With the EU law proposal “Regulation to Prevent and Combat Child Sexual Abuse” — more commonly know as the EU Chat Control Law — our democracy is threatened from the inside: by our own governments. Citing child protection as the reason, the EU wants to backdoor end-to-end encryption, so they can access and read any message, including photos and videos.
With the so-called Chat Control law, the EU would oblige all email and messenger providers to analyze content before it gets encrypted on the phone of the sender, using AI to detect child sexual abuse material (CSAM). If content is flagged, the providers must report it to the authorities for further investigation.
How did we get here, what does it mean for you, and what can you do to prevent it?
What is end-to-end encryption? A quick recap
With end-to-end encryption (E2EE), no one but the sender and receiver can access a message, including attachments such as photos and videos. To achieve this, the message gets scrambled into an illegible code on the sender’s phone. Only the receiver has the unique key stored on their device that lets it automatically decrypt the message to read it.
What is the issue with the proposed EU Chat Control Law?
It’s one of the rare cases that we agree with Big Tech, albeit for different reasons.
Big Tech firms are likely to support end-to-end encryption because moderating messages would be extremely expensive. With E2EE, they can easily claim that moderation isn’t possible, saving time and costs. At Nextcloud, we have been a long-term supporter of E2EE — not for financial reasons, but because we believe in privacy and want to keep the web free.
Governments, however, often have stronger incentives to want to break encryption. That’s why they have repeatedly tried to push for laws granting more insight into their populations’ messaging. In 2019, we already reported a German plan to force decryption of chat. More recently there was the attempt by the UK government, blocked by Apple.
An ironic twist to the law proposal: How the EU doesn’t want to play by its own rules
It’s important to add here that the EU government isn’t too keen on transparency. The EC President Ursula von der Leyen uses disappearing messages in Signal. By doing so, she ensures that her messages are not only encrypted, but also automatically deleted “to prevent possible major data leaks”.
When it comes to EU citizens and companies, the Commission doesn’t seem to share these same concerns for data breaches. There has even been talk they want to exclude themselves from their own Chat Control law, which seems to prove that they don’t trust the proposal themselves.
The Chat Control law propoes to use local decryption of messaging, making it a novel approach in reading encrypted messages. But the effects are the same: it gives governments a backdoor to your messages. And once that door is open, your online safety can quickly spiral.
While the reasoning for the Chat Control law seems noble, the effects are far-reaching. Just think of governments spying on the opposition under the guise of “terrorism prevention”. This possible cascade of surveillance makes the Chat Control law one of the biggest threats to our digital life in the past decade.
What does the EU Chat Control law mean for you?
The EU Chat Control Law states that all e-mail and messenger providers must gain access to your messages and scan them. This includes providers such as WhatsApp, Signal, Proton Mail, and many more apps. The scanning would apply to all EU citizens, except EU politicians. They might exempt themselves from the law under « professional secrecy » rules.
Unlike Big Tech, our model doesn’t depend on hosting or mining your data. As Nextcloud has no access to your data — and also doesn’t store or run it — we can’t give governments access to your information. If they want to see information you have privately hosted, they will have to deal with you directly. Most Enterprise customers also have this covered in their contract. We don’t plan to make changes to our software and, as we don’t host anything, we also cannot be contacted to release any information.
Does it actually protect children? What experts say
Child protection organizations have weighed in, and the reactions are mixed. Many of them are not convinced by the Chat Control law. They fear that mass surveillance might not be the most effective tool, while also noting the risk of false positives overwhelming their resources.
What can you do?
As awareness about the EU Chat Control Law and the possible impact on citizens’ lives grows, so do the initiatives, including:
Signing a petition: The German party Young Liberals set up the website StopChatControl.eu, aimed at a younger audience. With emojis and a video, it explains the issues with the law clearly, while providing visitors with Chat Control slides to create their own social media messages, as well as a petition to put further pressure on EU lawmakers.
Writing your EU representatives: The citizen-led initiative Fight Chat Control allows you to look up with just one click which EU countries are supporting, opposing, or undecided. Handy templates enable you to write a letter to your EU representatives asking them to oppose the law in a few easy steps.
Informing yourself and spreading the message:
The German digital rights activist Patrick Breyer launched a dedicated page to the EU Chat Control Law. From a timeline to a document pool and infographics to download and use, this is a one-stop page to learn everything about the law’s history, objections, and current status.
