EU 2026: Chat Control, eIDAS 2.0, Going-Dark Debate

TL;DR. The EU runs the most complex multi-statute surveillance architecture of any jurisdiction in our 34-country comparison. The CSAR proposal (COM/2022/209 final, May 2022) is the live encryption fight. The e-Privacy Directive (2002/58/EC) is the legal base for the scan-or-ban regime, and the ePrivacy derogation that allowed voluntary scanning expired on April 3 2026, ending the lawful basis for any current scanning and triggering the renewed trilogue. eIDAS 2.0 (Regulation (EU) 2024/1183) is the digital identity framework, mandatory for member states, opt-in for users, live from 2026. MiCA (Regulation (EU) 2023/1114) is the crypto framework. The Europol Regulation (EU) 2016/794 is the operational surveillance authority, and the "going dark" debate is the political pressure that drives the encryption fight. The enforcement record is GDPR (1.2B Meta 2023, 530M TikTok 2025), DSA (live proceedings against X and Meta), and AI Act (first enforcement 2025-2026). The right to anonymity in the EU is alive in 2026 (Tor is legal, EDRi is funded, the EDPB enforces GDPR), but the architecture to dismantle it is in place.

2 attacks on encryption

The CSAR proposal (COM/2022/209 final) and the persistent Europol "going dark" push. The e-Privacy Directive is the legal base, and the April 3 2026 expiration of the voluntary-scanning derogation reset the clock on the scan-or-ban fight.

1 identity wallet framework

eIDAS 2.0 (Regulation (EU) 2024/1183) mandates an EU Digital Identity Wallet for every member state by 2026-2027. The wallet is opt-in for users but mandatory for member states to issue.

3 enforcement bodies

The European Data Protection Board (EDPB) for GDPR, the European Commission for DSA and AI Act, and Europol for operational cybercrime coordination. They are independent. They do not coordinate.

20 primary sources

20 sources cited below. Mix of EU primary statute (eur-lex.europa.eu), EDPB and Europol, and the dossier-canonical Wikipedia anchors. Tier 1 (statute and regulator) leads.

6 enforcement cases on file

GDPR record fines (Meta 1.2B in 2023, TikTok 530M in 2025), DSA proceedings against X and Meta, CSAR legislative saga, AI Act first enforcement (2025-2026), ePrivacy derogation April 3 expiration, Signal EU exit threat.

1. End-to-end encryption under CSAR and the e-Privacy Directive

The EU is the jurisdiction that came closest, in the 2022-2026 cycle, to passing a continent-wide law that would mandate client-side scanning of encrypted messages. The Child Sexual Abuse Regulation (CSAR, Commission proposal COM/2022/209 final, May 11 2022) would have required messaging platforms to detect known CSAM and "grooming" patterns, and the only technically feasible detection path is client-side scanning, which breaks the security model of end-to-end messaging.[1][9]

The legal base for any in-message scanning is the e-Privacy Directive (Directive 2002/58/EC), Article 5(3) and Article 15(1). Article 5(3) prohibits the reading, listening, recording, or other kinds of interception of communications content without consent, with limited exceptions. Article 15(1) lets member states restrict the prohibition for national security, defence, public security, and the prevention of crime, subject to necessity and proportionality. The CSAR proposal sits inside Article 15(1), arguing that the prevention of CSAM is a public-security and crime-prevention ground.[3]

The 2024 ePrivacy derogation (Regulation (EU) 2021/1232, as extended) was the temporary lawful basis for voluntary scanning. It allowed messaging providers to scan messages for CSAM on a voluntary basis until April 3 2026. The European Parliament rejected an extension of the derogation in early 2026, and the derogation expired on April 3 2026 without renewal. As of the writing of this page, the legal basis for any in-production voluntary scanning has lapsed, and providers that had implemented CSAM detection under the derogation have either suspended the practice or moved to jurisdiction-specific opt-in. The CSAR proposal itself is in renewed trilogue as of May 2026, with a watered-down text on the table.[2][10]

