ScanRecords
Regulation (EU) 2021/1232 — in force until April 2028

What is the EU's Chat Control?

The rule that lets communication providers voluntarily scan private messages in the EU. Not mandatory, not universal, and end-to-end encrypted apps are excluded — which is why the real question is what each provider chooses. This page is the plain-language version, with primary sources.

What Chat Control is

Under the EU's ePrivacy rules, reading private communications is normally forbidden — for providers too. The ePrivacy derogation (Regulation 2021/1232, widely called "Chat Control 1.0") carves out an exception: providers may scan private messages for child sexual abuse material, if they choose to. It lapsed in April 2026, was reinstated by the Council and survived a European Parliament rejection vote in July 2026, and now runs until April 2028. An amendment adopted alongside it formally excludes end-to-end encrypted communications from its scope.

A separate, permanent regulation (the CSA Regulation, "Chat Control 2.0"), which could make detection mandatory — including on encrypted apps, via scanning on your device before encryption — remains under negotiation between the Council and Parliament. It is not law. If that changes, what these pages track — and this page — will change with it.

How we got here

  1. Dec 2020 — New EU telecom rules extend ePrivacy confidentiality to messengers; Facebook pauses CSAM scanning in the EU overnight.
  2. Jul 2021 — Regulation 2021/1232 enters into force: voluntary scanning becomes legal again. Chat Control 1.0.
  3. Aug 2021 — Apple announces on-device photo scanning for iCloud; abandons the plan by December 2022 after expert backlash.
  4. May 2022 — The Commission proposes the permanent CSA Regulation with mandatory detection orders. Chat Control 2.0.
  5. Nov 2023 — Parliament's position: no indiscriminate scanning, protect end-to-end encryption.
  6. Dec 2023 — Meta turns on E2EE by default for Messenger personal chats.
  7. Jun 2024 — Council's "upload moderation" compromise fails to find a majority; the vote is pulled.
  8. Dec 2025 — Council and Parliament begin trilogue negotiations on 2.0.
  9. Mar–Apr 2026 — Parliament rejects extending 1.0 (311–228); the derogation lapses on 3 April.
  10. Jul 2026 — The Council reinstates it; a Parliament rejection motion gets more no than yes votes (314–276) but misses the 361 absolute majority. Extended to April 2028, with E2EE formally excluded.
  11. Jun–Jul 2026 — The supposedly final 2.0 trilogue collapses over suspicionless scanning; negotiations continue.

1.0 vs 2.0 — don't mix them up

Chat Control 1.0 (in force)Chat Control 2.0 (draft)
What it isePrivacy derogation — Regulation 2021/1232CSA Regulation — proposed 2022, still in negotiation
ScanningVoluntary — each provider decidesCould be mandatory via detection orders
Encrypted appsFormally excludedCentral fight — client-side scanning would affect them
UntilApril 2028Not law; nothing to expire
What this site doesRecords who uses it, in their own words and filingsRecords the encryption language that would have to change first

Background reading: Euronews · fightchatcontrol.eu · EDRi's document pool

The paper trail — we archive the law's own pages too

Companies aren't the only ones who quietly edit their pages. The institutions writing Chat Control publish policy pages and status trackers of their own — so those are in the archive under the same rules: fetched daily, diffed, and preserved. If the Commission reframes what "voluntary detection" means, or the Parliament's tracker moves a step toward mandatory scanning, that edit becomes a recorded, citable event.

Who actually uses it

Providers scanning under the derogation must file annual reports, and the Commission's latest implementation report names exactly five: “Google, LinkedIn, Meta, Microsoft and Yubo submitted reports, for both 2023 and 2024” (COM(2025) 740). MEP Patrick Breyer's tracking adds that “only unencrypted US communication services such as Gmail, Facebook/Instagram Messenger, Skype, Snapchat, iCloud Mail, or Xbox” make use of it — note that Snapchat and Apple appear in that service list but not among the five reporting providers; both facts are shown on their pages. Some providers also publish EU-specific transparency reports of their own, like Google's report under Regulation 2021/1232 and Microsoft's jurisdictional reports — both tracked by this archive.

