The fight against online child abuse on the one hand, the protection of privacy and encryption on the other. It is on this delicate balance that the future of the so-called depends Chat Controlone of the most controversial dossiers of recent years in Europe.
In these hours, the European Parliament has approved the extension of the exemption to the ePrivacy regulation – which allows technology companies to monitor exchanges of messages on chats and emails in order to report the spread of child pornography material – until April 3, 2028avoiding a regulatory gap while negotiations continue on the definitive regulation against the dissemination of child pornography online (CSAM, Child Sexual Abuse Material).
We talked about it here: Will the EU really spy on our messages? What we know about the Chat Control surveillance project
A decision which, as expected, has reignited the conflict between those who consider these measures indispensable to protect minors and those who fear they could open the way to increasingly invasive forms of surveillance.
What is Chat Control
The expression “Chat Control” refers to the European regulatory project aimed at combating the spread of child pornography through messaging services, emails and digital platforms.
In reality, this latest vote, but extends a temporary derogation already in force since 2021. This allows providers of electronic communication services – such as WhatsApp, Messenger or other email services – to carry out, on a voluntary basis, activities of detection and reporting of content attributable to sexual abuse of minors, derogating from the rules established by the ePrivacy regulation.
The extension was approved because the negotiation on the permanent regulation has not yet been concluded.
What really changes after the vote
However, one of the most important aspects of the vote concerns the end-to-end encryption. The European Parliament has in fact approved a change to its negotiating position which aims to exclude communications protected by end-to-end encryption from the scope of future legislationthat is, those messages that can only be read by the sender and the recipient.
However, this is a negotiating position of Parliament and not one definitive rule. Now the text will have to be examined by the Council of the European Union: if the member states do not agree with all the changes, a conciliation phase will open. In other words, the future of chat encryption is still up for negotiation.
Because the measure divides
What emerges is that there is no great desire to question the need to combat the spread of child pornography material online, but – according to the supporters of the measure – maintaining the exemption means allow platforms to continue to detect and report illegal contentpreventing investigative tools considered fundamental for the protection of minors from disappearing during the regulatory vacuum.
Associations dealing with digital rights, numerous cybersecurity experts and part of the political world believe that the risk is that of creating a very dangerous precedent.
The criticisms do not concern the objective of the legislation so much as its possible impact on fundamental rights: among the main findings is the fear that automated content scanning systems could transform, in fact, into a form of generalized control of private communications.
Also the European Data Protection Supervisor (EDPS) and the European Data Protection Board (EDPB) have expressed strong reservations, underlining that an indiscriminate scanning of electronic communications would risk coming into conflict with the right to privacy guaranteed by European legislation.
Doubts have also been raised by Legal Service of the Council of the European Unionwhich highlighted possible critical issues with respect to the protection of privacy.
The node of cryptography
One of the most controversial points concerns the so-called client-side scanningi.e. the analysis of contents directly on the user’s device before the message is encrypted and sent. According to critics, such a system would end up bypassing, at least in part, the guarantees offered by end-to-end encryption.
Furthermore, entrusting detection to automatic tools could generate false positiveswith the risk of incorrect reporting and even serious consequences for users who are completely unrelated to illicit activities. Another concern concerns regulatory precedent: once an exception to the confidentiality of communications is introduced for a specific category of crimes, some observers fear that the use of similar tools could be extended to other areas in the future.
The extension approved by the European Parliament therefore does not represent the definitive green light for the so-called Chat Control, but rather serves to keep a temporary regulation in force while negotiations on the permanent regulation continue, still far from a definitive agreement between Parliament, Council and Commission.
The debate remains open and touches on one of the most delicate issues of the digital age: how to effectively protect minors online without compromising the right to privacy and the security of communications of millions of European citizens.