Skip to content

Text · Comparison of two versions

Changes from adopted text to adopted text

TA-10-2026-0095 → TA-10-2026-0266

From
TA-10-2026-0095 Adopted text of 26 Mar 2026
To
TA-10-2026-0266 Adopted text of 9 Jul 2026
Changes
Not comparable
Paragraphs
+156 added · −8 removed · 4 changed
More facts (2)
Title (from)
Amending Regulation (EU) 2021/1232 as regards the extension of its period of application
Title (to)
Temporary derogation from the ePrivacy directive

These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.

Every difference

The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.

Part 1 of 3: Paragraphs 1–60

RemovedP10_TA(2026)0095

AddedTEXTS ADOPTED

RemovedAmending Regulation (EU) 2021/1232 as regards the extension of its period of application

AddedP10_TA(2026)0266

AddedTemporary derogation from the ePrivacy directive

Committee on Civil Liberties, Justice and Home Affairs

RemovedPE784.310

AddedPE790.735

ChangedEuropean Parliament legislative resolution of 269 MarchJuly 2026 on the proposalCouncil forposition at first reading with a view to the adoption of a regulation of the European Parliament and of the Council amendingon Regulationa (EU)temporary 2021/1232derogation from certain provisions of Directive 2002/58/EC as regards the extensionuse of itstechnologies periodby providers of applicationnumber-independent (COM(2025)0797interpersonal communications services for the processing of personal and other data for the purpose of combating online child sexual abuse (11261/1/2026 – C10-0370/2025C100178/2026 – 2025/0429(COD))

Changed(Ordinary legislative procedure: firstsecond reading)

The European Parliament,

Changed– having regard to the CommissionCouncil proposalposition toat Parliamentfirst andreading the(11261/1/2026 Council– (COM(2025)0797),C10-0178/2026),

Removed– having regard to Article 294(2) and Article 16(2) and Article 114(1) of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C100370/2025),

Removed– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,

– having regard to the opinion of the European Economic and Social Committee of 21 January 2026,

Removed– having regard to Rule 60 of its Rules of Procedure,

Added– having regard to its position at first reading on the Commission proposal to Parliament and the Council (COM(2025)0797),

Changed– having regard to theArticle report294(7) of the CommitteeTreaty on Civil Liberties,the JusticeFunctioning andof Homethe AffairsEuropean (A10-0040/2026),Union,

Change 1

Removed1. Rejects the Commission proposal;

Added– having regard to Rules 68 and 170 of its Rules of Procedure,

Removed2. Calls on the Commission to withdraw its proposal;

Added1. Adopts its position at second reading hereinafter set out;

2. Instructs its President to forward its position to the Council, the Commission and the national parliaments.

Change 2

AddedP10_TC2-COD(2025)0429

AddedPosition of the European Parliament adopted at second reading on 9 July 2026 with a view to the adoption of Regulation (EU) 2026/… of the European parliament and of the Council on a temporary derogation from certain provisions of Directive 2002/58/EC as regards the use of technologies by providers of number-independent interpersonal communications services for the processing of personal and other data for the purpose of combating online child sexual abuse

Added(Text with EEA relevance)

AddedTHE EUROPEAN PARLIAMENT AND THE COUNCIL OF THE EUROPEAN UNION,

AddedHaving regard to the Treaty on the Functioning of the European Union, and in particular Article 16(2), in conjunction with Article 114(1) thereof,

AddedHaving regard to the proposal from the European Commission,

AddedAfter transmission of the draft legislative act to the national parliaments,

AddedHaving regard to the opinion of the European Economic and Social Committee,

AddedActing in accordance with the ordinary legislative procedure,

AddedWhereas:

Added(1) Directive 2002/58/EC of the European Parliament and of the Council lays down rules ensuring the right to privacy and confidentiality with respect to the processing of personal data in exchanges of data in the electronic communication sector. That Directive particularises and complements Regulation (EU) 2016/679 of the European Parliament and of the Council.

Added(2) Directive 2002/58/EC applies to the processing of personal data in connection with the provision of publicly available electronic communication services. Until 21 December 2020, the definition of ‘electronic communication service’ set out in Article 2, point (c), of Directive 2002/21/EC of the European Parliament and of the Council applied. On that date, Directive (EU) 2018/1972 of the European Parliament and of the Council repealed Directive 2002/21/EC. The definition of ‘electronic communications service’ in Article 2, point (4), of Directive (EU) 2018/1972 includes number-independent interpersonal communications services as defined in Article 2, point (7), of that Directive. Number-independent interpersonal communications services, which include, for example, Voice over internet Protocol, messaging and web-based email services, were therefore brought within the scope of Directive 2002/58/EC on 21 December 2020.

