Jana Stehlíková works as a Director of International Study Programmes at the European Academy Otzenhausen, an independent educational institution in Germany. She obtained a PhD in International Political Relations from the University of Economics in Prague, writing her dissertation on ‘The European Union as a Normative Power: The Extraterritorial Reach of the EU’s Personal Data Protection Standards’, examining the ‘Brussels effect’ and formal and behavioural compliance with EU standards in Norway, Serbia, and Ukraine. Her research focuses mainly on questions related to the recent development of European integration and digital affairs
Abstract
The security–privacy dilemma resurfaced in March 2026 when the Council of the EU and the European Parliament voted on extending the “Chat Control 1.0” Interim Regulation. The proposal prompted intense debate between data protection advocates and those favouring stronger cyber regulation. This paper analyses the controversy and the political and normative tensions underpinning it, and asks how the outcome—the termination of the provisional act after five years without a successor to combat online child sexual abuse—should be interpreted. It contributes to the broader debate on balancing security and privacy in the EU, questioning whether an effective protective tool was dismantled or whether a disproportionate surveillance gap was ultimately closed.
Digital privacy has scored 1.0 to zero at EU level
On Thursday, 26 March 2026, millions of people were scrolling through social media as usual, commenting on content, sending messages or emails to each other, and engaging with their contacts or followers. They were probably unaware that a voting session was taking place simultaneously in the European Parliament (EP), to decide on a controversial proposal that would have had a crucial impact on the privacy of their conversations from 4 April 2026 onwards. The vote concerned was on the future of the Interim Regulation (EU) 2021/1232 (also known as ‘Chat Control 1.0’)1 , which allows online platform providers to voluntarily scan non-encrypted private communications for child sexual abuse material (CSAM). The questions were: Would it be extended again despite conflicting with the ‘ePrivacy Directive’ (officially Directive 2002/58/EC), or would it expire by midnight on 3 April? And what about the original proposal to make it permanent legislation, referred to as ‘Chat Control 2.0’, which would give big tech companies such as Meta and Microsoft an unprecedented green light to monitor private conversations?
In the final vote, Members of the European Parliament (MEPs) rejected the extension of the provisional act. This therefore expired on 3 April without being replaced. You may now be wondering what this means. Should we celebrate the victory of privacy protection and the end of surveillance? After all, this decision confirms the EU’s commitment to safeguarding private spaces and digital rights. Or have we witnessed the creation of a regulatory gap that could undermine efforts to detect and prevent CSAM on online platforms?
The negotiations and the European Parliament’s final vote invite further analysis, particularly in the context of the Council of the EU’s anticipated position, at a time when several EU member states are introducing stricter social media regulation and agebased access restrictions. These recent developments highlight the continued relevance of the ‘Nothing to Hide’ narrative in shaping attitudes towards digital surveillance. However, they also raise concerns that such measures could have significant implications for privacy and fundamental rights by opening a regulatory ‘Pandora’s box’.
The well-known EU dilemma of security versus privacy
To answer the raised questions, we must take a step back and analyse the Interim Regulation, considering the benefits it brought during its five years in force, as well as the price paid for them, particularly within the broader EU privacy regulatory context. The security versus privacy dilemma is nothing new– it has been under discussion many times and, in many contexts,2 including with regard to digital privacy and cybersecurity.
Let’s focus on our particular case. In December 2025, the EC had to raise the issue of how to further proceed with ‘Chat Control 1.0’ with the Council of the EU and the European Parliament. This regulation allowed providers of certain communication services, such as social media platforms, to scan and analyse content for the purpose of detecting online CSAM, and removing such material immediately. The Regulation’s objective is laudable, and the benefits were clearly outlined by Swedish Home Affairs Commissioner Ylva Johansson when she introduced the proposal in 2021.
At the time, the regulation proposal received the necessary backing from both the Council of the EU and the European Parliament as an interim measure in response to the heightened risk of online sexual abuse during the Covid-19 pandemic, when much of the world’s activity moved online. The legislation also aimed to encourage providers - primarily overseas tech giants such as Meta and Google - to cooperate with the authorities and play an active role in safeguarding vulnerable members of society. At least, that was what the EC, represented by Ms Johansson, had hoped for.
However, it was intended as an interim measure only, pending the adoption of a long-term legal framework to address child sexual abuse at the EU level. The EC emphasised this to the co-legislative bodies in order to gain their support, given that Chat Control 1.0 clearly conflicted with the EU’s established legal framework for privacy policies, as set out in Directive 2002/58/EC (‘the ePrivacy Directive’) and Regulation (EU) 2016/679 (‘the General Data Protection Regulation’, or GDPR). The conflict was particularly apparent in relation to the necessity and proportionality of automatically analysing all text-based communications.
