The Council of the EU has initiated a written procedure for member states to approve the European Parliament's amendments to a draft regulation that temporarily derogates from Directive 2002/58/EC, allowing providers of number-independent interpersonal communications services to process personal and other data to combat online child sexual abuse. The Permanent Representatives Committee decided on 22 July 2026 to use the written procedure, with member states required to reply YES, NO, or ABSTENTION by 23 July 2026 at 14:00 Brussels time. The amendments are set out in document 11703/26 and, after legal-linguistic revision, in PE-CONS 14/26.
The draft regulation, which has been under negotiation between the European Parliament and the Council, aims to provide a temporary legal basis for providers of services such as messaging apps to use automated tools to detect and report child sexual abuse material, while respecting privacy and data protection rules. The temporary derogation from the ePrivacy Directive is intended to address a gap in EU law following the expiry of an interim measure and the ongoing legislative process for a permanent regulation on preventing and combating child sexual abuse.
Member states have until the deadline to submit their replies via email to the Council's codecision adoption mailbox. Unilateral statements may be made at the same time as the reply. If approved, the regulation will enter into force on the day following its publication in the Official Journal of the European Union, providing a time-limited framework for data processing by providers until a permanent solution is adopted.
The written procedure is a standard method for the Council to adopt legislative acts without convening a formal meeting, used when the text has been agreed upon in trilogues and requires formal approval. The European Parliament adopted its first-reading position on the draft regulation earlier in 2026, and the Council's approval of the amendments would finalise the legislative process at EU level.
The regulation directly affects providers of number-independent interpersonal communications services, such as WhatsApp, Signal, and Telegram, which will be permitted to process personal data for the specific purpose of detecting online child sexual abuse. This reduces legal uncertainty for these companies but may raise privacy concerns among users and civil society organisations advocating for strong data protection. National authorities responsible for combating child sexual abuse will benefit from increased reporting of potential offences, while EU institutions gain a temporary tool pending a permanent framework. The measure balances child protection with privacy rights, with the temporary nature limiting the impact on fundamental rights.