Sittings · Document

DRAFT REPORT (COM(2025)0797 – C100370/2025 – 2025/0429(COD)) 2026-02-05

On the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2021/1232 as regards the extension of its period of application

Committee on Civil Liberties, Justice and Home Affairs · Rapporteur: Birgit Sippel

PR_COD_1amCom

Symbols for procedures

* Consultation procedure

*** Consent procedure

***I Ordinary legislative procedure (first reading)

***II Ordinary legislative procedure (second reading)

***III Ordinary legislative procedure (third reading)

(The type of procedure depends on the legal basis proposed by the draft act.)

Amendments to a draft act

Amendments by Parliament set out in two columns

Deletions are indicated in bold italics in the left-hand column. Replacements are indicated in bold italics in both columns. New text is indicated in bold italics in the right-hand column.

The first and second lines of the header of each amendment identify the relevant part of the draft act under consideration. If an amendment pertains to an existing act that the draft act is seeking to amend, the amendment heading includes a third line identifying the existing act and a fourth line identifying the provision in that act that Parliament wishes to amend.

Amendments by Parliament in the form of a consolidated text

New text is highlighted in bold italics. Deletions are indicated using either the ▌symbol or strikeout. Replacements are indicated by highlighting the new text in bold italics and by deleting or striking out the text that has been replaced.

By way of exception, purely technical changes made by the drafting departments in preparing the final text are not highlighted.

DRAFT EUROPEAN PARLIAMENT LEGISLATIVE RESOLUTION

on the proposal for a regulation of the European Parliament and of the Council amending Regulation (EU) 2021/1232 as regards the extension of its period of application

(COM(2025)0797 – C100370/2025 – 2025/0429(COD))

(Ordinary legislative procedure: first reading)

– having regard to the Commission proposal to Parliament and the Council (COM(2025)0797),

– having regard to Article 294(2), Article 16(2) and Art. 114(1), of the Treaty on the Functioning of the European Union, pursuant to which the Commission submitted the proposal to Parliament (C100370/2025),

– having regard to Article 294(3) of the Treaty on the Functioning of the European Union,

– having regard to Rule 60 of its Rules of Procedure,

– having regard to the report of the Committee on Civil Liberties, Justice and Home Affairs (A100000/2026),

1. Adopts its position at first reading hereinafter set out;

2. Calls on the Commission to refer the matter to Parliament again if it replaces, substantially amends or intends to substantially amend its proposal;

3. Instructs its President to forward its position to the Council, the Commission and the national parliaments.

Amendment 1

Proposal for a regulation

Recital 2

Text proposed by the Commission

Amendment

(2) The proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse3 , which the Commission adopted on 11 May 2022, aims to provide the long-term legal framework. However, the interinstitutional negotiations on that proposal have not yet advanced sufficiently to be certain that they will be concluded on time for the long-term legal framework, including any amendments to Regulation (EU) 2021/1232 that it may contain, to be adopted and start to apply before 4 April 2026.

(2) The proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse, which the Commission adopted on 11 May 2022 (‘the 2022 proposal¨), aims to provide the long-term legal framework. However, the interinstitutional negotiations on that proposal have not yet advanced sufficiently to be certain that they will be concluded on time for the long-term legal framework, including any amendments to Regulation (EU) 2021/1232 that it may contain, to be adopted and start to apply before 4 April 2026. The European Parliament adopted its position and the mandate to enter into inter-institutional negotiations on 22 November 2023 while the Council was unable to reach its position before 26 November 2025. This requires further extension, even though Regulation (EU) 2021/1232 was designed to be a temporary and unique instrument that allowed for sufficient time for the adoption for the 2022 proposal.

__________________

__________________

3 Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse, COM/2022/209 final.

3 Proposal for a Regulation of the European Parliament and of the Council laying down rules to prevent and combat child sexual abuse, COM/2022/209 final.

Or. en

Amendment 2

Proposal for a regulation

Recital 4

Text proposed by the Commission

Amendment

(4) Given these circumstances, Regulation (EU) 2021/1232 should be amended to extend its period of application for a period of time limited to that which is strictly necessary for the long-term legal framework to be adopted and start to apply.