Added(3) In accordance with Article 6(1) of the Treaty on European Union (TEU), the Union recognises the rights, freedoms and principles set out in the Charter of Fundamental Rights of the European Union (the ‘Charter’). Article 7 of the Charter protects the fundamental right of everyone to respect for private and family life, home and communications, which includes the confidentiality of communications. Article 8 of the Charter contains the right to the protection of personal data.

Added(4) Article 3(1) of the 1989 United Nations Convention on the Rights of the Child (UNCRC) and Article 24(2) of the Charter provide that, in all actions relating to children, whether taken by public authorities or private institutions, the child’s best interests must be a primary consideration. Article 3(2) UNCRC and Article 24(1) of the Charter furthermore evoke the right of children to such protection and care as is necessary for their well-being.

Added(5) The protection of children, both offline and online, is one of the Union’s priorities. Sexual abuse and sexual exploitation of children constitute serious violations of human and fundamental rights, in particular of the rights of children to be protected from all forms of violence, abuse and neglect, maltreatment or exploitation, including sexual abuse, as provided for by the UNCRC and by the Charter. Digitalisation has brought about many benefits for society and the economy, but it has also brought about challenges, including an increase of online child sexual abuse. On 24 July 2020, the Commission adopted a communication entitled ‘EU strategy for a more effective fight against child sexual abuse’ (the ‘Strategy’). The Strategy aims to provide an effective response, at Union level, to the crime of child sexual abuse.

Added(6) In line with Directive 2011/93/EU of the European Parliament and of the Council, this Regulation does not govern Member States’ policies with regard to consensual sexual activities in which children may be involved and which can be regarded as the normal discovery of sexuality in the course of human development, taking into account the different cultural and legal traditions and of new forms of establishing and maintaining relations among children and adolescents, including through information and communication technologies.

Added(7) Some providers of certain number-independent interpersonal communications services (‘providers’), such as webmail and messaging services, use specific technologies on a voluntary basis to detect online child sexual abuse on their services and report it to law enforcement authorities and to organisations acting in the public interest against child sexual abuse, by scanning either the content, such as images and text, or the traffic data of communications using, in some instances, historical data. The technology used for those activities could be hashing technology for images and videos and classifiers and artificial intelligence for analysing text or traffic data. When using hashing technology, online child sexual abuse material is reported when a positive hit is returned, which means a match resulting from a comparison between an image or a video and a unique, non-reconvertible digital signature (‘hash’) from a database maintained by an organisation acting in the public interest against child sexual abuse that contains verified online child sexual abuse material. Those providers refer to national hotlines for reporting online child sexual abuse material and to organisations, located both within the Union and in third countries, whose purpose is to identify children, reduce child sexual exploitation and sexual abuse and prevent child victimisation. Such organisations might not fall within the scope of Regulation (EU) 2016/679. Collectively, such voluntary activities play a valuable role in enabling the identification and rescue of victims, whose fundamental rights to human dignity and to physical and mental integrity are severely violated. Such voluntary activities are also important in reducing the further dissemination of online child sexual abuse material and in contributing to the identification and investigation of offenders and to the prevention, detection, investigation and prosecution of child sexual abuse offences.

Added(8) Notwithstanding their legitimate objective, voluntary activities by providers to detect online child sexual abuse on their services and report it constitute an interference with the fundamental rights to respect for private and family life and to the protection of personal data of all users of number-independent interpersonal communications services (‘users’). Any limitation to the exercise of the fundamental right to respect for private and family life, including the confidentiality of communications, cannot be justified merely on the grounds that providers were using certain technologies at a time when number-independent interpersonal communications services did not fall within the definition of ‘electronic communications services’. Such limitations are only possible under certain conditions. Pursuant to Article 52(1) of the Charter, such limitations are to be provided for by law and are to respect the essence of the rights to private and family life and to the protection of personal data and, subject to the principle of proportionality, they are to be necessary and to genuinely meet objectives of general interest recognised by the Union or the need to protect the rights and freedoms of others. Where such limitations permanently involve a general and indiscriminate monitoring and analysis of the communications of all users, they interfere with the right to confidentiality of communications.

Added(9) Until 20 December 2020, the processing of personal data by providers by means of voluntary measures for the purpose of detecting online child sexual abuse on their services and reporting it and removing online child sexual abuse material from their services was governed solely by Regulation (EU) 2016/679. Directive (EU) 2018/1972, which was to be transposed by 20 December 2020, brought providers within the scope of Directive 2002/58/EC.

