Text · Comparison of two versions
Changes from adopted text to adopted text
TA-10-2026-0095 → TA-10-2026-0266
- From
- TA-10-2026-0095 Adopted text of 26 Mar 2026
- To
- TA-10-2026-0266 Adopted text of 9 Jul 2026
- Changes
- Not comparable
- Paragraphs
- +156 added · −8 removed · 4 changed
More facts (2)
- Title (from)
- Amending Regulation (EU) 2021/1232 as regards the extension of its period of application
- Title (to)
- Temporary derogation from the ePrivacy directive
These two texts have too little in common to be compared paragraph by paragraph (under 15 % of their paragraphs match): they are different documents rather than versions of one — for example a group’s motion and the joint text that was adopted.
Every difference
The full paragraph comparison, packaging included; long runs of unchanged paragraphs are folded. One part of the text per page.
Part 2 of 3: Paragraphs 61–120
Added(28) In order to ensure uniform conditions for the implementation of Article 3(1), point (g)(vii), of this Regulation, implementing powers should be conferred on the Commission. Those powers should be exercised in accordance with Regulation (EU) No 182/2011 of the European Parliament and of the Council.
Added(29) In order to support the supervisory authorities with their tasks, the Commission should request the European Data Protection Board to issue guidelines on the compliance of processing falling within the scope of the derogation laid down in this Regulation with Regulation (EU) 2016/679. When the supervisory authorities assess whether an established or new technology to be used is in accordance with the state of the art in the industry, the least privacy-intrusive and operating on an adequate legal basis under Regulation (EU) 2016/679, those guidelines should, in particular, assist the supervisory authorities in providing advice in the framework of the prior consultation procedure set out in that Regulation.
Added(30) This Regulation restricts the right to protection of the confidentiality of communications and derogates from the decision taken under Directive (EU) 2018/1972 to subject number-independent interpersonal communications services to the same rules that apply to all other electronic communications services as regards privacy for the sole purpose of detecting online child sexual abuse on those services and reporting it to law enforcement authorities or to organisations acting in the public interest against child sexual abuse and removing online child sexual abuse material from those services.
Added(31) With regard to all other activities that fall within the scope of Directive 2002/58/EC, providers should be subject to the specific obligations set out in that Directive and, consequently, to the monitoring and investigative powers of the competent authorities designated pursuant to that Directive.
Added(32) End-to-end encryption is an important tool to guarantee the security and confidentiality of the communications of users, including those of children. Any weakening of encryption could potentially be abused by malicious third parties. Nothing in this Regulation should therefore be interpreted as prohibiting or weakening end-to-end encryption.
Added(33) The right to respect for private and family life, including the confidentiality of communications, is a fundamental right guaranteed under Article 7 of the Charter. It is thus also a prerequisite for secure communications between victims of child sexual abuse and a trusted adult or organisations active in the fight against child sexual abuse and for communications between victims and their lawyers.
Added(34) This Regulation should be without prejudice to the rules on professional secrecy under national law, such as rules on the protection of professional communications, between doctors and their patients, between journalists and their sources, or between lawyers and their clients, in particular since the confidentiality of communications between lawyers and their clients is key to ensuring the effective exercise of the rights of the defence as an essential part of the right to a fair trial. This Regulation should also be without prejudice to national rules on registers of public authorities or organisations which offer counselling to individuals in distress.
Added(35) Providers should communicate to the Commission the names of the organisations acting in the public interest against child sexual abuse to which they report potential online child sexual abuse under this Regulation. While it is the sole responsibility of the providers acting as controllers to assess with which third party they can share personal data under Regulation (EU) 2016/679, the Commission should ensure transparency regarding the transfer of potential cases of online child sexual abuse by making public on its website a list of the organisations acting in the public interest against child sexual abuse communicated to it. That public list should be easily accessible. It should also be possible for providers to use that list in order to identify relevant organisations in the global fight against online child sexual abuse. That list should be without prejudice to the obligations of the providers acting as controllers under Regulation (EU) 2016/679, including with regard to their obligation to conduct any transfer of personal data outside the Union, pursuant to Chapter V thereof, and their obligation to fulfil all of the obligations, pursuant to Chapter IV thereof.
Added(36) The statistics to be provided by Member States under this Regulation are important indicators for the evaluation of policy, including legislative measures. In addition, it is important to recognise the impact of secondary victimisation inherent in the sharing of images and videos of victims of child sexual abuse that might have been circulating for years and which is not fully reflected in such statistics.
Added(37) In line with the requirements laid down in Regulation (EU) 2016/679, in particular the requirement that Member States ensure that supervisory authorities are provided with the human, technical and financial resources necessary for the effective performance of their tasks and exercise of their powers, Member States should ensure that supervisory authorities have such sufficient resources for the effective performance of their tasks and exercise of their powers under this Regulation.