(4) Given these circumstances, Regulation (EU) 2021/1232 should be amended to extend its period of application for a period of time limited to that which is strictly necessary for the long-term legal framework to be adopted and start to apply. The co-legislators therefore commit to reaching an agreement on the long-term legal framework as soon as possible and with a view to avoiding any further extensions of Regulation (EU) 2021/1232 in the future. Furthermore, taking into consideration that Regulation (EU) 2021/1232 was intended to apply during a limited period of time, it is necessary to clarify some provisions thereof and adapt them to the results from the Implementing Reports from the Commission of 19 December 20231a and of 27 November 20251b (‘the 2023 and 2025 implementing reports’) .

___________

1a COM(2023)0797

1b COM(2025)0740

Or. en

Amendment 3

Proposal for a regulation

Recital 5 a (new)

Text proposed by the Commission

Amendment

(5 a) The mere fact that certain providers of number-independent interpersonal communications services apply detection technologies on a voluntary basis does not relieve the co-legislators from their responsibility of establishing a comprehensive legal framework which meets the requirements of Articles 7 and 8 of the Charter of Fundamental Rights of the European Union (‘the Charter’) and does not undermine the prohibition of general monitoring under Union law

Or. en

Amendment 4

Proposal for a regulation

Recital 5 b (new)

Text proposed by the Commission

Amendment

(5 b) Nothing in this Regulation should be interpreted as prohibiting, weakening or undermining end-to-end encryption. Providers should in particular not be prohibited to offer end-to-end encrypted services.

Or. en

Amendment 5

Proposal for a regulation

Recital 7 a (new)

Text proposed by the Commission

Amendment

(7 a) The processing of images and videos under Regulation (EU) 2021/1232 should always be considered to be processing of special categories of personal data under Article 9 of Regulation (EU) 2016/679 of the European Parliament and of the Council1a as they are biometric data that are processed through a specific technical means allowing the unique identification or authentication of a natural person.

___________

1a Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119, 4.5.2016, ELI: http://data.europa.eu/eli/reg/2016/679/oj).

Or. en

Amendment 6

Proposal for a regulation

Recital 7 b (new)

Text proposed by the Commission

Amendment

(7 b) In light of the 2023 and 2025 implementing reports to ensure consistency and clarity, definitions which are no longer relevant due to incomplete, inaccurate data that cannot be independently audited should be deleted from Regulation (EU) 2021/1232. Since the scope of Regulation (EU) 2021/1232 should not include detection of not previously identified online child sexual abuse material, or solicitation of children, their definitions are redundant and therefore should be deleted. The 2023 and 2025 implementing reports also stress that no conclusive data on the proportionality of detecting not previously identified online child sexual abuse material, or solicitation of children can be relied upon to justify the restriction of certain rights as provided by Directive 2002/58/EC and Articles 7 and 8 of the Charter.

Or. en

Amendment 7

Proposal for a regulation

Recital 7 c (new)

Text proposed by the Commission

Amendment

(7 c) Considering the unproven effectiveness of Regulation (EU) 2021/1232 regarding not previously identified online child sexual abuse material, or solicitation of children, while at the same time the impact on the confidentiality of communications as provided by Directive 2002/58/EC of the European Parliament and of the Council1a, the detection of not previously identified child sexual abuse material and child solicitation should be taken out of the scope of Regulation (EU) 2021/1232. However, in order to prevent solicitation of children, certain providers of number-independent interpersonal communications services can and are encouraged to take mitigation measures, which do not interfere with Directive 2002/58/EC.

___________

1a Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on privacy and electronic communications), (OJ L 201, 31.7.2002, ELI: http://data.europa.eu/eli/dir/2002/58/oj).

