The European Parliament has voted to extend legislation allowing tech companies to voluntarily scan users' private messages for child sexual abuse material, a move critics say undermines digital privacy and sets a dangerous precedent for surveillance. Despite a majority of lawmakers voting against the proposal — a rare procedural outcome — the measure passed due to a quirk in parliamentary rules, according to WIRED.
The Vote and Procedural Maneuver
The legislation, nicknamed "Chat Control" by critics, reinstates permissions for firms including Meta, Google, and Microsoft to scan private text, email, and social media messages for child sexual abuse material. End-to-end encrypted chats, such as those on WhatsApp and Signal, remain exempt, per the ruling. The vote took place on Thursday, with more Members of the European Parliament voting against the regulation than for it. However, they fell short of the required absolute majority of 361 votes by 47 votes, meaning the proposal passed. The European People's Party (EPP), the largest political group in the European Parliament, had been pushing to bring back tech firms' legal basis to scan messages since a prior law expired in April. The EPP resorted to an "urgent procedure" — skipping preliminary committee debates where amendments would often be introduced — to force fresh votes after talks collapsed in March. The procedure stipulates that the regulation passes unless an absolute majority of 361 MEPs vote against it.
Reactions from Rights Advocates and Politicians
Simeon de Brouwer, policy advisor at Brussels-based advocacy group European Digital Rights, told WIRED: "It will mean that private companies may deny your right to have confidential digital conversations… they could, if they want to, read every message you write, every email you send, every picture you share." The EPP vice-chair Tomas Tobé defended the move, telling lawmakers earlier in the week: "We cannot go to the summer recess knowing that our children are not protected." Civil rights activist and former MEP Patrick Breyer called the ruling a "farce" that "damages democracy." In a blog post, Breyer wrote: "Our children are the real losers in this undemocratic process. Trying to protect children with suspicionless mass surveillance is like frantically mopping the floor while the faucet is still running. Blanket chat control is just as unacceptable as indiscriminately opening everyone's physical mail."
Implications for Digital Rights and Enterprise Security
The extension means tech companies will retain the right to scan messages for child sexual abuse detection until 2028, or until permanent legislation — already dubbed "Chat Control" by critics — replaces it. For enterprise technology decision-makers, the ruling highlights the ongoing tension between security and privacy in digital communications. While the exemption for end-to-end encrypted platforms like WhatsApp and Signal offers a measure of protection for business communications, the broader permission for scanning non-encrypted messages could affect corporate data privacy policies. Companies relying on cloud-based messaging and email services from Meta, Google, and Microsoft may need to reassess the confidentiality of their internal communications, as these platforms could technically scan messages without user consent. The decision also underscores the need for organizations to adopt end-to-end encryption solutions for sensitive business correspondence to avoid potential surveillance, even under the guise of child protection.
The procedural maneuver used to pass the legislation — bypassing committee debates — has drawn criticism from democracy advocates. The European Parliament is set to disperse for its summer break at the end of the month, which added urgency to the EPP's push. The ultimate fate of permanent legislation remains uncertain, but the current extension provides a multi-year window for tech companies to continue scanning, raising ongoing privacy concerns for both individuals and enterprises.