Two narratives circulate about chat control, and both are wrong. One says the EU now reads every private message. The other says nothing happened. In fact something very concrete was decided on 9 July 2026 — just not what most people understand by the term. This article separates the two legislative projects running under the same label and names the genuinely remarkable part: how it got there.
Two projects, one label
Most of the confusion comes from the fact that “chat control” denotes two entirely different legal acts. Without separating them the news is impossible to place.
| Chat Control 1.0 | Chat Control 2.0 | |
|---|---|---|
| Legal form the derogation was introduced in 2021 | Temporary derogation from the ePrivacy Directive | Free-standing CSA regulation |
| Effect detection orders under defined conditions | Permits voluntary scanning | Enables mandatory orders |
| Content covered including the debate over encrypted communication | Unencrypted chats and email | Considerably broader |
| Who is obliged this is the decisive difference | Nobody — providers may, need not | Providers can be compelled |
| Status July 2026 the agreement targeted for July 2026 did not materialise | Extended to 2028 | Still in trilogue, not adopted |
What was decided on 9 July 2026 is the extension of the voluntary derogation to 2028. Providers such as Meta, Google or Microsoft may therefore continue to search unencrypted communication automatically for known abuse material. They do not have to. A blanket obligation to scan private messages has not been introduced.
Presenting it otherwise makes it easy for the other side — and forfeits credibility for the part that genuinely is problematic.
The real event is the procedure
Because something else is problematic, and it sits in the chronology.
- 2021
The derogation is created
A temporary derogation from the ePrivacy Directive allows providers to search unencrypted chats and emails automatically and voluntarily for known abuse material.
- Since 2022
The regulation stalls
The broader CSA regulation with mandatory detection orders is stuck in trilogue. Data protection authorities, legal services and fundamental-rights organisations consistently raise objections.
- Repeatedly
Parliament pushes back
Parliamentary decisions repeatedly go against the project in its blanket form. The subject does not leave the agenda as a result.
- 7 July 2026
The procedural vote
By 331 votes to 304 Parliament clears the way for a renewed vote on a subject it had already rejected — under an expedited procedure.
- 9 July 2026
The third vote
Parliament votes to extend the derogation to 2028. At the third attempt the subject is through.
A margin of 27 votes on the question of whether an already rejected matter may be voted on again. That is the point deserving attention — and it can be described without any exaggeration, because the numbers speak for themselves.
Anyone wanting to know how robust a fundamental-rights position is should not look at the outcome of a single vote. They should look at how often the same question gets asked until the desired answer emerges.
What this means for a business in practice
An uncomfortable clarification is needed here, because the opposite is routinely sold in this field.
A Georgian company does not remove your communication from EU regulation. Anyone serving EU customers remains subject to European law under the market-location principle — Article 3 GDPR is the clearest example. The legal form of your company changes nothing about that, and anyone promising you “protection from surveillance” through a foreign incorporation is selling you a misunderstanding. Which regimes actually apply and which do not is set out in Georgian Company, German Authorities.
What is real and mundane: operational privacy is a question of tool choice, not of company domicile. End-to-end encrypted communication, separated business and private channels, deliberate selection of service providers, documented retention periods. That looks unspectacular next to the emigration narrative — but it is the part actually under your control.
What a Georgian structure does deliver sits on a different level: it relocates operations, taxation and banking, not communications regulation. Conflating the two leads to disappointment on both counts.
What follows from this
The July 2026 episode is neither cause for panic nor cause for relief. It is a data point in a series, and the direction of that series has been stable for years: the subject returns to the agenda regardless of how the previous round ended.
For entrepreneurs with a location-independent business model the conclusion is the same as with the other regulatory projects of this term — not haste, but optionality. Anyone who structures their affairs so that a change of location remains a decision rather than an emergency has already answered the question. The overall balance sheet of the location is in Government Ratio 50.3%, the parallel development on traffic data in Three Months That Become Thirteen.
Frequently asked questions
Are all private messages in the EU now being searched?
No. On 9 July 2026 the temporary derogation from the ePrivacy Directive was extended to 2028. It permits providers to search unencrypted chats and emails automatically and voluntarily for known abuse material — it obliges nobody to do so. A blanket scanning obligation would be a matter for the CSA regulation, and that has not been adopted.
What is the difference between Chat Control 1.0 and 2.0?
1.0 is the temporary derogation from the ePrivacy Directive introduced in 2021: providers may scan voluntarily. 2.0 is the planned free-standing CSA regulation, which provides for mandatory detection orders under defined conditions and reaches considerably further. What was extended is 1.0. What is deadlocked in trilogue is 2.0.
Is end-to-end encryption affected?
Not by the extended derogation. That concerns unencrypted communication. The debate about access to encrypted content belongs to the CSA regulation and is one of the reasons it has not been concluded for years. End-to-end encryption is not broken as at the time of writing.
What was notable about the vote of 7 July 2026?
It concerned procedure rather than substance: by 331 votes to 304 Parliament cleared the way to vote again on a subject it had already rejected several times — under an expedited procedure. The substantive decision followed two days later. What is remarkable is therefore less the outcome than the repetition of the question until the desired result emerged.
Does a Georgian company protect against EU communications regulation?
No, and we expressly do not claim that. Anyone serving EU customers remains subject to European law under the market-location principle; Article 3 GDPR is the clearest example. A foreign incorporation relocates operations, taxation and banking — not the rules governing your communication with European customers.
What can actually be done instead?
Operational privacy is a question of tools, not of company domicile: end-to-end encrypted communication channels, a clean separation of business and private communication, deliberate selection of service providers and their legal jurisdictions, defined retention periods. That is unspectacular and lies entirely in your hands.
This article is general information and does not constitute legal or tax advice. The statements relate to the European Parliament votes of 7 and 9 July 2026, the temporary derogation from the ePrivacy Directive introduced in 2021 and the trilogue on the CSA regulation, unconcluded at the time of writing. As of July 2026, subject to changes in the law.