The debate in the European Union over private communications scanning is again on the rise. The latest arrangements extend to 3 April 2028 the provisional rules allowing web platforms to voluntarily identify, report and remove illegal content related to child sexual abuse. While the current rules still exclude end-to-end encrypted communications, there is even greater concern as to whether the European Union will in the future expand its application with a permanent system.
Provisional rules extended to 2028
This measure continues to exempt some of the provisions of the Electronic Privacy Directive. The platform could therefore address, on a voluntary basis, relevant illegal content, including identification, reporting and removal.
The current key limitation remains unchanged: end-to-end encryption-protected communications services are not covered by the interim arrangement. This means that services such as Signal and WhatsApp do not need to scan the user's private mail for the time being.
Contest focuses on end-to-end encryption
In support of privacy protection, it was argued that to identify a particular content, it was technically necessary to access the content of the communication itself, which would raise broader privacy issues. Vyara Savova, the policy head of the European Ethereum Institute, stated that the impact of such content scanning should not be limited to single enforcement objectives.
End-to-end encryption often prevents the platform from reading its own message content and may therefore change the existing communications security design once private mail scanning is required. Vitalik Buterin, a co-founder of the ETA, has also criticized the EU “chat review” programme, arguing that a weakening of encryption could introduce new security loopholes to systems used by millions of users.
Encryption users at additional risk
This discussion is particularly sensitive to encrypted users. Message applications often include wallet addresses, transaction details, communication records with the trading platform, and account restoration information. Once communications protection is weakened, the risk of exposure to such information increases.
The European Privacy Regulatory Authority had previously called on legislators to avoid non-discrimination scanning and required measures to be proportionate. For the time being, the EU does not have a mandatory encryption platform to scan private dialogue, but whether the successor permanent framework extends the scope of law enforcement remains central to this debate.