Signal's response has been the most aggressive. Signal's president Meredith Whittaker stated in 2025 that Signal will withdraw from the EU rather than implement client-side scanning. As of 2026, Signal has not withdrawn. The threat is on file and is the position that has framed the political-economy argument against CSAR: if the largest encrypted messenger exits the EU market, the CSAM-detection gain is offset by the loss of secure-messaging coverage for the population the CSAR was supposed to protect.[11][12]

WhatsApp (Meta) has stated a similar position. Threema, Wire, and Element have all stated the same. The cryptographic community, organized through the Global Encryption Coalition and the IETF, has been unanimous since 2021 that client-side scanning breaks the security model of end-to-end messaging regardless of whether the scan happens on the device or on a server, because the detection pipeline must be present in the same trust domain as the message content.[13]

The "going dark" argument, advanced by Europol since at least 2016 and intensified in the 2024-2026 CSAR cycle, is that encryption is a barrier to law enforcement access to evidence. The argument is contested. Empirical research by EDRi and academic groups has shown that the marginal cases that "going dark" rhetoric relies on are a small fraction of total criminal evidence, and that the volume of lawfully-accessible digital evidence is increasing, not decreasing. The EU Court of Justice (CJEU) has, in 2020-2024 decisions on data retention (Cases C-511/18, C-623/17, C-520/21), narrowed the conditions under which general and indiscriminate retention of communications metadata is permissible, and has signaled that retention of communications content is permissible only on a case-by-case, targeted basis.[8]

The trilogue resumed in May 2026. The Council's May 2026 position is a watered-down version of the original CSAR: detection is opt-in for users, scanning is risk-based rather than per-message, and the "grooming detection" requirement is dropped. The Parliament's position is closer to the original proposal but with stronger judicial oversight. The May 4 2026 trilogue did not reach agreement, and the next round is scheduled for late June 2026. The ePrivacy derogation expiration on April 3 has changed the political dynamic: there is no longer a "temporary" lawful basis, and the choice is now between passing CSAR (or a successor instrument) and accepting that any future in-message scanning requires new primary legislation.[14]

2. Digital ID and the EU Digital Identity Wallet (eIDAS 2.0)

The EU's digital identity framework is eIDAS 2.0, the successor to eIDAS 1.0 (Regulation (EU) 910/2014). The new regulation is Regulation (EU) 2024/1183, adopted by the European Parliament on February 29 2024 and by the Council on March 26 2024. The headline change is the mandatory EU Digital Identity Wallet: every member state must make a wallet available to its residents by December 2026, with full functionality live by 2027.[4]

The wallet is opt-in for users, but mandatory for member states to issue. Users can use the wallet to authenticate to public services, to qualify electronic signatures, to verify their age, and to share attestations (driver's license, diploma, professional qualification, medical prescription). The technical architecture is a smartphone-resident wallet that stores verifiable credentials (W3C VC standard) and presents them to relying parties on demand. The wallet is issued by the member state, but the user controls the data shared: each presentation is a minimum-disclosure cryptographic proof, not a full credential disclosure.

The age-verification use case is the most contentious. The eIDAS 2.0 framework explicitly contemplates the wallet being used to prove "I am over 18" or "I am over 16" without disclosing the user's date of birth. The implementation specification, published by the European Commission in late 2025, requires that the wallet support a "zero-knowledge proof of age" mode. The technical approach has been validated by the cryptography community; the policy question is whether the wallet will be the de facto age-verification stack for the OSA (UK), CSAR (EU), and national age-verification regimes (Germany, France, Italy).[5]