Or. en

Amendment 8

Proposal for a regulation

Recital 7 d (new)

Text proposed by the Commission

Amendment

(7 d) Since the sole objective of this Regulation is to enable the limited and targeted, modified continuation of certain existing activities aimed at combating child sexual abuse online, the derogation provided for by this Regulation should be limited to well-established technology that is used by certain providers of number- independent interpersonal communications services for the purpose of detecting, reporting and removing child sexual abuse material, which functions by matching images and videos against a database of unique, non-reconvertible digital signatures ((‘hashes’) of identified child sexual abuse material.

Or. en

Amendment 9

Proposal for a regulation

Recital 7 e (new)

Text proposed by the Commission

Amendment

(7 e) In order to ensure an adequate level of transparency and accountability, as well as to enable comprehensive and comparable reporting, it is necessary to include administrative fines for non-compliance by certain providers of number- independent interpersonal communications services with the reporting and transparency obligations and requirements, notably the use of the standard form for report as established by Regulation (EU) 2024/1307 of the European Parliament and of the Council1a and subsequent Commission Implementing Regulation (EU) 2024/29161b.

___________

1a Regulation (EU) 2024/1307 of the European Parliament and of the Council of 29 April 2024 amending Regulation (EU) 2021/1232 on a temporary derogation from certain provisions of Directive 2002/58/EC as regards the use of technologies by providers of number-independent interpersonal communications services for the processing of personal and other data for the purpose of combating online child sexual abuse (OJ L, 2024/1307, 14.5.2024, ELI: http://data.europa.eu/eli/reg/2024/1307/oj).

1b Commission Implementing Regulation (EU) 2024/2916 of 25 November 2024 laying down a standard form for the data included in the report on the processing of personal data published and reported to the competent supervisory authority and to the Commission by service providers under Regulation (EU) 2021/1232 of the European Parliament and of the Council, (OJ L, 2024/2916, 26.11.2024, ELI: http://data.europa.eu/eli/reg_impl/2024/2916/oj).

Or. en

Amendment 10

Proposal for a regulation

Recital 7 f (new)

Text proposed by the Commission

Amendment

(7 f) In order to strengthen the enforcement of the rules of Regulation (EU) 2021/1232, administrative fines should be imposed for any infringement of that Regulation, in addition to, or instead of appropriate measures imposed by the supervisory authority pursuant to that Regulation.

Or. en

Amendment 11

Proposal for a regulation

Article -1 (new)

Regulation (EU) 2021/1232

Recital 16

Text proposed by the Commission

Amendment

Article -1

Recital 16 of Regulation (EU) 2021/1232 is replaced by the following:

‘The types of technologies used for the purposes of this Regulation should be the least privacy-intrusive in accordance with the state of the art in the industry. Those technologies should not be used to systematically filter and scan text in communications unless it is solely to detect patterns which point to possible concrete reasons for suspecting online child sexual abuse, and they should not be able to deduce the substance of the content of the communications.’

Or. en

Amendment 12

Proposal for a regulation

Article -1 a (new)

Regulation (EU) 2021/1232

Recital 21

Text proposed by the Commission

Amendment

Article -1a

Recital 21 of Regulation (EU) 2021/1232 is replaced by the following:

‘In order to ensure transparency and accountability in respect of the activities undertaken pursuant to the derogation provided for by this Regulation, providers should, by 3 February 2022, and by 31 January every year thereafter, publish and submit reports to the competent supervisory authority designated pursuant to Regulation (EU) 2016/679 (‘supervisory authority’) and to the Commission. Such reports should cover processing falling within the scope of this Regulation, including the type and volumes of data processed, the specific grounds relied on for the processing of personal data pursuant to Regulation (EU) 2016/679, the grounds relied on for transfers of personal data outside the Union pursuant to Chapter V of Regulation (EU) 2016/679, where applicable, the number of cases of online child sexual abuse identified, the number of cases in which a user has lodged a complaint with the internal redress mechanism or sought a judicial remedy and the outcome of such complaints and judicial proceedings, the numbers and ratios of errors (false positives) of the different technologies used, the measures applied to limit the error rate and the error rate achieved, the retention policy and the data protection safeguards applied pursuant to Regulation (EU) 2016/679, and the names of the organisations acting in the public interest against child sexual abuse with which data have been shared pursuant to this Regulation.’