Added(38) Where a provider has conducted a data protection impact assessment and consulted the supervisory authorities with regard to a technology in accordance with Regulation (EU) 2016/679 prior to the entry into force of this Regulation, that provider should not be obliged under this Regulation to carry out an additional data protection impact assessment or consultation provided that the supervisory authorities have indicated that the processing of data by that technology would not result in a high risk to the rights and freedoms of natural persons or that measures have been taken by the controller to mitigate such a risk.
Added(39) Users should have the right to an effective judicial remedy where their rights have been infringed as a result of the processing of personal and other data for the purpose of detecting online child sexual abuse on number-independent interpersonal communications services and reporting it and removing online child sexual abuse material from those services, for instance where a user’s content or identity have been reported to an organisation acting in the public interest against child sexual abuse or to law enforcement authorities or where a user’s content has been removed or a user’s account has been blocked or a service offered to a user has been suspended.
Added(40) In line with Directive 2002/58/EC and the principle of data minimisation, the processing of personal and other data should be limited to content data and related traffic data, in as far as strictly necessary to achieve the purpose of this Regulation.
Added(41) The derogation provided for by this Regulation should extend to the categories of data referred to in Article 5(1) and Article 6(1) of Directive 2002/58/EC, which are applicable to the processing of both personal and non-personal data processed in the context of the provision of a number-independent interpersonal communications service.
Added(42) The objective of this Regulation is to create a temporary derogation from certain provisions of Directive 2002/58/EC without creating fragmentation in the internal market. In addition, it is unlikely that all Member States could adopt national legislative measures in time. Since the objective of this Regulation cannot be sufficiently achieved by the Member States but can rather be better achieved at Union level, the Union may adopt measures, in accordance with the principle of subsidiarity as set out in Article 5 TEU. In accordance with the principle of proportionality as set out in that Article, this Regulation does not go beyond what is necessary in order to achieve that objective. It introduces a temporary and strictly limited derogation from the applicability of Article 5(1) and Article 6(1) of Directive 2002/58/EC, with a series of safeguards to ensure that it does not go beyond what is necessary for the achievement of the set objective.
Added(43) Considering the need to ensure, in a timely manner, legal certainty given the expiration of Regulation (EU) 2021/1232, this Regulation should enter into force as soon as possible.
Added(44) The European Data Protection Supervisor was consulted in accordance with Article 42(1) of Regulation (EU) 2018/1725 of the European Parliament and of the Council and delivered its opinion on 16 February 2026,
AddedHAVE ADOPTED THIS REGULATION:
AddedArticle 1 Subject matter and scope
Added1. This Regulation lays down temporary and strictly limited rules derogating from certain obligations laid down in Directive 2002/58/EC, with the sole objective of enabling providers of certain number-independent interpersonal communications services (‘providers’) to use, without prejudice to Regulation (EU) 2016/679, specific technologies for the processing of personal and other data to the extent strictly necessary to detect online child sexual abuse on their services and report it and to remove online child sexual abuse material from their services.
Added2. This Regulation does not apply to the scanning of audio communications.
Added2a. This Regulation does not apply to interpersonal communications to which end-to-end encryption is, has been or will be applied. [Am. 30]
AddedArticle 2 Definitions
AddedFor the purposes of this Regulation, the following definitions apply:
Added(1) ‘number-independent interpersonal communications service’ means a number-independent interpersonal communications service as defined in Article 2, point (7), of Directive (EU) 2018/1972;
Added(2) ‘online child sexual abuse material’ means:
Added(a) child pornography as defined in Article 2, point (c), of Directive 2011/93/EU;
Added(b) pornographic performance as defined in Article 2, point (e), of Directive 2011/93/EU;
Added(3) ‘solicitation of children’ means any intentional conduct constituting a criminal offence under Article 6 of Directive 2011/93/EU;
Added(4) ‘online child sexual abuse’ means online child sexual abuse material and solicitation of children.
