The European Parliament's recent vote has once again brought the EU's Chat Control debate into the spotlight. By extending the legal framework that allows providers to voluntarily scan certain non-end-to-end encrypted communications for child sexual abuse material (CSAM), lawmakers have ensured these practices can continue while negotiations on a permanent framework move forward.
| What is Chat Control? Chat Control refers to EU legislative proposals and temporary measures that allow or potentially require communication service providers to detect and report child sexual abuse material (CSAM) in digital communications. The debate centres on how to balance child protection with privacy, encryption, and the confidentiality of digital communications. |
This extension — often referred to as Chat Control 1.0 — does not require providers of end-to-end encrypted (E2EE) services to scan message content or weaken encryption. Those questions remain part of the ongoing negotiations around the proposed permanent legislation, commonly referred to as Chat Control 2.0.
What the recent vote means for organisations
Following the Parliament's vote, the voluntary scanning of communications by major technology providers such as Google, Microsoft, LinkedIn, and Meta will continue to have a legal basis under EU law for services covered by the current regulation.
Many organisations use Microsoft Teams, Google Workspace, or LinkedIn Messaging to collaborate with colleagues, customers, and partners. Communications flowing through certain services provided by these companies may already be processed by automated systems designed to detect certain types of content. Depending on the provider, reports generated by these systems may be submitted to external organisations outside the European Union, including the U.S.-based National Center for Missing & Exploited Children (NCMEC), as required under applicable laws.
Beyond privacy: governance, risk, and data sovereignty
For organisations handling confidential business information, this raises important governance questions. Sensitive communications may include legal advice, merger and acquisition discussions, compliance investigations, intellectual property, financial information or customer data. Security and compliance teams therefore need to understand not only where their data is stored, but also how it is processed, under which legal frameworks, and whether automated scanning forms part of that processing.
This is about more than privacy. It is about maintaining control over sensitive corporate information throughout its lifecycle. It also touches on a broader issue that is becoming increasingly important for European organisations: data sovereignty.
Understanding who can technically access your data, how it may be processed, and which legal jurisdictions can influence that processing is no longer just an IT concern — it is a strategic governance decision. Organisations pursuing greater digital sovereignty should evaluate not only where their data resides, but also who can technically access it and under which legal obligations it may be processed.
Where should confidential business conversations take place?
As organisations continue to strengthen their cybersecurity posture, they should also review where their most confidential conversations take place. Not every discussion carries the same level of sensitivity. Routine collaboration may be perfectly suited to mainstream productivity platforms, but communications involving highly confidential information deserve stronger protections designed to ensure that only the intended participants can access the content.
One way to reduce these risks is to keep sensitive discussions within end-to-end encrypted collaboration environments. Tresorit Engage helps organisations do exactly that. Its end-to-end encrypted data rooms provide a secure space for working with customers, partners, and other stakeholders, ensuring that only the intended participants can access both shared files and the conversations around them.
With the Pages feature, communication can happen directly within the Engage room instead of across separate messaging or collaboration tools. Teams can capture meeting notes, client discussions, project updates, key decisions, and documentation alongside the files they relate to, keeping everything organised, in context, and protected by end-to-end encryption.
Preparing for an uncertain regulatory future
The recent vote does not mark the end of the Chat Control debate — it simply extends the current framework while discussions on a permanent regime continue. Whether future legislation expands scanning obligations or preserves the current exemption for end-to-end encrypted services remains to be seen.
Regardless of how the regulatory landscape evolves, organisations should not wait to reassess where their most sensitive conversations take place. The most effective way to protect confidential communications is to ensure that only the intended participants — not service providers, automated scanning systems, or anyone else — can ever access them.
Katalin Jakucs
View more articles from this author



