Chat control: the safeguard nobody can point to reaches its deadline today
A condition of lawful CSAM scanning has gone unevidenced for five years, and the deadline for providers to start meeting it falls today. Ireland's Data Protection Commission is the body that would know how many ever did, and it now has a Freedom of Information request asking.
Today a deadline falls that almost nobody has heard of, on a safeguard that, on the public record, was never shown to have been used.
Since 2021 the EU has let messaging and cloud providers scan private communications for child sexual abuse material without the usual consent, under a temporary derogation from the ePrivacy rules, the regime most people know as chat control. That permission was never unconditional. Regulation (EU) 2021/1232 made voluntary detection lawful only where, for each specific technology, a data protection impact assessment under Article 35 of the GDPR and a prior consultation with a supervisory authority under Article 36 of the GDPR "have been conducted". Those are the words of Article 3(1)(c). They are conditions of lawfulness, not recommendations.
The derogation lapsed on 3 April 2026 and was re-enacted on 24 July as Regulation (EU) 2026/1881, now running to 3 April 2028. Its Article 3 carries the prior-consultation condition forward, and a transitional provision gives one narrow grace: providers that were scanning before 31 July 2026 without having completed a prior consultation keep their cover only if they begin one before today, 1 September 2026, and cooperate with the supervisory authority. That transitional clock runs out this morning. So it is a fair moment to ask a simple question. Across five years of scanning, is there any public evidence that the Article 36 consultation, the precondition, was ever done? I have looked, and the record is silent from end to end.

The safeguard nobody can point to
The Commission has published two implementation reports on the derogation, and both say the same thing. The second, COM (2025) 740 of 27 November 2025, states in terms: "No information was submitted by the providers on whether the technologies were deployed in line with the state of the art and in the least privacy-intrusive way, or on whether a prior data protection impact assessment, as referred to in Article 35 of Regulation (EU) 2016/679, and a prior consultation procedure, as referred to in Article 36 of that Regulation, had been conducted." The first report, COM (2023) 797 of 19 December 2023, had already recorded the same absence two years earlier.
It is easy to see why the information never arrived. The standard reporting form the Commission itself prescribes, in Implementing Regulation (EU) 2024/2916, has no field for a data protection impact assessment, no field for an Article 36 consultation, and no field naming the supervisory authority consulted. The form never asks. And the providers' own transparency reports under the Regulation, thirteen across Google, Microsoft and LinkedIn for 2021 to 2025, contain no reference to Article 35, to Article 36, or to any consultation with a supervisory authority.
I want to be exact, because the distinction is the whole point. This establishes that no information was ever submitted on whether a condition of lawfulness was met. It does not establish that the condition was unmet; a provider may have done every consultation and simply never reported it, because nothing asked. What is certain is that after five years the Commission has been given no information on the question, the form never sought it, and the providers never volunteered it.

The Irish body that would know
This has a specific Irish edge. Several of the providers that scanned under the derogation have their main establishment in Ireland, which makes the Data Protection Commission their lead supervisory authority. Article 3(1)(g)(vii) of the Regulation also requires providers to report annually to that authority. The DPC is therefore the one body in a position to say how many Article 36 consultations were actually conducted, and how many annual reports it actually received.

