In recent years, discussions have been ongoing within the institutions of the European Union regarding the so-called “Chat Control” Regulation (hereinafter – the Regulation). Its proposal was presented by the European Commission on 11 May 2022 (Proposal for a Regulation laying down rules to prevent and combat child sexual abuse, COM(2022) 209).

The objective of the Regulation is to strengthen the fight against the dissemination of child sexual abuse (CSA) material online by mandating electronic communications service providers to perform automated checks on messages, photos, and other data sent by users. Nevertheless, this draft legislative act has already sparked significant legal and political debate.

A pivotal moment is approaching – on 14 October 2025, a vote will be held in the Council of the EU aimed at adopting a general approach on the Regulation. Until now, this stage has been the primary obstacle, as the draft was stalled by a so-called “blocking minority” of Member States. If a qualified majority is reached this time, it would pave the way for negotiations with the European Parliament.

At first glance, the Regulation appears to pursue an indisputably important goal – preventing child sexual abuse online. However, due to the measures chosen, it has been dubbed “Chat Control” by the public. This informal name highlights not so much the aim of child protection, but the operating mechanism itself – the scanning of private conversations, covering not only messaging apps but also email and cloud storage. This is precisely what causes the most debate: are such measures, though based on a vital objective, proportionate and legally compatible with the fundamental rights to private life and the confidentiality of correspondence? Will their implementation not create more risks than benefits?

The mechanism of “Chat Control”
The “Chat Control” Regulation stipulates that electronic communications service providers (e.g., WhatsApp, Messenger, Gmail, Outlook, Google Drive, Dropbox) would be obliged to check individuals’ correspondence and identify and report messages that may contain child sexual abuse material, as well as attempts to establish contact with children (grooming).

Under the proposed model, all electronic communications service providers would first be subject to a mandatory risk assessment. Upon identifying a significant risk, a national authority could issue an obligatory detection order for such providers to implement automated content detection tools – and according to the current draft of the Regulation, prior judicial authorisation would not be required for this.

Upon receiving such an order, providers would be required to apply automated tools that detect the nature of prohibited content. If suspicious content is detected, the provider would have to report it to a newly established EU body – the “EU Centre to prevent and combat child sexual abuse.” This body would then transfer the information to the relevant national law enforcement authorities.

Thus, in short, the “Chat Control” Regulation would mean that every message, photo, document, and call within a user’s correspondence could become an object of mass surveillance – something that has not been provided for at the EU level until now. In this way, the fight against the dissemination of child sexual abuse material would expand into a constant check of every citizen’s correspondence and data.

Automated message checking would be carried out using hashing and hash matching technologies, artificial intelligence algorithms, and other tools. Although the initial text of the Regulation and its terminology are unclearly detailed, message scanning might potentially involve metadata analysis (e.g., sender/receiver, frequency, etc.) to identify suspicious behaviour. This would indirectly imply the accumulation of certain databases.

Potential risks
While the goal of combating child sexual abuse online is indisputably important and viewed positively, the proposed measures must be analysed from the perspective of proportionality: whether they infringe upon fundamental rights, compromise technological security, or create grounds for abuse.

The implementation of the “Chat Control” Regulation raises serious questions regarding compatibility with the Charter of Fundamental Rights of the European Union (hereinafter – the Charter) and the European Convention on Human Rights (ECHR).

Firstly, the automated checking of private messages may violate the right to private life, as the constant and systematic review of an individual’s communication constitutes mass surveillance, even in the absence of individual suspicion. Such message scanning may also violate the confidentiality of correspondence and an individual’s right to data protection, as large-scale data analysis and transfer to third parties would mean systematic data collection, often without clearly defined control by the data subject or effective legal remedies.

The case law of the European Court of Human Rights (ECtHR) has repeatedly analysed cases evaluating whether the monitoring of electronic communications is compatible with the Convention and fundamental human rights.

