EU Council Pushes Chat Control 2.0 Through Fast Track
- Martin Chen

- Jul 6
- 3 min read
Updated: Jul 20
EU Council approved Chat Control 2.0 through a fast-track written procedure. The move forces tech companies to scan encrypted communications after transitional rules expired on April 3.
The regulation aims to close a legal gap and put pressure on the European Parliament. Critics argue the process bypasses normal democratic checks.
The Council claims the scans stay limited to what is necessary. Data must be deleted within twelve months after detection. According to Heise reporting on the Council decision, the approved text requires that “the processing of data shall be limited to what is strictly necessary” and that detected data be “irreversibly deleted” after twelve months. The Council of the EU has published the text via its official press release on the written procedure.
Council Bypasses Standard Review
The written procedure allowed approval without a full plenary debate. This shortcut raised immediate objections from privacy groups.
Council documents state the new rule targets child sexual abuse material. Messages stay encrypted until a detection trigger occurs. The regulation focuses on detection standards such as NCMEC hash lists and perceptual hashing tools used by providers.
Parliament now faces the draft before the summer recess begins. Most members will already have left for holidays when the vote arrives.
Parliament Faces Limited Options
Any opposition now requires an absolute majority to block the text. The shortened timeline makes that threshold hard to reach.
Supporters inside the Council say the rule fills an urgent hole in existing law. The previous transitional regime ended on April 3 and left no replacement in place.
Civil society groups call the timing deliberate. They point to the recess period as evidence that oversight was intentionally reduced.
Data Rules Limit Retention
The text requires irreversible deletion of scanned data within twelve months. Only information tied to confirmed detections survives longer.
Tech firms must report the volume of scans and any matches found. These reports go to national authorities rather than a single EU body.
Privacy advocates warn that the limits do not cover all risks. Stored metadata could still reveal communication patterns even after content deletion.
Encryption Providers Must Adapt
Messaging services that rely on end-to-end encryption now face new detection duties. Companies must integrate scanning tools without breaking encryption for non-suspect users.
Current commercial solutions use client-side hashing or perceptual matching. Client-side hashing generates a unique fingerprint of an image or file directly on the user’s device and compares it locally against a database of known CSAM hashes, transmitting only matches to the provider. Perceptual matching applies algorithms such as PhotoDNA that detect visually similar content even after minor edits or resizing. The main challenge lies in ensuring these systems avoid generating false positives that would expose innocent users’ private content and in preventing the creation of systemic weaknesses that could be exploited beyond the intended CSAM use case. The regulation leaves the technical choice to each provider.
Smaller services may struggle with implementation costs. Larger platforms already run similar systems for other content categories.
Next Watch Points
EU member states must transpose the regulation into national law within eighteen months. National data protection authorities will publish the first compliance reports.
Parliament committees scheduled hearings for the autumn session. Any amendments require support from a qualified majority of remaining members.
Watch for court challenges from services that reject client-side scanning. Cases filed in Luxembourg could test whether the retention and deletion rules satisfy existing data protection standards.