With the Stop Scanning Me initiative of the European Digital Rights (EDRi) movement, you can find localized campaigns for the German, Danish, Swedish, Spanish, Portuguese and English speakers, so you can get informed and spread the word in your own language.
Join one or more of these initiatives to raise your concerns with your EU Member of Parliaments, preventing mass surveillance and your fundamental rights to privacy and data protection.
What’s next for privacy in Europe?
As your digital life is extremely valuable, you and your company’s data are always at risk. Big Tech monopolies sell data for ad revenue, governments want your data to track you, and hackers can exploit it to scam you.
By reclaiming control over your data, you take back control of your online privacy.
Curious where to get started? Check out how others, including government agencies, organizations, and companies, have taken their digital privacy in their own hands again with Nextcloud.
Join the global launch of Nextcloud Hub 25 Autumn!
Discover how easy it can be to make the switch to a digitally sovereign platform that respects your privacy. Reserve your seat for the online release of Nextcloud Hub 25 Autumn on September 27, 2025, at 10 AM (CEST)
Au début de l'année 2025, les hyperscalers américains ont commencé à promouvoir leurs nouvelles offres de « cloud souverain » dans le cadre d'une grande campagne de relations publiques en Europe. Au cours des dernières semaines, leur discours s'est effondré. Ce ne sont pas les critiques ou les organismes de surveillance qui ont mis en évidence les contradictions, mais les entreprises technologiques elles-mêmes qui ont admis que leurs promesses de « souveraineté » étaient vides de sens.
Les organisations, petites et grandes, ont besoin d'un moyen d'assurer la résilience et la souveraineté numérique de leurs opérations - une alternative à Teams, open-source et respectueuse de la vie privée. Aujourd'hui, nous vous présentons cette solution - Nextcloud Talk.
Nous vous présentons une mise à jour majeure de l'assistant Nextcloud IA, ainsi que de nouvelles informations sur notre collaboration avec plusieurs grands fournisseurs d'hébergement tels que IONOS et OVHcloud pour vous proposer des options d'IA en tant que service !
Bechtle et Nextcloud ont annoncé aujourd'hui une plateforme de collaboration entièrement administrée pour le secteur public, qui ne nécessite pas d'appel d'offres et peut être déployée immédiatement.
Découvrez comment passer de ownCloud à Nextcloud. Notre outil d'aide à la migration fournit des informations sur le processus de migration et vous aide à effectuer la transition en douceur.
Au cours de la dernière année, l'IA est devenue un sujet à la mode. Il y a de l'engouement, mais aussi du fondement. Il y a du positif et du négatif. Nous voulons vous offrir le positif, pas le négatif, et ignorer le battage médiatique ! […]
With the EU law proposal “Regulation to Prevent and Combat Child Sexual Abuse” — more commonly know as the EU Chat Control Law — our democracy is threatened from the inside: by our own governments. Citing child protection as the reason, the EU wants to backdoor end-to-end encryption, so they can access and read any […]
Join our workshops on September 27 and 28 as we come together in Berlin, Germany, for the Nextcloud Community Conference: a weekend of connecting, sharing, and building together. This year, we’re excited to bring you a series of hands-on workshops designed to help you sharpen your skills, explore new ideas, and collaborate with experts. From […]
Nous enregistrons certains cookies pour compter les visiteurs et faciliter l'utilisation du site. Ces données ne quittent pas notre serveur et ne sont pas destinées à vous suivre personnellement ! Consultez notre politique de confidentialité pour plus d'informations Personnaliser
Les cookies utilisés pour enregistrer les données saisies dans les formulaires, telles que le nom, l'adresse électronique, le numéro de téléphone et la langue préférée.
Nom du cookie :nc_form_fields
Description du cookie :Mémorise les données saisies dans les formulaires pour une prochaine visite (nom, adresse électronique, numéro de téléphone et langue préférée).
Les cookies statistiques collectent des informations de manière anonyme et nous aident à comprendre comment nos visiteurs utilisent notre site web. Nous utilisons la solution open source de mesure de statistiques web Matomo
Service:Matomo
Description du cookie :
_pk_ses*: Compte la première visite de l'utilisateur
_pk_id*: Aide à ne pas compter deux fois les visites.
mtm_cookie_consent: Se souvient que l'utilisateur a donné son accord pour le stockage et l'utilisation de cookies.
Expiration du cookie :_pk_ses*: 30 minutes
_pk_id*: 28 jours
mtm_cookie_consent: 30 jours