Failure to present the anticipated long-term legal framework in a timely manner led to an initial extension of the legal force of the interim ‘Chat Control 1.0’ legislation, which had been set to expire on 3 April 2026. However, even this extended period proved insufficient for the European Commission to develop a comprehensive long-term strategy to combat CSAM. Consequently, in an effort to address the regulatory gap, the Commission proposed a further extension, alongside plans to make the original Interim Regulation permanent (commonly referred to as ‘Chat Control 2.0’). This approach, however, was not endorsed by MEPs, who did not accept the premise that an imperfect measure was preferable to no framework at all. The proposal was ultimately rejected by the European Parliament in a closely contested vote on 26 March.3
Tough Trilogue Disputes: When Surveillance Opponents Clash with Security Advocates
Those who expected the negotiations to be rather routine and predictable may have been surprised. During the first round of negotiations between the Council of the EU and the Parliament, several MEPs emphasised their readiness to advocate strongly for privacy and data protection, thereby reinforcing the broader tendency within Parliament to align more closely with a privacy-protection perspective than with a ‘Nothing to Hide’ approach. For example, Birgit Sippel (S&D/DEU), while recognising the responsibility to address the horrific crime of child sexual abuse, emphasised in her statement the importance of safeguarding fundamental rights for all.4, 5
The EU governments have indicated their willingness to compromise on digital privacy for the sake of online security, especially when it comes to protecting children. Thus, tough negotiations and carefully balanced compromises were required to give the legislation a realistic prospect of adoption by both legislative bodies during the trilogue process.
Several crucial amendments proposed by the MEP to the original Commission proposal were negotiated during the trilogue sessions. Firstly, the European Parliament rejected the proposed two-year extension (until 3 April 2028) and instead proposed a oneyear extension.6 The next amendment aimed to strengthen the focus on data processing in line with the proportionality principle, by (1) restricting automated analysis to known online child sexual abuse material, (2) limiting the detection of the solicitation of children and (3) not allowing the processing of interpersonal communications for which end-to-end encryption has been, is, or will be used.7 The third proposed amendment suggested limiting the users whose communications could be scanned to those representing a higher risk, such as individual users, specific groups of users or subscribers to a specific communication channel, who had been identified by the competent judicial authority.8 Ultimately, the scope of regulation should have been limited to instances where the provider has received a specific report or notification regarding child sexual abuse from a user, a trusted flagger, or an organisation acting in the public interest concerning a particular communication.9
As the Council of the EU rejected the EP-approved amendments to the original EC proposal, the final vote on the proposal was also rejected in a neck-andneck vote (36 % in favour (228 votes); 49 % against (311 votes); 15 % abstentions (92)).10 As a direct consequence, the Interim Regulation expired on 3 April 2026 without the promised replacement by the longterm legal framework to address child sexual abuse at the EU level.
No Fear of Legal Limbo
Following the failure of the legislation, initial critiques highlighted the vulnerability of victims and the unnecessary risk posed to children by limitations on national authorities’ ability to protect them, which would be exacerbated by the loss of access to automated analysis of all text-based communications. According to advocates of the implementation of ‘Chat Control 2.0’ or at least the prolongation of the legal effects of the Interim Regulation, these limitations could indirectly empower perpetrators by hindering disclosure.
Many of these arguments had already been challenged prior to the final vote on the proposal. First, targeted telecommunications surveillance based on concrete suspicion and authorised by a judicial warrant remained fully available after 3 April 2026. Moreover, statistical evidence - for example from Ireland - suggests that the inaccuracy rate of reported cases is relatively high, indicating current limitations in the technical capacity required to render such measures sufficiently reliable and proportionate.11 This evidence lends support to the opinion of the European Data Protection Supervisor on ‘Chat Control 1.0’, particularly with regard to the necessity and proportionality of the automated analysis of all text-based communications.12
Rather than making ‘Chat Control 1.0’ a permanent regulation, terminating it primarily prevents social media platform providers — many of which are registered outside the EU — from scanning and analysing users’ communications in an unnecessary and disproportionate manner.13 Even if you have nothing to hide, there is no valid reason why your conversations should be the subject of automated analysis for whatever reason the provider may have.
Conclusion
The insurmountable obstacles to reaching a compromise between the European Parliament and the Council of the EU on balancing privacy protection with security on online platforms came as no surprise. The two legal bodies have been in conflict for a long time over ‘not if, but how’ to secure online platforms.
Given recent developments in France, Denmark, and Ireland - where national governments have proposed bans or age restrictions (typically 15 or 16) - the Council’s position was to be expected. The European Parliament, by contrast, has consistently prioritised strengthening the rights of EU citizens and their control over privacy and personal data. This divergence reflects a deeper structural tension between a security-oriented regulatory logic and a rights-based digital governance approach. Unless a shared normative framework emerges, future negotiations are likely to reproduce the same deadlock, potentially shifting meaningful regulatory outcomes to the national level.
What lessons have been learned from presenting the Interim Regulation as a proposal for permanent regulation and from the trilogue process? In this particular case, the outcome can be interpreted as a victory for privacy, though this does not necessarily translate into a broader normative success, as a comprehensive legal framework to address child sexual abuse in the digital sphere remains absent. Nevertheless, it is evident that social media platforms and their lobbyists have actively campaigned to prevent the loss of access to automated analysis of user communications, framed under the ostensibly noble objective of protecting child victims of sexual abuse - albeit ultimately without success.
