top of page

Child Protection or Mass Surveillance? The Human Rights Implications of the European Union's (EU) "Chat Control" Debate

Human Rights Research Center
23 hours ago
10 min read

September 23, 2026


Introduction


Online child sexual abuse and child sexual abuse material (CSAM) are serious and growing problems. According to figures cited by the European Commission itself, the National Center for Missing & Exploited Children (NCMEC) received over 21 million related reports in 2020, with more than 1 million concerning EU Member States, rising to nearly 30 million in 2021. More recent Commission data show a jump from 1 million reports in 2010 to over 23 million in 2025, containing 61.8 million files. Digital platforms make it easier to spread illegal material and approach minors, prompting calls for stronger regulatory measures to protect children from online sexual abuse. 


In May 2022, the European Commission presented a proposal widely known as “Chat Control”. The proposal would enable competent authorities to issue “detection orders”, requiring service providers to scan content for the purpose of identifying CSAM and communications potentially linked to the solicitation of children for sexual purposes, commonly referred to as grooming. The proposal, however, triggered intense opposition, particularly from data protection authorities, academics, civil rights organizations, and cybersecurity experts.

Alongside the negotiations on the permanent framework, a temporary regime allowing providers to voluntarily detect, report, and remove online child sexual abuse material was established under Regulation (EU) 2021/1232. The interim Regulation expired on April 3, 2026, after Parliament rejected the proposed extension at the end of its first reading. On July 9, 2026, Parliament adopted amendments at second reading, including the exclusion of communications to which end-to-end encryption applies, has applied, or will apply. The Council subsequently approved Parliament’s amendments on July 23, 2026, and the temporary regime was formally reinstated until April 3, 2028 by Regulation (EU) 2026/1881. Meanwhile, negotiations on the permanent framework, commonly referred to as “Chat Control 2.0”, remain ongoing.


The key issue is not whether children should be protected, but whether protecting them requires the monitoring of everyone’s private communications. This article examines how the proposed measures may affect privacy, data protection, freedom of expression, and encryption. It argues that child protection and digital privacy can, and should, be protected at the same time. Any interference with private communications must therefore have a clear legal basis, be strictly necessary and proportionate, and include effective safeguards.


2. The Proposed “Chat Control” Framework


“Chat Control” is the informal name commonly used for the European Commission’s 2022 proposal to prevent and combat child sexual abuse online. Unlike the temporary rules, which allowed certain providers to scan voluntarily, the proposed permanent framework would require online services to assess and reduce the risk that they are used for child sexual abuse. If those measures were not enough, a court or independent authority could issue a detection order.


Such orders could require providers to search for known CSAM, new CSAM, and messages linked to the solicitation of children, or grooming. The difference is important. Known CSAM can usually be identified by matching files against verified digital indicators. Detecting new material or grooming requires more complex automated tools and is more likely to produce errors.


The proposal is especially controversial when applied to private messages protected by end-to-end encryption, which normally allows only the sender and recipient to read them. One possible method discussed is client-side scanning, where content is checked on the user’s device before encryption or after decryption. Although this does not directly break the encryption system, critics argue that it weakens the privacy it is meant to protect.


Grooming detection creates further problems because software must interpret language, context, and the development of a conversation. Ordinary or unclear exchanges may therefore be wrongly flagged. The European Data Protection Board (EDPB) and the European Data Protection Supervisor  (EDPS) warned that general access to communications for grooming detection could affect the essence of the rights to privacy and data protection under Articles 7 and 8 of the EU Charter. They also called for a clear rule that the Regulation must not prohibit or weaken encryption.


The main issue is therefore not only whether the technology works. It is whether detection orders could turn targeted investigation into preventive scanning of communications belonging to many people who are not suspected of any crime. While the Commission describes the proposed measures as targeted and proportionate, the EDPB and EDPS have warned of a risk of general and indiscriminate monitoring.


3. Child Protection as a Legitimate Aim


There is no doubt that states have a duty to protect children from sexual abuse and exploitation. Digital services can be used to spread CSAM, approach children for sexual purposes, and carry out sexual extortion. Europol has also noted that offenders use end-to-end encrypted services to communicate and exchange CSAM. These are serious concerns, and effective action is clearly needed.


