What Happened in July

On March 26, 2026, the European Parliament rejected the extension of the ePrivacy derogation (Regulation 2021/1232 — "Chat Control 1.0") by 311 votes to 228, with 92 abstentions. The derogation lapsed on April 3. For the first time since 2021, platforms scanning private messages in the EU had no specific legal basis.

That lasted three months.

On July 9, a motion to reject the extension failed to reach the absolute majority needed in second reading — 314 votes against, short of the 361 required. The derogation is back in force, now with an expiry of April 3, 2028. It covers voluntary scanning of communications for known CSAM — material already in identification databases. Instagram DMs, Discord, Snapchat, Xbox chat, Gmail, iCloud Mail: all inside the perimeter. An exemption for end-to-end encrypted traffic was adopted, though Patrick Breyer called it symbolic, because platforms don't scan E2EE traffic anyway.

How a defeated bill came back: Parliament President Roberta Metsola invited the Council to proceed with its first-reading position on a law her own chamber had voted down — a June 22 note from the Cyprus presidency asked capitals to consider the invitation, "even if this would be without precedent in the present circumstances." It was. MEPs working on the file described it as going over their heads. Markéta Gregorová: "extremely surprised... unacceptable." Hilde Vautmans: "Parliament has rejected it twice, and that will not change." Three weeks later it passed anyway, because a rejection motion that fails to hit an absolute majority is, procedurally, an approval.

Why the Voluntary Part Is Not the Harmless Part

The July vote authorizes platforms to scan voluntarily. Voluntary for the platform is not voluntary for the person whose messages are scanned. And the record of the last five years is documented:

  • Per the European Commission's own figures, scanning of private chats accounted for just 36% of abuse reports in 2024. Most reports come from public posts and cloud storage.
  • Germany's BKA found 48% of alerts are not criminally relevant, and 40% of resulting investigations target minors themselves.
  • 99% of Meta's reports involve previously known material doing nothing about active abuse.
  • The Commission admits there is no evidence that suspicionless scanning of private messages has increased convictions or rescued more children.
  • The enforcement tools that actually work — court-ordered wiretaps, user reports, scanning of public platforms and cloud storage — were never at risk.

The deeper problem is precedent. Every extension normalizes the idea that private message content is a thing platforms scan as a matter of routine, and every normalized scan becomes the infrastructure a mandatory regime can be switched onto. That's not an argument from my side — it's the structure of the negotiation. The permanent Child Sexual Abuse Regulation is still in trilogue, and the Council's version still wants detection obligations. EFF's warning from April stands: if platforms are expected to adopt scanning as part of compliance, it stops being voluntary in any meaningful sense. The other thing to watch for in September is age verification hardening into a default requirement — an identity checkpoint in front of every communication tool.

The Pattern

This proposal has been declared dead more times than any law in recent memory. October 2025: vote scrapped amid opposition. March 2026: trialogue collapses, extension rejected 311-228. April 2026: derogation lapses. July 2026: revived by presidential fiat, passed. September 2026: negotiations on the permanent regulation resume.

Zombie legislation, EFF called it. The lesson isn't that campaigning is useless — the March rejection and the 2022 Austrian binding resolution happened because of sustained public pressure. The lesson is that no vote is final, and the pressure has to be re-applied every cycle, indefinitely, because the people who want the scanning power never stop wanting it.

Which means the strategy of relying on parliamentarians is a maintenance contract, not a solution. You can hold this line for five years and lose it in one procedural maneuver. That's what July demonstrated.

What Doesn't Depend on the Vote

Here in July's immediate aftermath: a Matrix homeserver run by a fire hall is not an interpersonal communications service covered by the derogation. There is no platform account to deputize, no provider scanner to legalize, no terms of service that changed overnight. The messages live on hardware the community owns, in a jurisdiction the community knows, running code the community can read. Same for a town office's Nextcloud Talk instance, a co-op's XMPP server, a Signal group is not this — Signal is a US service provider, inside the perimeter as a service, even though its E2EE protects content (for now — the Council's 2.0 history included client-side scanning proposals aimed precisely at breaking that).

This is the same argument this site made about BitChat and India's takedown order: the architecture is the offense — and its mirror image, the architecture is the defense. A takedown notice can't remove a protocol nobody controls. A scanning mandate can't reach a server nobody else operates. India's I4C targeted BitChat's design because the design defeated them. The same property that makes federated, self-hosted systems resistant to censorship makes them resistant to scanning mandates. It's one property: no central choke point to regulate.

When your community runs its own Matrix homeserver — Continuwuity on 256 MB of RAM, a single binary a volunteer sysadmin can explain in an afternoon — you're not just saving licensing fees. You're placing your members' private communications outside every perimeter this legislation draws, permanently, regardless of how the September trilogue ends. When a community stays on Discord or Gmail instead, every member's DMs are inside a scanning perimeter that was expanded this month by 314 votes and can be expanded again in September by a smaller one.

What to Watch in September

The trilogue on the permanent CSAR resumes with three specific failure modes:

  1. "Voluntary" obligations hardening into compliance expectations. Watch whether risk-assessment obligations under the regulation effectively force platforms to scan to demonstrate good faith. Voluntary on paper, mandatory in procurement.
  2. Age verification as a de facto ID requirement. Every communication tool adding identity gates to satisfy a child-protection rule is the end of anonymous communication — whistleblowers, abuse survivors, and organizers in hostile jurisdictions lose first.
  3. Client-side scanning re-entering through a back door. Member states publicly dropped forced scanning of encrypted messages. Watch whether "voluntary measures" plus liability pressure reconstructs it.

The vote in September doesn't need your optimism. It needs your letters — and, running quietly underneath, your infrastructure. Watch the trilogue. Run the homeserver regardless. One of those is a weekly news item. The other is the thing the news item can never take away.