Added(10) Regulation (EU) 2021/1232 of the European Parliament and of the Council provided for a temporary regime as regards of the use of technologies by providers of publicly available number-independent interpersonal communications services for the purpose of combating online child sexual abuse, pending the adoption of a long-term legal framework addressing the prevention of and combating online child sexual abuse (the ‘long-term legal framework’). Regulation (EU) 2021/1232 was amended by Regulation (EU) 2024/1307 of the European Parliament and of the Council, extending the period of application of that Regulation until 3 April 2026.

Added(11) The proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse, which the Commission adopted on 11 May 2022, aims to provide the long-term legal framework. The interinstitutional negotiations on that proposal are still ongoing.

Added(12) On 19 December 2025 the Commission proposed to extend the period of application of Regulation (EU) 2021/1232, by two years until 3 April 2028. As the co-legislators were not able to reach an agreement on that proposal by 3 April 2026, Regulation (EU) 2021/1232 has expired.

Added(13) Given the importance of effectively combatting child sexual abuse online and pending the adoption and application of the long-term legal framework, it is necessary to allow for a temporary derogation from Article 5(1) and Article 6(1) of Directive 2002/58/EC in compliance with the conditions set out in this Regulation. Given the particular circumstances, the period of application of this Regulation should be limited to the time necessary to allow the long-term legal framework to be adopted and to be applied.

Added(14) Directive 2002/58/EC does not contain any specific provisions concerning the processing of personal data by providers in connection with the provision of electronic communication services for the purpose of detecting online child sexual abuse on their services and reporting it and removing online child sexual abuse material from their services. However, pursuant to Article 15(1) of Directive 2002/58/EC, Member States can adopt legislative measures to restrict the scope of the rights and obligations provided for in, inter alia, Articles 5 and 6 of that Directive, which concern the confidentiality of communications and traffic data, for the purposes of the prevention, detection, investigation and prosecution of criminal offences linked to child sexual abuse. In the absence of such national legislative measures and pending the adoption of a longer-term legal framework to tackle child sexual abuse at Union level, providers can no longer rely on Regulation (EU) 2016/679 to continue to use voluntary measures to detect online child sexual abuse on their services and report it and to remove online child sexual abuse material from their services beyond 21 December 2020. While this Regulation does not provide for a legal ground for the processing of personal data by providers for the sole purpose of detecting online child sexual abuse on their services and reporting it and removing online child sexual abuse material from their services, it provides for a derogation from certain provisions of Directive 2002/58/EC. This Regulation lays down additional safeguards which are to be respected by providers if they wish to rely on it.

Added(15) Processing of data for the purposes of this Regulation could entail the processing of special categories of personal data as set out in Regulation (EU) 2016/679. Processing of images and videos by specific technical means which allow for the unique identification or authentication of a natural person is considered processing of special categories of personal data.

Added(16) This Regulation provides for a temporary derogation from Article 5(1) and Article 6(1) of Directive 2002/58/EC, which protect the confidentiality of communications and traffic data. The voluntary use by providers of technologies for the processing of personal and other data to the extent necessary to detect online child sexual abuse on their services and report it and to remove online child sexual abuse material from their services falls within the scope of the derogation provided for by this Regulation provided that such use complies with the conditions set out in this Regulation and is therefore subject to the safeguards and conditions set out in Regulation (EU) 2016/679.

Added(17) Directive 2002/58/EC was adopted on the basis of Article 114 of the Treaty on the Functioning of the European Union (TFEU). Moreover, not all Member States have adopted legislative measures in accordance with Directive 2002/58/EC to restrict the scope of the rights and obligations related to the confidentiality of communications and traffic data as set out in that Directive, and the adoption of such measures involves a significant risk of fragmentation likely to negatively affect the internal market. Consequently, this Regulation should be based on Article 114 TFEU.

Added(18) Given that data related to electronic communications involving natural persons usually qualify as personal data, this Regulation should also be based on Article 16 TFEU, which provides a specific legal basis for the adoption of rules relating to the protection of individuals with regard to the processing of personal data by Union institutions, bodies, offices and agencies, and by the Member States when carrying out activities which fall within the scope of Union law, and rules relating to the free movement of such data.

Added(19) Regulation (EU) 2016/679 applies to the processing of personal data in connection with the provision of electronic communications services by providers for the sole purpose of detecting online child sexual abuse on their services and reporting it and removing online child sexual abuse material from their services to the extent that that processing falls within the scope of the derogation provided for by this Regulation.

