CURRENT AFFAIRS
The reopened breach in the privacy of communications: a European case, a universal standard
23 July 2026 — European Union / Geneva (UN)
Article 17 of the International Covenant on Civil and Political Rights (ICCPR), ratified by 173 States, establishes that no one shall be subjected to arbitrary interference with their privacy or correspondence. On 27 April 2026 a group of UN experts, including Special Rapporteur on the right to privacy Ana Brian Nougrères, issued a joint warning on the risks of systemic digital interference with civic freedoms. It is in this framework — not only a European one — that the case known as "Chat Control" belongs: a specific instance of a phenomenon that concerns any State with the technical means to do it.
Facts
In the European Union, regulation 2021/1232 (in force since 3 August 2021) allows providers of unencrypted communication services — according to the sources consulted, among them Gmail, Facebook Messenger, Skype and Snapchat, with Google, Meta, Microsoft and Snap among the most cited providers — to voluntarily scan communications for child sexual abuse material. Explicitly excluded are end-to-end encrypted services: WhatsApp — although owned by Meta — Signal, iMessage.
On 26 March 2026 the European Parliament rejected the renewal of the derogation (311 against, 228 in favour, 92 abstentions); the measure expired on 3 April. On 19 March, even before the expiry, Snap, TikTok, LinkedIn and other major platforms signed a joint statement asking for an extension; on 27 March Google's institutional blog, in a text reflecting a line shared with Meta, Microsoft and Snap, announced the companies would continue voluntary scanning regardless. Two hundred and forty-seven child-protection organisations signed a counter-appeal in support of the legislative extension. On 2 July the Council resubmitted the same already-rejected text as a formally new act; on 7 July the Parliament's relative-majority group (EPP) obtained an urgency procedure (331 votes to 304); on 9 July a first vote to reject the text gathered 314 votes against 276 — a simple majority, but below the 361 threshold required at second reading — while an amendment excluding end-to-end encrypted communications passed with sufficient margin. On 23 July 2026 the Council gave final approval: the measure is in force until 3 April 2028.
Legal reading
Numerous independent sources report that the Council's Legal Service, in an opinion dated 10 June 2026, deemed the mechanism — even in its "voluntary" form — a generalised scanning of interpersonal communications, incompatible with Article 7 of the EU Charter of Fundamental Rights absent reasonable suspicion and prior judicial authorisation. The original document was not located in this session: this remains a declared gap, to be verified against the Council's primary source before any definitive citation. The same necessity-and-proportionality principle is also the standard of ICCPR Article 17, applicable well beyond the EU's borders. Germany's Federal Commissioner for Data Protection, Louisa Specht-Riemenschneider, called the measure mass surveillance "without cause", exceeding the stated legitimate aim.
The case is not isolated. In the United Kingdom, the Online Safety Act has required, since 25 July 2025, "highly effective" age verification on online content. In the United States, the EARN IT Act — repeatedly reintroduced in Congress — seeks to hold platforms liable for abuse content without guaranteeing a safe harbour for end-to-end encryption. In China and Russia, far more extensive digital-communication control mechanisms operate without comparable public debate or independent bodies equivalent to a data protection authority or a supranational Court of Justice. The European case is not an isolated anomaly: it is the point where the conflict between digital security and the privacy of communications is most visible and publicly documented, not the only place where it happens.
Implications
The technical mechanism under discussion — pre-emptive scanning of non-suspect communications, without individual indication — does not change nature depending on its stated purpose. Symmetry test: if the same mechanism were proposed to counter terrorism or disinformation, would the proportionality judgment change? If so, the assessment is following the shareability of the goal, not the legal criterion itself — test outcome: the mechanism does not hold up to a change of purpose, and this remains a legal finding, not a moral opinion.
The extension of surveillance tools beyond their original purpose has concrete, not hypothetical, precedents. The EURODAC database, created to identify asylum seekers, was later also used to counter terrorism. The EU Data Retention Directive (2006/24/EC), introduced for serious crime, was annulled by the Court of Justice of the EU in 2014 (cases C-293/12 and C-594/12, Digital Rights Ireland) precisely for lacking sufficient limits on purpose and access. These precedents do not prove Chat Control will follow the same path — no such proposal is currently under discussion — but they make the objection about the future extension of its scope a hypothesis grounded in a real pattern, not an isolated fear.
Germany's position shows how little a single State's line is univocal. The government actively supported the temporary, voluntary extension approved in July, while the Bundestag's majority party (CDU/CSU) opposes any form of client-side scanning of encrypted services in the future permanent regulation. The debate is not fought between blocs of supporters and opponents, but between a voluntary tool and a mandatory one — a distinction worth keeping in mind when reading any headline that summarises the affair as "Europe approves mass surveillance".
Editorial note
The permanent regulation — the one that will determine whether scanning becomes mandatory rather than optional, including for encrypted services — remains under negotiation after five failed trilogues; the sixth is set for 29 September 2026 under the Irish presidency. That is where the real contest begins.
Sources: OHCHR (27/4/2026) · Consilium, comunicato stampa (23/7/2026) · Ansa, Il Post (9-10/7/2026) · netzpolitik.org (2/7, 9/7/2026) · Next.ink · Cyber Security 360 (17/4/2026) · CJEU, Digital Rights Ireland (2014)