AddedArticle 3 Scope of the derogation
Added1. Article 5(1) and Article 6(1) of Directive 2002/58/EC shall not apply to the confidentiality of communications involving the processing by providers of personal and other data in connection with the provision of number-independent interpersonal communications services provided that:
Added(a) the processing is:
Added(i) strictly necessary for the use of specific technology for the sole purpose of detecting and removing online child sexual abuse material and reporting it to law enforcement authorities and to organisations acting in the public interest against child sexual abuse and of detecting solicitation of children and reporting it to law enforcement authorities or organisations acting in the public interest against child sexual abuse;
Added(ia) not applied to interpersonal communications to which end-to-end encryption is, has been or will be applied; [Am. 26cp3, 31cp3, 6 and 21]
Added(ii) proportionate and limited to technologies used by providers for the purposes set out in point (i);
Added(iii) limited to content data and related traffic data that are strictly necessary for the purposes set out in point (i);
Added(iv) limited to what is strictly necessary for the purposes set out in point (i);
Added(b) the technologies used for the purposes set out in point (a)(i) of this paragraph are in accordance with the state of the art in the industry and are the least privacy-intrusive, including with regard to the principle of data protection by design and by default laid down in Article 25 of Regulation (EU) 2016/679 and, to the extent that they are used to scan text in communications, they are not able to deduce the substance of the content of the communications but are solely able to detect patterns which point to possible online child sexual abuse;
Added(c) in respect of any specific technology used for the purposes set out in point (a)(i) of this paragraph, a prior data protection impact assessment as referred to in Article 35 of Regulation (EU) 2016/679 and a prior consultation procedure as referred to in Article 36 of that Regulation have been conducted;
Added(d) with regard to new technology, meaning technology used for the purpose of detecting online child sexual abuse material that has not been used by any provider in relation to services provided to users of number-independent interpersonal communications services (‘users’) in the Union before … [the date of entry into force of this Regulation], and with regard to technology used for the purpose of identifying possible solicitation of children, the provider reports back to the competent authority on the measures taken to demonstrate compliance with written advice issued in accordance with Article 36(2) of Regulation (EU) 2016/679 by the competent supervisory authority designated pursuant to Chapter VI, Section 1, of that Regulation (‘supervisory authority’) in the course of the prior consultation procedure;
Added(e) the technologies used are sufficiently reliable in that they limit to the maximum extent possible the rate of errors regarding the detection of content representing online child sexual abuse and, where such occasional errors occur, their consequences are rectified without delay;
Added(f) the technologies used to detect patterns of possible solicitation of children are limited to the use of relevant key indicators and objectively identified risk factors such as age difference and the likely involvement of a child in the scanned communication, without prejudice to the right to human review;
Added(g) the providers:
Added(i) have established internal procedures to prevent abuse of, unauthorised access to, and unauthorised transfers of, personal and other data;
Added(ii) ensure human oversight of and, where necessary, human intervention in the processing of personal and other data using technologies falling under this Regulation;
Added(iii) ensure that material not previously identified as online child sexual abuse material, or solicitation of children, is not reported to law enforcement authorities or organisations acting in the public interest against child sexual abuse without prior human confirmation;
Added(iv) have established appropriate procedures and redress mechanisms to ensure that users can lodge complaints with them within a reasonable timeframe for the purpose of presenting their views;
Added(v) inform users in a clear, prominent and comprehensible way of the fact that they have invoked, in accordance with this Regulation, the derogation from Article 5(1) and Article 6(1) of Directive 2002/58/EC concerning the confidentiality of users’ communications solely for the purposes set out in point (a)(i) of this paragraph, the logic behind the measures they have taken under the derogation and the impact on the confidentiality of users’ communications, including the possibility that personal data are shared with law enforcement authorities and organisations acting in the public interest against child sexual abuse;
Added(vi) inform users of the following, where their content has been removed or their account has been blocked or a service offered to them has been suspended:
Added(1) the avenues for seeking redress from them;
Added(2) the possibility of lodging a complaint with a supervisory authority; and
Added(3) the right to a judicial remedy;
Added(vii) by … [six months after the date of entry into force of this Regulation] and by 31 January every year thereafter, publish and submit to the competent supervisory authority and to the Commission a report on the processing of personal data under this Regulation, including on:
Added(1) the type and volumes of data processed;
Added(2) the specific ground relied on for the processing pursuant to Regulation (EU) 2016/679;
Added(3) the ground relied on for transfers of personal data outside the Union pursuant to Chapter V of Regulation (EU) 2016/679, where applicable;
Added(4) the number of cases of online child sexual abuse identified, differentiating between online child sexual abuse material and solicitation of children;
Added(5) the number of cases in which a user has lodged a complaint with the internal redress mechanism or with a judicial authority and the outcome of such complaints;
Added(6) the numbers and ratios of errors (false positives) of the different technologies used;
Sources & citation
Where the facts on this page come from, and how to cite it.
- Permalink
- https://news.eu-parl.st-solutions.dev/texts/TA-10-2026-0095/compare/TA-10-2026-0266?all=1&part=2
- Data source
- Licensed CC BY 4.0.
- Retrieved
- 29 September 2026
Cite as
European Parliament (2026). “Changes between TA-10-2026-0095 and TA-10-2026-0266”. Text, 9 July 2026. from TA-10-2026-0095, to TA-10-2026-0266. EU Parl Watch Research. https://news.eu-parl.st-solutions.dev/texts/TA-10-2026-0095/compare/TA-10-2026-0266?all=1&part=2 (retrieved 29 September 2026). Data: European Parliament Open Data, https://data.europarl.europa.eu/ (CC BY 4.0).
BibTeX
@misc{epw-text-2026-07-09,
author = {{European Parliament}},
title = {{Changes between TA-10-2026-0095 and TA-10-2026-0266}},
year = {2026},
date = {2026-07-09},
howpublished = {\url{https://news.eu-parl.st-solutions.dev/texts/TA-10-2026-0095/compare/TA-10-2026-0266?all=1&part=2}},
url = {https://news.eu-parl.st-solutions.dev/texts/TA-10-2026-0095/compare/TA-10-2026-0266?all=1&part=2},
urldate = {2026-09-29},
publisher = {EU Parl Watch Research},
note = {Text. from TA-10-2026-0095, to TA-10-2026-0266. Data: European Parliament Open Data (CC BY 4.0)}
}