Digital Policy

European Parliament Vote Allows Big Tech to Scan Private Messages Despite Opposition

The European Parliament has voted to reinstate permissions for major technology companies—including Meta, Google, and Microsoft—to scan users’ private texts, emails, and social media messages for child sexual abuse material, despite more lawmakers opposing the bill than supporting it. The decision extends voluntary message monitoring until 2028, drawing sharp criticism over privacy and democratic process concerns.

What Happened

The bill, often referred to by critics as “Chat Control,” restores legal grounds for tech firms to voluntarily scan private communications on their platforms to detect child sexual abuse. The authorization applies to messages on platforms operated by these companies but excludes end-to-end encrypted services such as WhatsApp and Signal. The ruling was passed after the previous legislation expired in April. The European People’s Party (EPP), the largest faction in the parliament, pushed aggressively for the bill’s renewal, claiming such scanning efforts are critical for identifying and rescuing victims of online child sexual abuse.

The vote took place in early July 2026, with the EPP employing an “urgent procedure” mechanism to fast-track the legislation without preliminary committee debates or amendments. Although a majority of Members of the European Parliament (MEPs) voted against the measure, they did not reach the absolute majority threshold of 361 votes needed to block it, falling short by 47 votes. The bill will remain in effect until 2028 or until permanent legislation replaces it.

Key Facts

  • The renewed legislation allows voluntary scanning of private messages by large technology companies.
  • End-to-end encrypted communication services remain exempt from message scanning.
  • The vote was held under an “urgent procedure” that bypassed typical parliamentary debates and amendment processes.
  • A majority of MEPs voted against the bill, but it failed to reach the required absolute majority to reject it.
  • The bill will remain active until 2028 or until replaced by permanent laws.
  • The law aims at detecting child sexual abuse material online to aid victim protection efforts.

What This Means

This decision raises significant privacy implications for European citizens, as it authorizes private companies to scan potentially vast amounts of personal communications. Although intended to combat child sexual abuse, critics warn that allowing such message scanning undermines individuals’ rights to confidential digital conversations. The exclusion of end-to-end encrypted apps illustrates a compromise, but concerns persist that message scanning could still erode digital privacy and chill free expression.

Moreover, the tactic used to pass the bill—circumventing normal parliamentary debate—has sparked accusations of undermining democratic transparency and accountability. For users, this may translate into increased surveillance of personal communications, sparking tensions between child safety initiatives and privacy protections. The ruling underscores the ongoing struggle within Europe to balance digital rights against law enforcement and protection objectives in the technology sector.

Background

This legislation follows the expiration of a previous law granting similar voluntary scanning permissions to tech companies in April 2026. Since then, the EPP has sought to restore this measure, citing the necessity of continued monitoring to prevent and respond to child sexual abuse online. Critics, including civil rights advocacy groups like European Digital Rights (EDRi), have long assailed the practice, warning it threatens privacy and poses risks to digital confidentiality.

Advocacy figures such as former MEP Patrick Breyer characterized the ruling as a democratic “farce,” arguing that it sacrifices fundamental rights under the guise of child protection. They liken blanket surveillance of private communications to the indiscriminate opening of personal mail—both seen as unacceptable breaches of privacy.

What Remains Unclear

The full scope of how extensively messaging data will be scanned and processed under the renewed bill remains undefined in the public domain. There is no detailed information on whether all affected users have been notified about the scanning or on the oversight frameworks in place to prevent abuse. Additionally, the eventual form and timing of the permanent legislation slated to replace this temporary extension are currently unsettled.

Sources

This article is based on reporting and publicly available information from the following source:

Read more Digital Policy stories on Goka World News.

Nora Lindholm
About the editor

Nora Lindholm

Nora Lindholm Role: Digital Policy Editor Nora Lindholm writes about digital rights, online safety, data privacy, internet regulation, and technology policy. Her articles focus on how digital rules affect users, platforms, companies, and public institutions. She emphasizes official documents, clear sourcing, and balanced explanations.

View all posts by Nora Lindholm