However, recognizing the seriousness of the problem does not mean that every proposed response is justified. Less intrusive forms of investigation must also be considered, including user reports, targeted access to relevant communications data, and evidence gathered under judicial supervision. The Court of Justice of the European Union has accepted certain forms of targeted or expedited retention of communications data for the investigation of serious crime, provided that strict conditions and safeguards are respected.


Ross Anderson also argues that child sexual abuse should not be treated mainly as a technical problem. A large part of the abuse takes place within families or wider circles of trust and is not limited to online spaces. The Council of Europe estimates that in around 80% of cases, the offender is known to the child. Anderson therefore suggests that policy should begin with the needs of the child at risk, rather than with the technologies that authorities are able to deploy. Reducing the issue to message scanning may overlook the wider social and family circumstances in which abuse occurs.


The real choice is therefore not between protecting children and taking no action. It is between different forms of protection and investigation. Child protection is a legitimate and important aim, but it is only the starting point. Under Article 52(1) of the EU Charter, any restriction of fundamental rights must be provided for by law, respect the essence of those rights, and be necessary and proportionate.


4. The Impact on Human Rights


4.1 Privacy and Confidentiality of Communications

Automatically scanning private messages interferes with the right to respect for private life and correspondence under Article 8 of the European Convention on Human Rights (ECHR) and Article 7 of the EU Charter. The fact that software, rather than a person, examines the content does not remove the interference, since the messages are still processed and may be reported to providers or authorities.


The European Court of Human Rights accepts that covert surveillance may sometimes be used to fight serious crime, but only under clear legal rules and with effective safeguards. In Podchasov v. Russia, the Court found that a legal duty to decrypt end-to-end encrypted communications was disproportionate. It stressed that weakening encryption for selected users would affect the security of communications for all users of the service.


4.2 Data Protection

Scanning messages, photographs, and videos involves the processing of personal data. Private conversations may also reveal health information, political opinions, religious beliefs, or details about a person’s sex life, which fall within the special categories of data under Article 9 of the General Data Protection Regulation (GDPR). Any such processing must therefore have a clear legal basis and respect the principles of purpose limitation, data minimisation, accuracy, and security.


Errors are a particular concern when systems search for new CSAM or grooming. The EDPB and EDPS noted that these tools may have relatively high error rates and can lead to lawful content being reported as suspicious. Even technologies used for known material must be supported by reliable indicators and effective review.


4.3 Freedom of Expression

Confidential communications also support freedom of expression under Article 10 of the ECHR and Article 11 of the Charter. People may change what they say if they believe their messages could be scanned. The EDPB and EDPS warned that large-scale scanning could discourage users from sharing lawful content, especially where the rules are unclear. This may be particularly serious for journalists and sources, lawyers and clients, activists, and people seeking help.


4.4 Fair Trial and the Presumption of Innocence

Further issues arise if an automated report leads to an investigation or is later used as evidence. Article 22 of the GDPR is not automatically triggered by every detection report, because it applies only to decisions based solely on automated processing that produce legal or similarly significant effects. The main question is whether there is meaningful human review.


If scanning results are used in criminal proceedings, the person concerned must have a fair chance to understand and challenge the evidence. This follows from the rights to a fair trial and defense under Articles 47 and 48 of the Charter and Article 6 of the ECHR. Human-rights compliance therefore depends not only on the purpose of scanning, but also on its scope, accuracy, transparency, and safeguards.


5. End-to-End Encryption and Cybersecurity


End-to-end encryption allows only the sender and intended recipient to read a message. It protects communications used by individuals, journalists, lawyers, businesses, and public authorities. The EDPB describes it as a crucial safeguard against access by third parties, including service providers.


Client-side scanning does not alter the encryption algorithm itself. Instead, it checks content on the user’s device before encryption or after decryption. The message may still be encrypted in transit, but its content has already been examined. Signal and other critics argue that this weakens the protection offered by end-to-end encryption.


