Temporary EU Scanning Rules Close Legal Gap but Preserve Encrypted-Message Exemption

by EUToday Correspondents

The EU interim measure restores a legal basis for voluntary detection of child sexual abuse material, but leaves the hardest encryption dispute unresolved.

EU governments have endorsed the restoration of a temporary measure allowing platforms to detect and remove child sexual abuse material without breaching ePrivacy rules, extending the regime until 3 April 2028. The Council’s public register and press materials describe the measure as a temporary derogation while permanent legislation remains under negotiation. Reuters reported that the compromise excludes end-to-end encrypted communications such as Signal, Telegram and WhatsApp from the interim regime.

The legal problem arose because the earlier derogation expired in April. Without it, platforms that voluntarily scan for known abuse material or grooming patterns risked conflicting obligations: privacy rules on one side and child-protection expectations on the other. The restoration closes that gap for non-encrypted services, but it does not resolve the central political conflict over encrypted messaging.

The issue is not whether child sexual abuse material should be removed. There is broad agreement on that. The dispute is about how detection can occur without creating surveillance powers that weaken privacy, security and freedom of expression. Voluntary scanning of cloud storage, messaging attachments or platform-hosted content raises different legal questions from scanning end-to-end encrypted chats.

End-to-end encryption is designed so that service providers cannot read message content. That protects journalists, dissidents, lawyers, victims of abuse, businesses and ordinary users from criminals, hostile states and intrusive intermediaries. Requiring platforms to scan encrypted messages can mean client-side scanning on user devices or some form of weakened encryption. Critics argue that such measures create vulnerabilities that can be abused beyond the original purpose.

Supporters of scanning argue that criminals exploit privacy tools and that platforms should not be allowed to hide behind architecture when children are being harmed. They point to the scale of online abuse material and grooming networks. They also argue that detection can be targeted, audited and governed by safeguards. The challenge is that technology does not always respect legal intent. A scanning capability built for one purpose can be demanded for another.

EU Today recently examined Europe’s need for a digital counter-terrorism reset. The child-protection derogation sits in the same policy family: governments want digital platforms to prevent serious harm, while civil-liberties advocates warn that emergency measures can become permanent infrastructure. The temporary nature of the derogation is therefore important but not sufficient.

The 2028 expiry date creates a runway for permanent legislation. It also creates a risk of repeated temporary extensions if member states cannot agree. Temporary regimes can become policy habits. They may avoid the most difficult decision while keeping enough legal cover for current practices. That may be practical, but it is not a stable long-term framework.

Platforms will welcome legal clarity, but they will still face operational uncertainty. Voluntary detection requires investment, moderation teams, reporting channels, appeals processes, safety engineering and cooperation with law enforcement. If the permanent law changes the scope again, companies may need to redesign systems. Smaller platforms may struggle most because compliance capacity is uneven across the sector.

The encrypted-services exemption is politically tactical. It allows governments to restore the legal basis for scanning where there is less controversy, while deferring the fight over encrypted messaging. That may be sensible if it prevents a broad collapse of the measure. But it also means the EU has not answered the question that has divided lawmakers most sharply.

Law enforcement agencies will continue to press for access to evidence in encrypted environments. Privacy advocates will continue to warn against tools that can scan private messages before encryption or after decryption. Technology companies will argue that they cannot build a backdoor only for good actors. The permanent legislation will have to confront those claims directly.

The measure also raises a governance question: how voluntary is voluntary scanning when governments create legal regimes expecting platforms to use it? A platform that declines may face reputational pressure, political criticism or future regulatory scrutiny. Clear rules are needed on transparency reports, error rates, independent audits and user remedies when content is wrongly flagged.

The temporary derogation therefore solves an immediate legal conflict but not the deeper democratic one. Europe wants to protect children and protect privacy. It wants platforms to act responsibly but not become unaccountable surveillance intermediaries. It wants law enforcement access without weakening the security of everyone else. Those objectives cannot be reconciled by slogans.

The restored measure buys time. Whether it buys trust depends on what the EU does next. A permanent law that ignores encryption risks will face resistance from technologists and civil society. A permanent law that ignores abuse detection will fail victims. The hard work begins after the temporary gap is closed.

__________________________________________________________________________________________________________________

Click here for more News & Current Affairs at EU Today

Click here to check out EU TODAY’S SPORTS PAGE!

___________________________________________________________________________________________________________________

You may also like

EU Today brings you the latest news and commentary from across the EU and beyond.

Editors' Picks

Latest Posts