Its own publications do not say. The DPC Annual Report for 2022 records, at page 44, that it "engaged with several providers of interpersonal communications services such as Meta, LinkedIn, Microsoft, Google and Twitter" on their handling of child sexual abuse material, and made recommendations on transparency, retention and purpose limitation. That passage never mentions Regulation (EU) 2021/1232, an Article 36 consultation, a data protection impact assessment, or the annual reports the Regulation requires. I could find no published statement from the DPC that addresses either question.
So I have asked it directly. On 20 August I filed a Freedom of Information request with the Data Protection Commission asking how many prior consultations under Article 36 it has received in connection with this Regulation, and how many annual provider reports it has received under Article 3(1)(g)(vii). The request was acknowledged on 25 August, which puts its statutory decision date around 17 September. I will publish the answer.
The carve-out, and who is holding the pen
There is a second reason this autumn matters, and it runs the other way. The new Regulation is not a copy of the old one. By Article 1(3), Regulation (EU) 2026/1881 "does not apply to interpersonal communications to which end-to-end encryption is, has been or will be applied". For the first time the scanning derogation carves encrypted messaging out of scope entirely.
That carve-out is already contested. When the Council adopted the act on 23 July, the record at ST 12382/26 shows Hungary against and Belgium abstaining, and carries a statement from France recording "serious concern regarding the amendment adopted by the European Parliament on the exclusion of encrypted communications". France calls the wording "very broad" and says the conclusions of the Commission's expert group on encryption, expected in November, "should not be pre-empted". One large member state has put on the record that it wants the question left open.
Where that gets settled is the negotiation on the permanent Regulation, the compelled-detection instrument this derogation sits alongside, and Ireland has chaired it since taking the Council presidency on 1 July. The Presidency's programme states at page 35 that "the Irish Presidency stands ready to progress work on the Child Sexual Abuse Directive and Regulation". The next Justice and Home Affairs Council meets on 1 and 2 October, and the Presidency's conference on online safety for children takes place in Dublin on 10 and 11 September. The question worth watching is narrow: does the encryption exclusion survive the six months Ireland holds the pen?
An opinion that was never revisited
Ireland has been here before, and said something sharp, and then went quiet.
On 28 March 2023 the predecessor Joint Committee on Justice adopted a formal opinion on the compelled-detection proposal, COM (2022) 209, reference 33/JC/37, and transmitted it to the Minister, the Presidents of the Commission, Parliament and Council, every member state's national parliament, and Ireland's MEPs. It called the proposal "unprecedented in requiring indiscriminate scanning of digital communications and cloud storage", and warned it "would significantly undermine the security of our communications and online services by requiring firms to either remove end-to-end encryption or introduce backdoors into apps or other local software ('client-side scanning')". It cited the REPHRAIN evaluation, which found none of five detection systems met fundamental-rights standards, and a formal opinion from a former judge of the Court of Justice, Prof. Dr Ninon Colneric, that the law was incompatible with EU case law.
Two fairness points, because the other side will raise them. The Committee was not opposed in principle: it called itself "supportive of the fundamental objective", and at paragraph 7(q) recommended that voluntary detection be preserved, the very regime this article concerns, so the January 2026 clearance of the extension was consistent with the Committee's own recommendation rather than a departure from it. And the Commission recorded 33/JC/37 as political dialogue, not a reasoned opinion on subsidiarity; no chamber anywhere filed one on this proposal. It was a substantive objection answered and refused, not a subsidiarity challenge ignored.
It was refused. The Commission replied on 19 July 2023, by letter C(2023) 4991 final, signed by Vice-President Maros Sefcovic and Commissioner Ylva Johansson: keeping encrypted services in scope was "necessary", excluding them "would be arbitrary", and "decisions about detection should not be left to private parties, acting on the basis of their private interests".
I can find no sign the Committee looked at that reply, or at its own opinion, again. No committee decision since March 2023 revisits COM (2022) 209, and no public hearing on the file appears in the record in over four years. When the extension came through, the Department's information note of 21 January 2026 categorised it as of "Major Significance"; six days later the Committee's decision list recorded it in one row as "Low", "No further scrutiny required", with no reason, because a decision list records none.
That last point is not an Irish peculiarity, and I should say so: twenty-six of the twenty-seven member states' parliaments filed nothing at all on the extension, only Italy's Camera dei Deputati filing an opinion. Silence was the norm. What makes the Irish silence worth remarking on is narrower. The Oireachtas has 113 opinions in that register, so it is an active user of the channel, and this was a choice rather than an incapacity. Two smaller details sit alongside it: the annual scrutiny reports for 2022, 2023 and 2024, references 34/JCEUA/07 to 09, were laid on a single day, 30 April 2026, the 2022 foreword dated more than three years after the year it describes; and the most accessible complete copy of Ireland's own 2023 opinion is hosted not by the Oireachtas but by the Senate of the Netherlands.
The votes, for the record
The parliamentary record of this summer is public, and I will state it flatly, imputing motive to no one. On 9 July 2026 the European Parliament voted on two motions to reject the Council's position, roll call PV-10-2026-07-09-RCV_FR.xml; the corrections annex carries no Irish entries, so the record stands as cast. On the first motion, eleven of the fourteen Irish MEPs voted against rejection, McNamara alone voted to reject, and two, Flanagan and Funchion, did not vote. On that same motion The Left group divided thirty-five votes in favour to one against across its forty-five members; the vote against was Boylan's. On the second motion Ó Ríordáin switched to rejection and Boylan did not vote. I wrote to the Midlands-North-West MEPs on 20 August, and to the members named here on 29 August, setting out the roll call and inviting comment. I will publish any response.
The arguments against me, met
A piece like this owes its readers the strongest replies to it.
COM (2025) 740 says there are "no indications that the derogation is not proportionate". True, and the same report records that seven member states, Ireland among them, did not provide all the required data. An absence of contrary indications drawn from data the report itself calls incomplete is a thin foundation, and both halves belong in the same sentence.
On actionability, the 2023 Committee recorded that of all NCMEC reports to the Garda in 2020 only 9.7% were actionable; the Commission's reply cites NCMEC that around 63% of image-based referrals to Swiss police contained graphic material. Both can hold, because they measure different things, and REPHRAIN's finding that detection systems could not quantify their false positives sits underneath both.
The strongest argument against the carve-out is that NCMEC attributes about a 30% drop in 2024 EU reports partly to services moving to end-to-end encryption and ceasing detection. That is a real cost and deserves stating plainly. The answer on the record is the 2023 evidence: a regime that cannot bound its own error rate, and that the Committee found would require breaking encryption or building client-side scanning for everyone, is not obviously the proportionate way to recover those reports. Reasonable people weigh that differently, which is why France wants the exclusion reopened and why the Irish chair matters.
Finally, the Department did engage. Parliamentary Question 701 of 30 September 2025 lists the organisations consulted, from the DPC and the Garda to Thorn, the ICCL and a row of providers. This was not formed in a vacuum. The oddity is elsewhere: the Register of Lobbying records no return lobbying the Government on this EU file since 1 January 2025, the EU-file activity on it all directed at MEPs instead.
What happens next, and how you will know
I'm not writing to demand anything. I have put a set of questions into the machinery that has to answer them, and the answers are due soon.
On 25 August I made a submission to the Clerk of the Joint Committee on Justice, Home Affairs and Migration, asking it to record whether its 2023 opinion still stands, to put Ireland's national position to the Minister, Jim O'Callaghan, before the 1 to 2 October Council, and to ask the DPC for the two numbers above. The following day I refined two Freedom of Information requests to the Department of Justice, after the Department invoked section 15 of the FOI Act. An access-to-documents request to the Council of the EU, over documents withheld on the negotiation file, is due a reply around 10 September. None of these is answered yet. Each will be, on a timetable, by a body that keeps records.
When the DPC says how many Article 36 consultations it has ever received, when the Council releases or refuses what it holds, when the Committee records whether Ireland still thinks indiscriminate scanning is "unprecedented", I will report exactly what they say, with the document numbers attached.
A safeguard nobody can point to is not the same as a safeguard that was never there. Today the window to qualify for the grace closes. The point of the requests is to replace what I could not find with something a public body has put its name to. That starts now.