Noticias de hosting · 6 min de lectura

314 MEPs Voted To Reject Chat Control. It Survived Anyway.

314 MEPs Voted To Reject Chat Control. It Survived Anyway.

On 9 July 2026, 314 MEPs voted to reject the Council's position on reinstating Chat Control, 276 voted against rejecting it, and 17 abstained. A clear majority of those voting were against it. But rejection at second reading requires an absolute majority of Parliament's members, currently 360, so the motion fell 46 votes short and the Council's text survived. 1

That is not the same thing as the law being in force, and the difference is being reported carelessly. The previous interim regulation expired on 3 April 2026, after Parliament rejected the Commission's proposed extension in March with 228 votes in favour and 311 against. 2 What happened on 9 July is that Parliament failed to block the reinstatement and then amended it. The amended text now goes to the Council, which has three months to accept or reject those amendments; if it doesn't accept all of them, the two institutions go to conciliation. 1

So the practical outcome, assuming the Council accepts, is that voluntary CSAM scanning by providers including Google, Microsoft and Meta returns and runs to 2028. 3 As of today it's on course rather than done.

However you feel about the policy, the mechanism is worth paying attention to. A majority of voting members opposed the text and it survived, because an absolute-majority threshold is measured against Parliament's full membership rather than against the members in the room. Abstentions and absences aren't counted as support; they simply make the threshold harder to reach, which in a rejection vote comes to the same thing. That's a legitimate procedure. It's also how significant surveillance powers move forward without anyone having to defend them in a headline vote.

What it does and doesn't cover

Precision matters here, because both the alarm and the reassurance are being overstated.

It's voluntary rather than mandatory. It permits providers to scan; it doesn't compel them to.

It isn't a ban on end-to-end encryption. Parliament's amendments exclude "communications to which end-to-end encryption is, has been or will be applied" from the scope of the law. 1 Note whose amendments those are: Parliament's, and the Council hasn't signed off on them yet. Beyond the legal text, services like WhatsApp and Signal encrypt with keys only the sender and recipient hold, which makes server-side scanning technically impossible rather than merely prohibited. That says nothing about scanning on the device before encryption is applied, which is a separate fight and not settled by this vote.

And a VPN doesn't help with any of it. A VPN hides your location and your network traffic. It can't stop a platform from scanning a message inside its own application. Encryption is what protects the content; a VPN protects the path.

We want to be explicit about that last point, because we sell a VPN and it would be commercially convenient to be vague. It would also be false. Anyone marketing a VPN as a Chat Control defence is selling you the wrong tool.

What does follow

The durable lesson isn't about messaging apps. It's about where your data lives and who can be compelled or permitted to look at it.

Scanning happens at the point where data is legible. For a hosted service, that point is the service operator. The structural defences are the boring ones.

Self-host what matters, because data on infrastructure you control can't be scanned by a platform that never receives it.

Encrypt at rest with keys you hold, so that if your provider can't decrypt it, permission to scan is academic.

Choose your jurisdiction deliberately. EU, non-EU, and which non-EU are different regulatory answers, and this is a per-workload decision rather than a company-wide one.

Minimise what exists, because the most robust protection for a record is that it was never created.

Our footprint, stated plainly

We're a European ISP with a small footprint of customer data, and this is the kind of week where that's worth restating concretely.

We don't collect identity documents to sell you a server, so we hold none. We accept crypto, so you aren't obliged to route your identity through a card network to buy hosting. We don't monitor your traffic beyond what running the service requires, and visitor IP addresses are processed transiently by our abuse-prevention systems rather than retained, so what isn't recorded can't be produced, scanned or leaked. The one exception is a packet capture while we're absorbing a DDoS, which is about keeping the network up rather than watching you.

We also run four jurisdictions chosen per machine: Tirana, Skopje, Amsterdam and London. One of those is in the EU and three are outside it, which buys you a different set of legal exposures rather than an escape from all of them. That's a choice you make at deploy time rather than a support ticket.

We run a WireGuard VPN too, and we'll describe it accurately. It protects your traffic in transit and your apparent network location. It doesn't protect the contents of a message you hand to a third-party platform. Those are different problems and they need different tools.

For self-hosting the things you'd rather nobody scanned, whether that's your own mail, your own Matrix or XMPP server, or your own file storage, a €5/mo VPS with full KVM root access is the entire requirement. It isn't convenient in the way a hosted platform is convenient. It is, however, the only arrangement where the question of who's allowed to scan this has the answer nobody, because nobody else has it.

This returns before 2028

If the Council signs off, the reinstated regime runs to 2028, which means this argument returns. It'll return during a quieter news cycle, and it'll be decided by whether enough people show up.

In the meantime the technical position hasn't changed and isn't complicated. Encryption protects content, jurisdiction protects records, and self-hosting removes the intermediary that can be asked in the first place. None of those are new. This month is simply a good reminder to check which of them you're actually relying on.

Sources

  1. Combating child sexual abuse: support for a more limited ePrivacy derogation, European Parliament, 9 July 2026
  2. Child sexual abuse online: voluntary detection measures will not be extended, European Parliament, 26 March 2026
  3. Europe revives law allowing big tech to scan for CSAM, The Record, 10 July 2026