The EU’s controversial proposal, commonly referred to as Chat Control, enters a new round of negotiations on Tuesday. One of the central points of contention is whether messaging services should be able to scan private messages without the user being suspected of a crime.
On Tuesday, September 29, the European Commission, the Council of Ministers, and the European Parliament will meet for the sixth trilogue negotiation on the permanent regulation against online child sexual abuse, often called Chat Control 2. The Council of Ministers prepared its position at a Coreper meeting on September 23.
According to Femte juli, the parties are still far apart on the issue of monitoring the content of electronic messages.
The Parliament Wants to Limit Scanning
The European Parliament’s negotiating position is that so-called detection orders should be targeted at specific users or groups where there are reasonable grounds for suspicion. The Parliament has also decided that end-to-end encrypted messages should not be subject to such decisions.
The Parliament’s text also states that general and indiscriminate monitoring of all users’ private communications may conflict with fundamental rights. This creates a clear distinction from parts of the position previously advocated by the member states in the Council of Ministers.
The Council Wants to Retain Voluntary Scanning
According to information from the Council’s internal negotiation documents, the Council of Ministers wants at least to retain the possibility for platforms to voluntarily scan users’ messages, similar to the system that applies under the temporary legislation Chat Control 1.
This means that scanning could take place even without any individual user first being identified as a suspect.
A discussed compromise, according to Femte juli, would mean that such monitoring would not necessarily be allowed permanently, but could be approved for limited periods of time. The site describes this as the core conflict remaining, as the surveillance would still not need to be directed at suspected individuals.
The Council presidency has at the same time raised the question of whether private messages should be left entirely outside parts of the permanent regulation if the parties fail to reach a compromise. An internal document prepared for Tuesday’s trilogue explicitly poses this question to the member states.
Temporary Rules Apply Until 2028
At the same time, there is already a temporary EU regulation in place which allows some communication services to voluntarily search for material containing child sexual abuse.
After a prolonged legislative process, the temporary solution has been extended until April 2028. During the process, the European Parliament has tried to limit the scope of the rules and has, among other things, demanded that end-to-end encrypted communication should be exempt.
This has reduced the pressure on the institutions to quickly reach an agreement on the permanent law.
The Proposal Has Been Negotiated Since 2022
The European Commission presented the permanent regulation as early as 2022. The aim is to impede the distribution of documented child sexual abuse and to detect so-called grooming online.
The proposal has also drawn extensive criticism from privacy organizations, security experts, and politicians who have warned that technical solutions for reviewing private messages risk creating mass surveillance and weakening security in encrypted communications services.
The current European Parliament position attempts to address this criticism by explicitly stating that detection orders should be targeted, time-limited, and subject to judicial review, and that end-to-end encryption should be protected.
The outcome of Tuesday’s negotiations will determine whether the institutions can move closer to an agreement or if the issue will be postponed once again. If no agreement is reached during the Irish presidency, responsibility for the Council’s ongoing work will pass to Lithuania at the turn of the year.
