EU Chat Control (2026): Where It Stands, and the Privacy Question a VPN Cannot Answer

Disclosure: VPNFin is reader-supported. If you buy a VPN through links on this page, we may earn a commission at no extra cost to you. This never affects our ratings — here’s our full disclosure.

On 9 July 2026 the European Parliament voted on whether to reject the temporary rules that let platforms scan private messages. Three hundred and fourteen members voted to reject; two hundred and seventy-six voted against rejection.

The rejection failed. A second-reading rejection requires an absolute majority of all members — 361 — rather than a majority of those voting, and the vote fell forty-seven short. The regime now runs to April 2028.

⚠️ We take no position on the policy. The regulation exists to detect child sexual abuse material, which is a serious purpose, and the objections to it are technical and legal. Both are set out below as their own authors put them.

What Is Actually Being Debated

Two separate things carry the same nickname. Keeping them apart is most of the work of understanding this.

The temporary derogation, from July 2021. It permits providers to scan unencrypted messages voluntarily, as an exception to European privacy rules. Meta, Google and Microsoft have operated under it — a permission rather than a restriction on users, which is the distinction our legality guide keeps returning to.

The permanent regulation, proposed in May 2022. This is the larger question: whether detection becomes a legal obligation, and whether it can reach encrypted services. It is not law, and five rounds of negotiation have not settled it.

⚠️ So nothing mandatory has passed. Coverage often merges the two, and the difference between a permission and an obligation is the whole argument.

How the Year Went

26 March 2026. Parliament voted 307 to 306, with 24 abstentions, against extending the temporary rules. The civil liberties committee had already rejected the draft 38 to 28.

3 April 2026. The derogation expired.

2 July 2026. The Council moved to revive it through an urgent procedure, arguing that voluntary detection helps identify offenders and locate victims.

7 and 9 July 2026. Parliament approved the urgency by 331 to 304, then failed to reject the substance by the margin described above.

The recorded European Parliament votes on the temporary message-scanning rules between March and July 2026

What Each Institution Wants

The Commission proposed three detection routes: matching against known material by hash, artificial-intelligence detection of previously unknown material, and detection of grooming behaviour.

Parliament’s position, adopted November 2023, narrowed all three. Known-material matching only, judicial authorisation targeted at named suspects, no client-side scanning, and explicit protection for end-to-end encryption. The headline vote was 311 to 228.

Ministers went further in November 2025. The Council dropped the mandatory element after sustained objections, and kept a permanent framework for voluntary scanning together with age-verification obligations.

⚠️ The fifth round of talks collapsed in June 2026, over whether that voluntary framework becomes permanent. Negotiations were due to resume in September.

The positions of the Commission, Parliament and Council on the EU child sexual abuse regulation

The Case for It

The purpose is the detection of child sexual abuse material, and the Council’s stated reasoning is that voluntary detection identifies offenders, helps locate victims and reduces circulation of the material.

Platforms have been scanning under the derogation since 2021, and reporting has come from it. Letting the permission lapse removed the legal basis for work already under way.

Supporters also note that the mandatory requirement was withdrawn. What remains under discussion permits rather than compels, which they describe as a proportionate middle position.

The Case Against It

The European Data Protection Board and the European Data Protection Supervisor issued a joint opinion in July 2022 stating that the detection measures went beyond what is necessary and proportionate.

A false-positive rate as high as 20% appears in the Commission’s own implementation report, for artificial-intelligence detection of previously unknown material — roughly one flagged conversation in five was not what it was flagged as.

Cryptographers have said since 2021 that grooming detection cannot be implemented without breaking the security model of end-to-end messaging, and hundreds have signed open letters to that effect.

⚠️ And the encryption industry’s objection is about precedent. Its position is that any detection order against an encrypted service creates a mechanism that can later be widened without new primary legislation — the same argument we apply to infrastructure that holds nothing: a capability that does not exist cannot be compelled.

