EU's new law will let tech companies scan their platforms for child sexual abuse material for the next three years without fear of violating EU's privacy laws
The European Parliament on Tuesday approved a controversial law that would allow digital companies to detect and report child sexual abuse …
Context & Ripple Effects
This vote is a stopgap against a deadline the Parliament itself set: [[a:960664|a law taking effect December 20 that restricts monitoring of email, messaging, and other services]] would have criminalized the very CSAM scanning platforms already perform voluntarily. The three-year derogation keeps that detection work legal while Brussels works out permanent rules.
It also extends a pattern established months earlier by [[a:965790|the law forcing internet companies to remove flagged terrorist content within one hour of notification]] — the EU is steadily converting platforms into obliged detectors and removers of unlawful content, now with an explicit privacy carve-out.
First-order effects
- Platforms running voluntary CSAM detection on email and messaging get a guaranteed legal shield through roughly mid-decade, removing the compliance risk that the December monitoring restrictions would otherwise have created.
- The European Parliament hands itself a built-in review point: when the three years lapse, the interim permission expires unless replaced by standing legislation.
Second-order effects
- The sunset clause turns the interim period into a negotiating window — member states and MEPs must converge on a permanent child-protection framework or watch legal cover for scanning lapse, giving safety advocates leverage over privacy objections.
- Messaging services that market encryption face sharpened pressure during those three years, since the same legal logic that shields scanning here is the argument for mandating it there.
Third-order effects
- If the pattern holds alongside the terrorist-content takedown regime, EU platform governance settles into a structure where detection obligations for public-safety purposes are written directly into law, and privacy rules acquire recurring public-interest exemptions rather than absolutes.
- A successful three-year derogation becomes precedent other jurisdictions can copy: time-boxed legal immunity for scanning as a way to defuse the privacy-versus-child-safety standoff.
The trend: The EU is bridging from blanket privacy restrictions toward permanent, legally mandated platform scanning duties, using temporary derogations to keep detection alive while the permanent framework is negotiated.