Wire flash
TechEuropean Parliament passes Chat Control 1.0, allowing warrantless scanning of user communications
Editorial responsibility
- No named human review is recorded for this page.
- Source reporting is collected, normalized, translated or condensed automatically when needed.
- Automatically published source-backed update
The European Parliament has passed Chat Control 1.0, a law permitting companies to mass-scan user communications without warrants under the guise of detecting child sexual abuse material (CSAM). The law was previously rejected multiple times but was resurrected via a procedural maneuver by Parliament President Roberta Metsola, who invoked Rule 163's urgent procedure and scheduled a second reading on the last day before summer recess. The vote required an absolute majority (50%+1) to reject, and although 315 of 607 voting members opposed it, the threshold of 361 was not met, allowing the law to pass. The law applies to interpersonal communications services like email and chat (e.g., Gmail, Discord, Instagram) but exempts end-to-end encrypted services like WhatsApp. Critics decry the process as undemocratic and warn of privacy implications. The law remains in effect until 2028 and sets the stage for September's debate on Chat Control 2.0.
Source report
The Chat Control 1.0 law, which enables warrantless mass scanning of digital communications, has been voted against multiple times by the EU Parliament. Yet, like a movie zombie, it keeps getting resurrected through various legal sleight-of-hand maneuvers. Yesterday, one of those tricks succeeded, as Chat Control 1.0 passed (or rather, was not rejected) in a forced re-vote that required an absolute majority (50% + 1) for active refusal. This extends the law until 2028 and sets a different stage for September's upcoming discussion on Chat Control 2.0.
What the Law Allows
After the impending publication in the EU Official Journal, online direct-communication platforms will be permitted to mass-scan their users' data without a warrant, under the guise of searching for child sexual abuse material (CSAM).
The scanning is not mandatory, but big tech firms will now have a legal mechanism to rifle through user data. EU firms have historically refrained from doing so, presenting privacy and data sovereignty as selling points. Nevertheless, the legal door is now officially open.
Platforms Affected
The obvious platforms where monitoring can now take place include email and chat services. Immediate examples include:
- Gmail
- iCloud
- Hotmail
- Discord
- Slack
- Teams
- Snapchat
- Xbox
- Google Chat
Although the law's scope covers "interpersonal communications services," the legal mechanism might hypothetically extend to some gray areas like Google Drive, where sending someone a link to a cloud file could fall within the law's scope.
Key Limitations and Exemptions
It's worth noting that "direct communication" is not restricted to one-to-one chats, as it includes group chats — just not public or undirected communications. Additionally, EU law enforcement remains beholden to the same warrant requirement as before. Chat Control 1.0 does not grant a blank pass to authorities to mass-scan user data or request companies to do so without a targeted warrant.
Thanks to two amendments in yesterday's vote, end-to-end-encrypted (E2EE) communications means (e.g., WhatsApp) stay exempt. This means that for now, Chat Control 1.0 is not a commandment to break encryption — something that has been regularly suggested by lawmakers around the world.
Privacy Considerations
It's as good a time as any to remind people that Instagram messages are no longer E2EE as of May, and that although WhatsApp's messages are encrypted, the service leaks every single bit of metadata about them — sender, recipient, time, size, etc. As always, Signal is recommended as a privacy-focused communications app.
Controversial Parliamentary Procedure
This latest development in the EU Parliament is eliciting widespread public outcry due to the nature of the law itself, but also due to the manner in which it happened. Critics and opponents of the rule suggest this move is unprecedented.
Chat Control 1.0 had already been shot down repeatedly, most recently in March. However, European Parliament President Roberta Metsola forced a second reading of the law and invoked Rule 163's "urgent procedure" mechanism. This had several effects:
- Bringing up a law that was voted against for discussion yet again
- Turning the decision into a denial vote (vote-to-deny, not vote-to-pass)
- Exploiting the second-reading requirement that demands an absolute majority vote (50% + 1)
- Letting the President herself set the schedule
Metsola scheduled the second reading for the very last day before the European Parliament summer recess.
The Vote
The result was that out of 720 representatives, only 607 actually cast a vote. Of those, 315 (over half) voted against Chat Control 1.0. That figure did not meet the supermajority threshold of 361, which was calculated against a full chamber.
Resources for Opponents
Opponents to Chat Control have posted resources at the Fight Chat Control website, including a breakdown of member-state and individual representative voting positions and contact information.
Stay on the cutting edge: Get the Tom's Hardware Newsletter — Tom's Hardware's best news and in-depth reviews, straight to your inbox.
Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, and reviews in your feeds.
Source
Latest from Tom's HardwareWestern
Part of this Story
EU Parliament Passes Controversial Chat Control Law via Procedural Maneuver