Law / European Union

Temporary Derogation for Detecting Online Child Sexual Abuse in Messaging Services

Regulation (EU) 2026/1881

In force since .

An interception and recording consent rule binding private bodies.

Private right of action
Yes
Obligation class
DPIA, Governance, Disclosure, Reporting, Retention

As of .

What it requires

  • Regulation (EU) 2026/1881 entered into force on the third day after its publication on , which is , and applies until (Article 11). It reaches you if you are a provider of a number-independent interpersonal communications service (Article 2, point (1)) and you choose to use specific technologies to detect online child sexual abuse on your service, report it and remove online child sexual abuse material from your service (Article 1(1)).
  • You may process personal and other data in connection with the service without Article 5(1) and Article 6(1) of Directive 2002/58/EC applying to the confidentiality of the communications only where every condition of Article 3(1) is met. The Regulation does not apply to the scanning of audio communications (Article 1(2)) or to interpersonal communications to which end-to-end encryption is, has been or will be applied (Article 1(3), Article 3(1), point (a)(ii)).
  • Limit the processing to what is strictly necessary for the use of specific technology for the sole purpose of detecting and removing online child sexual abuse material and reporting it to law enforcement authorities and to organizations acting in the public interest against child sexual abuse, and of detecting solicitation of children and reporting it, keep it proportionate and limited to the technologies you use for those purposes, and limit it to the content data and related traffic data that are strictly necessary (Article 3(1), point (a)).
  • Use technologies that are in accordance with the state of the art in the industry and the least privacy-intrusive, including with regard to data protection by design and by default, and that, to the extent they scan text in communications, are not able to deduce the substance of the content of the communications but are solely able to detect patterns which point to possible online child sexual abuse (Article 3(1), point (b)).
  • Use technologies that are sufficiently reliable in that they limit to the maximum extent possible the rate of errors in detecting content representing online child sexual abuse and, where occasional errors occur, rectify their consequences without delay (Article 3(1), point (e)). Limit the technologies you use to detect patterns of possible solicitation of children to relevant key indicators and objectively identified risk factors such as age difference and the likely involvement of a child in the scanned communication, without prejudice to the right to human review (Article 3(1), point (f)).
  • Conduct a prior data protection impact assessment and a prior consultation procedure under Articles 35 and 36 of Regulation (EU) 2016/679 for any specific technology you use for these purposes (Article 3(1), point (c)). Until this does not apply to a provider that was using a specific technology before without having completed a prior consultation procedure, starts one before and duly cooperates with the competent supervisory authority (Article 3(2)).
  • For new technology, meaning technology used to detect online child sexual abuse material that no provider had used in relation to services provided to users in the Union before , and for technology used to identify possible solicitation of children, report back to the competent authority on the measures you have taken to demonstrate compliance with the written advice the supervisory authority issued under Article 36(2) of Regulation (EU) 2016/679 in the prior consultation (Article 3(1), point (d)). Until that condition does not apply to a provider that was using such a technology before without having completed a prior consultation procedure for it, starts a procedure as referred to in point (d) before and duly cooperates with the competent supervisory authority (Article 3(3)).
  • Establish internal procedures to prevent abuse of, unauthorized access to and unauthorized transfers of personal and other data, and ensure human oversight of and, where necessary, human intervention in the processing (Article 3(1), point (g)(i) and (ii)). Do not report material not previously identified as online child sexual abuse material, or solicitation of children, to law enforcement authorities or to organizations acting in the public interest against child sexual abuse without prior human confirmation (Article 3(1), point (g)(iii)).
  • Establish procedures and redress mechanisms that let users lodge complaints with you within a reasonable timeframe to present their views (Article 3(1), point (g)(iv)). Inform users in a clear, prominent and comprehensible way that you have invoked the derogation from Article 5(1) and Article 6(1) of Directive 2002/58/EC solely for these purposes, of the logic behind the measures you have taken and of the impact on the confidentiality of users' communications, including the possibility that personal data are shared with law enforcement authorities and organizations acting in the public interest against child sexual abuse (Article 3(1), point (g)(v)). Where a user's content has been removed, an account blocked or a service suspended, inform the user of the avenues for seeking redress from you, the possibility of lodging a complaint with a supervisory authority and the right to a judicial remedy (Article 3(1), point (g)(vi)).
  • By and by 31 January every year thereafter, publish and submit to the competent supervisory authority and to the Commission a report on the processing of personal data under the Regulation, with the content Article 3(1), point (g)(vii), lists, provided in writing by means of the standard form the Commission determines by implementing act (the closing subparagraph of Article 3).
  • Store the content data and related traffic data processed for these purposes, and the personal data generated through that processing, in a secure manner and solely for the purposes Article 3(1), point (h), lists once suspected online child sexual abuse has been identified, and no longer than strictly necessary for those purposes and in any event no longer than 12 months from the date of the identification of the suspected online child sexual abuse (Article 3(1), points (h) and (i)).
  • Report every case of a reasoned and verified suspicion of online child sexual abuse without delay to the competent national law enforcement authorities or to organizations acting in the public interest against child sexual abuse (Article 3(1), point (j)). By , communicate to the Commission a list of the names of the organizations to which you report under the Regulation, and communicate changes to that list to the Commission on a regular basis (Article 7(1)).

