EU Reopened Voluntary Message Scanning. E2EE Is Out—for This Temporary Law
The EU reinstated a temporary legal route for providers to scan some private communications voluntarily through April 2028. Parliament excluded end-to-end encrypted communications. The implementation receipts are still missing.

The EU has reopened a temporary legal route for communications providers to scan some private messages voluntarily for child-sexual-abuse material and solicitation. That is a serious confidentiality exception. It is not a universal scanning order, and Parliament excluded end-to-end encrypted communications from this temporary law. The next accountability fight is provider implementation: data volume, tools, errors, retention, reports, and appeals.
The European Union did not pass a law ordering every platform to scan every message.
It did something narrower and still consequential.
On July 23, the Council of the European Union announced that it had adopted—and “reinstated”—a temporary exception to the confidentiality rules in the ePrivacy Directive. The exception lets covered communications providers use specified technologies voluntarily to detect, report, and remove online child sexual abuse, subject to legal conditions.
The previous measure expired on April 3. The replacement applies until April 3, 2028.
Parliament also changed the text in one critical way: end-to-end encrypted communications are excluded from this temporary derogation.
That means two popular summaries are wrong at the same time.
“The EU mandated scanning of every private message” outruns the law. “The EU abandoned message scanning” ignores the confidentiality exception it just reopened for covered non-E2EE communications.
Reality is less convenient and more useful: a temporary permission is back, E2EE communications are fenced out of this instrument, and providers that use the permission will create the evidence needed to judge whether its safeguards work outside Brussels paperwork.
What the law permits
The Council’s first-reading position, document 11261/1/26 REV 1, describes a temporary derogation from Article 5(1) and Article 6(1) of the ePrivacy Directive. Those provisions protect communications confidentiality and traffic data.
Covered number-independent interpersonal communications services include messaging, webmail, and voice-over-internet services. The derogation permits providers to process strictly necessary content and related traffic data for the sole purpose of:
- detecting and removing online child-sexual-abuse material;
- reporting suspected material to law enforcement or qualifying public-interest organisations;
- detecting possible solicitation of children;
- reporting suspected solicitation.
The text contemplates hashing for known images and videos, classifiers and artificial intelligence for analysing text or traffic data, and pattern detection for possible solicitation.
This is not a blank cheque. The Council text says technology must be least privacy-intrusive, sufficiently reliable, subject to a data-protection impact assessment and prior consultation, and limited to what is strictly necessary. It also requires human oversight.
For material not already identified as abusive—and for suspected solicitation—the text requires human confirmation before a report goes to law enforcement or a qualifying organisation.
Those are legal requirements. They are not proof that every provider follows them, every regulator can enforce them, or every classifier performs acceptably in the field.
A safeguard on paper is a testable promise. It is not a completed test.
What Parliament excluded
The European Commission’s July 15 opinion states that Parliament adopted three amendments excluding “number-independent interpersonal communications to which end-to-end encryption is, has been or will be applied.”
The Commission accepted the amendments for this temporary measure. It also said the exclusion’s scope would benefit from “more precision and clarity.”

European Commission, COM(2026) 393, July 15, 2026, page 2. This is the Commission’s official description of Parliament’s amendments. It is not evidence about any provider’s implementation. Read the official PDF.
The supported claim is precise: E2EE communications are excluded from this temporary derogation.
“Encrypted apps are exempt” is too broad. A single service can contain E2EE message content, unencrypted metadata, public posts, account reports, cloud backups, optional non-E2EE features, and recipient-created copies. Those objects may be governed by different policies and laws.
The exclusion also does not settle the EU’s separate, long-term child-sexual-abuse regulation. The Commission explicitly says its acceptance here is without prejudice to its position in those negotiations.
Temporary file. Temporary fence. Separate permanent fight.
The status feeds do not all agree yet
Official systems update at different speeds, which is why legislative status should not be written like a sports score.
The Council’s July 23 release says formal adoption is complete. At Kyber’s July 24 research cutoff, the European Parliament Legislative Observatory still displayed “Awaiting Council decision, 2nd reading.” The Council document itself still contained blank placeholders for the final regulation number and date.
That does not cancel the Council’s adoption notice. It does mean the Official Journal record had not been retrieved and the public status feeds were asynchronous.
The Council text says the regulation enters into force on the third day after publication in the Official Journal of the European Union. Until that publication posts, do not invent a regulation number or claim the law became operational on July 23.
The defensible status is: Council adoption announced; Official Journal number and exact commencement pending direct confirmation.
The safeguards worth auditing
The Council text is unusually specific about the records providers should produce. A provider relying on the derogation must publish and submit reports six months after entry into force and every January 31 thereafter.
Those reports are supposed to include:
- type and volume of data processed;
- legal grounds used under the GDPR;
- grounds for transfers outside the EU;
- number of identified cases, separated between material and solicitation;
- internal complaints and judicial challenges, plus outcomes;
- false-positive numbers and ratios for each technology;
- measures used to reduce errors and the error rate achieved;
- retention policy and data-protection safeguards;
- names of public-interest organisations receiving data.
That list is the real story waiting to happen.
A legislature can write “least privacy-intrusive” into a recital. Providers must show which system they selected, how much data it touched, how often it was wrong, who reviewed the output, where reports went, what was retained, and what happened when a user challenged a bad decision.
Without those receipts, “strict safeguards” is institutional brochure language.

