For the third time in four months, lawmakers in the European Parliament cast ballots on a derogation from the EU's ePrivacy Directive. Though the measure gained approval, the outcome represents a significant victory: it demonstrates Parliament's unwavering stance against mass surveillance in the broader CSA Regulation negotiations and locks in safeguards for encryption technology.

Big Tech scanning users' private messages will likely be back soon – here's why

On 26 March 2026, the European Parliament voted to reject an extension of the 2021 'temporary' interim ePrivacy derogation – sometimes called "Chat Control 1.0". This legislation permitted technology giants including Microsoft and Meta to conduct mass scans of user private messages in search of child abuse material. Following Parliament's rejection, the temporary derogation lapsed on 4 April 2026. Given how uncommon such rejections are, observers considered the legislative proposal finished.

Then Roberta Metsola, president of the European Parliament and member of the European People's Party (EPP), made an unexpected move. Metsola proposed to the European Council that it disregard Parliament's position. EU governments quickly agreed to resurrect the text, compelling Parliament through an uncommon mechanism: a third vote, this time designated a "second reading".

The setback: Parliament could not prevent the temporary derogation's return. The silver lining: lawmakers still managed to communicate forcefully that mass surveillance has no place in the CSA Regulation, known as "Chat Control 2.0", the permanent legal framework under parallel negotiation that poses substantially greater risks to privacy and secure online communication.

What happened, concretely

The EPP group leveraged the second reading procedure combined with an urgency mechanism. They requested urgency status to bypass the competent committee (Committee on Civil Liberties, Justice and Home Affairs – LIBE) and place the vote directly on the final plenary agenda before summer recess. Over 100 MEPs were absent from that session – roughly one-seventh of Parliament's total membership. Under second reading rules, the proposed text passes automatically unless rejected. Critically, rejection or amendment requires an "absolute majority" (50% plus one of all MEPs, equalling 360 votes) rather than the standard "simple majority". This framework effectively counts absent or abstaining MEPs as supporting the text and opposing any amendments. Lawmakers seeking to challenge this last-minute manoeuvre faced structural disadvantages.

Beyond normalising harmful practices and damaging parliamentary procedure through forced reconsideration, the genuine danger lay in potentially weakening Parliament's negotiating position on the CSA Regulation. Parliament had consistently opposed mass surveillance and encryption undermining.

The outcome proved different: this vote actually strengthened Parliament's stance, with more than half of present lawmakers voting to reject and amend the temporary derogation proposal. Though a supermajority was required here, such thresholds will not apply during CSA Regulation talks – signalling to negotiators that no agreement permitting mass surveillance can win support.

Despite the temporary derogation passing, MEPs successfully adopted two amendments (AM30 and PC3) defending end-to-end encrypted interpersonal communications, including protections against client-side scanning. These modifications represent a crucial achievement in maintaining the principle that communications must remain safe and secure.

These amendments also prevented automatic adoption: the Commission had to issue an opinion on the amended text (it endorsed the encryption protections), and the Council had to accept it, before the measure became law.

The new derogation runs from 31 July 2026 through 3 April 2028.

Upcoming files: the European Parliament still stands against mass surveillance

Institutions are now turning to long-term legislation: the CSA Regulation, where negotiators have already agreed to protect encryption and eliminate age verification provisions. Outstanding questions centre on detection methods: whether scanning will be mandatory or voluntary, targeted or mass-based. The next CSA Regulation trilogue is scheduled for 29 September. Negotiators now understand clearly: no majority exists for mass surveillance or "Chat Control". Only a balanced, proportionate approach without mass scanning of private communications can produce a final agreement. Thousands of citizens who contacted elected representatives and governments deserve credit for this outcome.

Parliament's broad backing for encryption protection also sends a powerful message to the Council and Commission regarding other proposals, including any future initiatives stemming from the "Technology Roadmap on Encryption", an expert assessment due in 2027 examining technical methods enabling law enforcement access to encrypted data. EDRi, alongside 68 civil society groups, industry bodies and professional associations, has already cautioned against the Commission's continued pursuit of encryption-weakening or circumvention techniques, which would damage both safe online communication and EU cybersecurity goals.

Contribution by: Simeon de Brouwer, Policy Advisor, EDRi & Konstantin Macher, Board Member of EDRi member Digitale Gesellschaft

Source: EDRi (European Digital Rights)