Why a VPN Does Nothing About This

This is the part our readers most often get wrong, and it is worth being exact.

A VPN encrypts traffic in transit. It covers the journey between your device and the network — who can see which sites you reach, and what address they read.

Scanning happens at the ends. Either on the device before a message is sent, or at the platform after it arrives. Both sit outside the tunnel, so the tunnel is irrelevant to either.

⚠️ Which makes this the clearest case of what a VPN does not hide. The same distinction applies to platform data generally — the regulator in Dublin governs that, and no tunnel affects its work either.

What does matter is which messenger you use. End-to-end encryption is applied by the application, not by the network, and several free measures cover more of this ground than a subscription does.

Where a VPN protects your traffic compared with where message scanning takes place
See What Costs Nothing →
Encrypted messaging and DNS do more for this than any subscription

What to Watch Next

The permanent regulation, resuming in autumn 2026. Whether detection becomes an obligation, and whether encrypted services fall inside it, remain open.

Whether the voluntary framework becomes permanent. That is what the June talks failed over, and it is the substantive question rather than a procedural one.

April 2028. The temporary regime expires again, and the same argument will recur unless the permanent file has settled it. Germany’s long argument over retention suggests these questions outlive several parliaments.

⚠️ And national measures move separately. Sweden’s framework reaches the device before encryption and Switzerland has proposed obligations reaching VPN providers — neither depends on the European file.

How We Research

This page draws on Euronews and Help Net Security for the state of negotiations and the extension to April 2028, on published accounts of the recorded votes of 26 March, 7 July and 9 July 2026 and the absolute-majority threshold that decided the last of them, on the European Data Protection Board’s and Supervisor’s joint opinion of July 2022, and on the Commission’s own implementation report for the reported false-positive rate. Several sources on this subject are advocacy publications, including material from a member of the European Parliament campaigning against the proposal and from digital rights organisations; we have used them for dates and documents rather than for conclusions, and we name them here. Vote counts differ by one or two in some accounts, and we have used the figures that appear consistently across sources. We take no position on the policy. Our method lives on the About Us page.

Chat Control FAQ

Is Chat Control law in the EU?

Partly. The temporary derogation permitting providers to scan unencrypted messages voluntarily was revived in July 2026 and runs to April 2028. The permanent regulation, which would decide whether detection becomes an obligation and whether it can reach encrypted services, is not law and remains in negotiation.

Does Chat Control mean my messages are being scanned?

It means providers of unencrypted services may scan voluntarily, not that all of them do. Meta, Google and Microsoft have operated under the permission since 2021. Nothing currently obliges any provider to scan, and the mandatory element was withdrawn from the permanent proposal.

Would a VPN protect me from message scanning?

No. A VPN encrypts traffic in transit between your device and the network. Scanning takes place either on the device before sending or at the platform after arrival, both of which sit outside the tunnel entirely. The application’s own encryption is what matters here.

Why did the July 2026 vote pass when most MEPs opposed it?

Because of the procedure. In a second reading, rejecting a Council position requires an absolute majority of all members of Parliament — 361 — rather than a majority of those voting. 314 voted to reject, which was 47 short of that threshold.

What do data protection authorities say about it?

The European Data Protection Board and the European Data Protection Supervisor issued a joint opinion in July 2022 stating the detection measures went beyond what is necessary and proportionate. The Commission’s own implementation report later found a false-positive rate as high as 20% for detection of previously unknown material.

The Verdict

Nothing mandatory has passed, and the temporary permission is back until 2028. Those two facts are what most coverage of this subject conflates.

The July vote turned on a procedural threshold rather than on the numbers. A majority of those voting opposed the measure and it carried, which is how a second reading works.

And none of it is a VPN question. If this is what concerns you, the answers are your choice of messenger and the law itself — not a subscription, however it is advertised.

Check Proton VPN →
For the part a tunnel does cover — the network between you and everything else
Scroll to Top