Data Protection

Encrypted messaging apps and CSAM: provider obligations in the EU in 2026

E
Equipo Editorial CambiosLegales
28 Jul 2026 7 min 15 views

Key data

RegulationRegulation (EU) 2026/1881 of the European Parliament and of the Council
PublicationJuly 28, 2026 (EU Official Journal)
Entry into forceJuly 24, 2026
Affected partiesProviders of interpersonal communications services independent of numbering operating in the EU (encrypted messaging apps)
CategoryData Protection / ePrivacy
Regulation that modifiesTemporary exception to Directive 2002/58/EC (ePrivacy Directive)
NatureTemporary — has an expiration date and will be replaced by permanent legislation
Impact analysis reserved for subscribers
The detailed impact analysis of this regulation is available with the PRO and Business plans. Access the full content and receive personalized alerts.
From €9.99/month · Cancel anytime

Providers of encrypted messaging apps operating in the European Union have new legal obligations as of July 24, 2026. Regulation (EU) 2026/1881 establishes a temporary exception to the ePrivacy Directive (2002/58/EC) to allow the processing of personal data and content with a specific objective: to detect, report and remove material of child sexual abuse online (CSAM, by its English acronym).

The measure is not indefinite. It responds to the need to maintain operational detection tools while permanent regulation is negotiated at the European level. But while it is in force, non-compliance exposes providers to significant legal and reputational consequences.

What does this regulation establish?

The ePrivacy Directive (2002/58/EC) protects the confidentiality of electronic communications, which in practice prevents messaging providers from analyzing message content. Regulation (EU) 2026/1881 opens a temporary and limited exception to that protection, exclusively for the fight against CSAM.

The key elements established by the regulation are:

  • Authorization to process personal data and content for the specific purpose of detecting, reporting and removing material of child sexual abuse online.
  • Exclusive application to providers of interpersonal communications services independent of numbering — that is, messaging apps that do not use traditional telephone numbering (such as WhatsApp, Signal, Telegram or similar).
  • Obligation to implement detection mechanisms under strict guarantees of data protection and fundamental rights.
  • Temporary nature: the regulation has an expiration date and will be replaced by permanent legislation once the ongoing European legislative process concludes.
  • Notification protocols to authorities: providers must establish procedures to communicate detected cases to the competent authorities.
Previous situation (Directive 2002/58/EC)Situation after Regulation 2026/1881
General prohibition on analyzing the content of encrypted communicationsTemporary exception allowed for CSAM detection
No obligation for active CSAM detection in encrypted messagingObligation to implement detection mechanisms under safeguards
No specific protocol for notification to authorities for CSAMObligation to establish notification protocols to authorities
Legal basis for processing: not applicable for this purposeNew temporary legal basis enabled by the Regulation

Economic and operational impact

The impact is not only legal: it is operational and technological. Affected providers must assume real adaptation costs in several dimensions:

  • Development or integration of CSAM detection technology compatible with encrypted messaging environments, respecting the safeguards required by the Regulation.
  • Review and update of privacy policies to reflect the new legal basis for data processing enabled by the temporary exception.
  • Adaptation of processing activity records (PAR) required by the GDPR to include this new processing.
  • Design of internal notification protocols to competent authorities when CSAM is detected.
  • Data protection impact assessment (DPIA): given that this is high-risk data processing, it is foreseeable that it will be mandatory.
  • Medium-term planning: being a temporary regulation, companies must anticipate adaptation to the permanent regulation that will replace it.

Who does it affect?

  • Providers of encrypted messaging apps operating in the EU: WhatsApp, Signal, Telegram, and any equivalent service.
  • Technology companies that offer interpersonal communications services independent of numbering as part of their product (corporate chats, collaboration platforms with integrated messaging).
  • European startups and scale-ups in the digital communications sector that have developed messaging products.
  • Data Protection Officers (DPO) of any organization operating this type of service: they must lead the adaptation.
  • Legal and compliance teams of technology providers with presence in the EU, regardless of where they are headquartered.

It does not affect companies that only use messaging apps as an internal tool (employees using WhatsApp to communicate). The obligation falls on the providers of the service, not on its corporate users.

