The European Union is struggling to answer one of the information-era dilemmas: for the sake of security, what’s the negotiating line on privacy exceptionality? Theorised under child pornography concerns, the “Chat Control” package may set a precedent in blurring the line of EU citizens’ right to private communications.
What critics call “Chat Control” is not one law but a tangle of two. An emergency derogation patched together in 2021 and repeatedly extended, and a permanent regulation proposed in 2022 that has spent years stuck in trilogue over the same unresolved question: mandatory scanning, or voluntary. On 9 July 2026, that tangle produced its most contested moment yet, when the European Parliament voted on a Council text it had already rejected months earlier and, through a procedural quirk rather than a change of political will, let it pass anyway. The roll-call behind that vote exposes fractures inside groups that had presented themselves as unified on digital rights, turning a technical dossier into a case study in how coalitions actually hold, or don’t, when security and privacy collide.
Here are some details of the events.
The History of the EU “Skynet”
The EU’s “Chat Control” saga concerns two distinct instruments frequently conflated in coverage. The permanent CSAR proposal (COM(2022)209) sought mandatory detection orders for CSAM on interpersonal communication services, including end-to-end encrypted ones, and remains stalled in trilogue after Member State opposition—led by Germany, Poland, and the Netherlands—forced the Danish presidency to strip mandatory scanning from the Council’s November 2025 general approach. Separately, Regulation 2021/1232 established a temporary ePrivacy derogation permitting voluntary CSAM scanning; this “bridge” measure, already extended twice, lapsed on 3 April 2026 after LIBE rejected a further extension (38-28) and plenary confirmed the rejection on 26 March (311-228).
A last-ditch EPP attempt to salvage the extension failed. Facing the resulting legal gap, the Council took an unprecedented step on 26 June 2026: Cypriot presidency ambassadors agreed to relaunch the very extension Parliament had rejected, via an internal note acknowledging the move was “without precedent” given Parliament’s clear rejection. The Council formalised this as its own first-reading position on 2 July 2026, reopening a second-reading vote in Parliament under an expedited procedure that bypassed committee scrutiny.
Who voted (and who defected)
On 9 July 2026, the European Parliament voted on whether to reject the Council of the European Union’s revived text reinstating “Chat Control 1.0”—the temporary derogation from the ePrivacy Directive that lets platforms voluntarily scan unencrypted communications for known child sexual abuse material. Two days earlier, Parliament had already approved an emergency procedure fast-tracking the file directly to plenary, a move critics argued allowed the European People’s Party (EPP) to bypass the ordinary legislative process. By reopening the negotiations, Parliament President Roberta Metsola enabled the Council text to return despite no change in Parliament’s political support. Although a majority of MEPs voted in favour of ending the derogation, the proposal survived because opponents failed to reach the procedural threshold. Parliament nevertheless adopted amendments exempting end-to-end encrypted services such as WhatsApp, Signal and iMessage.
The Socialists and Democrats (S&D) are the sharpest case. A majority of the group broke with Birgit Sippel, the S&D rapporteur who had authored the supervised compromise Parliament adopted back in March in place of the Commission’s original proposal: 59% of voting members chose to keep the derogation alive. That is not a handful of outliers; rather, the group reversed the position its own negotiator had set five months earlier. One name that stands out among the MEPs voting to preserve the derogation is Iratxe García Pérez, who has led the S&D Group since 2019.
Renew Europe is the second notable case. Although the liberal group has generally presented itself as a defender of digital rights and civil liberties, 35% of MEPs crossed over to vote against rejecting the Council’s position. With over a third of the group backing the Council, this was more than routine internal dissent—Pascal Canfin’s vote illustrates how concerns over law enforcement and child protection cut across the liberal camp’s usual emphasis on privacy and fundamental rights.
The remaining groups largely voted as expected: Greens/EFA had all but three members abstaining, with the remainder voting for rejecting the proposal; meanwhile, The Left voted almost unanimously to strike down the derogation, with Lynn Boylan, the Irish Sinn Féin MEP who chairs the Parliament’s delegation for relations with Palestine, casting the only dissenting vote. Looking at the right side of the hemicycle, both the Patriots for Europe and the European Conservatives and Reformists Group (ECR) saw 88% and 67% of their members, respectively, support ending the derogation.
Timeline to watch
The vote on July 9 in Strasbourg approved modifications to a derogation from the ePrivacy rules that had officially expired on April 3, 2026. Instead of simply renewing the previous text, Parliament adopted a decisive amendment that excludes all communications protected by end-to-end encryption from the scope of scanning. This modified file has now returned to the Council of the EU, which has a three-month window to either accept or reject the Parliament’s amendment. If the Council does not accept it, a conciliation procedure will be initiated between the two institutions, likely keeping this temporary measure unresolved well into the autumn.
The more consequential legislative battle concerns the Child Sexual Abuse Regulation (often called “Chat Control 2.0”), which the Commission first proposed in 2022. This permanent framework would move beyond the current voluntary transitional measure to introduce binding legal obligations, including mandatory detection orders and risk assessments. While the Council of the EU reached its position on this permanent text in late 2025, negotiations with Parliament remain ongoing. Digital rights observers and the European Data Protection Supervisor have warned that the proposed model, which relies on private companies to perform automated scanning, lacks sufficient judicial supervision and risks becoming a system of indiscriminate mass surveillance. Even member states like Italy, while supporting the temporary derogation, have formally expressed concerns about granting private platforms such extensive powers over citizens’ private communications.