Added(20) The types of technologies used for the purposes of this Regulation should be the least privacy-intrusive in accordance with the state of the art in the industry. Those technologies should not be used to systematically filter and scan text in communications unless it is solely to detect patterns which point to possible concrete reasons for suspecting online child sexual abuse, and they should not be able to deduce the substance of the content of the communications. In the case of technology used for identifying solicitation of children, such concrete reasons for suspicion should be based on objectively identified risk factors such as age difference and the likely involvement of a child in the scanned communication.

Added(21) Appropriate procedures and redress mechanisms should be put in place to ensure that individuals can lodge complaints with providers. Such procedures and mechanisms are, in particular, relevant where content that does not constitute online child sexual abuse has been removed or reported to law enforcement authorities or to an organisation acting in the public interest against child sexual abuse.

Added(22) In order to ensure accuracy and reliability as much as possible, technology used for the purposes of this Regulation should, in accordance with the state of the art in the industry, limit the numbers and ratios of errors (false positives) to the maximum extent possible and should, where necessary, rectify without delay any such errors that might nonetheless occur.

Added(23) The content data and traffic data processed and the personal data generated when carrying out the activities covered by this Regulation, and the period during which the data are subsequently stored in the event of the identification of suspected online child sexual abuse, should remain limited to what is strictly necessary to carry out those activities. Any data should be immediately and permanently deleted as soon as they are no longer strictly necessary for one of the purposes specified in this Regulation, including where no suspected online child sexual abuse is identified, and in any event no later than 12 months from the date of the detection of suspected online child sexual abuse. This should be without prejudice to the possibility to store relevant content data and traffic data in accordance with Directive 2002/58/EC. This Regulation does not affect the application of any legal obligation under Union or national law to preserve data that applies to providers.

Added(24) This Regulation does not prevent a provider that has reported online child sexual abuse to law enforcement authorities from requesting those authorities to acknowledge receipt of the report.

Added(25) In order to ensure transparency and accountability in respect of the activities undertaken pursuant to the derogation provided for by this Regulation, providers should, by six months from the date of its entry into force, and by 31 January every year thereafter, publish and submit reports to the competent supervisory authority designated pursuant to Regulation (EU) 2016/679 (‘supervisory authority’) and to the Commission. Such reports should cover processing falling within the scope of this Regulation, including the type and volumes of data processed, the specific grounds relied on for the processing of personal data pursuant to Regulation (EU) 2016/679, the grounds relied on for transfers of personal data outside the Union pursuant to Chapter V of Regulation (EU) 2016/679, where applicable, the number of cases of online child sexual abuse identified, differentiating between online child sexual abuse material and solicitation of children, the number of cases in which a user has lodged a complaint with the internal redress mechanism or sought a judicial remedy and the outcome of such complaints and judicial proceedings, the numbers and ratios of errors (false positives) of the different technologies used, the measures applied to limit the error rate and the error rate achieved, the retention policy and the data protection safeguards applied pursuant to Regulation (EU) 2016/679, and the names of the organisations acting in the public interest against child sexual abuse with which data have been shared pursuant to this Regulation.

Added(26) It is necessary to ensure reporting to the Commission both from the Member States and from providers of number-independent interpersonal communication services. It is also important to stress that the Commission should report on the implementation of this Regulation in a timely manner.

Added(27) In order to facilitate reporting by providers of number-independent interpersonal communications services, in particular to ensure that their reports are machine readable and easily accessible, a common reporting format for those reports should be established.

Sources & citation

Where the facts on this page come from, and how to cite it.

Data source
Licensed CC BY 4.0.
Retrieved
27 September 2026

Cite as

European Parliament (2026). “Changes between TA-10-2026-0095 and TA-10-2026-0266”. Text, 9 July 2026. from TA-10-2026-0095, to TA-10-2026-0266. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/TA-10-2026-0095/compare/TA-10-2026-0266?all=1 (retrieved 27 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2026-07-09,
  author = {{European Parliament}},
  title = {{Changes between TA-10-2026-0095 and TA-10-2026-0266}},
  year = {2026},
  date = {2026-07-09},
  howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/TA-10-2026-0095/compare/TA-10-2026-0266?all=1}},
  url = {https://news.eu-parl.st-solutions.dev/texts/TA-10-2026-0095/compare/TA-10-2026-0266?all=1},
  urldate = {2026-09-27},
  publisher = {EU Parl Watch Research},
  note = {Text. from TA-10-2026-0095, to TA-10-2026-0266. Data: European Parliament Open Data (CC BY 4.0)}
}