MOZOM-analyse
The EU-Brussels CREEP: child protection or mass surveillance through the back door?

- Source
- Europees Parlement, Raad van de EU, EUR-Lex, Europese Commissie, EDPS/EDPB, Euronews, CDT, Patrick Breyer en kinderveiligheidsorganisaties
- MOZOM headline
- The EU-Brussels CREEP: child protection or mass surveillance through the back door?
- Original headline
- European Parliament allows temporary ePrivacy exception for voluntary CSAM detection to continue after rejection did not reach an absolute majority
- Author
- the MOZOM.nl editorial team
- Date
- 18 juli 2026 om 06:24
- Subject
- MOZOM analyzes Chat Control, the temporary ePrivacy exception and the permanent EU proposal on online child abuse as a question of power: does this protect children, or does Brussels normalize a scanning infrastructure that can be expanded later?
Summary of the original report
In July 2026, the European Parliament voted on the temporary ePrivacy exception that allows providers to voluntarily scan for CSAM, or Child Sexual Abuse Material. A majority of voting MEPs wanted to reject the Council line: 314 voted in favor of rejection, 276 against and 17 abstained. Yet that was not enough, because formal rejection at this stage required an absolute majority of all MEPs: 360 votes. This allowed the temporary arrangement to continue. Critics call that Chat Control through the back door. Proponents point to real victims, reports to investigation services and the risk that detection will be lost. The legal core remains: if end-to-end encrypted communication is not really exempted, the system technically shifts towards client-side scanning, i.e. scanning on the device before a message is encrypted. Then the encryption is not broken, but the private message has already been viewed before it is locked.
Own source research
MOZOM has put the timeline side by side. In 2021, Regulation (EU) 2021/1232 was introduced, a temporary exception to ePrivacy for voluntary detection of online child sexual abuse. In 2022, the European Commission presented COM(2022) 209, the permanent CSAM proposal with detection orders. In 2023, the European Parliament sought to limit the most serious scanning risks and strengthen protection for end-to-end encrypted communications. The dossier returned to the Council several times in 2024 and 2025, with broad criticism of scanning, encryption and client-side scanning leading to postponements and compromises. On November 26, 2025, the Council reached a position on an amended permanent law. In July 2026, the temporary derogation went through the process again. So there were not five identical votes, but at least five decisive political moments in which the same scanning issue was put on the table again. The striking thing about July 2026 is the procedure: most voting members wanted to reject the Council line, but because there were not 360 votes against, the process continued. That moment just before the summer period was procedurally favorable for the Council line. No hard evidence has been found in public sources for deliberate tactical planning; the effect was there.
Striking in this message
The “child protection” frame is powerful because no one can be serious about abusive material. As a result, the debate shifts quickly: those who are against scanning seem to be against protection. But the real question is not whether children should be protected. The real question is whether protection can normalize a technical scanning layer that can later be used for other categories.
Less visible context
What is less visible is that client-side scanning crosses a different line than regular platform moderation. With classic moderation, a platform looks at public posts or content that is already on its server. With client-side scanning, software on the device itself looks at the message before encrypting it. This affects the confidentiality of communication at the source. Once such a system is standard in messaging apps, phones, tablets, laptops and cloud systems, a future government or legislature can expand the categories. Today CSAM; terrorism tomorrow; then hate speech, extremism, disinformation, copyright, prohibited trade or 'socially harmful content'. In a darker scenario, the same infrastructure can be deployed against political threats, gatherings, preparation of demonstrations or networks labeled as anti-democratic. That is exactly the risk of CREEP: not the promise of today, but the power that will be technically ready tomorrow.
Possible message behind the news
The visible message from Brussels is child protection. The critical MOZOM reading is that the same route sets a precedent: once private messages are allowed to pass through scan gates, the next political battle will no longer be whether such scan gates exist, but which categories should go through them.
Neutral conclusion
The conclusion: Chat Control is legally and socially newsworthy because it is not just about child abuse, but about the architecture of digital power. The July 2026 vote shows how a majority of voting MEPs can still be insufficient when the procedure requires an absolute majority of all members. That is legal within the rules, but politically sensitive. The dossier also shows how often the same scanning issue recurs until a compromise, extension or procedural opening becomes possible. The firm claim that Brussels already wants to eavesdrop on political opponents has not been proven. On the other hand, the warning that a scanning infrastructure once built in can later be expanded to include terrorism, hate speech, extremism, disinformation, copyright, prohibited trade, protest preparation or political security labels is real. That is precisely why the line must be drawn now: child protection must not become a blank gateway to mass surveillance through the side door.
Source:
- Europees Parlement: stemming over beperktere ePrivacy-derogatie
- Raad van de EU: tijdelijke maatregel tegen online seksueel kindermisbruik herstellen
- Raad van de EU: positie over permanente CSAM-wet, 26 november 2025
- EUR-Lex: Regulation (EU) 2021/1232, tijdelijke ePrivacy-derogatie
- Europese Commissie: COM(2022) 209, voorstel CSAM-verordening
- EDPB/EDPS: Joint Opinion 04/2022 over het CSAM-voorstel
- EDPS: Opinion 7/2026 over verlenging van Regulation 2021/1232
- Euronews: Chat Control 1.0 through the back door
- Center for Democracy & Technology: kritiek op mass scanning en procedure
- Patrick Breyer: kritische tijdlijn en stemanalyse Chat Control