted messaging will ultimately be decided.
What This Means For You
For everyday users, this news does not change how your messaging apps currently operate. Platforms that have opted into the voluntary CSAM detection framework can continue doing so through 2028, but no new obligation has been placed on services that have chosen not to participate. If you use end-to-end encrypted messaging apps, your communications are not automatically subject to new scanning as a result of this vote. That said, this is an evolving legislative area, and the final shape of the CSAR regulation could eventually introduce binding requirements that do affect encrypted services. Staying informed about the difference between procedural votes and substantive policy changes is the best way to avoid reacting to inaccurate claims, whether they come from politicians, journalists, or social media posts.
Key Takeaways
Before reacting to headlines about EU surveillance mandates, check whether the news concerns the voluntary Chat Control derogation or the still-pending CSAR regulation, since these are frequently conflated. Follow official European Parliament and Council communications directly when possible, rather than relying solely on secondhand summaries from social media. If you use encrypted messaging services, keep an eye on CSAR negotiations specifically, as that is where binding scanning requirements would eventually be decided. And if privacy matters to you, consider using services that are transparent about whether they participate in voluntary CSAM detection programs, so you can make informed choices about which platforms align with your expectations for privacy.




