Overview
- The European Parliament voted on Thursday, July 9, to revive the 2021 ePrivacy derogation that permits platforms to voluntarily scan private messages for child sexual abuse material after opponents failed to reach the absolute majority needed to block the measure.
- MEPs adopted an explicit exemption for communications protected by end-to-end encryption, but critics say that exemption may be symbolic because device-level or client-side scanning could still inspect content before encryption and pressure providers to change app architectures.
- The vote used an uncommon fast-track second-reading procedure that required an absolute majority of the full chamber to reject the Council’s position, producing a confused plenary and complaints from lawmakers who said they did not fully understand the process.
- Parliament has sent its amended text to the Council, which has three months to accept or reject the changes; if the Council rejects parts of the amendments the file will go to conciliation and legal uncertainty for providers will continue.
- The interim derogation will remain in place until 2028 or until a permanent CSAM regulation is adopted, and negotiators plan to resume talks on a lasting law later this year that will decide whether detection stays voluntary or becomes mandatory and how encryption is protected.