Mass Surveillance in Europe with ChatControl 1.0: Should You Care?

By Stephane Carrez

On July 9, 2026, the European Parliament revived ChatControl 1.0, a law that allows tech companies to scan your private messages, emails, and social media communications for illegal material—without a warrant, without suspicion, and without your consent. The law passed not because it won a vote, but because the opposition failed to meet a procedural threshold. This is mass surveillance by the back door, and it sets a dangerous precedent for digital rights in Europe. Your privacy is at risks but we have some solutions!

Images/eu-mass-surveillance.jpg

Why You Should Care

  1. Your Messages Are No Longer Private by Default
    • ChatControl 1.0 legalizes the scanning of unencrypted or server-side encrypted communications (e.g., Gmail, Facebook Messenger, Instagram DMs, Snapchat, Skype) for known CSAM (Child sexual abuse material), grooming, and AI-generated abuse material.
    • No exceptions: Even if you’ve done nothing wrong, your conversations could be automatically analyzed by algorithms or human reviewers.
  1. It’s Not Just About CSAM
    • While the goal is to combat child abuse, history shows that surveillance powers expand. Once the infrastructure for scanning exists, it can be repurposed for censorship, political monitoring, or mass data collection.
    • For example, in 2020, the EU’s ePrivacy Directive was weakened to allow metadata collection for "national security". Today, that data is used for everything from targeted ads to law enforcement fishing expeditions.
  1. Encryption Is Under Attack
    • ChatControl 1.0 doesn’t yet apply to end-to-end encrypted (E2EE) apps like twinme, Skred, or Signal. But ChatControl 2.0—the permanent regulation being negotiated—could force even E2EE platforms to implement client-side scanning, breaking encryption for everyone.
    • Client-side scanning means your device scans your messages before they’re encrypted. This is a backdoor in disguise—and once it exists, it can be exploited by hackers, governments, or malicious actors.
  1. It’s Anti-Democratic
    • The law passed despite 314 MEPs voting against it—a majority of those present. It only survived because the opposition fell 47 votes short of the 361 absolute majority needed to block it.
    • Many MEPs were absent due to summer recess, and critics call the process a procedural loophole that undermines democracy.

Why twinme and Skred Are Different

We built twinme and Skred with privacy as the foundation. Your messages are end-to-end encrypted (E2EE): only you and the person you’re communicating with can read them. Not us, not governments, not anyone else. Even more, there is no central server that stores your messages, even encrypted. If your messages are not stored on a server, they cannot be decrypted, analyzed or scanned. How do we achieve this in our applications ?

With our Twincode technology, when you send a message it is sent directly to your contact without being stored on a server. As a consequence, your message cannot be scanned or analyzed: we just don't see them. Your message are stored exclusively on your device and the device of your contact. They are stored in a SQLCipher database locally to your phone which means they are encrypted locally. To send messages, we use peer-to-peer technology (WebRTC) to connect devices directly. A WebRTC connection is established between the two devices and a secure data channel allows our applications to send and receive messages, images or files. The WebRTC connection uses DTLS-SRTP with ephemeral keys. No interception or decryption is possible.

Our applications are published as Open Source on our GitHub Twinlife organization so that you can verify our implementation.

To summarize, here’s how we protect you:

Feature

Twinme/SkredMost Other Apps (Gmail, FB Messenger, etc.)
EncryptionEnd-to-end (E2EE)Server-side or none
Message StorageLocal device only and encrypted in a SQLCipher databaseCentralized servers
CommunicationPeer-to-peer (WebRTC)Server-relayed
Access to ContentOnly you and the recipientPlatforms, governments, or third parties
ScanningImpossible (we can’t see your data)Voluntary or mandatory

Result: ChatControl 1.0 does not apply to us. We cannot and will not scan your messages.

What’s Next? The Fight for ChatControl 2.0

ChatControl 1.0 is a temporary measure, but the EU is already negotiating ChatControl 2.0 (CSAR), which could:

  • Mandate scanning for all messaging apps, including E2EE services.
  • Require client-side scanning, forcing apps to break encryption to comply.
  • Create a precedent for global surveillance, as other countries may follow the EU’s lead.

Timeline:

  • Now: ChatControl 1.0 is in effect until 2028 or until ChatControl 2.0 passes.
  • September 2026: Negotiations for ChatControl 2.0 resume.
  • October 2026: The Council of the EU has three months to accept or reject the current text. If accepted, the E2EE exemption could become law—but the long-term trend is toward expanded surveillance.

What You Can Do

  1. Switch to E2EE Apps: Use twinme, Skred, or Threema, these are European applications to keep your messages private.
  2. Demand Better Laws: Contact your MEP (Member of the European Parliament) and demand they oppose ChatControl 2.0 Find your MEP
  3. Spread the Word: Share this statement with #SaveEncryption and #StopChatControl.

Privacy is not a luxury. It’s a right. And we won’t let it be taken away.

Add a comment

(How to get a Mini-code ?)