International Edition
Latest News
Technology

EU CSAM Detection: Tech Companies Urge Action on ePrivacy Rule

EU Faces Deadline as Child Sexual Abuse Material Detection Rules Hang in the Balance Brussels – A critical deadline looms as European lawmakers grapple with extending voluntary rules designed to detect child sexual abuse material (CSAM) online. The…

EU CSAM Detection: Tech Companies Urge Action on ePrivacy Rule

EU Faces Deadline as Child Sexual Abuse Material Detection Rules Hang in the Balance

Brussels – A critical deadline looms as European lawmakers grapple with extending voluntary rules designed to detect child sexual abuse material (CSAM) online. The current legal basis, a derogation of the ePrivacy Directive, is set to expire on April 3, 2026, potentially hindering efforts to protect children from online exploitation.

The Impending Expiration and Its Consequences

The ePrivacy Directive derogation, in place since 2021, has allowed technology companies to voluntarily detect and report known CSAM. Without an extension or a new framework, a significant gap in protection could emerge, reducing the clarity that has enabled companies for nearly 20 years to proactively combat the spread of this illegal content. Google and Microsoft have both voiced concerns about the potential repercussions of allowing the current rules to lapse.

How Voluntary Detection Works: Hash Matching

A key tool in the fight against CSAM is hash matching. This established method utilizes irreversible digital fingerprinting to identify known CSAM. By comparing unique “hashes” – digital signatures – against a secure database of previously identified material, the system enables high-precision detection while aiming to respect privacy principles. This process is crucial for law enforcement investigations, helping to identify ongoing abuse and prevent the further dissemination of harmful content.

Parliamentary Support for Extension, with Conditions

The European Parliament has endorsed a temporary extension of the current derogation until August 3, 2027, with 458 votes in favor, 103 against, and 63 abstentions. MEPs recognize the need for continued voluntary detection measures while a long-term legal framework is established. Although, they have stipulated that these measures must remain proportional and targeted.

Key Restrictions and Safeguards

Several key restrictions have been proposed to safeguard fundamental rights:

  • No Scanning of Encrypted Communications: Voluntary measures should not apply to end-to-end encrypted communications.
  • Limited Data Scanning: Scanning of traffic data alongside content data is not permitted.
  • Targeted Application: Technology should only be applied to material already identified as CSAM or flagged by trusted sources (users, flaggers, or organizations).
  • Judicial Oversight: Measures should target users or groups identified by a judicial authority as reasonably suspected of involvement with CSAM.

The Path Forward

Rapporteur Birgit Sippel emphasized the importance of balancing the need to address child sexual abuse with the protection of fundamental rights, stating that the interim derogation is a “temporary, strictly limited instrument.” The extension provides time to reach an agreement on a permanent framework, but swift action from lawmakers is crucial to ensure continued protection for vulnerable children.

About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”