Scanning under US law is not Chat Control

Most large US platforms scan uploads for known abuse material and report to NCMEC — that is a US legal regime, and it says nothing about whether a company invokes the EU derogation to scan private communications of EU users. This site keeps the two separate: a filled red dot means EU evidence; a hollow red dot means US-law scanning with no EU evidence found. Conflating the two overstates the record, so we don't.

What this means for you

  • If you use Gmail, Facebook or Instagram messaging, Outlook, or LinkedIn in the EU — the provider scans under the derogation, legally and by its own choice. Scanning means automated matching of content against known-abuse databases and classifiers, not a person reading your mail — but it is your private correspondence being processed.
  • If you use Signal, WhatsApp, Threema, Olvid, Wire or Element — message content is end-to-end encrypted; the provider has nothing readable to scan, and E2EE is formally excluded from 1.0.
  • A VPN does not change any of this — scanning happens at the provider, not on the network path. The only variable that matters is which app you use.
  • Telegram is its own case — cloud chats are not E2EE, so Telegram could read them; whether it scans them is exactly what it doesn't say. Its page records what is known.

The five statuses

  • Scans under the EU's Chat Control — The derogation's mandatory reports exist only for providers actually scanning private communications under it. Exactly five filed them, for both 2023 and 2024, per the Commission's own implementation report — this is Chat Control use, documented by the EU itself.
  • Scans globally — no EU evidence — Their documents disclose content scanning under US law (NCMEC reporting, PhotoDNA). No evidence found that they invoke the EU derogation for private communications — US-law scanning and Chat Control are separate regimes. Absence of evidence is a fact about the public record, not proof of absence: a provider could scan and not disclose it.
  • No clear statement — Not end-to-end encrypted, and no clear public statement about scanning private communications was found either way. Silence measures disclosure, not behavior.
  • States it does not scan — The company publicly states that it does not scan message content.
  • End-to-end encrypted — out of scope — Content is end-to-end encrypted; E2EE communications are formally excluded from Chat Control's voluntary scanning.

How statuses are assigned

  • In order of strength: the Commission's implementation reports → a company's own EU-specific transparency reporting → its policies and security pages (which this site snapshots daily, and quotes where relevant) → US reporting data as context only.
  • They are observations of what companies say and file, not measurements of what their software does. Behavioral measurement is a different and harder project.
  • And the negative buckets are claims about the record, not the world: "no EU evidence" means none was found in public documents and filings — a provider could scan and not say so. That asymmetry is why the confirmed group has a hard floor (the Commission's own naming) while the other groups are explicitly provisional, re-read daily.
  • Each status was last assessed on 26 Jul 2026 and is reviewed when the underlying documents change — which is exactly what the daily snapshots watch for.
  • Companies can dispute a status by opening an issue; per the editorial policy, disputes and responses are published.

What would change a status

Their own words. If a provider switches scanning on — or an encrypted messenger weakens the sentence "we cannot read your messages" — it has to surface in the documents this site records every morning. When it does, the change appears on the front page with its full before and after, and the status gets re-assessed.

Common questions

Is someone reading my WhatsApp or Signal messages?

Not under Chat Control 1.0. Both are end-to-end encrypted, E2EE apps are formally excluded, and the provider has no readable content to scan. The pressure point for encrypted apps is the draft 2.0 regulation — which is not law.

Is Chat Control the thing that would break encryption?

That's 2.0 — the draft CSA Regulation, whose detection orders could force scanning on your device before encryption. It has been stuck in negotiation since 2022, most recently collapsing over suspicionless scanning in June 2026. What is actually in force, 1.0, excludes E2EE.

Can I opt out of the scanning that exists today?

Only by choosing your app. Scanning under 1.0 happens provider-side, so the practical opt-out is using an end-to-end encrypted service — see the seven tracked apps that can't read your messages.

Does a company scanning "for CSAM" mean it reads everything I send?

Disclosed methods are automated: hash matching against known-abuse databases and, in some cases, classifiers — with human review of flagged material. That is narrower than "someone reads your mail," and still means private correspondence is processed; both things are true, and false positives on legal content are a documented problem in the Commission's own report.

Why do you say "no EU evidence" instead of "doesn't scan in the EU"?

Because absence of evidence is what we actually have. A provider could scan EU communications without it appearing in the sources this site can check; what we can say is that the mandatory reporting names five providers, and the others aren't in it. We publish the strongest true sentence, not the strongest sentence.

Sources