By Dejan Hinic and Gabriël Moens
On 9 July 2026, the European Parliament passed a new, controversial privacy-related law.[1] The controversy related not just to the substance of the law itself, but also to how it was adopted. The new law, the Chat Control 2.0, is the European Union’s Child Sexual Abuse Regulation (CSAR). It mandates the scanning of private digital communications across virtually all major messaging platforms. Under this regime, applications such as WhatsApp, Signal, Telegram, iMessage, Instagram, Facebook Messenger, Viber, and others that have more than ten thousand users must deploy client‑side scanning (CSS) technologies that analyse user content before encryption occurs.
This means that every message, image, video, or voice note is inspected on the user’s device through automated classifiers designed to detect prohibited material, including in attachments. Reports generated by private platforms are forwarded to the newly established EU Centre to Prevent and Combat Child Sexual Abuse, which filters and validates flagged content. In other words, an application has access to your device, phone or computer, to freely search through it without your approval or control to stop it or limit it. Moreover, while the law is currently limited to child sexual abuse materials (CSAM), the existence of CSS technologies increases the risk of mission creep, whereby scanning could be expanded to other categories such as extremism, misinformation, or political speech.[2]
Client‑side scanning represents a radical departure from established privacy norms. Unlike traditional interception methods, CSS operates directly on the user’s device, analysing content prior to encryption. This approach undermines the very purpose of end‑to‑end encryption: ensuring that only communicating parties can access message content. Under this new law, the end-to-end encryption is pointless.
The implications of CSS scanning are profound because it transforms personal devices into surveillance instruments, eroding the confidentiality of communications and undermining the foundational security guarantees of end‑to‑end encryption. The Regulation effectively normalises generalisedmonitoring, a practice that European courts have historically rejected as incompatible with fundamental rights such as the right to privacy and the right to free speech. The Court of Justice of the European Union has repeatedly ruled against general monitoring obligations, most notably in Digital Rights Ireland[3], Schrems I[4], and Schrems II[5].
As such, CSS raises significant concerns under the Charter of Fundamental Rights of the European Union, particularly Articles 7 (respect for private and family life) and 8 (protection of personal data).[6] The European Data Protection Board (EDPB) and European Data Protection Supervisor (EDPS) have warned that CSS constitutes a form of “pervasive surveillance” incompatible with EU fundamental rights protections.[7] Moreover, CSS risks violating GDPR principles such as data minimisation, purpose limitation, and proportionality.
One of the most troubling aspects of Chat Control 2.0 is the outsourcing of surveillance to private corporations. The regulation requires messaging platforms to implement and operate the scanning systems, meaning that for‑profit companies become responsible for analysing private communications.
This privatisation raises several concerns. Profit motives may influence how scanning technologies are developed, deployed, or expanded. Lack of transparency in algorithmic decision‑making increases the risk of false positives and wrongful investigations. Unclear data‑storage practices create uncertainty about where sensitive information is stored, how long it is retained, and who may access it. Potential commercial incentives could encourage companies to repurpose scanning infrastructure for advertising, behavioural analytics, or other non‑law‑enforcement uses.
The Regulation does not clearly define the boundaries of data retention, nor does it specify how private actors must safeguard sensitive information. This ambiguity creates structural vulnerabilities that could be exploited by corporations, governments, or malicious actors. In addition, such practice can amount to state-mandated surveillance and further expand to other online applications and services.
Private corporations play a central role in Chat Control 2.0, yet they are not democratically accountable institutions. By outsourcing client‑side scanning to companies such as Meta, Apple, Telegram, and others, the EU effectively outsources a core law‑enforcement function to entities the primary obligation of which is to maximise shareholder value rather than to safeguard fundamental rights. This creates a structural conflict of interest: corporations are incentivised to expand data collection, refine behavioural profiling, and repurpose scanning infrastructure for commercial gain.
Moreover, the regulation provides no clear guarantees about where flagged data will be stored, how long it will be retained, or whether it will be processed by subcontractors outside the EU’s jurisdiction. In practice, sensitive material could be routed through opaque global data‑processing chains, including servers in countries with weaker privacy protections. The absence of strict oversight mechanisms means that users have no meaningful recourse if their private communications are misclassified, mishandled, or exposed through corporate negligence.
By embedding surveillance capabilities directly into consumer devices, Chat Control 2.0 creates a permanent monitoring infrastructure controlled by profit‑driven actors who operate beyond the reach of democratic scrutiny. This raises profound questions about accountability, transparency, and the long‑term erosion of digital autonomy.
