On 9 July 2026, the European Parliament voted on one of Europe's most controversial privacy issues. The numbers appeared straightforward: 314 MEPs voted to reject the Council's position, while 276 voted against its rejection. Yet the legislation moved forward.
How can a measure opposed by more MEPs than supported still survive?
The answer lies in parliamentary procedure. But behind the unusual vote is a much bigger debate: Europe is trying to tackle the growing problem of child sexual abuse online while deciding how far technology providers should be allowed to go in analysing private communications. Where should the boundary between protection and privacy be drawn — particularly when those communications are encrypted?
How 314 Votes Against Were Not Enough
The vote took place at the second-reading stage, rejecting the Council's position required an absolute majority of all 720 MEPs — at least 361 votes — rather than simply a majority of those voting.
Opponents secured 314 votes, 47 short of that threshold, despite outnumbering those voting against rejection. The legislation therefore survived and subsequently entered into force as Regulation (EU) 2026/1881, extending the temporary framework until 3 April 2028.

The result settled the temporary extension, but it did little to settle the controversy surrounding Chat Control.
Why Does Europe Want Chat Control?
The scale of online child sexual abuse helps explain why European policymakers are pursuing detection measures. According to European Commission figures, online service providers made more than 23 million reports of suspected child sexual abuse in 2025, compared with approximately one million in 2010. The Commission also states that up to 80% of criminal investigations into child sexual abuse begin with reports from online service providers.
Reports of suspected online child sexual abuse: approximately 1 million in 2010 → more than 23 million in 2025.
Those figures make a powerful case for detection. But they also lead directly to the privacy question: if technology can analyse private communications to identify one category of illegal content, what safeguards prevent that capability from being extended in the future?
What Does Chat Control Actually Mean?
The temporary framework currently in force allows certain communications providers, under defined conditions, to voluntarily use technologies to detect and report online child sexual abuse material. It does not introduce a general requirement to scan every private message.
The bigger controversy concerns the proposed permanent Child Sexual Abuse Regulation (CSAR), often referred to by critics as "Chat Control 2.0", which remains under negotiation.
Encryption sits at the centre of that debate. End-to-end encryption is designed so that only the sender and intended recipient can access the content of a communication. This creates an obvious challenge: if providers are expected to detect prohibited material while maintaining encryption, where can that detection happen?
One approach discussed in this context is client-side scanning, where content can be analysed on a user's device. While this may leave the encrypted transmission technically intact, critics argue that inspecting content before encryption raises a fundamental question: if a private message can be analysed before it is encrypted, how private is it in practice?
Supporters of stronger detection measures point to the difficulty of identifying serious criminal activity in inaccessible communications. Privacy and cybersecurity advocates warn that creating mechanisms capable of analysing private communications could have consequences far beyond their original purpose.
Privacy vs. Safety — or Is That the Wrong Question?
Presenting Chat Control simply as a choice between protecting children and protecting privacy misses the complexity of the debate.
The millions of reports received every year demonstrate why online platforms play an important role in detecting abuse. At the same time, secure communications protect personal conversations, commercially sensitive information, legal privilege, journalism and countless other legitimate activities.
For businesses, this makes the issue relevant well beyond the technology sector. Organisations increasingly rely on encrypted platforms to exchange personal data, confidential information and sensitive business communications. Any change to how those communications may be analysed therefore raises questions for privacy, legal, compliance and cybersecurity teams.
The real challenge is whether Europe can create an effective framework for detecting illegal material without building infrastructure that fundamentally changes what users can expect from private communication.
And that question has not yet been answered.
The Conversation Continues in Berlin
The July vote determined the future of the temporary framework, but the permanent CSAR remains under negotiation. Decisions around encryption, detection technologies, safeguards and platform responsibilities could ultimately have much greater consequences for digital privacy in Europe.
This debate will be part of the 10th Annual Privacy & Data Protection Summit, taking place in Berlin on 22–23 October 2026. Join privacy, legal and compliance professionals, including Rand Hammoud, Director of the Security, Surveillance and Human Rights Programme and Regional Encryption Lead at CDT Europe, as they tackle the questions surrounding Chat Control, encryption and the future of private communications in Europe.
Be in the room where one of Europe's most pressing privacy debates continues.
Published by Luxatia International
21 August 2026