Norway’s Data Protection Authority says the EU’s proposed framework for combating online child sexual abuse could go too far by enabling broad scanning of private communications and weakening the practical protections provided by end-to-end encryption. The warning comes as European lawmakers continue negotiating the long-term rules.
The fight over Europe’s proposed “Chat Control” rules is intensifying again, with Norway’s privacy regulator warning that efforts to combat child sexual abuse online could create a system of widespread surveillance of private communications.
In an August 31, 2026 statement, Norway’s Data Protection Authority, Datatilsynet, said it strongly opposes elements of the European Commission’s proposed regulation for preventing and combating online child sexual abuse.
The regulator supports the underlying goal of protecting children and stopping the distribution of child sexual abuse material. Its objection is to how far authorities could potentially go in pursuing that goal.
At the center of the dispute are proposed powers commonly described as “Chat Control”: mechanisms that could require online platforms and communications providers to detect suspected child sexual abuse material and grooming activity within their services.
The concern is that such detection could ultimately encompass private messages, photographs, audio and other communications sent by ordinary users who are not suspected of any crime.
That becomes particularly controversial when the service uses end-to-end encryption.
Norway’s regulator argues that forcing providers to inspect communications before encryption or otherwise circumvent encryption protections would fundamentally alter what users understand private communication to mean.
What Is the EU’s “Chat Control” Proposal?
“Chat Control” is not the formal name of a European law.
It is the term commonly used for controversial detection provisions contained in the European Commission’s proposed regulation to prevent and combat child sexual abuse online.
The Commission originally proposed the long-term regulation in May 2022.
The broader proposal would create obligations for certain digital services to assess the risk that their platforms are being used for child sexual abuse, take steps to reduce those risks, report suspected material and comply with certain orders issued by authorities.
A particularly contentious component of the original proposal involved detection orders.
Under that framework, authorities could potentially require certain hosting or interpersonal communications services to use technology to identify known or previously unknown child sexual abuse material, as well as potential grooming activity.
Unlike conventional content moderation on public websites, this raises questions about private communications.
The original Commission proposal did not simply concern posts visible on social networks or public forums. Detection technologies could potentially be applied to text, images and audio transmitted through private communications services.
That is what triggered the “Chat Control” label and years of political and legal debate.
Why End-to-End Encryption Is at the Center of the Fight
End-to-end encryption is designed so that only the people participating in a conversation can read its contents.
When implemented correctly, the service provider itself does not possess the key necessary to read the message.
A message might leave one person’s phone in encrypted form, travel through the provider’s servers and only become readable again when it reaches the intended recipient.
That architecture is used by services including Signal and WhatsApp to protect private conversations.
The obvious technical problem is that a provider cannot easily scan the content of something it cannot see.
One possible approach is therefore to inspect content before it becomes encrypted on the sender’s device.
That approach, often discussed in connection with client-side scanning, is one of the most controversial elements of the broader Chat Control debate.
From a purely technical perspective, encryption might remain intact while information is transmitted.
From a privacy perspective, however, critics argue that this distinction offers little comfort if software has already inspected the message before encryption takes place.
If every photograph or conversation must first pass through an automated detection system, the practical confidentiality of the communication has changed even if the encrypted transmission itself remains mathematically secure.
Norway’s Privacy Authority Says the Proposal Crosses the Line
Datatilsynet’s objection is rooted in proportionality.
Privacy and confidentiality of communications are protected as fundamental rights in Europe. Governments can interfere with those rights in certain circumstances, particularly when investigating serious crime.
But broad surveillance ordinarily raises a different question than surveillance based on individualized suspicion.
The Norwegian authority argues that the proposed approach risks monitoring entire populations of users rather than individuals suspected of criminal activity.
Most people whose communications would potentially be analyzed would never have done anything wrong.
That is the central legal and philosophical objection.
The goal may be legitimate.
The method may still be disproportionate.
The regulator also argues that child protection and privacy should not be treated as mutually exclusive objectives. Authorities could instead place greater emphasis on targeted interventions, platform design changes and measures that make it harder for adults to approach children online.
There Is Also a Cybersecurity Problem
The controversy is not only about privacy.
Encryption is also a cybersecurity control.
Businesses, governments, journalists, lawyers, healthcare professionals, executives and ordinary individuals rely on encrypted communications because the same systems that prevent providers from reading messages also make interception more difficult for attackers.
Creating a mechanism capable of inspecting otherwise private communications introduces another component into that security architecture.
Critics worry that any mechanism intentionally designed to circumvent the confidentiality provided by encryption could eventually be exploited by someone other than the authority it was designed to assist.
That could include:
- cybercriminals;
- foreign intelligence services;
- hostile governments;
- commercial spyware operators; or
- insiders with unauthorized access.
Norway’s regulator specifically points to people such as whistleblowers and confidential journalistic sources as examples of users who may have legitimate and important reasons for requiring genuinely private communications.
This is why the encryption debate has resisted simple solutions.
A mechanism cannot necessarily distinguish between a vulnerability used for a socially desirable purpose and the same vulnerability exploited by a malicious actor.
Automated Detection Is Not Perfect
Another problem is accuracy.
Automated systems can identify known illegal images through technologies such as cryptographic hashing with a relatively high degree of confidence when they are comparing content against previously identified material.
Finding new illegal content is much harder.
Detecting grooming conversations is harder still.
These systems may require machine learning models to determine whether an image or conversation appears suspicious.
That introduces false positives.
An innocent photograph could potentially resemble content the detection system was trained to identify.
A legitimate conversation could contain words or patterns that an automated system associates with grooming.