Or. en

Amendment 13

Proposal for a regulation

Article -1 b (new)

Regulation (EU) 2021/1232

Article 2 – point 3

Text proposed by the Commission

Amendment

Article -1b

In Article 2 of Regulation (EU) 2021/1232, point 3 is deleted.

Or. en

Amendment 14

Proposal for a regulation

Article -1 c (new)

Regulation (EU) 2021/1232

Article 2 – point 4

Text proposed by the Commission

Amendment

Article -1c

In Article 2 of Regulation (EU) 2021/1232, point 4 is deleted.

Or. en

Amendment 15

Proposal for a regulation

Article -1 d (new)

Regulation (EU) 2021/1232

Article 3 – paragraph 1

Text proposed by the Commission

Amendment

Article -1d

In Article 3 of Regulation (EU) 2021/1232, paragraph 1 is replaced by the following:

‘1. Articles 5(1) and 6(1) of Directive 2002/58/EC shall not apply to the confidentiality of communications involving the processing by providers of personal data in connection with the provision of number-independent interpersonal communications services provided that:

(a) the processing is:

(i) strictly necessary for the use of specific technology for the sole purpose of detecting and removing known online child sexual abuse material and reporting it to law enforcement authorities and to organisations acting in the public interest against child sexual abuse;

(ii) proportionate and limited to technologies used by providers for the purpose set out in point (i);

(iii) limited to content data that are strictly necessary for the purpose set out in point (i);

(iv) limited to what is strictly necessary for the purpose set out in point (i);

(b) the technologies used for the purpose set out in point (a)(i) of this paragraph are in accordance with the state of the art in the industry and are the least privacy-intrusive, including with regard to the principle of data protection by design and by default laid down in Article 25 of Regulation (EU) 2016/679 and, to the extent that they are used to detect possible known online child sexual abuse material;

(c) in respect of any specific technology used for the purpose set out in point (a)(i) of this paragraph, a prior data protection impact assessment as referred to in Article 35 of Regulation (EU) 2016/679 and a prior consultation procedure as referred to in Article 36 of that Regulation have been conducted;

(d) with regard to new technology, meaning technology used for the purpose of detecting online child sexual abuse material that has not been used by any provider in relation to services provided to users of number-independent interpersonal communications services (‘users’) in the Union before 2 August 2021, the provider reports back to the competent authority on the measures taken to demonstrate compliance with written advice issued in accordance with Article 36(2) of Regulation (EU) 2016/679 by the competent supervisory authority designated pursuant to Chapter VI, Section 1, of that Regulation (‘supervisory authority’) in the course of the prior consultation procedure;

(e) the technologies used are sufficiently reliable in that they limit to the maximum extent possible the rate of errors regarding the detection of content representing known online child sexual abuse material and, where such occasional errors occur, their consequences are rectified without delay;

(f) the providers:

(i) have established internal procedures to prevent abuse of, unauthorised access to, and unauthorised transfers of, personal data;

(ii) ensure human oversight of and, where necessary, human intervention in the processing of personal data using technologies falling under this Regulation;

(iii) ensure that material not previously identified through other means than voluntary detection as online child sexual abuse material, or solicitation of children, is not reported to law enforcement authorities or organisations acting in the public interest against child sexual abuse without prior human confirmation;

(iv) have established appropriate procedures and redress mechanisms to ensure that users can lodge complaints with them within a reasonable timeframe for the purpose of presenting their views;

(v) inform users in a clear, prominent and comprehensible way of the fact that they have invoked, in accordance with this Regulation, the derogation from Articles 5(1) and 6(1) of Directive 2002/58/EC concerning the confidentiality of users’ communications for the sole purpose set out in point (a)(i) of this paragraph, the logic behind the measures they have taken under the derogation and the impact on the confidentiality of users’ communications, including the possibility that personal data are shared with law enforcement authorities and organisations acting in the public interest against child sexual abuse;

(vi) inform users of the following, where their content has been removed or their account has been blocked or a service offered to them has been suspended:

(1) the avenues for seeking redress from them;