For these reasons, we argue that Chat Control 2.0 constitutes a serious threat to privacy and the integrity of digital communication.
We further contend that the law’s adoption, without a majority “yes” vote, reveals structural weaknesses in EU legislative procedure that enable controversial measures to pass without genuine democratic consent. This means, if there is no genuine democratic consent, it does not matter what the majority of present members in the parliament think or how they vote; this mirrors the modus operandi of the former Soviet Union.
Indeed, the Regulation’s passage did not reflect a clear majority of support within the European Parliament. Instead, it resulted from the procedural dynamics of the ordinary legislative procedure (OLP) at the second reading stage, governed by Articles 289 and 294 of the Treaty on the Functioning of the European Union (TFEU).[8] To reject the Council’s position, Parliament must achieve an absolute majority of all Members of the European Parliament (MEPs), currently 361 votes.[9]
On 9 July 2026, the Parliament voted on a motion to reject the Council’s text. The vote result was that the 314 MEPs voted in favour of rejection, while 276 voted against rejection and 17 abstained. However, because the rejection motion failed to reach the required threshold of 361 votes as required by Article 294 TFEU – a majority of its component members – it was deemed unsuccessful. Under the OLP, this failure results in automatic adoption of the Council’s position.
Why is the legislative OLP practice dangerous? This procedural structure creates a democratic deficit. Abstentions and absences effectively count as affirmative votes because they reduce the likelihood of reaching the absolute majority threshold. The Chat Control 2.0 law thus passed despite having more opponents than supporters, undermining the principle of majority rule. Also, the timing of the vote, immediately before parliamentary recess, limited participation and debate. The complexity of the procedure obscures accountability and public understanding. In effect, Chat Control 2.0 was adopted not through democratic endorsement, but through procedural inertia.
In summary: Chat Control 2.0 represents a significant threat to privacy, democratic legitimacy, and the integrity of digital communication. By mandating client‑side scanning, the Regulation undermines established privacy protections and creates a surveillance infrastructure with far‑reaching implications. Equally troubling is the way the law was adopted: through a procedural mechanism that allowed abstentions and absences to function as de facto affirmative votes, resulting in the passage of a law that lacked a true majority.
The outsourcing of surveillance to private corporations further exacerbates these risks, introducing uncertainty about data storage, algorithmic transparency, and commercial incentives. As Europe continues to define its digital future, it must ensure that the protection of children does not become a pretext for the erosion of fundamental rights. In addition, members of the European Parliament must ensure that the laws are passed by the true majority without using backdoors, loopholes or other creative legal avenues, such as counting the absentee votes in favour of the ruling power.
Dejan Hinic is a financial and investment expert operating from Belgrade, Serbia He received his law degrees from the University of Belgrade and the University of Queensland.
Gabriël Moens AM is an emeritus professor of law at the University of Queensland where he served as the Garrick Professor of Law. He also served as pro vice-chancellor and dean at Murdoch University. He is the co-author of The Legal Right to Disobey Law, Sidestream Press, 2026.
[1] Available at: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A52022PC0209.
[2] European Commission, Proposal for a Regulation Laying Down Rules to Prevent and Combat Child Sexual Abuse, COM(2022) 209 final, EUR-Lex, 11 May 2022, at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52022PC0209.
[3] Digital Rights Ireland Ltd v Minister for Communications C‑293/12, EUR-Lex, 8 April 2014, at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A62012CJ0293.
[4] Schrems v Data Protection Commissioner, C‑362/14, EUR-Lex, 6 October 2015, at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:62014CJ0362.
[5] Schrems II, C‑311/18, EUR-Lex, 16 July 2020, at https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:62018CJ0311.
[6] Available at: https://www.europarl.europa.eu/charter/pdf/text_en.pdf.
[7] Joint Opinion on the Proposal for a Regulation Laying Down Rules to Prevent and Combat Child Sexual Abuse, EDPB & EDPS, 28 July 2022, at https://www.edpb.europa.eu/documents/legislative-opinion/edpb-edps-joint-opinion-042022-on-the-proposal-for-a-regulation-of_en.
[8] Available at: https://eur-lex.europa.eu/resource.html?uri=cellar:2bf140bf-a3f8-4ab2-b506-fd71826e6da6.0023.02/DOC_2&format=PDF.
[9] Treaty on the Functioning of the European Union (TFEU), Article 294, EUR-Lex, 26 October 2012, at https://eur-lex.europa.eu/eli/treaty/tfeu_2012/art_294/oj/eng.