The eIDAS 2.0 implementation is uneven. Germany and Italy have been the most aggressive in wallet development, with pilot programs in 2025 covering public services and a subset of private-sector use cases. France has lagged, in part because the national digital identity framework (FranceConnect) is already a mature system and the eIDAS wallet is being positioned as a complement, not a replacement. The Netherlands and Spain have been slow. The smaller member states (Malta, Estonia, the Baltic states) have used the eIDAS opportunity to consolidate and modernize their national identity stacks. The December 2026 deadline is widely expected to be missed by a meaningful number of member states, with formal extensions to 2027-2028 likely.[4]

The interaction between eIDAS 2.0 and CSAR is the politically sensitive piece. The CSAR debate, in 2024-2026, has explicitly referenced the eIDAS wallet as a potential age-verification mechanism for "grooming detection" (the requirement that platforms detect when an adult is trying to groom a child). The technical argument is that the wallet could prove the user's age bracket without disclosing identity, and the platform could enforce the age gate without scanning the message. The civil-liberties objection is that the eIDAS wallet becomes the single point of identity proof for every regulated interaction on the internet, and the metadata of every age-verification request becomes a surveillance dataset. EDRi and the EDPB have both flagged this concern.[9]

For EU-based readers: the practical risk today is not that the eIDAS wallet is mandatory to use. It is that (a) regulated services (banking, public services, age-restricted content) will increasingly require the wallet, (b) the wallet's metadata (which relying party requested which attestation) becomes a permanent ledger of the user's online activity, and (c) the CSAR scan-or-ban fight uses the wallet as a political compromise, with the cost being a permanent identity layer that the platform layer then relies on. The architecture is in place. The merging instruments have not been issued. See our EU AI Act biometric surveillance explainer for the parallel read on the AI-driven identity-verification regime.

3. Anonymity networks and the e-Privacy framework

As of mid-2026, Tor is legal in every EU member state. There is no EU-level statute criminalising the use of Tor, I2P, or comparable anonymity networks. The e-Privacy Directive (2002/58/EC) protects the confidentiality of communications content and metadata, with the Article 5(3) consent rule applying to the storage of and access to information stored on a user's terminal equipment (cookies, fingerprinting, etc.). The e-Privacy framework predates Tor's mainstream adoption and is technology-neutral on anonymity networks: the question is whether the use of the network is "interception" (prohibited) or "communication" (protected). The CJEU has not ruled on Tor specifically, but the framework's logic extends to Tor as a "communication" technology.[3]

EDRi (European Digital Rights), a Brussels-based NGO with member organizations in 19 EU member states, has been the consistent civil-society advocate for anonymity in the EU policy process. EDRi's position, articulated in 2023-2026 submissions to the Commission and the Parliament, is that anonymity is a necessary precondition for the exercise of other rights (whistleblowing, journalism, activism, religious practice) and that the legal presumption should be in favor of anonymity, not against it.[15]

The legal pressure on anonymity in the EU is indirect and cuts through three channels. First, the CSAR scan-or-ban regime, if passed in any form that requires "risk-based" detection, would functionally require platforms to de-anonymize users for the purpose of detection. The detection pipeline (whether client-side or server-side) is, by definition, a de-anonymization pipeline. Second, the Europol "going dark" push has, since 2016, framed encryption and anonymity as twin threats to law enforcement access. The Europol Regulation (EU) 2016/794 was amended in 2022 (Regulation (EU) 2022/991) to explicitly authorize Europol to process "large datasets" for the purpose of research and innovation, and the practical effect has been to broaden the scope of metadata analysis. Third, the CJEU data-retention case law (Cases C-511/18, C-623/17, C-520/21) has narrowed the conditions under which general and indiscriminate retention of communications metadata is permissible, but has not foreclosed targeted retention. The combined effect is that anonymity is legally protected at the user level but operationally narrowed at the platform and network levels.