Kyber scope map reconstructed from Council 11261/1/26 REV 1 and Commission COM(2026) 393. This is an explanatory graphic, not an official EU diagram or live provider architecture.
A scan is not a conviction
The law’s own reporting structure separates the stages that headlines usually crush together.
- Data is processed.
- A technology produces a flag or match.
- A human reviews new material or suspected solicitation.
- A provider may submit a report.
- An authority may investigate.
- A child may be identified.
- A perpetrator may eventually be convicted.
Those denominators are not interchangeable.
A hash match against verified known material is not the same technical event as a classifier prediction. A classifier flag is not a confirmed report. A report is not an arrest. An arrest is not a conviction.
Article 8 asks member states to report the number of provider reports, identified children, and convicted perpetrators separately. That separation should survive every press release and transparency report.
If a provider publishes one impressive number without the stages around it, the public has been handed marketing, not accountability.
Retention is not one number
The Council text says that where suspected online child sexual abuse is identified, specified content, traffic data, and generated personal data may be securely stored only for listed purposes and no longer than strictly necessary. It sets an outer limit of 12 months from identification.
Then it adds a caveat: other EU or national legal preservation obligations may still apply.
That is not a universal promise that every copy disappears after 12 months.
The implementation audit must separate:
- scanned source content;
- traffic data;
- generated classifier output;
- hash values;
- human-review records;
- provider reports;
- internal complaint files;
- audit logs;
- exports to public-interest organisations;
- law-enforcement copies;
- backups;
- evidence and legal holds.
“Retention: 12 months” is meaningless unless the provider names the object, clock, purpose, deletion event, and exceptions.
The institutional case—and its limit
The Council and Commission argue that the derogation restores legal certainty for voluntary provider action while negotiations continue on permanent legislation. Their stated objective is protecting children, identifying victims, limiting repeated circulation of abusive material, and supporting targeted investigation of offenders.
That objective is legitimate. Child sexual abuse is not a rhetorical invention, and privacy is not a shield for exploitation.
But a legitimate objective does not erase the rights of every user whose communications enter the system. The Council text itself acknowledges that voluntary detection interferes with the privacy and data-protection rights of all users of covered services. It says general and indiscriminate monitoring of everyone’s communications interferes with confidentiality.
That admission matters. The policy argument is not “privacy versus children,” as if only one can survive. The standard is targeted, proportionate detection with independent oversight, measurable errors, human review, remedies, and a real boundary around encrypted communications.
Governments love turning hard crimes into universal infrastructure arguments. The correct answer is to pursue offenders with evidence while refusing to make permanent inspection the default condition of private communication.
What readers can do
Prefer actual E2EE for sensitive conversations
Use a service where end-to-end encryption is enabled for the conversation you are having, not merely mentioned somewhere on the product page. Check whether encryption applies to messages, group membership, metadata, backups, linked devices, and reports separately.
E2EE protects message content in transit from provider access. It does not stop the recipient from saving or reporting a message, protect an unlocked endpoint, or make account metadata disappear.
Audit cloud backups
A private conversation can be E2EE while its backup is exposed under a different key and policy. Review whether backups are end-to-end encrypted, who controls the recovery key, and whether disabling a backup actually deletes old copies.
Watch provider notices
The Council text requires providers invoking the derogation to explain that fact, the logic of their measures, the effect on confidentiality, and the possibility of sharing with law enforcement or qualifying organisations. Preserve those notices. Compare revisions. Ask which service features and data categories are covered.
Demand the required error data
When transparency reports appear, do not settle for total reports. Ask for:
- volume of data processed;
- tool and version;
- known-material hashing versus classifier use;
- false-positive count and denominator;
- human-confirmation rate;
- complaints and reversals;
- retention by data object;
- downstream recipients;
- investigations and adjudicated outcomes.
Use the appeals route
The text requires complaint and redress mechanisms and notice when content is removed, an account is blocked, or service is suspended. Preserve the notice, exact content, timestamps, policy version, and appeal result. Do not assume an automated flag is infallible because the subject matter is radioactive.
The next receipts
This story should be updated when the Official Journal publishes the final act. That will settle the regulation number, publication date, entry into force, and final consolidated wording.
After that, track five things:
- which providers publicly invoke the derogation;
- which features and data types they scan;
- which technologies and versions they use;
- whether published error, retention, and complaint data match Article 3;
- whether regulators enforce the conditions when providers fail.
For the broader platform-control problem, read Kyber’s field guide to automated moderation as a platform dependency. For the device-side version of permissioned access, read how remote attestation turns app compatibility into a control layer.
The temporary law is not the permanent surveillance machine some critics describe. It is also not harmless administrative housekeeping.
It reopens a legal permission to inspect covered private communications, leaves encrypted communications outside this particular fence, and creates a reporting trail that should make implementation auditable.
Now comes the part institutions usually prefer nobody reads: the error rates.
Sources
- https://www.consilium.europa.eu/en/press/press-releases/2026/07/23/fighting-child-sexual-abuse-online-interim-measure-protecting-children-now-reinstated/
- https://data.consilium.europa.eu/doc/document/ST-11261-2026-REV-1/en/pdf
- https://www.europarl.europa.eu/RegData/docs_autres_institutions/commission_europeenne/com/2026/0393/COM_COM(2026)0393_EN.pdf
- https://oeil.secure.europarl.europa.eu/oeil/en/procedure-file?reference=2025/0429(COD)