What can we expect or hope for next? Policymakers must find solutions that will effectively protect children from online predators. ‘Chat Control 2.0’ was not the right solution. However, this does not diminish the importance of ensuring a safe online environment; on the contrary, it is arguably more important than ever. The focus of future discussions should therefore be on what is truly at stake, and on the societal and legal costs that different approaches entail. The ‘nothing to hide’ principle has not been adopted as a guiding standard within the EU’s legal framework.
References
1 F. Light , Protesters clash with Georgian police over government’s EU application delay, Reuters (29 Nov. 2024)
2 Georgian Public Broadcaster, PM Kobakhidze describes EU Ambassador as tragic figure not allowed for his ambassadorship (23 Jun. 2025)
3 L. Kunchulia, Georgian Dream Takes On The ‘Global War Party’, Radio Free Europe Radio Liberty (18 May 2024)
4 Georgia Today, PM: Despite two foreign-funded revolutionary attempts, we have saved our country from Ukrainization and maintained peace (1 Dec. 2024)
5 J. Dowsett, Slapped With Sanctions, Georgian Oligarch Ivanishvili Brings Assets Home, OCCRP (14 Feb. 2025)
6 Interpressnews, Maria Zakharova: Tbilisi has made a firm choice in favor of restoring the country’s sovereignty - we are ready to deepen Russia-Georgia ties, and we do so sincerely (10 Jun. 2026)
7 YouTube, Mariam Lashkhi: NGO Nation - Who Speaks for Georgia? (15 Jun. 2025)
8 Civil Georgia, PM Appoints Special Envoy for Relations with Russia (1 Nov. 2012)
9 Eurasianet, Georgian government’s ‘deep state’ bromance with Trump remains unrequited (19 May 2025)
10 Civil Georgia, Kobakhidze Says ‘Global War Party’ Uses EU Visa Threat to Open Second Front in Georgia (17 Jul. 2025)
11 Interpressnews, Irakli Kobakhidze: Our history, our culture, our identity are all European, but the European bureaucracy must recognize our right to sovereignty and democracy - being pro-European does not mean being anti-Georgian (29 May 2025)
12 Sova, Maria Zakharova: Georgia Has Chosen a Multi-Vector Policy (29 May 2026)
13 Civil Georgia, UN General Assembly Passes Georgia IDP Resolution (4 Jun. 2025)
14 Interpressnews, Prime Minister’s report: Georgia continues multi-vector cooperation and harmonization with the European Union in foreign policy (2 Jun. 2026)
15 Civil Georgia, EU’s Kallas Says European Security Interest Is for Russian Troops Not to Be in Georgia, Moldova (28 May 2026)
16 International Republican Institute, IRI Georgia Poll Shows Political Threat from Russia, Concerns with the Presence of Russian Citizens, High Political Polarization (15 Nov. 2023)
17 Formula News, Macharashvili: It won’t make much difference whether a married man travels abroad with a visa or visa-free (4 Dec. 2025)
18 MID Russia, Briefing by Foreign Ministry Spokeswoman Maria Zakharova (7 Feb. 2024)
19 Civil Georgia, Official Results of 2024 Vote: What They Show (27 Oct. 2024)
20 International Republican Institute, IRI Georgia Poll: Georgians are Less Optimistic, Continue to Desire Deeper Ties with the West, Wary of Perceived Russian Threat, Concerned Regarding Economy (31 Mar. 2015)
21 National Democratic Institute, NDI poll: Georgians increasingly support EU and Euro-Atlantic aspirations; view Russia as a threat (12 May 2027)
22 National Democratic Institute, NDI Poll: EU and NATO Support Remains Strong but Threatened by Russia and Perception of Harm to Culture and Values; Armenian and Azeri Communities Respond Differently to NATO Membership (20 May, 2019)
23 National Democratic Institute, Taking Georgians’ pulse (Mar. 2022)
24 Interpressnews, According to EU NEIGHBOURS EAST survey, 71% of respondents support Georgia’s accession to the EU, 79% believe that EU membership will bring more advantages, and 51% believe that the EU has hidden interests (19 Jun. 2026)
25 Georgian Public Broadcaster, IRI poll: 68% of Georgians support joining EU, 77% – NATO membership (2 Aug. 2021)
26 International Republican Institute, IRI Releases Expanded Nationwide Survey of Georgian Public Opinion (5 Jan 2012)
27 Supra n.25
28 EU in Georgia, Facts and Figures (2026)
29 U.S. Department of State, U.S. security assistance to Georgia (2022).
30 Civil Georgia, Exit Polls Show Conflicting Results as Polls Close (26 Oct. 2024)
31 Interpressnews, NDI poll: 24% of respondents say that Georgian Dream is closest to their views, 9% name National Movement, 8% say that none of the parties is closest to their views (27 Jan. 2022)