PART 00 · THE WHY
Understand the threat
Before you change tools, understand what you are protecting against. Otherwise you install random apps and feel safe when you are not.
Chat Control 1.0 and 2.0, plainly
“Chat Control” is the nickname for two EU texts that allow (or would require) scanning your private messages for child sexual abuse material (CSAM). The stated goal is legitimate; the method, blanket scanning of the communications of unsuspected people, amounts to mass surveillance.
| Chat Control 1.0 | Chat Control 2.0 (CSAR) | |
|---|---|---|
| Text | Regulation (EU) 2021/1232, ePrivacy derogation | Proposal COM/2022/209 (Ylva Johansson, May 2022) |
| Scanning | Voluntary, platforms may scan | Commission proposal: mandatory via “detection orders”. Council position (Nov 2025): voluntary scanning made permanent, plus “risk-mitigation measures” |
| Who | Mostly unencrypted US services: Gmail, Messenger/Instagram, Skype, Snapchat, iCloud Mail, Xbox | All platforms, including end-to-end encrypted messengers |
| Duration | Temporary: lapsed on 3 April 2026, reinstated on 23 July 2026 until 3 April 2028 | Permanent (no expiry date planned) |
| Status (Oct 2026) | In force, end-to-end encrypted communications excluded from its scope | Under negotiation (trilogue): no final text, nothing in force |
Chat Control 1.0 today: what is covered, what is not
The interim regulation lapsed on 3 April 2026, then came back: after a second reading in the European Parliament, the Council gave it final approval on 23 July 2026 (Regulation (EU) 2026/1881), until 3 April 2028. It allows, without requiring, providers to scan private communications for child sexual abuse material.
- What is covered: communication services that are not end-to-end encrypted and whose provider chooses to scan, for example Messenger or Instagram messages, Gmail or Outlook e-mail, chat built into game consoles and platforms. Google, Microsoft, Meta and Snapchat are among the signatories of the 19 March 2026 call to keep this detection going.
- What is excluded: an amendment adopted by Parliament, then accepted by the Council, removes from its scope communications “to which end-to-end encryption is, has been or will be applied”. Messengers that are end-to-end encrypted by default, such as Signal, Session, Threema, SimpleX Chat or Olvid, are therefore not covered by this text (see encrypted messaging).
This exclusion only applies to this interim text. The permanent regulation, or a harsher version, can go back on it: this guide plans for that scenario and recommends tools that stay protective even if scanning became mandatory.
Proton Mail and Tuta encrypt messages between their own users. But an e-mail exchanged with a Gmail or Outlook address reaches that provider in the clear, and it can scan it on its side: neither Proton nor Tuta can prevent that. PGP encryption also works from Gmail; it protects the message body, but not the subject line or the metadata (see encrypted e-mail).
Chat Control 2.0: what the text would do
The permanent regulation (CSAR) is still being negotiated between the Commission, the Council and Parliament (trilogue). The sixth trilogue, on 29 September 2026, ended without agreement and technical talks continue. There is no final text and nothing is in force.
- The Commission proposed mandatory “detection orders” in 2022, encrypted messengers included.
- The Council (position of 26 November 2025) dropped mandatory orders, but makes voluntary scanning permanent and requires “risk-mitigation measures”, which could include scanning.
- Parliament wants detection limited to suspects, on a judge’s order, and end-to-end encryption protected.
If client-side scanning became mandatory
What follows is not in force: these are the plausible consequences if the final text required scanning on devices.
- Messengers that comply would ship an EU version with a scanning module running before encryption, distinct from the versions offered elsewhere.
- Messengers that refuse could leave the European market, as Signal publicly announced in October 2025. The app would then disappear from European app stores: on iOS it would become hard or impossible to get; on Android the publisher can offer the APK on its official website. If the download or the service were blocked from the EU, only a VPN or Tor would reach it.
- Scanning at operating-system level: if the obligation targeted the systems themselves, a free app would no longer be enough. Out of reach would remain non-cooperating systems, GrapheneOS on mobile and non-regional GNU/Linux distributions on computers (see free operating systems), used with a messenger that also refuses scanning.
Thanks to Jérémy Roche, lawyer at the Béziers bar, for his advice on this part.
Client-side scanning: the legal wiretap
The heart of Chat Control 2.0 is a technique called client-side scanning. The idea: instead of breaking encryption in transit, software is installed directly on your phone to inspect every message, photo or link before it is encrypted and sent. Signal put it in one line: it is “like malware on your device”.
