On 24 July 2026, the Council of the European Union adopted a regulation introducing a temporary derogation from certain provisions of Directive 2002/58/EC (the ePrivacy Directive) to allow providers of number-independent interpersonal communications services to process personal and other data for the purpose of combating online child sexual abuse. The regulation aims to enable voluntary detection of child sexual abuse material and grooming in encrypted communications while maintaining strong privacy safeguards.
The regulation, adopted as a legislative act, provides a time-limited legal basis for providers to use technologies to scan communications for known child sexual abuse material and indicators of grooming. It includes strict conditions: processing must be proportionate, limited to what is necessary, and subject to oversight by national data protection authorities. The derogation applies only until the entry into force of the permanent framework under the proposed regulation on preventing and combating child sexual abuse, which remains under negotiation.
The measure represents a compromise between child protection and privacy concerns. It allows providers to act voluntarily, avoiding mandatory scanning obligations that had drawn criticism from privacy advocates and some Member States. The regulation includes provisions for transparency, requiring providers to publish reports on their use of the derogation, and for data minimization, ensuring that only metadata and content strictly necessary for detection are processed.
Stakeholder impact is significant. For technology companies offering messaging services, the regulation provides legal certainty to deploy detection technologies without violating EU privacy rules, but may impose compliance costs for implementing oversight and reporting mechanisms. Privacy and civil society groups have raised concerns about potential overreach and the risk of normalizing surveillance, though the temporary and voluntary nature of the derogation may mitigate some objections. National data protection authorities gain new oversight responsibilities, requiring them to assess and monitor providers' processing activities. Child protection organizations welcome the measure as a tool to address the widespread problem of online child sexual abuse, but caution that the temporary nature may create uncertainty for long-term investments in detection technologies.
The regulation now enters into force on the twentieth day after publication in the Official Journal of the European Union. The European Parliament and Council will continue negotiations on the permanent framework, which is expected to provide a more comprehensive and durable solution.