The consequences become more serious if flagged communications are automatically escalated to authorities or a centralized European organization.
Norway’s regulator warns that lawful communications could therefore be reported while sophisticated offenders may adapt their behavior to evade detection.
That creates an uncomfortable policy problem: intrusive monitoring does not necessarily guarantee effective monitoring.
The EU’s Current Position Is More Complicated Than the Original Proposal
The status of Chat Control in 2026 requires an important distinction.
There are actually two related legislative tracks.
The first is the permanent regulation proposed by the Commission in 2022. That long-term law remains under negotiation.
The second is a temporary exemption from parts of the EU’s ePrivacy rules that allows certain service providers to voluntarily detect and report child sexual abuse material.
That temporary framework became especially important in 2026.
The previous exemption expired on April 3, creating a temporary legal gap.
European lawmakers subsequently reached a new agreement, and the Council gave final approval on July 23, 2026.
The reinstated temporary regime now runs until April 3, 2028, while lawmakers negotiate the permanent framework.
Crucially, the European Parliament successfully pushed to exclude communications protected by end-to-end encryption from this temporary regime.
The Council ultimately accepted those amendments for the temporary measure.
That does not mean the broader encryption fight has disappeared.
The Council specifically noted that its acceptance of the encryption exclusion in the temporary legislation does not determine its position on the permanent CSAM regulation.
The long-term rules remain the real battleground.
Permanent Rules Are Still Being Negotiated
The Council adopted its negotiating position on the permanent CSAM regulation in November 2025.
That position calls for online services to assess and mitigate child sexual abuse risks and would create mechanisms for reporting, removing and blocking illegal material. It would also establish a dedicated EU body to support the system.
The European Parliament has taken a more protective position toward encryption.
Its negotiating position explicitly states that the regulation should not weaken end-to-end encryption or create a system of generalized monitoring.
Negotiations made significant progress in June 2026.
By the end of that month, negotiators had reportedly reached compromises on most of the proposed regulation, including definitions, reporting, removal, blocking, risk assessments and governance.
Detection remained one of the most difficult unresolved subjects.
That context makes Datatilsynet’s August warning particularly timely.
This is not a debate over a proposal that has quietly disappeared.
European institutions are actively trying to reach a final agreement.
Child Protection Does Not Require Accepting Every Form of Surveillance
One of the weaknesses in the public debate over Chat Control is the tendency to frame the issue as a binary choice.
Either governments gain broad scanning powers or society is failing to protect children.
That is not the only possible policy framework.
Platforms can make structural changes that reduce opportunities for abuse without inspecting every private message.
Possible interventions include restricting unsolicited contact with minors, strengthening account controls for young users, improving reporting mechanisms, identifying accounts engaged in suspicious behavior and designing services so that unknown adults have fewer opportunities to contact children.
European lawmakers have also been developing separate criminal-law measures aimed directly at grooming, AI-generated child sexual abuse material, livestreamed abuse and sextortion. In June 2026, Parliament and the Council reached an agreement on updated criminal-law rules addressing several of those emerging threats.
The policy question is therefore not whether governments should combat child sexual exploitation.
They should.
The harder question is how much surveillance of everyone else should be permitted in the process.
The False-Positive Problem Could Become an AI Governance Issue
The debate also has a growing artificial intelligence component.
Systems attempting to detect previously unknown abusive material or analyze conversations for grooming behavior may depend on automated classification.
Those systems effectively make risk judgments about private communications.
That raises familiar AI governance questions:
What was the system trained on?
What constitutes suspicious behavior?
What is the false-positive rate?
Does a human review a flagged communication?
How can an innocent person challenge an incorrect classification?
How long is flagged information retained?
Who receives it?
Can the detection system itself become a source of sensitive personal data?
These questions become particularly serious when the data involved consists of private conversations and intimate photographs rather than public social-media posts.
An inaccurate advertising algorithm may show someone an irrelevant product.
An inaccurate surveillance system could report an innocent private conversation to authorities.
Those are not comparable errors.
Europe Is Deciding What Private Communication Will Mean
The long-term significance of the Chat Control debate extends well beyond child sexual abuse regulation.
Europe is effectively deciding whether end-to-end encrypted communications should remain technologically inaccessible to intermediaries or whether governments can require some form of automated inspection at the edge of those systems.
The decision could influence messaging platforms globally.
Large technology providers rarely maintain completely independent technical architectures for every jurisdiction. A legal requirement imposed in Europe can therefore influence product design far beyond EU borders.
It could also establish a precedent.
If technology can be required to inspect encrypted communications for one category of serious criminal activity, lawmakers may eventually face pressure to apply similar infrastructure to terrorism, organized crime or other illegal content.
That possibility is one reason privacy regulators and cryptographers have treated the debate so seriously.
Infrastructure created for one objective can later acquire another.
Norway’s Warning Is Ultimately About Proportionality
Datatilsynet is not arguing that digital platforms should ignore child sexual abuse.
Its position is that protecting children does not justify indiscriminate monitoring of private communications.
The regulator wants policymakers to pursue approaches that focus resources and surveillance on genuine risks rather than subjecting every user of a communications service to automated inspection.
That distinction will remain at the center of the EU negotiations.
The temporary European framework now protects end-to-end encrypted communications from voluntary scanning until 2028.
The permanent legislation is not yet settled.
And that means the fundamental question behind “Chat Control” remains unanswered:
Can Europe build an effective system for combating online child sexual abuse without creating infrastructure capable of examining the private communications of everyone else?
Norway’s privacy regulator believes the Commission’s original approach has not yet found that balance.