EU Chat Control Could Spell an End to Private Messaging

Opinion 6 min read — EU Institutions | Technology & AI | Media | Democracy

EU Chat Control Could Spell an End to Private Messaging

The EU has long seen itself as the world’s gold standard for digital privacy. Chat Control is a reckoning for that claim.

EU Chat Control Would Spell an End to Private Messaging

Image Credit: Euro Prospects

By Kristóf Hermann

Edited by Francesco Bernabeu Fornara

6 August 2026

Follow our European analysis:

Instagram

On 9 July 2026, the European Parliament passed Chat Control 1.0 through a controversial procedural manoeuvre initiated by EP President Roberta Metsola after the Parliament had already rejected the proposal in March. The legislation renews a temporary regulation allowing service providers to voluntarily scan users’ private messages for child sexual abuse material. It passed not because a majority voted for it, but because the absolute majority required to reject it was not reached.

More fundamentally, Chat Control 1.0 has reignited doubts over the EU’s presumed stringent data protection regulations. What comes next, however, is far more consequential: Chat Control 2.0 — a permanent and mandatory update that extends to end-to-end encrypted services.

The Origins of Chat Control

For many years, Directive 2002/58/EC — or the so-called “ePrivacy” Directive — prohibited providers of online communications services like Facebook from systematically scanning users’ private correspondence. This legislation made detecting child sexual abuse material (CSAM) more difficult, certainly, but it also protected the privacy and data of millions of ordinary users.

That changed with the adoption of Regulation (EU) 2021/1232, a temporary measure allowing service providers to voluntarily scan users’ messages for child sexual abuse. Crucially, the regulation did not extend to end-to-end encrypted (E2EE) messaging services like WhatsApp or Signal, preserving a baseline level of privacy for users.

Chat Control 1.0, passed by the European Parliament (EP) last month through a procedural loophole initiated by EP President Roberta Metsola, updated and reinstated that Regulation. While more MEPs voted against than in favor of the proposal, the absolute majority required to reject it was not reached, thereby approving it. By resurrecting a defeated bill on the eve of a major holiday break through a rare procedure, the move represents a power play unprecedented in the Parliament’s history, and may set a dangerous precedent with the extended Chat Control 2.0 still on the table.

Chat Control 2.0 was proposed in 2022, which unlike 1.0’s temporariness and voluntariness, is a permanent regulation requiring platforms to scan conversations between users, including services providing end-to-end encryption (E2EE). The scanning of messages would take place before encryption, rendering E2EE technology essentially pointless from a privacy standpoint. As a result, fears of the potential for future mass surveillance and criticism of EU democratic legitimacy have understandably been proliferating.

Bypassing the Parliament: A Question of Democratic Legitimacy

Indeed, circumventing the EU’s ordinary legislative procedure in such a way raises serious questions. The European Parliament, being the only directly elected body of the EU, not only provides a forum for representatives of European citizens to debate relevant topics, it is also a core source of the Union’s already-fragile democratic legitimacy.

Setting aside the legality of the legislative circumvention, democratic legitimacy is in large part a matter of citizens’ perception. With MEPs being the representatives closest to EU citizens, Roberta Metsola’s methods are easily read as anti-democratic in effect. Combined with the underlying privacy concerns, the situation raises serious doubts about the EU’s adherence to citizens’ right to digital privacy — and about what precedent it sets for the future in light of the proposed Chat Control 2.0.

A New Era, New Struggles for Privacy

The slow pace of European lawmaking has always been a challenge when it comes to regulating fast-moving advancements in the IT sector. This, however, does not justify disregarding citizens’ privacy.

EU lawmakers already struggle to regulate Big Tech, including giants such as Meta, Google, OpenAI and Anthropic. Experience has repeatedly shown that entrusting such companies with sensitive information carries real risk, and giving them access to scan private correspondence opens the door to perverse incentives, at best.

Whether such data would end up being leaked, repurposed to train large language models, or sold to malicious actors is impossible to say in advance. Chat Control 1.0, however, will surely not make it harder to do so, and incentives are certainly not aligned. Corporations are made to be profit-seeking entities, and have historically treated user data in that light: as an asset to be monetised, rather than private information to be protected.

