EU child safety push stalls as ePrivacy derogation expires, age verification app hacked, and CSA Regulation stuck in trilogue

This article was published on April 24, 2026 Summary: Europe’s effort to protect children online has collided with its own privacy architecture. The ePrivacy derogation allowing voluntary CSAM scanning expired on April 3 after Parliament voted 311-228 to reject its extension, the EU’s new age verification app announced April 15 was hacked in under two minutes, and the CSA Regulation (“Chat Control”) remains stuck in trilogue with a July deadline. The ECHR has ruled encryption backdoors violate fundamental rights, while the GDPR, DSA, and proposed CSA Regulation each require knowing whether a user is a child, which itself requires collecting the data that privacy law says you cannot collect about children. On April 3, the European Parliament voted 311 to 228 to let its temporary ePrivacy derogation expire. That derogation had allowed platforms such as Meta, Google, and Microsoft to voluntarily scan private messages for child sexual abuse material without violating EU privacy law. When it lapsed, the legal basis for those scans disappeared. Twelve days later, the European Commission announced a new privacy-preserving age verification app designed to protect children online. Researche
Source: For the complete article, please visit the original source link below.