VPNs are legal and widely used in the EU. There is no EU-level statute criminalising the use of a commercial VPN, and the e-Privacy Directive's consent rule applies to the VPN provider in its capacity as a communications service. The AMLD 5 (Directive (EU) 2018/843) and the AMLD 6 (Directive (EU) 2024/1640) require VPN providers offering services in the EU to register with national authorities and to apply customer due diligence. The 2024 AMLD 6 also brought "fully decentralised" wallet providers and anonymous crypto-asset transfers above EUR 1,000 into the AML perimeter.[7]

For EU-based readers: the practical risk today is not that Tor itself is illegal. It is that (a) CSAR, in any form, would create a de-anonymization duty on platforms, (b) the eIDAS 2.0 wallet becomes the de facto identity layer that platforms rely on for age-verification, and (c) the metadata of wallet-based age-verification becomes a permanent record. The architecture of anonymity survives; the platforms that connect anonymized users to the rest of the web are under pressure. See our EU Digital Omnibus analysis for the broader deregulatory pressure on the e-Privacy framework.

4. Crypto regulation: MiCA and the AMLD travel rule

The EU's crypto framework is the Markets in Crypto-Assets Regulation (MiCA, Regulation (EU) 2023/1114), adopted by the European Parliament on April 20 2023 and by the Council on May 16 2023, and fully applicable from December 30 2024. MiCA is the world's first sector-wide crypto regulation and covers asset-referenced tokens (ARTs, including stablecoins), e-money tokens (EMTs), and other crypto-assets that are not already covered by existing financial regulation.[6]

MiCA's headline requirements: issuers of ARTs and EMTs must be authorized by a national competent authority and must meet capital, governance, and disclosure requirements. The European Banking Authority (EBA) coordinates ART/EMT authorization at the EU level for "significant" tokens (those with more than EUR 1 billion in users, more than 10 million transactions per quarter, or other systemic indicators). Crypto-asset service providers (CASPs) must be authorized, must apply AML/CFT measures, must publish a "white paper" for each crypto-asset they offer, and must apply consumer-protection rules (right of withdrawal, complaint handling, conflict-of-interest rules).[5]

Self-custody is not prohibited in the EU. There is no provision in MiCA that requires an EU user to surrender control of private keys, and the recitals explicitly confirm that "unhosted wallets" are not, by themselves, regulated. The travel rule (TFR, Regulation (EU) 2023/1113) applies at the CASP boundary, not at the self-custody boundary: CASPs must collect and transmit originator and beneficiary information on transfers above EUR 1,000. The practical effect is that an EU user can hold self-custodied bitcoin in a hardware wallet without any regulatory interaction. The moment the user wants to convert self-custodied crypto to fiat through an EU-regulated CASP, the TFR travel rule kicks in and the CASP must collect counterparty information.[7]

MiCA's "significant" stablecoin regime has been the most operationally consequential. Tether (USDT), the largest stablecoin by market capitalization, has not registered for MiCA compliance and was delisted from EU exchanges in late 2024. Circle (USDC), the second-largest, registered. The delisting of USDT was, in effect, the first major test of MiCA's extraterritorial reach: a non-EU issuer that did not register was functionally shut out of the EU market by the EU-regulated CASPs that held the liquidity. Tether has signaled it will register; the application is pending.[6]

Decentralized finance (DeFi) is in a gray zone under MiCA. The recitals state that "fully decentralised" crypto-asset services are not, by definition, CASPs, and are therefore not directly subject to MiCA. The threshold for "fully decentralised" is contested: a smart contract protocol with a deployer address, a governance token, and a frontend operated by a known entity is, in EBA guidance, treated as a CASP if the frontend is the point of access for EU users. The September 2024 ESMA guidance clarified that a "purely technical" infrastructure provider (e.g., a block explorer, a node operator) is not a CASP, but a protocol frontend, a governance token issuer, and a service that "promotes" or "recommends" a crypto-asset to EU users is. The result is that most major DeFi protocols have chosen to geo-block EU users rather than risk enforcement.[7]

For EU-based readers: the practical risk today is not that self-custody is illegal. It is that (a) the universe of fiat on-ramps and off-ramps that an EU user can use has narrowed (Tether delisting, USDC retention, fewer exchanges), (b) the travel rule means that any meaningful transfer of value leaves a record, and (c) MiCA's CASP licensing is, in practice, an entry barrier for non-EU crypto firms. The architecture of crypto self-custody survives; the regulated perimeter is tightening. See our crypto row in the comparison table for the country-level cross-jurisdiction comparison.

