The European Union has updated its regulatory framework to allow digital platforms to voluntarily scan online communications for child sexual abuse material (CSAM), according to official statements from the European Council and European Parliament.
Webmail, Cloud Storage, and Social Media Face New Monitoring Rules
According to the European Parliament, the regulation applies to online service providers, including webmail hosts, cloud storage operators, and social media networks.
However, lawmakers instituted a strict exemption for end-to-end encrypted (E2EE) messaging services. Platforms such as WhatsApp, Signal, and Telegram remain shielded from mandatory or permissive scanning mandates under the current text, reflecting ongoing legislative tension over privacy protections and digital surveillance.
Privacy Advocates Warn of a Fragmented Enforcement Landscape
Years of Contentious Debate Precede the Temporary Derogation
Law Enforcement Demands Clash with Long-Term Regulatory Talks
Frequently Asked Questions About the ePrivacy Directive Extension
What types of digital services are affected by the new rules?
According to European Union regulatory summaries, the rules cover web-based email providers, cloud storage platforms, and social media networks that host or transmit user-generated content.
Are encrypted messaging apps included in the scanning authorization?
No. According to the European Parliament’s adopted amendments, end-to-end encrypted messaging services like Signal and WhatsApp are explicitly excluded from these scanning provisions.
Is this scanning mandate permanent?
Related reading