There are also wider cybersecurity concerns. A scanning system added to private devices or messaging services could become a target for hackers, criminals, or hostile states. It could also later be adapted to search for other types of content. ENISA has warned that backdoors can weaken the security of digital communications and services. In a 2025 letter to the German government, Signal argued that no backdoor can safely be limited to authorized users, stating that encryption “either works for everyone, or it doesn’t work for anyone.”


The issue is therefore not simply privacy versus security. It is also a choice between investigative access and the security of digital communications as a whole.


6. Necessity and Proportionality


A legitimate aim does not by itself justify interference with fundamental rights.


Under Article 8(2) of the ECHR and Article 52(1) of the EU Charter, a measure must also be necessary, proportionate, and supported by safeguards.

The Court of Justice of the European Union (CJEU) has applied these requirements strictly. In Digital Rights Ireland, it held that retention of communications data covering almost the whole population went beyond what was strictly necessary. In La Quadrature du Net, the Court allowed general retention only in response to a serious threat to national security, for a limited period, and under effective review. These cases concerned metadata, not message content, but show the scrutiny applied to broad surveillance.


The type of detection matters. Matching known CSAM against verified indicators is more limited than searching for new material or grooming, which requires automated analysis and carries greater risks of error. The EDPB and EDPS have raised concerns about these methods.


Necessity also requires consideration of less intrusive tools. Security researchers argue that scanning methods can be inaccurate, easy to avoid, and harmful to encrypted communications.


For these reasons, proportionality is especially difficult to establish for detecting new CSAM and grooming within encrypted services.


7. Conclusion


Protecting children from sexual abuse is an urgent and legitimate aim, but it should not lead to the general scanning of private communications. Any EU framework must respect privacy, data protection, and freedom of expression, while also protecting the security of encrypted services.


A more balanced approach would preserve end-to-end encryption, limit detection measures to clearly defined cases, and include strong judicial oversight, transparency, and remedies for users who are wrongly flagged. The EU should show that child protection and fundamental rights can be protected together, rather than treating one as the price of the other.


Glossary


  • Client-side scanning: The examination of content on a user’s device before encryption or after decryption.

  • CSAM: Visual material depicting children engaged in real or simulated sexually explicit conduct.

  • Detection order: An order requiring a service provider to take measures to detect online child sexual abuse on a specific service.

  • End-to-end encryption: A security method that allows only the sender and intended recipient to read a communication.

  • False positive: Lawful content that an automated system incorrectly identifies as suspicious.

  • Grooming: The solicitation of a child for sexual purposes.

  • Known CSAM: Child sexual abuse material that has previously been detected and identified as such and can be detected using corresponding digital indicators.

  • Metadata: Information about a communication, such as its sender, recipient, time, or location, rather than its content.

  • New CSAM: Material not previously detected that is likely to constitute child sexual abuse material but has not yet been confirmed as such.

  • Proportionality: The principle that a measure must not go beyond what is necessary to achieve its legitimate aim.


References


  1. European Commission, Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse, COM(2022) 209 final, 11 May 2022, available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52022PC0209

  2. Euronews, What Is the EU’s “Chat Control” and How Does It Work?, 27 July 2026, available at: https://www.euronews.com/my-europe/2026/07/27/what-is-the-eus-chat-control-and-how-does-it-work-ask-the-euronews-ai-chatbot

  3. European Parliament, Combating Child Sexual Abuse: Support for a More Limited ePrivacy Derogation, 9 July 2026, available at: https://www.europarl.europa.eu/news/en/press-room/20260706IPR46318/combating-child-sexual-abuse-support-for-a-more-limited-eprivacy-derogation

  4. European Parliament, Amendments Adopted on 9 July 2026 on the Council Position at First Reading with a View to the Adoption of a Regulation Amending Regulation (EU) 2021/1232, P10_TA(2026)0266, available at: https://www.europarl.europa.eu/RegData/seance_pleniere/textes_adoptes/definitif/2026/07-09/0266/P10_TA%282026%290266_EN.pdf