5. Government surveillance authority: Europol, Eurojust, SIS

The EU's operational surveillance authority is Europol, the European Union Agency for Law Enforcement Cooperation, based in The Hague. The legal base is the Europol Regulation (Regulation (EU) 2016/794, in force since May 1 2017), as amended by Regulation (EU) 2022/991 (the 2022 amendment that expanded Europol's mandate on "large datasets" and "research and innovation"). Europol is not a law enforcement agency in the operational sense: it does not have arrest powers, it does not have subpoena power, and it does not conduct investigations. It is a coordination and analysis hub that supports member-state investigations.[8]

Europol's analytical products, particularly the annual Internet Organised Crime Threat Assessment (IOCTA) and the Serious and Organised Crime Threat Assessment (SOCTA), are the canonical source for the EU's "threat picture" in cybercrime and organized crime. The IOCTA has, since 2016, included a "law enforcement access to encrypted communications" section, framed as a "going dark" problem. The framing has been criticized by civil-society groups (EDRi, Access Now, Privacy International) and by the cryptographic community, who argue that the threat picture is over-stated and the "going dark" rhetoric is a political-economy argument rather than an empirical claim.[16]

Eurojust, the European Union Agency for Criminal Justice, is the EU's judicial-cooperation body. It supports member-state prosecutors in cross-border investigations, facilitates the execution of mutual legal assistance (MLA) requests, and can set up Joint Investigation Teams (JITs). The legal base is Regulation (EU) 2018/1727. Eurojust is not a surveillance authority in the operational sense, but it is the EU's primary mechanism for cross-border evidence sharing.[17]

The Schengen Information System (SIS) is the EU's largest IT system for security and border management, with over 1.2 billion records as of 2025. SIS II is the second-generation system, in operation since 2013 and significantly expanded by Regulation (EU) 2018/1860 (police cooperation), Regulation (EU) 2018/1861 (border checks), and Regulation (EU) 2018/1862 (return of illegally staying third-country nationals). SIS records include alerts on wanted persons, missing persons, objects (including vehicles, documents, firearms), and refusal of entry or stay. National authorities (police, border guards, consular services) have read access; Europol has read access for its mandate; Eurojust has read access for its mandate.[18]

The EDPB (European Data Protection Board) is the EU's independent data-protection authority, composed of the national data-protection authorities of the member states and the European Data Protection Supervisor (EDPS). The EDPB's role is to ensure consistent application of the GDPR (Regulation (EU) 2016/679) across the EU. The EDPB has, since 2020, issued a series of opinions and guidelines on the interaction between surveillance, data retention, and the GDPR, including the 2021 EDPB Guidelines 05/2020 on consent and the 2023 EDPB Statement on the EU-UK data-transfer post-Brexit.[17]

The e-Evidence regime (Regulation (EU) 2023/1543 and Directive (EU) 2023/1544, the "e-Evidence package") is the EU's most consequential cross-border evidence-gathering framework. The regulation, fully applicable from August 2026, allows a judicial authority in one member state to issue a European Production Order (EPO) or a European Preservation Order (EPresOrder) directly to a service provider in another member state, without going through the MLA process. The regime covers electronic evidence in criminal matters and applies to all electronic communications services (messaging, email, cloud). The e-Evidence regime does not apply to content data of encrypted messages where the service provider does not have technical access to the cleartext, which functionally excludes the largest end-to-end encrypted messengers from the scope of the regime. The 2024 EDPB Opinion 14/2024 on the e-Evidence package flagged this scope question and recommended clarification.

