The European Parliament and the Council have adopted a temporary derogation from the ePrivacy Directive, allowing providers of number-independent interpersonal communications services—such as webmail, messaging, and VoIP—to voluntarily process personal and other data to detect, report, and remove online child sexual abuse material. The regulation, published on 22 July 2026, applies from its entry into force until a permanent legal framework is adopted and applied, and is limited in duration.
The temporary measure overrides Articles 5(1) and 6(1) of Directive 2002/58/EC, which guarantee the confidentiality of communications and traffic data. Providers may now scan communications for child sexual abuse content, but must use the least privacy-intrusive technologies available per industry state of the art. Systematic filtering or scanning of text is prohibited unless detecting patterns that indicate a concrete suspicion of child sexual abuse, such as age difference or likely child involvement. Data processed must be strictly necessary and immediately and permanently deleted if no abuse is identified, and no later than 12 months from detection of suspected abuse.
Providers are required to establish complaint and redress mechanisms for users. By six months from entry into force, and by 31 January each year thereafter, they must publish and submit reports to the competent supervisory authority and the European Commission, covering data types and volumes, error rates, retention policies, and organisations with which data was shared. The Commission will establish a common reporting format via implementing acts. The regulation explicitly states it does not govern Member States' policies on consensual sexual activities among children.
Stakeholder impact
For EU consumers, the regulation raises privacy concerns as it temporarily weakens confidentiality protections, though safeguards such as the prohibition on systematic text scanning and mandatory deletion aim to limit intrusion. Providers of messaging and webmail services face new compliance obligations, including reporting and redress mechanisms, but gain legal clarity to deploy detection technologies without breaching ePrivacy rules. National data protection authorities will oversee compliance and receive annual reports, adding to their supervisory workload. Child protection organisations may welcome the measure as a tool to combat online abuse, though they may push for a permanent framework with stronger safeguards.
Institutional follow-up
The regulation enters into force on the twentieth day following its publication in the Official Journal of the European Union. The Commission is tasked with adopting implementing acts on the common reporting format. The temporary measure will remain in place until the long-term legal framework—currently under negotiation as part of the proposed regulation on preventing and combating child sexual abuse—is adopted and applied.