  5. Council of the European Union, Fighting Child Sexual Abuse Online: Interim Measure Protecting Children Now Reinstated, 23 July 2026, available at: https://www.consilium.europa.eu/en/press/press-releases/2026/07/23/fighting-child-sexual-abuse-online-interim-measure-protecting-children-now-reinstated/

  6. European Data Protection Board and European Data Protection Supervisor, Joint Opinion 04/2022 on the Proposal for a Regulation of the European Parliament and of the Council Laying Down Rules to Prevent and Combat Child Sexual Abuse, 28 July 2022, available at: https://www.edpb.europa.eu/system/files/documents/2022-07/edpb_edps_jointopinion_202204_csam_en_0.pdf

  7. European Data Protection Supervisor, Combatting Child Sexual Abuse Online Presents Serious Risks for Fundamental Rights, 29 July 2022, available at: https://www.edps.europa.eu/press-publications/press-news/press-releases/2022/combat-child-sexual-abuse-online-presents-serious-risks-fundamental-rights_en

  8. Europol, Internet Organised Crime Threat Assessment 2026: The Evolving Threat Landscape—How Encryption, Proxies and AI Are Expanding Cybercrime, 2026, available at: https://www.europol.europa.eu/publication-events/main-reports/iocta-2026-evolving-threat-landscape

  9. Court of Justice of the European Union, G.D. v Commissioner of An Garda Síochána and Others, Case C-140/20, Judgment of 5 April 2022, ECLI:EU:C:2022:258, available at: https://infocuria.curia.europa.eu/tabs/jurisprudence?lang=en&sort=DOC_DATE-DESC&searchTerm=%2522ECLI%253AEU%253AC%253A2022%253A258%2522

  10. Council of Europe, Violence—Manual on Human Rights Education for Children, available at: https://www.coe.int/en/web/compasito/violence

  11. European Court of Human Rights, Podchasov v. Russia, Application no. 33696/19, Judgment of 13 February 2024, available at: https://hudoc.echr.coe.int/eng#{%22itemid%22:[%22001-230854%22]}

  12. European Data Protection Board, Statement 1/2024 on Legislative Developments Regarding the Proposal for a Regulation Laying Down Rules to Prevent and Combat Child Sexual Abuse, 13 February 2024, available at: https://www.edpb.europa.eu/system/files/documents/2024-02/edpb_statement_202401_proposal_regulation_prevent_combat_child_sexual_abuse_en.pdf

  13. Signal, Content Moderation in End-to-End Encrypted Systems: Client-Side Scanning, available at: https://signal.org/blog/pdfs/upload-moderation.pdf

  14. European Union Agency for Cybersecurity (ENISA), Encryption: Strong Encryption Safeguards Our Digital Identity, December 2016, available at: https://www.enisa.europa.eu/sites/default/files/all_files/2016-12-12-ENISA%20opinion%20paper%20on%20encryption.pdf

  15. Signal, Open Letter to the German Government on the EU Chat Control Proposal, 2025, available at: https://signal.org/blog/pdfs/germany-chat-control.pdf

  16. Court of Justice of the European Union, Digital Rights Ireland Ltd and Seitlinger and Others, Joined Cases C-293/12 and C-594/12, Judgment of 8 April 2014, ECLI:EU:C:2014:238, available at: https://infocuria.curia.europa.eu/tabs/document?source=document&docid=150642&doclang=EN

  17. Court of Justice of the European Union, La Quadrature du Net and Others, Joined Cases C-511/18, C-512/18 and C-520/18, Judgment of 6 October 2020, ECLI:EU:C:2020:791, available at: https://infocuria.curia.europa.eu/tabs/document?source=document&docid=232084&doclang=EN

  18. Security and Cryptography Researchers, Open Letter on the Dangers of the EU Commission’s Proposed Regulation for Fighting Child Sexual Abuse, available at: https://hpi.de/oldsite/fileadmin/user_upload/fachgebiete/lehmann/Publications/Open_Letter_CSA_v2.pdf

​Address:

2000 Duke Street, Suite 300, Alexandria, VA 22314, USA

Tax exempt 501(c)(3)

EIN: 87-1306523

© 2026 HRRC

bottom of page