For EU-based readers: the practical risk today is not that the EU has a single "surveillance authority" with a single warrant power. It is that the EU has built a network of operational, judicial, and regulatory bodies that together cover the full chain of evidence gathering (Europol for analysis, Eurojust for judicial cooperation, SIS for alerts, EDPB for privacy, e-Evidence for direct service-provider orders). The architecture is distributed. The law is harmonized. The enforcement is uneven across member states. See our CSAR coverage for the encryption-fight angle on Europol's role.

6. 2024-2026 enforcement actions and rulings

The EU's 2024-2026 enforcement record is the most active of any jurisdiction in our 34-country comparison. GDPR enforcement alone has produced record fines. The Digital Services Act (DSA, Regulation (EU) 2022/2065) entered full force in February 2024 and the European Commission has, since then, opened formal proceedings against X, Meta, TikTok, AliExpress, and others. The AI Act (Regulation (EU) 2024/1689) entered force on August 1 2024, with the first enforcement actions landing in 2025-2026. The ePrivacy derogation expiration on April 3 2026 was, in itself, an enforcement event: providers that had implemented voluntary CSAM detection had to suspend or geo-restrict the practice.

GDPR record fines. The largest GDPR fine ever issued was EUR 1.2 billion against Meta (Facebook) by the Irish Data Protection Commission (DPC) in May 2023, for the company's transfers of European user data to the United States in reliance on standard contractual clauses. The second-largest was EUR 530 million against TikTok by the Irish DPC in September 2023, for failures to protect children's data. The Meta fine was reduced on appeal to the Irish High Court in 2024 to EUR 91 million (the court found that the DPC had over-estimated the number of affected users); the TikTok fine is under appeal. The cumulative GDPR fine total across all member states as of end-2025 was approximately EUR 5.5 billion, with the Irish DPC, the French CNIL, the Italian Garante, and the German BfDI accounting for the largest shares.[17]

DSA proceedings against X (formerly Twitter). The European Commission opened a formal DSA investigation against X in December 2023, focused on the platform's compliance with the DSA's illegal-content, transparency, and risk-assessment obligations. The investigation has been expanded several times, with formal preliminary findings in July 2024 and a Statement of Objections in 2025. The Commission's preliminary view is that X is in breach of multiple DSA provisions, including the "dark patterns" prohibition, the transparency obligations on advertising repositories, and the risk-assessment obligations. The case is the first major DSA enforcement and is being closely watched as a precedent.[19]

DSA proceedings against Meta, TikTok, AliExpress. The Commission opened DSA proceedings against Meta in April 2024 (focused on the "pay-or-consent" model for Instagram and Facebook), against TikTok in December 2023 (focused on the protection of minors and the "addictive design" provisions), and against AliExpress in March 2024 (focused on illegal products). All three are in the formal proceedings phase as of 2026. The Meta "pay-or-consent" case is the most consequential for the surveillance architecture: the Commission's preliminary view is that the model amounts to a "consent" that is not freely given under GDPR, and that the model effectively prices user data at EUR 12.99/month.

AI Act first enforcement (2025-2026). The AI Act entered force on August 1 2024, with a tiered applicability schedule: prohibited practices (e.g., social scoring, certain biometric identification) applicable from February 2025; general-purpose AI (GPAI) rules from August 2025; full applicability for high-risk systems from August 2026. The first enforcement actions have been against general-purpose AI providers for non-compliance with the GPAI transparency requirements (e.g., failure to publish training-data summaries, failure to implement copyright-compliance policies). The Commission's AI Office, based in Brussels, is the lead enforcement body. The national market-surveillance authorities (typically the national data-protection authority or a separate consumer-protection agency) handle most cases.[20]

ePrivacy derogation expiration, April 3 2026. The temporary lawful basis for voluntary CSAM scanning (Regulation (EU) 2021/1232, as extended) expired on April 3 2026 without renewal. Providers that had implemented CSAM detection under the derogation (including several large messaging platforms) suspended the practice on or before April 3 2026, pending either a renewed derogation or a final CSAR. The Commission's proposed renewal was rejected by the Parliament in March 2026. The legal effect is that, as of April 3 2026, in-production voluntary CSAM scanning in the EU has no legal basis and providers that continue the practice are exposed to enforcement under the e-Privacy Directive and the GDPR. See our April 3 CSAR expiration coverage.

