PART 23 · THE RECEIPTS

Thirty years of precedents

Every generation is told the surveillance is new, limited and temporary. Dated and sourced: the same script since 1993. Click a date to cite an entry.

  1. the promise

    The Clipper Chip

    The NSA pushes an encryption chip with a government-held key escrow, "for law enforcement, under warrant only". Flaws demonstrated (Blaze, 1994), massive rejection: abandoned by 1996. The first crypto war, same script as today.

    EPIC · Clipper Chip →

  2. revealed

    ECHELON confirmed by the European Parliament

    Six days before 9/11, the European Parliament adopts in plenary (367–159–39) the report of its temporary committee (approved in committee on 3 July) confirming the existence of a global network intercepting private and commercial communications (US, UK, Canada, Australia, New Zealand).

    European Parliament · A5-0264/2001 →

  3. the creep

    23 days after 9/11

    A secret presidential order starts the NSA’s warrantless domestic spying. The crisis creates the program; the program outlives the crisis. The Patriot Act follows on 26 October, also "temporary": its sunset clauses get renewed for 14 years.

    EFF · NSA Spying Timeline →

  4. revealed

    Room 641A

    AT&T technician Mark Klein hands EFF the documents describing the NSA’s secret room in the San Francisco switching hub: interception at the infrastructure level, on all traffic, not on suspects.

    EFF · Jewel v. NSA evidence →

  5. the creep

    EU Data Retention Directive

    The EU mandates retention of the whole population’s telecom metadata (6–24 months), "against serious crime". No one is a suspect, everyone is on file. Chat Control’s exact blueprint, twenty years earlier.

    Directive 2006/24/EC →

  6. revealed

    Snowden: "collect it all"

    The Guardian publishes the secret FISA order forcing Verizon to hand over all customers’ metadata, then PRISM. In March, intelligence director Clapper had sworn to Congress it wasn’t happening; days after the leak he calls that the "least untruthful" answer he could give.

    The Guardian · 5 June 2013 →

  7. struck down

    The CJEU strikes down blanket retention

    Digital Rights Ireland (joined cases C-293/12 and C-594/12): the 2006 directive is annulled outright: indiscriminate surveillance of the whole population violates the Charter of Fundamental Rights. A tiny volunteer NGO brought down an EU directive.

    CJEU · C-293/12 & C-594/12 →

  8. the creep

    The UK "Snooper’s Charter"

    The Investigatory Powers Act legalises bulk collection and state hacking, and forces ISPs to keep everyone’s browsing history. Three weeks later the CJEU (Tele2/Watson) repeats that blanket retention is unlawful; London keeps it anyway.

    legislation.gov.uk →

  9. the creep

    Australia vs mathematics

    The Assistance and Access Act lets the state secretly order a company to re-engineer its products ("technical capability notices"). Critics warn this weakens encryption in all but name, even though the Act nominally bans "systemic weaknesses". The PM had set the tone: "the laws of Australia prevail over the laws of mathematics".

    legislation.gov.au · C2018A00148 →

  10. revealed

    Crypto AG: the safe-maker kept the keys

    The Washington Post reveals (backed by the CIA’s own internal history) that the CIA and BND secretly owned Crypto AG, the Swiss encryption vendor of 120 governments, since 1970. In the 1980s, 40% of the diplomatic cables NSA decoded came through it. Moral: a "trusted" backdoor is a backdoor.

    Washington Post · Operation Rubicon →

  11. struck down

    La Quadrature du Net at the CJEU

    The Court upholds the ban on blanket retention against France and Belgium (joined cases C-511/18, C-512/18 and C-520/18), and against the UK the same day in Privacy International (C-623/17), while carving out "national security" windows. Twin lesson: lawsuits work, and every exception becomes the next rule. The Commission has never opened an infringement case against states that retain anyway.

    CJEU · C-511/18, C-512/18 & C-520/18 →

  12. the promise

    Chat Control 1.0, "temporary"

    Regulation 2021/1232 allows "voluntary" scanning of private messages, derogating from ePrivacy. Sunset on 3 August 2024, promised. Regulation 2024/1307 extends it to 3 April 2026, where it expires… then rises from the dead (see below).

    Regulation (EU) 2021/1232 →

  13. revealed

    The Pegasus Project

    80+ journalists across 17 newsrooms in 10 countries document the spying on journalists, lawyers, dissidents and heads of state via NSO’s spyware. Amnesty’s forensics (peer-reviewed by Citizen Lab) prove zero-click infections of fully patched iPhones: when the device is targeted, encryption is not enough. Exactly the client-side scanning logic.

