Overview
- The EU Council formally approved the temporary exception to data‑protection rules on Thursday, restoring a legal basis for platforms to run voluntary scans of private messages until 3 April 2028.
- Under the reactivated rule, providers may scan unencrypted emails and messages for known images or videos of child sexual abuse but may only forward suspected matches to authorities after a human reviewer has verified them.
- The measure explicitly bars breaking end‑to‑end encryption and prohibits client‑side scanning, meaning no software may scan content on users’ devices before encryption is applied.
- The restart followed a contested fast‑track parliamentary procedure pushed by Germany and the European People’s Party, drawing sharp criticism from privacy groups and some MEPs who said the move sidestepped an earlier rejection.
- The exception is temporary while Council, Parliament and Commission continue negotiating a permanent ‘Chatkontrolle 2.0’, a process that will decide binding obligations for platforms and shape future tensions between child protection and privacy.