(2) the possibility of lodging a complaint with a supervisory authority; and

(3) the right to a judicial remedy;

(vii) by 3 February 2022, and by 31 January every year thereafter, publish and submit to the competent supervisory authority and to the Commission a report on the processing of personal data under this Regulation, including on:

(1) the type and volumes of data processed;

(2) the specific ground relied on for the processing pursuant to Regulation (EU) 2016/679;

(3) the ground relied on for transfers of personal data outside the Union pursuant to Chapter V of Regulation (EU) 2016/679, where applicable;

(4) the number of cases of online child sexual abuse identified, differentiating between online child sexual abuse material and solicitation of children;

(5) the number of cases in which a user has lodged a complaint with the internal redress mechanism or with a judicial authority and the outcome of such complaints;

(6) the numbers and ratios of errors (false positives) of the different technologies used;

(7) the measures applied to limit the error rate and the error rate achieved;

(8) the retention policy and the data protection safeguards applied pursuant to Regulation (EU) 2016/679;

(9) the names of the organisations acting in the public interest against child sexual abuse with which data has been shared pursuant to this Regulation;

(g) where suspected online child sexual abuse has been identified, the content data and related traffic data processed for the purpose set out in point (a)(i), and personal data generated through such processing are stored in a secure manner, solely for the purposes of:

(i) reporting, without delay, the suspected online child sexual abuse to the competent law enforcement and judicial authorities or organisations acting in the public interest against child sexual abuse;

(ii) blocking the account of, or suspending or terminating the provision of the service to, the user concerned;

(iii) creating a unique, non-reconvertible digital signature (‘hash’) of data reliably identified as online child sexual abuse material;

(iv) enabling the user concerned to seek redress from the provider or pursue administrative review or judicial remedies on matters related to the suspected online child sexual abuse; or

(v) responding to requests issued by competent law enforcement and judicial authorities in accordance with the applicable law to provide them with the necessary data for the prevention, detection, investigation or prosecution of criminal offences as set out in Directive 2011/93/EU;

(h) the data are stored no longer than strictly necessary for the relevant purpose set out in point (h) and, in any event, no longer than 12 months from the date of the identification of the suspected online child sexual abuse;

(i) every case of a reasoned and verified suspicion of online child sexual abuse is reported without delay to the competent national law enforcement authorities or to organisations acting in the public interest against child sexual abuse.’

Or. en

Amendment 16

Proposal for a regulation

Article -1 e (new)

Regulation (EU) 2021/1232

Article 9 – paragraph 1

Text proposed by the Commission

Amendment

Article -1e

In Article 9 of Regulation (EU) 2021/1232, paragraph 1 is replaced by the following:

‘1. On the basis of the reports submitted pursuant to Article 3(1), point (g)(vii), and the statistics provided pursuant to Article 8, the Commission shall, by 4 September 2026, prepare a report on the implementation of this Regulation and submit and present it to the European Parliament and to the Council’.

Or. en

Amendment 17

Proposal for a regulation

Article -1 f (new)

Regulation (EU) 2021/1232

Article 7 a (new)

Text proposed by the Commission

Amendment

Article -1f

The following article is inserted:

‘Article 7a

General conditions for imposing administrative fines

The Commission shall impose fines for the infringement or failure to comply with this Regulation which shall in each individual case be effective, proportionate and dissuasive.

Infringements of this Regulation shall be subject to administrative fines up to 10,000,000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher.

The exercise by the Commission of its powers under this Article shall be subject to appropriate procedural safeguards in accordance with Union and Member State law, including effective judicial remedy and due process.’

Or. en

Amendment 18

Proposal for a regulation

Article 1 – paragraph 1

Regulation (EU) 2021/1232

Article 10 – paragraph 2

Text proposed by the Commission

Amendment

It shall apply until 3 April 2028.

It shall apply until 3 April 2027.