Signal EU exit threat. Signal's president has stated Signal will withdraw from the EU rather than implement client-side scanning. As of 2026, Signal has not withdrawn. The threat is on file and is the position that has framed the political-economy argument against CSAR.

WhatsApp EU position. WhatsApp (Meta) has stated a similar position. Meta's position is that WhatsApp will withdraw from the EU rather than implement client-side scanning. As of 2026, WhatsApp has not withdrawn.

See our May 4 2026 trilogue coverage and the Signal EU exit threat coverage for the live record.

7. Chronology (2016 to 2026)

The EU surveillance architecture has been built in distinct phases. The 2016 Europol Regulation was the foundation. The 2016-2018 GDPR + ePrivacy framework set the privacy baseline. The 2022-2024 CSAR saga is the encryption fight. The 2023 MiCA framework is the crypto perimeter. The 2024 eIDAS 2.0 is the digital identity framework. The 2024-2026 DSA, AI Act, and e-Evidence package is the enforcement expansion. The April 3 2026 ePrivacy derogation expiration is the most recent inflection point.

  • April 2016. General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) adopted by the European Parliament on April 14 2016 and by the Council on April 27 2016. Replaces the 1995 Data Protection Directive.
  • May 2016. Europol Regulation (EU) 2016/794 adopted, replacing the 2009 Council Decision. Europol becomes an EU agency.
  • July 2016. e-Privacy Directive (Directive 2002/58/EC) as amended, with the consent rule for cookies and terminal-equipment access codified.
  • May 2018. GDPR becomes applicable. One-year transition complete.
  • December 2020. ePrivacy Regulation proposal stalls in Council, in part over CSAM scanning. The proposal has not advanced as of 2026.
  • May 2022. Commission publishes CSAR proposal COM/2022/209 final. The "scan-or-ban" language triggers the encryption fight.
  • November 2022. Europol Regulation amended by Regulation (EU) 2022/991, expanding Europol's mandate on "large datasets" and "research and innovation."
  • April 2023. MiCA Regulation (EU) 2023/1114 adopted. Crypto framework set.
  • May 2023. Irish DPC issues EUR 1.2 billion GDPR fine against Meta, the largest ever.
  • July 2023. Parliament adopts position on CSAR with weakening amendments. Trilogue begins.
  • September 2023. Irish DPC issues EUR 530 million GDPR fine against TikTok.
  • November 2023. Commission opens DSA proceedings against X.
  • December 2023. Commission opens DSA proceedings against TikTok.
  • February 2024. eIDAS 2.0 (Regulation (EU) 2024/1183) adopted. EU Digital Identity Wallet framework set.
  • February 2024. DSA fully applicable for "very large online platforms" and "very large online search engines."
  • March 2024. Commission opens DSA proceedings against AliExpress.
  • April 2024. Commission opens DSA proceedings against Meta.
  • August 1 2024. AI Act (Regulation (EU) 2024/1689) enters force. Tiered applicability schedule begins.
  • December 30 2024. MiCA fully applicable. Tether (USDT) delisted from EU exchanges.
  • February 2025. AI Act prohibited-practices provisions applicable (e.g., social scoring, certain biometric identification).
  • August 2025. AI Act general-purpose AI (GPAI) rules applicable.
  • December 2025. Commission publishes eIDAS 2.0 implementation specification, including the "zero-knowledge proof of age" mode.
  • December 2025. Council adopts position on watered-down CSAR, with detection opt-in and risk-based scanning.
  • March 2026. Parliament rejects the proposed extension of the ePrivacy derogation. Commission withdraws the proposal.
  • April 3 2026. ePrivacy derogation (Regulation (EU) 2021/1232) expires. In-production voluntary CSAM scanning loses its legal basis.
  • May 4 2026. Renewed CSAR trilogue. No agreement reached.
  • August 2026. AI Act fully applicable for high-risk systems. e-Evidence regulation (Regulation (EU) 2023/1543) fully applicable.
  • December 2026. eIDAS 2.0 deadline for member states to make the EU Digital Identity Wallet available to residents.

