Members of the European Parliament (MEPs) voted on a derogation of the EU’s ePrivacy Directive for the third time in 4 months. While the proposal passed, the vote nonetheless remains a triumph because it reinforces the Parliament’s position against mass surveillance on the more dangerous CSA Rregulation, and because it enshrines the protection of encryption.

On 26 March 2026, the European Parliament voted to reject an extension of the 2021 ‘temporary’ interim ePrivacy derogation – the law sometimes referred to as “Chat Control 1.0”. This law allowed Big Tech companies like Microsoft and Meta to mass scan their users’ private messages to search for child abuse material. After the Parliament’s valid rejection of the extension, this temporary derogation expired on 4 April 2026. Because of the rarity of such rejections, the legislative proposal was considered politically dead, or so everyone thought.

Enter: Roberta Metsola, president of the European Parliament and a member of the European People’s Party (EPP), which is rapidly gaining infamy for undermining democratic processes.

Roberta Metsola surprised everyone by suggesting to the European Council to ignore the position of the Parliament she represents . The EU governments swiftly agreed to push the text again, forcing the Parliament through a rarely-used procedure: a third vote, this time for a “second reading” of the file.

The bad news is that the European Parliament failed to stop the return of the temporary derogation.

The good news is that they still managed to send a clear signal that mass surveillance would not be accepted in the CSA Regulation , sometimes known as “Chat Control 2.0”, the permanent framework which is being negotiated in parallel and which has the potential to be much more dangerous for our right to private and secure communications online.

The conservative EPP group used a combination of the second reading procedure with an urgency procedure to its advantage. In second readings, the proposed text is automatically adopted unless it is rejected . Further, in second readings the threshold for amendments to be adopted is an “absolute majority” (50% +1 of the total number of MEPs, i.e. 360 votes) instead of the usual “simple majority” (more ‘yes’ than ‘no’ in the votes cast). This means that MEPs who are absent or do not vote are counted as being in favour of the text, and against all amendments . EPP then requested an urgency procedure to bypass the competent Parliament committee (Committee on Civil Liberties, Justice and Home Affairs – LIBE), and directly add this vote to the agenda of the last plenary before the summer break. Many MEPs tend to be absent at this plenary – in this case, 100+ MEPs were absent , meaning that more than 1/7 of the ‘votes’ against amendments and against rejection were from MEPs who did not actually vote. Essentially, anyone in the European Parliament who wanted to oppose this last-minute surprise move was at a disadvantage from the outset .

Beside the risk of normalising harmful and disproportionate practices, and undermining the Parliament’s democratic process by forcing another reading, the real risk with this vote was that it could have undermined the Parliament’s strong position on the CSA Regulation . The European Parliament had, so far, opposed mass surveillance and the undermining of end-to-end encryption.

Fortunately, instead of undermining the Parliament’s position, this vote reinforced it, with more than half of the present MEPs voting to reject and amend the proposal for the temporary derogation. A bigger-than-normal majority was needed this time, but that won’t be the case for the CSAR negotiations, signalling to the negotiators that they can’t get support for a deal which allows for mass surveillance.

Despite the temporary derogation being voted through, MEPs managed to pass two amendments ( AM30 and PC3 ) protecting end-to-end encrypted interpersonal communications, including against client-side scanning. These changes to the proposal are an important success for safeguarding the principle that communications should be safe and secure .

These changes also meant that the proposal was not automatically adopted: first the Commission had to issue an opinion on the text as amended (it gave a green light on the protection of encryption), then the Council had to accept it too, before the measure could be made into law.

The new derogation applies from 3 August 2026 until 3 April 2028.

Now, the …