Who enforces it

Enforcement body

The supervisory authorities designated pursuant to Chapter VI, Section 1, of Regulation (EU) 2016/679 monitor processing falling within the scope of the Regulation (Article 6).

What this law does

Drafted with AI

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page. How this site is made

Research summary

Legal information, not legal advice. This is LexLint's own research summary of a public legal source, and it creates no attorney-client relationship. For decisions that matter, consult qualified counsel in the relevant jurisdiction. About LexLint

Regulation (EU) 2026/1881 lays down temporary and strictly limited rules derogating from certain obligations laid down in Directive 2002/58/EC, with the sole objective of enabling providers of certain number-independent interpersonal communications services to use specific technologies to detect online child sexual abuse on their services and report it and to remove online child sexual abuse material from their services.

Article 2, point (1), defines a number-independent interpersonal communications service by reference to Article 2, point (7), of Directive (EU) 2018/1972. Article 3(1) provides that Article 5(1) and Article 6(1) of Directive 2002/58/EC do not apply to the confidentiality of communications involving the processing by providers of personal and other data in connection with the provision of number-independent interpersonal communications services, provided that the conditions it lists are met.

Among those conditions, the processing must be strictly necessary for the use of specific technology for the sole purpose of detecting and removing online child sexual abuse material and reporting it to law enforcement authorities and to organizations acting in the public interest against child sexual abuse, and of detecting solicitation of children and reporting it, and must not be applied to interpersonal communications to which end-to-end encryption is, has been or will be applied.

Article 1(2) provides that the Regulation does not apply to the scanning of audio communications. Article 1(3) provides that the Regulation does not apply to interpersonal communications to which end-to-end encryption is, has been or will be applied. Article 3(1), point (c), requires a prior data protection impact assessment and a prior consultation procedure for any specific technology used for those purposes.

Until , the condition in Article 3(1), point (c), does not apply to a provider that was using a specific technology before without having completed a prior consultation procedure, starts a prior consultation procedure before and duly cooperates with the competent supervisory authority.

Article 3(1), point (g)(v), requires providers to inform users in a clear, prominent and comprehensible way that they have invoked the derogation, of the logic behind the measures they have taken and of the impact on the confidentiality of users' communications.

Article 3(1), point (g)(vii), requires providers to publish and submit to the competent supervisory authority and to the Commission, by and by 31 January every year thereafter, a report on the processing of personal data under the Regulation. Article 3(1), point (i), requires the data to be stored no longer than strictly necessary for the relevant purposes and, in any event, no longer than 12 months from the date of the identification of the suspected online child sexual abuse.

Article 7(1) requires providers to communicate to the Commission, by , a list of the names of organizations acting in the public interest against child sexual abuse to which they report online child sexual abuse under the Regulation. Article 5 gives users the right to an effective judicial remedy where they consider that their rights have been infringed as a result of the processing of personal and other data for those purposes.

Article 6 provides that the supervisory authorities designated pursuant to Chapter VI, Section 1, of Regulation (EU) 2016/679 monitor processing falling within the scope of the Regulation. Article 11 provides that the Regulation enters into force on the third day following that of its publication in the Official Journal of the European Union and applies until .

Recital 12 records that Regulation (EU) 2021/1232 has expired because the co-legislators were not able to reach an agreement by on the Commission's proposal to extend it.

When LexLint raises it

When your app profile says your app provides telecom services.

Back to the example  ·  Lint your app