    Amnesty · Forensic Methodology Report →

  14. struck down

    Apple announces on-device scanning… then walks it back

    Apple unveils on-device CSAM photo scanning for the iPhone. Researchers and NGOs revolt: it is the infrastructure of generalisable surveillance. December 2022: Apple abandons it, and will later invoke, in an August 2023 letter, a "slippery slope of unintended consequences". The very mechanism Chat Control 2.0 wants to mandate.

    WIRED · Apple kills CSAM scanning →

  15. the creep

    Chat Control 2.0: mandatory scanning

    The Commission proposes the CSAR regulation (COM/2022/209): "detection orders" that can force scanning on every platform, including end-to-end encrypted ones. 2021’s voluntary becomes 2022’s mandatory: scope creep in the literal sense.

    COM/2022/209 →

  16. the creep

    Online Safety Act: the "spy clause"

    The UK grants itself the power to order messengers to scan encrypted content (section 121). "Where technically feasible" is not in the Act: it was the minister’s concession, Lord Parkinson’s statement to the Lords (6 September 2023), after Signal and WhatsApp threatened to leave. The government admits it is not feasible, but keeps the power on the books.

    Online Safety Act 2023 · s.121 →

  17. the creep

    The "temporary" gets its first extension

    Regulation 2024/1307 pushes Chat Control 1.0’s sunset from 3 August 2024 to 3 April 2026. An emergency measure that renews itself is no longer an exception: it is a regime.

    Regulation (EU) 2024/1307 →

  18. the creep

    UK: show ID to use the internet

    The Online Safety Act switches on "highly effective" age verification (ID, credit card, face estimation) for large parts of the web. Proton measures hourly VPN signups jumping over 1,400%; the Lords are already debating limits on VPNs.

    Ofcom · age assurance →

  19. the creep

    The Council moves to delete the sunset clause

    The Council’s trilogue position (doc. 15318/25): simply delete the sunset clause of "voluntary" scanning, making it permanent. The Danish presidency draft contemplated mandatory client-side scanning. In February 2026 the EDPS answers the Commission’s December proposal to extend the derogation to 2028 (COM(2025) 797): substantial degradation of confidentiality, indiscriminate analysis disproportionate.

    EDPS · Opinion 7/2026 →

  20. struck down

    Parliament says no

    The European Parliament rejects extending voluntary scanning to 2028 (228 for, 311 against, 92 abstentions). Consequence: the legal basis expires on 3 April 2026. Citizen pressure and NGO work held the line. For three months.

    European Parliament · 26 March 2026 →

  21. revealed

    The law lapses, the scanning continues

    With the derogation lapsed, the giants that signed the 19 March joint appeal to entrench the regime (Google, Meta, Microsoft, Snap, TikTok) announce they will keep scanning messages, legal basis or not. The admission that "compliance" was scenery.

    The Record · Big Tech vows to keep scanning →

  22. the creep

    The Council resurrects the lapsed text

    Three months after the lapse, the Council adopts its position to reinstate voluntary scanning until 3 April 2028, sent to Parliament at second reading: the procedure where rejection needs an absolute majority (361 of 720), not a majority of votes cast.

    Council of the EU · 2 July 2026 →

  23. struck down

    Rejection fails, but E2EE is carved out

    Urgent procedure passed on 7 July (331/304/11), vote on the 9th: 314 MEPs vote to reject the Council’s position: a simple majority, short of the 361 required. But Parliament then adopts the amendments excluding end-to-end encrypted communications from the scanning regime (369 and 362 votes), and a last attempt to reject the amended position fails too (276/286/30). The amended text returns to the Council, which has about three months (until around 9 October 2026) to accept the amendments (voluntary scanning of non-E2EE services until 3 April 2028) or open conciliation. The Council accepts the amendments on 23 July (full roll calls).

    European Parliament · 9 July 2026 →

  24. the creep

    Chat Control 1.0 reinstated, encryption excluded

    The Council accepts Parliament’s amendments and gives final approval: the derogation allowing voluntary scanning of messages is reinstated until 3 April 2028. End-to-end encrypted communications (WhatsApp, Signal…) are excluded from its scope. The permanent regulation (Chat Control 2.0) is still under negotiation.

    Council of the EU · 23 July 2026 →

Not sure where to start? Take the 12-question quiz →