Privacy as a Human Right: How Far Can the EU Go?

The right to privacy has long been recognized in international human rights principles. Article 17 of the UN’s International Covenant on Civil and Political Rights (ICCPR), and Article 8 of the European Convention on Human Rights (ECHR) codify it as such. Both provisions affirm the importance of private and family life, and notably, of correspondence.

The EU has similarly embedded this principle within its own legal order, through the Charter of Fundamental Rights of the European Union (CFREU) which governs all EU laws and actions. Article 7 could not be clearer: “Everyone has the right to respect for his or her private and family life, home and communications.”

Article 8 of the Charter separately guarantees the right to protection of personal data, though the clauses regarding how that data may be processed are phrased rather ambiguously. Given that Chat Control 2.0 would directly affect the private communications of innocent users, it is fair to ask whether the EU is preparing to test the limits of its own treaty.

The scanning of messages before encryption is certainly invasive in nature, but the ambiguous wording of the treaty articles still permits the Parliament and Commission a wide range of legislative options. If lawmakers and courts conclude that pre-encryption scanning is not considered arbitrary interference with privacy, there may be little legal ground for objection.

End-to-End Encryption: The last means of online privacy?

Given the pace of technological change, the rapid progress of AI, and the increasing importance of social media, the question arises: to what extent should users remain in control of their private data?

Most of what large tech companies know about users is shared willingly, most commonly through ‘cookies’, but private messaging is different. People routinely share confidential information over messaging platforms at work, in education and in everyday life — including sensitive private circumstances.

End-to-end encryption remains one of the last meaningful safeguards of privacy for ordinary users, while a significant portion of criminal communication already takes place on other channels, such as the dark web. Weakening or eliminating E2EE would not only grant authorities more visibility into online communication — it would also leave users exposed to Big Tech companies and malicious actors looking to profit from stored information. Removing this layer of protection would not only move the EU closer to mass surveillance, it would directly oppose values the Union claims to uphold.

Digital Privacy, or the Protection of Children?

It is impossible to dissect the topic of Chat Control without mentioning the tensions between digital privacy and child protection. Both issues are highly sensitive and are regularly invoked by opposing sides of the political spectrum.

The protection of children online is, without question, a matter of key importance for our society, including the EU. Regardless, introducing measures such as Chat Control 2.0 would affect every citizen of the Union while potentially failing to bring distributors of CSAM to justice, as perpetrators could simply switch to other channels, such as the dark web.

Scanning every citizen’s private messaging not only introduces serious security risks — it also treats innocent EU citizens as suspects by default. Chat Control 2.0 would set a precedent in which the mere potential to commit a crime is enough to warrant suspicion.

Experts have also warned about the accuracy of detection algorithms, which, even at their highest achievable levels of accuracy, could still generate tens of thousands of false positives per month. Given the sheer volume of messages scanned, these algorithms would likely create a flood of false positives, far more than law enforcement could realistically verify.

While the need to protect children online is of crucial importance, Chat Control 2.0 is unlikely to solve the issue it seeks to address. The distribution of CSAM would likely shift to other channels, while Member States would be left struggling to process flagged messages and deal with false accusations. Since the European Parliament voted to extend the temporary Chat Control 1.0, unencrypted messages will continue to be scanned for CSAM, while E2EE remains intact.

What comes next is far more consequential: the ongoing debate on Chat Control 2.0. Discussions regarding the temporary regulation on private messaging apps using E2EE will continue in September. Until then, European users’ right to private messaging remains uncertain.

Disclaimer: While Euro Prospects encourages open and free discourse, the opinions expressed in this article are those of the author(s) and do not necessarily reflect the official policy or views of Euro Prospects or its editorial board.

Kristóf Hermann

Kristóf Hermann

European Politics Correspondent

Kristóf Hermann joined Euro Prospects in January 2025. Originally from Hungary, he has a background in business economics and marketing and is currently studying European Studies at the University of Amsterdam. His work focuses on Hungarian politics, democracy, and EU affairs, with a particular interest in governance and political shifts. Committed to accuracy and depth, he prioritizes thorough fact-checking and shedding light on overlooked stories.

Edited by Francesco Bernabeu Fornara  |  Follow our European journalism

Close