Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Scanning Plans On Europe’s CSAM May Violate International Law
News & Analysis Business and Policy GRC

Scanning Plans On Europe’s CSAM May Violate International Law

Olivia WilliamBy Olivia WilliamMay 9, 2023Updated:December 20, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Scanning Plans On Europe's CSAM May Violate International Law
Scanning Plans On Europe's CSAM May Violate International Law
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

According to reports, legal experts for the EU have warned that plans to force tech companies to scan customers’ private chats for child abuse (CSEA) content are likely to be struck down by the courts.

A contentious clause of the UK’s Online Safety Bill, Clause 110, is similar to the proposed “chat control” laws. Providers of end-to-end encryption may be issued “detection orders” mandating pre-encryption scanning of client messages for CSEA content.

If you have not read the EU Council Legal Service opinion on the EU's #ChatControl proposal — their version of the #OnlineSafetyBill spyware clauses — you really should.

It is *damning* about EU/UK state anti-encryption proposals:

Extracts below; src: https://t.co/aYbfLqnKBo pic.twitter.com/oa9fk6GlVc

— Alec Muffett (@AlecMuffett) May 8, 2023

For this purpose, “client-side scanning” technology would be used to compare incoming media like videos, photos, and text against a blacklist.

Here’s more on the proposed Internet Safety Act: WhatsApp and Signal say that users’ privacy and security will be compromised by the online safety bill.

However, the legal office of the EU Council has reportedly cautioned in a leak that the measures represent a “particularly serious limitation to the rights to privacy and personal data,” and that there is quite a “serious risk” of them being struck down by judges.

Due to a European Court of Justice judgment that even communications metadata might only be vetted for national security, recent plans may not be suitable for CSEA.

The guidelines, which were printed in The Guardian, would call for a screening that is both general and indiscriminate of the data that is processed by a particular service provider. Furthermore, they would apply uniformly and without difference to everyone who uses that particular service, with no exceptions allowed.

Client-side scanning has a lot of problems in the eyes of privacy advocates. This is what they say; scientists have determined it may produce an excessive amount of false positives and is vulnerable to other forms of hacking.

Client-side scanning may put sensitive information at risk if it were exploited by governments or hackers from other countries.

Child molesters, as previously with services like EncroChat, will migrate to unpoliced apps if client-side scanning becomes mandatory.

In the nearest future, this technique could be used to secretly monitor a wider variety of user-generated content.

It’s worth noting that the UK’s client-side scanning measures would also reduce security for domestic businesses and customers, and that the heads of several prominent messaging applications have publicly indicated they’d rather leave the country than comply with them.

Lawyers in the EU are allegedly concerned that the bloc’s proposals would lead to widespread profiling of individuals, including their biometric information, by requiring messaging companies to implement age verification.

Conclusion

A legal opinion on a controversial European Union legislative plan proposed last May by the Commission to combat child sexual abuse online by requiring platforms to scan for abuse and grooming suggests the plan is incompatible with EU laws that prohibit general and indiscriminate monitoring of people’s communications. The Council’s legal advice on the proposed Child Sexual Abuse Regulation (also known as “Chat control”), which leaked online this week. finds that the regulation as drafted violates fundamental European rights like privacy and data protection; freedom of expression; and the right to give respect for a private family life, as critics have warned.

The Commission argued that the strategy is legal since it will only apply “targeted” and “proportionate” restrictions to platforms where online child sexual exploitation is a problem, combined with “robust conditions and safeguards”. The legal opinion destroys that defense. However, it’s “highly probable” that a judicial review of the regulation’s detection orders, which require platforms to adequately scan for child sexual abuse material (CSAM) and other related activity (like grooming), will find that the screening obligations are “general and indiscriminate” rather than targeted and proportionate, as EU law requires.

The Council’s legal guidance states that the Commission’s “targeting” of orders at dangerous platforms does not target specific platform users, requiring “general screening” of all service users.

Olivia William
  • Olivia William
    Ciso Playbook: Cyber Resilience Strategy
  • Olivia William
    Apple Responds Swiftly to Active Security Threats with iOS 16.5.1 Update
  • Olivia William
    Zacks Investment Research Faces Larger Data Breach Affecting 8.8 Million Users
  • Olivia William
    British Airways and Boots Battling Data Breaches, Millions of Customers Affected

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}