Against client-side scanning, neither a VPN nor end-to-end encryption is enough if the app or the operating system cooperates. The scan happens on the device, before encryption: the VPN has nothing to protect, and encryption kicks in too late. What actually protects you is choosing free/open-source software that refuses to implement scanning, favourable jurisdictions, self-hosting, and taking back control of your device (an untampered OS). Everything else in this guide follows from this truth.
Everyone’s privacy is sacrificed for a technology that fails. The European Parliament’s own study concludes no system detects this content without a high error rate (because across billions of messages, even a tiny false-positive rate yields millions of false accusations). Irish police figures show it: of automated reports, only about 20% were actual material, and over 11% were outright false positives. Landmark research (“Bugs in Our Pockets,” 2021) further shows that once client-side scanning is installed, it is inevitably repurposed (terrorism, copyright, opinions).
The pretext: “protecting children”
No one is against protecting minors, which is exactly what makes it such an effective lever. Fighting child abuse serves as an emotional Trojan horse: who would dare object? Under that banner, a principle is made acceptable that, on its own, would be flatly rejected, the automated inspection of the private communications of hundreds of millions of unsuspected people. Children are the stated motive; the real target is everyone’s encryption and privacy.
The tell: the companies pushing hardest for this scanning are the ones whose business model is surveillance. On 19 March 2026, a joint appeal urged EU lawmakers to entrench “voluntary” detection, signed by:
“Failure to do so would be irresponsible.” The tech giants’ argument for keeping message scanning alive.
Those same players even announced they would keep scanning messages after the legal basis lapsed on 3 April 2026. Citizens are thus asked to entrust the inspection of their intimate conversations to the very companies known for harvesting and monetising their data. This is the real face of Chat Control: an attack on privacy wrapped in a motive no one can refuse.
This is not “just” surveillance
They try to reassure you: “it’s only Gmail, Instagram, Snapchat, Messenger.” That’s false, and it’s the most alarming part. Three shifts hide behind that downplaying.
- It’s not targeting, it’s dragnet. This doesn’t watch suspects: it installs systematic collection of entire populations’ communications. Surveillance at state scale, continuously.
- It’s no longer reading, it’s the power to block. Software that inspects a message before it’s sent can also refuse to send it. Client-side scanning builds the infrastructure of prior censorship: blocking speech before it even reaches its recipient.
- Once the infrastructure exists, it gets repurposed. A system built “for the children” becomes a general-purpose control tool. The motive changes; the machine stays.
The same logic is about to reach your money. The ECB’s digital euro rests on a traceable currency, bars companies from holding any, and comes with a holding cap: the ECB has floated about €3,000 per person as a working assumption, and the position voted in the European Parliament’s committee (June 2026) leaves the cap for the Commission to set on the ECB’s recommendation, reviewed every two years. The ECB swears the currency won’t be “programmable,” but the cap and the traceability are very much on the menu. When it lands, will you say “relax, it’s only a cap”? That’s the very same rhetorical trap as “it’s only Gmail.” The real question is never what is controlled today, but the control infrastructure being installed for tomorrow.
Which profile are you?
No tool is magic and nobody needs to do everything. Find your profile: each section tells you how far to go.
🟢 The ordinary citizen
You just want your conversations and private life to stop being scanned and monetised. Goal: everyday privacy, without becoming an expert.
🟡 The pseudonymous account
Information account, activist page, creator: you fear being deanonymised, doxxed, or losing your account. Goal: separate your real identity from your public one.
🔴 The whistleblower
Journalist, activist, source, facing a powerful adversary (state, employer). Goal: strong anonymity, anti-correlation, passing documents without being caught.
Manifesto
Changing tools is an act of individual responsibility, one that belongs to each of us: it is how you refuse an illegitimate mass surveillance.
Encrypting is protecting your private life. Self-hosting is pulling yourself out of Big Tech's surveillance. Taking back control of your tools is becoming ungovernable and sovereign.
The fight is political. Support the organisations opposing it, like the fightchatcontrol.eu initiative, and write to your representatives. That is what almost brought Chat Control down.
But since the solution will probably come neither from the ballot box nor from the European Parliament, it falls to each of us to win our freedom and protect our privacy with every tool the Internet offers.