Or. en

EXPLANATORY STATEMENT

Statement on behalf of the Rapporteur

Birgit Sippel

Proposal for a

REGULATION OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL

amending Regulation (EU) 2021/1232 as regards the extension of its period of application 2025/0429 (COD)

The Interim-Derogation was understood as a strictly temporary and exceptional instrument. Its sole purpose was to create a narrowly defined legal bridge, allowing voluntary measures by providers while giving the co-legislators sufficient time to design, negotiate, and adopt a comprehensive and permanent legal framework to prevent and combat online child sexual abuse in full compliance with fundamental rights. It was never intended to become a long-lasting substitute for a proper legislative solution.

The first prolongation proposal already violated that commitment. Since 2023, the European Parliament has been ready to enter into negotiations on a permanent framework to reach an agreement as swiftly as possible, explicitly with a view to avoiding any further extensions of the Interim-Derogation. Despite our political readiness, the Council has failed to use the available time effectively. As a result, we now find ourselves in the problematic situation where restrictions from core fundamental rights under the ePrivacy Directive risk remaining in force far longer than originally envisaged. This prolonged reliance on an exceptional measure undermines legal certainty and erodes trust in the Union’s commitment to proportionality and necessity.

In light of the two implementation reports published by the European Commission, and taking into account the incomplete and often inaccurate data provided by Member States and service providers, it is essential to draw the right conclusions. The Commission was unable to distinguish between reports based on voluntary measures in comparison by NGOs, Hot- and Helplines and user-reports.

The evidence base remains insufficient to justify a broad scope of application. Any further continuation of the Interim-Derogation must therefore be strictly limited to what is demonstrably proportionate and necessary. In particular, activities that risk constituting general monitoring obligations must be excluded. This includes the detection of grooming and the detection of new child sexual abuse material, where the lack of reliable data and clear safeguards raises serious concerns regarding compliance with fundamental rights.

At the same time, the experience with the Interim-Derogation has exposed a significant enforcement gap. Providers currently dictate the practical terms under which processing takes place, while the Commission, as the designated enforcer, lacks effective tools to ensure compliance. Reporting obligations and transparency requirements remain largely unenforced, leaving policymakers without the reliable information needed to assess effectiveness, proportionality, and necessity. To address this imbalance, it is imperative to equip the Commission with appropriate enforcement instruments, including an effective system of fines. Without credible sanctions, obligations remain largely declaratory, and accountability is weakened.

Given the explicit commitment to avoid any further extensions of the Interim-Derogation, and relying on the political will to deliver a permanent framework, I am prepared to support a strictly limited extension under clear conditions. Such an extension should be confined exclusively to the detection of known, hashed child sexual abuse material and be limited to a maximum duration of twelve months. Any broader scope would contradict both the temporary nature of the instrument and the conclusions that must be drawn from the available evidence.

In parallel, the Commission must make full use of all tools at its disposal and prepare an additional implementation report to support the work on the permanent instrument. This report must be delivered within the legally established deadline and must provide a clear and transparent assessment of when, how, and to what extent voluntary scanning has contributed to achieving the stated objectives. Only on the basis of timely, accurate, and comprehensive information can the co-legislators make informed decisions and ensure that the Union’s response to online child sexual abuse is both effective and fully respectful of fundamental rights.

ANNEX: DECLARATION OF INPUT

Pursuant to Article 8 of Annex I to the Rules of Procedure, the rapporteur declares that she included in her report input on matters pertaining to the subject of the file that she received, in the preparation of the draft report, from the following interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register, or from the following representatives of public authorities of third countries, including their diplomatic missions and embassies:

1. Interest representatives falling within the scope of the Interinstitutional Agreement on a mandatory transparency register

European Digital Rights

CCIA

Doteurope

Google

Microsoft

Snapchat

X/ Twitter

2. Representatives of public authorities of third countries, including their diplomatic missions and embassies(3)

The list above is drawn up under the exclusive responsibility of the rapporteur.

Where natural persons are identified in the list by their name, by their function or by both, the rapporteur declares that she has submitted to the natural persons concerned the European Parliament's Data Protection Notice No 484 (https://www.europarl.europa.eu/data-protect/index.do), which sets out the conditions applicable to the processing of their personal data and the rights linked to that processing.