EU Parliament extends ‘Chat Control’ exemption for private‑message scanning until 2028
A procedural vote overrides a majority of MEPs, keeping the temporary rule that lets platforms such as Meta and Google scan unencrypted communications for child sexual abuse material.

Members of the European Parliament have voted to keep Regulation 2021/1232 – commonly known as the “Chat Control” exemption – in place until at least April 2028. The measure allows digital platforms to voluntarily monitor private, unencrypted communications for illegal content related to child sexual abuse (CSAM) without imposing a legal duty to do so.
How the vote was taken
The extension was approved through a procedural mechanism that overrode a clear majority of MEPs who had voted against the measure. The original exemption, adopted in 2021 as a stop‑gap, was due to expire on 26 March 2026. The recent parliamentary action pushes the deadline forward to a legislative package expected to be finalised by April 2028.
What the exemption permits
Under the 2021 rule, operators may scan the content of messages and e‑mails that are not protected by end‑to‑end encryption. The law does not prescribe a specific technology; each company decides how to implement the scans. Meta, Google, Microsoft and other firms already use existing automated systems for the scanning under this exemption.
The exemption does not apply to services that employ end‑to‑end encryption – such as Signal, Threema, Delta Chat, Telegram, WhatsApp and Messenger – meaning that users of those apps are not subject to the scans. Consequently, some users have switched to apps that promise such security.
Legal backdrop
The European Court of Justice has ruled that reading private communications without consent breaches the ePrivacy Directive. The EU has therefore created narrow exceptions for serious criminal offences, with child sexual abuse consistently included. The temporary exemption was introduced as a narrow carve‑out for CSAM, and the European Data Protection Board has indicated that any mandatory decryption requirement would need to be narrowly tailored and proportionate.
Future proposals – “Chat Control 2.0”
A draft “Chat Control 2.0”, circulating since 2020, proposes to make scanning mandatory and to extend it to encrypted messages. Under that proposal, platforms that fail to comply could face fines, and companies might be forced to redesign their architecture to break or bypass encryption. The European Commission is expected to present a formal proposal for “Chat Control 2.0” later this year after consultations.
Reactions from stakeholders
The European Trade Union Confederation (ETUC) welcomed keeping tools that help protect children but warned that making scanning compulsory could lead to surveillance creep that harms workers who use private messaging for organising.
Consumer organisations Which? condemned the parliamentary procedure that allowed the exemption to pass despite a clear majority voting against it.
The Internet Association Europe said the temporary measure provides companies with legal certainty to continue investing in AI‑driven detection tools without fear of retroactive penalties. It added that a mandatory scanning regime could force firms to redesign their architecture, potentially increasing costs that would be passed on to consumers.
Financial and legal implications
The exemption means that messages sent through platforms such as Facebook Messenger and Gmail may be examined by automated systems for suspected CSAM, without user notification or a clear way to contest false positives. The EU has not allocated additional funding for the scanning programmes; the cost burden remains with the tech firms.
A coalition led by EDRi has filed a preliminary injunction in the Court of Justice of the EU, arguing that the 2021 exemption violates the GDPR principle of data minimisation. The case could reach the EU’s top court before the 2026 deadline.
Trade unions have called for stronger safeguards to ensure engineers are not compelled to develop backdoors that could be misused. Parliamentary committees are likely to examine the impact of any permanent framework on fundamental rights, especially the right to private communication in the EU Charter.
Legislators now have a narrow window to decide whether to let the exemption lapse in March 2026 or replace it with a permanent regime. The outcome will shape the balance between child‑protection objectives and the privacy rights of European citizens.

