The European Union’s proposed “Chat Control” legislation has triggered controversy across the tech industry. Secure messaging app Signal is warning that the proposed law, aimed at fighting online child abuse, actually poses a major threat to privacy, data security, and the future of encrypted communications in Europe.
Table of Contents
What Is EU Chat Control?
Chat Control is a nickname for proposed EU regulations that would make it mandatory for all messaging platforms operating in the region to scan photos, links, and videos for illegal child sexual abuse material (CSAM). Unlike standard online scanning, this law demands that scanning occur directly on user devices—including before messages are encrypted for secure delivery.
For encrypted services like Signal, WhatsApp, or Proton, this approach undermines the very core of end-to-end encryption. Encryption works by making sure only the sender and recipient can read a message. If it gets scanned on your phone before encryption, privacy is compromised.
Why Signal and Privacy Advocates Are Alarmed
Signal’s leadership, including Global Affairs VP Udbhav Tiwari and President Meredith Whittaker, say the proposal is more like installing spyware or malware than a legitimate security measure. Mandatory device-side scanning—also known as client-side scanning—grants unprecedented access to personal communications, creating both security risks and ethical concerns.
Tiwari warns, “Apart from the legal bit, that’s exactly how malware works. It compromises your device in order to gain access to information … The idea that a device will scan content before it is encrypted for us negates the very purpose of encryption.”
Signal has said it would rather leave Europe than weaken its encryption or offer a different, less secure version of its app for EU residents.
Encryption on the Chopping Block
Cryptographers, privacy experts, and digital rights groups agree with Signal that client-side scanning makes encryption almost pointless. By reading messages before they are protected, authorities and even malicious actors could access private content, making personal chats vulnerable to abuse, surveillance, or hacking.
European countries like Sweden and the Netherlands also view the proposal as a national security threat, warning that creating exceptions for widespread scanning leaves everyone more vulnerable.
Is There Political Support for the Law?
EU lawmakers are divided, with important votes and debates coming up. Germany, a key swing country, has shifted from opposition to an undecided status ahead of an October 14 decision. If large states like Germany support the law, it could pass, drastically changing how European citizens communicate online.
Despite some attempts to limit the scope, such as excluding government and military accounts, privacy advocates believe this sets a “slippery slope” for future expansion—potentially including scanning for terrorism, intellectual property issues, or political speech.
What Happens if the Law Passes?
If Chat Control becomes law, encrypted services like Signal might exit the EU. Large platforms would face pressure to comply or also withdraw, significantly reducing private communication options. Mandatory scanning could establish precedents for surveillance legislation worldwide, influencing privacy policy even outside Europe.
Why Should You Care?
Chat Control could set a global precedent. If democracies break strong encryption to scan for harmful content, authoritarian states might follow for other purposes. Privacy and free communication are fundamental rights—compromising them for security could have long-term consequences for society.