Sources

20 sources, all from the STA-305 source dossier (Archivist) and the SOS newsroom's CSAR coverage. Tier 1 (EU statute and regulator) leads. Tier 2 (EDRi, EFF, Global Encryption Coalition, Signal, ComputerWeekly, Wikipedia anchors) for the policy analysis. Sorted within tier by primary statute first, then policy analysis.

  1. [1] Tier 1 Commission proposal COM/2022/209 final. Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse. CSAR proposal (eur-lex.europa.eu) (accessed 2026-06-17)
  2. [2] Tier 1 Regulation (EU) 2021/1232 of the European Parliament and of the Council of 14 July 2021 on a temporary derogation from certain provisions of Directive 2002/58/EC. ePrivacy derogation Regulation (EU) 2021/1232 (eur-lex.europa.eu) (accessed 2026-06-17)
  3. [3] Tier 1 Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (e-Privacy Directive). e-Privacy Directive 2002/58/EC (eur-lex.europa.eu) (accessed 2026-06-17)
  4. [4] Tier 1 Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework (eIDAS 2.0). eIDAS 2.0 Regulation (EU) 2024/1183 (eur-lex.europa.eu) (accessed 2026-06-17)
  5. [5] Tier 2 eIDAS (Wikipedia) (accessed 2026-06-17)
  6. [6] Tier 1 Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assets (MiCA). MiCA Regulation (EU) 2023/1114 (eur-lex.europa.eu) (accessed 2026-06-17)
  7. [7] Tier 1 Regulation (EU) 2023/1113 of the European Parliament and of the Council of 31 May 2023 on information accompanying transfers of funds and certain crypto-assets (TFR / travel rule). TFR Regulation (EU) 2023/1113 (eur-lex.europa.eu) (accessed 2026-06-17)
  8. [8] Tier 2 Europol (Wikipedia) (accessed 2026-06-17)
  9. [9] Tier 2 EDRi: Chat Control campaign (accessed 2026-06-17)
  10. [10] Tier 2 EFF: CSAR, after years of controversy, nears its final hurdle (December 2025) (accessed 2026-06-17)
  11. [11] Tier 2 Signal: EU Chat Control (accessed 2026-06-17)
  12. [12] Tier 2 WIRED: Signal EU exit threat (accessed 2026-06-17)
  13. [13] Tier 2 Global Encryption Coalition: Steering Committee statement on Council of the EU position (January 2026) (accessed 2026-06-17)
  14. [14] Tier 2 ComputerWeekly: EU CSAR / Chat Control spring 2026 (accessed 2026-06-17)
  15. [15] Tier 3 EDRi: Anonymity topic (accessed 2026-06-17)
  16. [16] Tier 1 Europol: Crime areas and trends (accessed 2026-06-17)
  17. [17] Tier 1 European Data Protection Board (EDPB) (accessed 2026-06-17)
  18. [18] Tier 2 Schengen Information System (Wikipedia) (accessed 2026-06-17)
  19. [19] Tier 1 EU Parliament Legislative Train: CSAR spotlight (accessed 2026-06-17)
  20. [20] Tier 1 Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (AI Act). AI Act Regulation (EU) 2024/1689 (eur-lex.europa.eu) (accessed 2026-06-17)