For example, in the case of Klass and Others v. Germany (1978), the ECtHR recognised that secret surveillance of communications may be necessary to ensure national security, but such a measure must be accompanied by adequate safeguards against abuse. In the case of Big Brother Watch and Others v. the United Kingdom (2021, Grand Chamber), the ECtHR stated that the bulk interception of communications data does not in itself contradict the Convention, but strict safeguards must be established (limited scope, independent oversight, data destruction rules).

These rulings demonstrate that any measures of a mass nature aimed at covering all user messages pose a significant risk to the individual rights enshrined in the Convention. They also show that broad surveillance is only possible if strict control mechanisms exist and it is ensured that the measure is not excessive.

Potential to increase public vulnerability
Another major risk is the checking of content in encrypted messaging channels (e.g., WhatsApp, Signal). The current draft of the Regulation provides for the possibility of obliging service providers to implement measures that allow for the detection of illegal content even within an “end-to-end” (E2EE) encryption environment. This would mean the implementation of so-called “client-side scanning” mechanisms, where content is scanned before encryption or immediately after decryption on the user’s device.

According to security specialists, such a model fundamentally weakens the reliability of encryption, as it creates the possibility for unauthorised access to user data. This not only contradicts the logic of digital security but also creates opportunities for third parties, including cybercriminals or hostile state structures, to abuse such technologies. Thus, a measure aimed at protecting children could, paradoxically, increase the general vulnerability of society.

Another crucial aspect is the identification of suspicious messages. Information technologies, including artificial intelligence, are not immune to errors – AI may incorrectly identify content as potentially prohibited (so-called “false positives”) and classify that individual as a suspect, resulting in reputational, legal, or personal consequences.

Finally, the integrity of the service providers themselves must be evaluated – whether the “legalisation” of such measures will create an opportunity to use the collected data beyond its original purpose. The infrastructure itself (scanning algorithms, databases, access mechanisms for national authorities) could be adapted not only for the fight against child sexual abuse material but also for other, less proportionate purposes.

By imposing an obligation on service providers to systematically collect and analyse data, the risk increases that this data could be used for commercial purposes, such as advertising or user behaviour analysis, thereby violating the data subjects’ expectations of confidentiality and personal data protection.

No less important is the issue of security – the technical content scanning measures applied must meet a high level of cybersecurity; otherwise, there is a danger of data leaks or illegal use, creating a centralised flow of sensitive information.

In summary, the “Chat Control” Regulation aims to address an exceptionally important problem – the fight against the dissemination of child sexual abuse material online. The proposed measures, including the automated checking of user messages, photos, and documents, should help identify and prevent illegal content and ensure a faster response for law enforcement authorities.

However, the proposal for the Regulation raises numerous legal, technological, and ethical questions. Therefore, while “Chat Control” has a clear and important goal, the principles of its implementation must be thoroughly evaluated according to the criteria of proportionality, legality, and security. The protection of children’s rights and the human right to privacy cannot be pitted against each other but should be viewed as compatible priorities.

Prepared by Brigida Bacienė, Senior Associate, and Arnas Sabalys, Lawyer, at the law firm Glimstedt.

Presidential Business Forum on Resilience Brings Nearly 150 Leaders Together in New York City
2026-09-224 min

Presidential Business Forum on Resilience Brings Nearly 150 Leaders Together in New York City

Agnė MeiduvienėAgnė Meiduvienė
BACC-organised Presidential Business Forum to take place in New York: focus on energy security and resilience
2026-09-182 min

BACC-organised Presidential Business Forum to take place in New York: focus on energy security and resilience

Agnė MeiduvienėAgnė Meiduvienė
Glimstedt has advised sellers of Šiaurės Licėjus in their transaction with Tesonet and INVL Fund
2026-08-132 min

Glimstedt has advised sellers of Šiaurės Licėjus in their transaction with Tesonet and INVL Fund

Agnė MeiduvienėAgnė Meiduvienė