Practical example

A European company that has developed an encrypted messaging app for corporate use and has users in several EU countries falls within the scope of Regulation 2026/1881.

Until now, its privacy policy established that the content of messages was completely private and was not analyzed under any circumstances, supported by the ePrivacy Directive. With the entry into force of the Regulation, this company must:

  1. Update its privacy policy to reflect that, exceptionally and under the safeguards of the Regulation, message content can be processed for the purpose of detecting CSAM.
  2. Implement or contract a certified CSAM detection technology solution compatible with its encrypted architecture.
  3. Establish an internal protocol that defines what to do when a case is detected: who notifies, which authority, in what timeframe.
  4. Update its Processing Activity Record and assess whether a Data Protection Impact Assessment is necessary.
  5. Monitor the progress of permanent regulation to anticipate the next round of adaptations.

Do you need to track this and other regulations?

Check the full details in CambiosLegales

What should companies do now?

  1. Verify if you are an affected provider: check if your service fits the definition of "interpersonal communications service independent of numbering". If you offer encrypted messaging to users in the EU, you probably do.
  2. Review and update the privacy policy: it must reflect the new legal basis for processing enabled by Regulation 2026/1881 for CSAM detection.
  3. Update the Processing Activity Record (PAR): include the new data processing with its purpose, legal basis, data categories and recipients (authorities).
  4. Conduct or update the Data Protection Impact Assessment (DPIA): given the high risk of processing, it is a recommended compliance measure and possibly mandatory.
  5. Design the notification protocol to authorities: define the internal procedure for communicating detected CSAM cases to the competent authorities of each Member State.
  6. Evaluate CSAM detection technology solutions: identify tools compatible with the encrypted architecture of the service and that comply with the safeguards required by the Regulation.
  7. Plan the transition to permanent regulation: the regulation is temporary; anticipating the changes that permanent legislation will bring will avoid a second round of urgent adaptations.

Frequently asked questions

Which messaging apps are required by Regulation (EU) 2026/1881?

The Regulation affects providers of interpersonal communications services independent of numbering operating in the EU. This includes apps such as WhatsApp, Signal, Telegram and any equivalent encrypted messaging service that does not use traditional telephone numbering. It does not affect companies that simply use these apps as an internal tool.

When does the obligation to detect CSAM in encrypted messaging come into force?

Regulation (EU) 2026/1881 came into force on July 24, 2026, although it was published in the EU Official Journal on July 28, 2026. Affected providers must act immediately.

What needs to be changed in the privacy policy due to this regulation?

Privacy policies must be updated to reflect the new legal basis for processing enabled by the Regulation: the processing of personal data and message content for the specific purpose of detecting, reporting and removing material of child sexual abuse (CSAM). The Processing Activity Record must also be updated and, presumably, a Data Protection Impact Assessment must be conducted.

Is this regulation permanent or does it have an expiration date?

The regulation has a temporary nature. Regulation 2026/1881 is a provisional exception to the ePrivacy Directive (2002/58/EC) adopted while permanent regulation is negotiated at the European level. When that permanent legislation is approved, the Regulation will be repealed and providers will have to adapt again.

What happens if a messaging provider does not comply with Regulation 2026/1881?

The Regulation does not specify concrete sanctions in its summary, but non-compliance can result in liability under the GDPR framework (which provides for fines of up to 4% of global annual turnover or 20 million euros) and under the national legislation implementing the ePrivacy Directive in each Member State. Additionally, non-compliance in CSAM detection carries a very high reputational and legal risk.

Official source

Consult the complete regulation in official source

Disclaimer: This article is for informational purposes only and does not constitute legal advice. For specific decisions, consult a qualified professional. Source: https://eur-lex.europa.eu/./legal-content/AUTO/?uri=OJ:L_202601881



Share:
E
Equipo Editorial CambiosLegales

El equipo editorial de CambiosLegales analiza diariamente los cambios normativos que afectan a empresas y autónomos en España, ofreciendo análisis pro...

Comments

No comments yet. Be the first to comment!

Leave a comment
Activate alerts