On 9 July 2026, the European Parliament approved an extension of the controversial “Chat Control” rules.
This means Google, Meta, Microsoft and other companies now have legal permission to continue scanning people’s private emails and photos until April 2028.
For anyone using Google, Facebook, Microsoft, services on Pc or Phone, this is particularly relevant.
What Does This Actually Mean?
Chat Control: Who Will Be Responsible If Our Private Family Data Is Exposed?
On 9 July 2026, the European Parliament voted to extend a temporary EU measure allowing online communication providers to voluntarily continue certain measures to detect child sexual abuse material (CSAM). On 23 July, the Council gave final approval. The measure is due to remain in force until 3 April 2028, while permanent legislation is negotiated.
Why should the private photographs and communications of innocent people be subjected to automated detection at all?
People store photographs of their children, family holidays, birthdays, christenings, homes and private lives with companies such as Google, Meta and Microsoft.
These are not ordinary pieces of data.
But why should we simply trust these companies?
Look at Meta.
On 31 January 2024, Mark Zuckerberg appeared before the U.S. Senate Judiciary Committee at a hearing concerning Big Tech and the protection of children online. Parents whose children had suffered serious harm or died were present. Zuckerberg apologised to families during the hearing.
The Senate hearing itself raised serious questions about the failure of major technology companies to protect children.
An apology is not the same thing as accountability.
So why should the public simply assume that enormous technology companies should now be trusted with even greater amounts of sensitive information about families and children?
Who actually has access?
This question deserves much more attention.
If our photographs and communications are processed by these companies:
- Who inside the companies can access them?
- Can employees or contractors access them?
- What about engineers and security personnel?
- What third-party processors are involved?
- What automated systems analyse the material?
- Can a human ever view a photograph?
- Under exactly what circumstances?
- Who authorises that access?
- Who independently monitors it?
- How long are photographs, reports, hashes or other information derived from them retained?
- Can information be transferred to another company or processor?
- What happens if information reaches criminals or commercial data brokers?
The companies’ own privacy policies acknowledge that personal information can, in specified circumstances, be processed by affiliates, service providers, contractors and other parties.
These questions should have clear answers before the public is expected to accept the system, not afterwards.
What happens if security fails?
No technology company can honestly guarantee that its systems will never be hacked, breached or misused.
Ireland already knows what a catastrophic data breach can look like.
The HSE cyberattack resulted in highly sensitive personal and medical information being compromised. Once deeply personal information escapes onto the internet, it can be copied, redistributed and remain outside the victim’s control for years.
Now imagine the information is not a medical record.
Imagine it is photographs of your children.
What happens if those photographs are stolen?
What happens if they are copied?
What happens if they are sold or transferred?
What happens if they reach criminals?
Who takes responsibility?
Will the victims simply be told to take the company to court after the damage has already been done?
GDPR provides important rights and can provide a route to compensation where an infringement causes material or non-material damage. But compensation cannot put a photograph back under your control once it has been copied and distributed.
There is no “undo” button.
Questions for the MEPs who supported this
Did you specifically assess the consequences of a major cyberattack involving enormous quantities of private family photographs and communications?
Did you assess the risks of insider access?
Did you assess the risks created by contractors and third-party processors?
Did you assess what could happen if information reaches criminals or commercial data brokers?
Did you establish who is legally responsible if the system fails?
Did you establish what compensation and other remedies would be available to families whose private information is exposed?
Did you examine less intrusive alternatives?
And most importantly:
What legally prevents this technology and infrastructure from eventually being used for purposes beyond its original justification?
So I want every MEP who supported this measure to answer one simple question:
If private family photographs are scanned or processed under this system and are subsequently exposed, stolen, transferred, sold, misused or otherwise released beyond control, who is legally responsible?
If Meta has already faced serious congressional scrutiny over its handling of child safety, why should the public simply assume that Meta and other technology companies should be trusted with even more sensitive information?
Meta’s privacy policy says it uses information for advertising and profiling and says information is shared across Meta companies and with partners, vendors, service providers and other third parties. It also says some processing can involve manual/human review.
https://www.facebook.com/privacy/policy/?entry_point=data_policy_redirect&entry=0
Sen. Josh Hawley, during a hearing on child safety, called on Meta CEO Mark Zuckerberg to directly apologize to the families in the room whose children were harmed online
Chat Control



