The European Union is at it again, with regulations that not only threaten the privacy rights of Europeans but also set a dangerous global precedent due to the Brussels effect. On 9 July 2026, the European Parliament managed to extend “Chat Control 1.0,” a major exemption to European privacy laws that allows platforms to voluntarily scan private chats, despite the majority of MEPs voting against it.
This dangerous exemption, known as a “temporary derogation,” will now remain in force until at least April 2028. The infamous “Chat Control 1.0,” which first came into force in August 2021, expired in April 2026 after MEPs voted against its extension. Despite that, European Parliament (EP) President Roberta Metsola forced the reopening of the file, under the pretext that the expiration of Chat Control 1.0 would pose significant risks to online child protection.
What is Chat Control 1.0?
“Chat Control 1.0” (Regulation (EU) 2021/1232) is aimed at the EU’s e-Privacy rules which protect the confidentiality of communications. Invoking online child protection, especially the fight against the dissemination of child sexual abuse material (CSAM), the derogation permits providers of interpersonal communication services, such as messaging apps, to voluntarily scan private messages without a warrant, a judicial order or even prior suspicion. The derogation essentially strips users from their right to privacy and grants the private sector the power of investigative authorities, without any legal safeguards.
The way the Regulation was extended is also problematic. Although MEPs rejected it in March, President Metsola reopened the file by sending it to the Council, exploiting a loophole in parliamentary procedure. In fact, despite a majority of Parliament voting against the extension, the complex legislative process at the EU requires an absolute majority (currently 361 out of 720 votes) for the Parliament to reject the amended position in the second reading.
This majority was not achieved, mainly because the file was sent back to the Parliament just before the summer recess, leaving opponents with limited time to get organized. Now the Council has 3 months to approve the extension.
There is one provision that differentiates the amended position from the text that was rejected in March, but it comes with a twist. The derogation (exemption) will not apply to end-to-end encrypted messages, but only for services encrypted by default, such as Signal and Whatsapp.
This means that all other platforms and services will not be excluded from the scanning regime. Meta has stated that the company already implements the EU CSAM Derogation, while X’s direct messages (DMs) were not encrypted to begin with. Standard email services also fall under the scope of the derogation.
What does this mean for the right to privacy?
Under EU law, the right to privacy is enshrined in Article 7 (respect for private and family life) and Article 8 (protection of personal data) of the Charter of Fundamental Rights. All EU member states are also signatory parties to the European Convention on Human Rights (ECHR), Article 8 of which protects the right to privacy. Lastly, all 27 member states are bound by Article 17 of the International Covenant on Civil and Political Rights (ICCPR).
Each of these provisions sets forth the possibility for limitations to the right to privacy. The restrictions, however, must fulfill certain requirements under EU law, namely be consistent with national or EU law and necessary for the prevention of crime. Article 52 para 1 of the EU Charter of Fundamental Rights further states that limitations are subject to the principle of proportionality. Additionally, General Comment No 16 on Article 17 ICCPR emphasizes that surveillance of any form of communication should be prohibited.
Chat Control 1.0 fails to adhere to these standards. A blanket mass surveillance, instead of targeted monitoring of suspects, cannot be considered proportionate to the aim pursued or justified under international human rights standards and would compromise the very essence of the right to privacy.
The temporary derogation grants US companies law enforcement capabilities, without any legal protections. National authorities may need a warrant or a judicial order, but private companies outside the EU can legitimately spy on their users by freely accessing their private communications. Such a development not only threatens the right to privacy and the protection of personal data, but also undermines the very essence of democratic processes in the EU.
Handing mass surveillance capabilities to the private sector poses a major risk to the same values the EU supposedly seeks to protect. By lowering security standards for all users, Chat Control 1.0 fails to protect children too. Besides, mass scanning of communications will inevitably lead to false positives, putting users at even higher risk. The second report on systemic risks on VLOPs and search engines under the DSA repeatedly refers to content moderation as a risk factor. Still, automated systems fall short of interpreting cultural nuances, sarcastic tone or other forms of speech which are not straight-forward. This is especially the case with content in minority languages of diaspora populations established in the EU, such as Arabic.
A dangerous precedent
EU legislation often sets the course for legislative orders around the world. The General Data Protection Regulation (GDPR) served as an example for similar data protection frameworks for states outside the EU territory. In the WANA region, for instance, most of the recently adopted Personal Data Protection Laws (PDPLs) drew inspiration or heavily relied on the GDPR’s provisions. The Brussels effect is very much alive and should not be overlooked. EU legislators must take into account that EU rules produce effects at a global scale, and consult with non-EU stakeholders.
Although Chat Control 1.0 is only temporary, Chat Control 2.0, a proposed permanent regulation for child sexual abuse, is currently being negotiated. If adopted, it will establish a legal obligation for digital platforms to detect and report CSAM. The Council and the Parliament have failed to reach an agreement on mandatory scanning and the inclusion of end-to-end encrypted messages, but negotiations will resume in September.
Legislative and political developments in the EU show that it might be the time for countries in West Asia and North Africa (WANA) to question the EU’s influence. Certainly, the EU has produced pioneering legislations, such as the GDPR and the Digital Services Act (DSA), aiming to protect fundamental rights, such as the right to privacy and freedom of expression. Yet, recent legislative attempts such as the Digital Omnibus and Chat Control 1.0 and 2.0 demonstrate a shift in the EU’s priorities, which are not grounded in human rights.
The post Chat Control 1.0 extended: EU’s attempts to legalize mass surveillance could impact users’ privacy beyond its borders appeared first on SMEX.
