On 23 July 2026, the Council concluded a written procedure approving the European Parliament's second-reading amendments to a draft regulation that temporarily derogates from Directive 2002/58/EC (ePrivacy) to allow providers of number-independent interpersonal communications services to voluntarily process personal and other data for detecting online child sexual abuse. The regulation extends the temporary framework until April 2028 and will be formally adopted after legal-linguistic revision (PE-CONS 14/26).
The written procedure, initiated by Council document CM 3755/26, marks the final step in the legislative process for this temporary measure. The regulation permits providers to voluntarily detect child sexual abuse material in non-encrypted communications, but broadly excludes encrypted communications from detection, reflecting the European Parliament's position. France, while consenting to avoid delaying adoption, issued a statement expressing concern that the encryption exclusion may reduce detection effectiveness and regretted insufficient attention to data access challenges. The measure is explicitly temporary and does not pre-empt the Commission's expert group on encryption, whose roadmap is expected in November 2026.
The regulation provides legal certainty for providers of number-independent interpersonal communications services (e.g., messaging apps) to continue voluntary detection without violating ePrivacy rules, but the encryption exclusion limits their ability to detect abuse in encrypted channels. Child protection NGOs may see reduced detection effectiveness in encrypted services, while privacy advocates welcome the protection of encryption. EU institutions gain a temporary solution while a permanent detection regime is debated, but France's concerns highlight ongoing tensions between child safety and data privacy. The measure avoids a gap in detection capabilities that would have occurred if the previous derogation expired.