Mass surveillance of digital communications is making a comeback in the EU, and it looks set to get more intrusive, not less. On July 9, in a process many called irregular, the European Parliament voted to extend Chat Control 1.0 legislative initiative until 2028, a measure whose extension had already been rejected twice the previous March.
In practice, this means tech giants can scan our private messages on platforms like Facebook and Instagram, and our email on Gmail and Apple iCloud, without a court order or any prior suspicion.
That includes medical test results sent to or from a doctor, property contracts sent to a notary, communications with public agencies, friends, or colleagues, private jokes, and personal photos, all exposed to scanning by the companies running these services.
Experts say this measure undermines the confidentiality of communications and effectively strips away protection for personal data, gutting fundamental rights for EU citizens. For now, Chat Control 1.0 doesn’t allow scanning on encrypted messaging platforms like WhatsApp.
Background
Chat Control 1.0 was passed in 2021 as a temporary exemption from the ePrivacy Directive, which normally protects the confidentiality of communications and personal data. That exemption let tech giants mass-scan Europeans’ electronic communications for child sexual abuse material or grooming.
Even though its backers say it’s necessary to protect children, it drew strong pushback from the start over opening the door to mass scanning of private messages and email.
The temporary rule expired on April 3 this year, after the European Parliament rejected extending it in two votes in March, the second of which saw 311 MEPs vote against extension versus 228 in favor.
On July 2, the European Council brought the extension back to Parliament, and on July 9, under an emergency procedure, MEPs voted 314 against to 276 in favor. But because the emergency procedure required an absolute majority of 361 votes to reject it, the extension passed anyway.
Reactions
In September 2025, more than 800 scientists from universities including Cambridge and MIT sent an open letter to the EU presidency acknowledging the problem of child sexual abuse online, but arguing that mass scanning of mail and messages is technically risky, ineffective, and disproportionate. They warned it would create mass surveillance and urged the EU to focus on targeted, judicially supervised methods instead.
Dimitrios Simos, a cybersecurity professor at the University of Salzburg, told TO VIMA that pushing for a third vote during the summer recess after policymakers were unhappy with the two earlier results wasn’t the best approach for transparency or honest dialogue with the scientific community.
The issue sits at the heart of a genuine conflict between protecting children and the right to privacy. No one disputes that children need real protection online, but experts argue mass surveillance isn’t the answer, comparing it to installing a camera in every home to cut down on burglaries. Simos argues that instead of undermining privacy and confidentiality, authorities should focus on transparency around surveillance practices and open public debate on balancing security with fundamental rights.
It’s also worth noting that available data doesn’t show mass scanning of private communications has meaningfully helped protect children online. The European Commission itself acknowledges there’s no proof that mass scanning has led to more arrests or convictions for child abuse online. Experts say tools like court-authorized wiretaps, user reports, and scanning of public platforms are more effective at protecting children without undermining communication privacy, and warn that child protection could be used as a Trojan horse to police political beliefs, target dissidents, or clamp down on criticism of governments.
What’s Coming
The EU is moving from the temporary Chat Control 1.0 toward a permanent, far more ambitious framework: Chat Control 2.0. The new regulation would require online platforms to systematically detect child sexual abuse material, mainly through AI scanning of messages, photos, and videos, even on end-to-end encrypted apps like Signal and WhatsApp. It would also require mandatory age verification on many platforms using biometric data.
Simos notes that technically, Chat Control 2.0 brings mandatory scanning on the user’s own device, meaning a message would be scanned before it’s even sent. He adds that layering AI content analysis on top of that inherently breaks end-to-end encryption, creating major mass-surveillance risks with unacceptable error rates, and that there’s also serious doubt whether such measures are technically feasible at all, since age verification can’t currently be done in a privacy-safe way given the reliance on biometric data.





