Regulation (EU) 2021/1232 creates a temporary exception to the ePrivacy Directive, giving providers a legal basis to voluntarily scan private messages for child sexual abuse material. Originally set to expire 3 August 2024.
With the permanent regulation (Chat Control 2.0) nowhere near agreement, the derogation is extended until 3 April 2026.
The Commission proposes extending the derogation by another two years, to April 2028.
In a surprise vote, the Parliament's civil liberties committee rejects the draft extension by 38 votes to 28.
The plenary votes 458–103 for a compromise: extend to 2027, but only with targeted and proportionate detection of known content, no end-to-end encrypted communications, and limiting scanning to suspected users or groups identified by the competent judicial authority.
The Council rejects Parliament's conditions and shows no flexibility in negotiations; talks on the extension break down.
311 MEPs vote against extending the derogation (228 in favour, 92 abstentions). The critical Amendment 34, rejecting automated assessment of unknown photos and texts, passes by a single vote (307–306).
The legal ground for voluntary, indiscriminate scanning ends. Google, Meta, Microsoft, and Snap state they will continue scanning private messages regardless.
EU ambassadors agree to push a temporary revival — unprecedented, as Parliament's rejection was considered final. Because an expired regulation cannot be extended, the Council proposes a formally new law with identical content via an expedited procedure.
The Council adopts its position on the "new" regulation via written procedure.
Parliament voted 331–303 (11 abstentions) to fast-track the expired derogation, skipping the responsible Committee. A binding vote follows on Thursday, 9 July, where an absolute majority of 361 MEPs is needed to stop it.
Home Affairs Commissioner Ylva Johansson unveils a proposal for a permanent regulation making detection and reporting of child sexual abuse material a legal requirement for platforms — including a requirement to bypass end-to-end encryption.
No scanning of end-to-end encrypted services, detection limited to visual material, judicial warrants targeted at specific suspects, and no mandatory age verification.
After years of Council deadlock, Germany announces it will vote against mandatory suspicionless scanning. The Danish presidency drops detection orders and shifts to risk assessment and mitigation obligations for providers, while proposing to make the voluntary suspicionless scanning (interim regulation) permanent.
The Council adopts the softened Danish compromise, opening trilogue negotiations. Critics note the text still allows “voluntary” suspicionless detection and imposes broad risk-mitigation duties, including mandatory age verification, that could reshape private messaging in practice.
Negotiations between Parliament, Council, and Commission take place on 9 December 2025, 26 February, 16 April, and 11 May 2026 — without agreement on the core issues.
The Council Legal Service states that the "voluntary" scanning proposal still constitutes generalised scanning of communications — incompatible with Article 7 of the EU Charter absent reasonable suspicion and prior judicial authorisation.
The fifth trilogue, billed as the last with adoption targeted for July, produces no deal. Negotiators cannot agree on making suspicionless scanning permanent, as requested by Council. Progress is reported on excluding mandatory age verification, but agreement is postponed and talks continue under the incoming Irish presidency.
Regulation (EU) 2021/1232 creates a temporary exception to the ePrivacy Directive, giving providers a legal basis to voluntarily scan private messages for child sexual abuse material. Originally set to expire 3 August 2024.
Home Affairs Commissioner Ylva Johansson unveils a proposal for a permanent regulation making detection and reporting of child sexual abuse material a legal requirement for platforms — including a requirement to bypass end-to-end encryption.
No scanning of end-to-end encrypted services, detection limited to visual material, judicial warrants targeted at specific suspects, and no mandatory age verification.
With the permanent regulation (Chat Control 2.0) nowhere near agreement, the derogation is extended until 3 April 2026.
After years of Council deadlock, Germany announces it will vote against mandatory suspicionless scanning. The Danish presidency drops detection orders and shifts to risk assessment and mitigation obligations for providers, while proposing to make the voluntary suspicionless scanning (interim regulation) permanent.
The Council adopts the softened Danish compromise, opening trilogue negotiations. Critics note the text still allows “voluntary” suspicionless detection and imposes broad risk-mitigation duties, including mandatory age verification, that could reshape private messaging in practice.
The Commission proposes extending the derogation by another two years, to April 2028.
Negotiations between Parliament, Council, and Commission take place on 9 December 2025, 26 February, 16 April, and 11 May 2026 — without agreement on the core issues.
In a surprise vote, the Parliament’s civil liberties committee rejects the draft extension by 38 votes to 28.
The plenary votes 458–103 for a compromise: extend to 2027, but only with targeted and proportionate detection of known content, no end-to-end encrypted communications, and limiting scanning to suspected users or groups identified by the competent judicial authority.
The Council rejects Parliament’s conditions and shows no flexibility in negotiations; talks on the extension break down.
311 MEPs vote against extending the derogation (228 in favour, 92 abstentions). The critical Amendment 34, rejecting automated assessment of unknown photos and texts, passes by a single vote (307–306).
The legal ground for voluntary, indiscriminate scanning ends. Google, Meta, Microsoft, and Snap state they will continue scanning private messages regardless.
The Council Legal Service states that the “voluntary” scanning proposal still constitutes generalised scanning of communications — incompatible with Article 7 of the EU Charter absent reasonable suspicion and prior judicial authorisation.
EU ambassadors agree to push a temporary revival — unprecedented, as Parliament’s rejection was considered final. Because an expired regulation cannot be extended, the Council proposes a formally new law with identical content via an expedited procedure.
The fifth trilogue, billed as the last with adoption targeted for July, produces no deal. Negotiators cannot agree on making suspicionless scanning permanent, as requested by Council. Progress is reported on excluding mandatory age verification, but agreement is postponed and talks continue under the incoming Irish presidency.
The Council adopts its position on the “new” regulation via written procedure.
Parliament voted 331–303 (11 abstentions) to fast-track the expired derogation, skipping the responsible Committee. A binding vote follows on Thursday, 9 July, where an absolute majority of 361 MEPs is needed to stop it.