Habr•August 10, 2026•🇷🇺Translated from Russian

EU Extends Chat Control 1.0 Regulation to 2028 Despite Privacy Concerns and Parliamentary Opposition

The European Council has extended the temporary Regulation (EU) 2021/1232, commonly referred to as Chat Control 1.0, until 2028. This regulation permits internet service providers to voluntarily scan unencrypted communications on platforms including Discord and Gmail for CSAM material.

What is Chat Control 1.0

Officially titled the Regulation to Prevent and Combat Child Sexual Abuse, the measure has been in force since 2021. It applies to email and messaging providers, allowing them to conduct voluntary mass scanning of user traffic. Because the regulation is time-limited, periodic extensions are required.

Chat Control 2.0 Proposal

A follow-up proposal, COM(2022) 209, would make scanning mandatory and extend it to encrypted communications. This approach directly conflicts with the principles of end-to-end encryption used in modern messaging services. Privacy advocates argue that the measure would grant authorities access to all private correspondence across Europe.

The Chat Control 2.0 draft is intended as permanent legislation rather than a temporary regime. It remains under active debate in both the European Parliament and the Council.

How the Extension Was Approved

The original deadline for the current regime was April 2026. The European Commission proposed an extension, while the Parliament sought amendments to limit scanning and protect encryption. The Council rejected these changes. A parliamentary vote scheduled for 9 July 2026, the final plenary session before summer recess, saw 112 members absent. The motion to block the extension received 314 votes in favor and 276 against, with 17 abstentions, falling short of the 361-vote threshold needed.

Investigations by Balkan Insight highlighted close links between Commissioner Ilva Johansson's cabinet and the U.S. nonprofit Thorn, a vendor of CSAM detection software, as well as the WeProtect Global Alliance. The European Data Protection Supervisor ruled that targeted advertising promoting the regulation on X in several member states violated EU data-protection rules by excluding users based on political interests.

Related articles

Securitylab•Policy & Regulation

VPN Rules in Russia 2026: No Fine for Ordinary Users but Strict Penalties for Advertising and Extremist Content Access

As of September 2026, Russia maintains no separate administrative fine for ordinary citizens simply connecting to a VPN service. Responsibility arises only for specific actions such as deliberately searching for known extremist materials, advertising tools to bypass restrictions, or failing to comply with Roskomnadzor demands as a service operator. Corporate VPNs used for remote access to company networks remain fully legal under exceptions in Article 15.8 of Law No. 149-FZ. New provisions in the Code of Administrative Offenses, including Articles 13.53, 13.52 and 14.3 introduced by Laws 281-FZ and 282-FZ, impose fines ranging from 3,000 to 500,000 rubles depending on the violation and the offender category. The rules distinguish clearly between end users, service owners and advertisers. VPN technology itself is not banned, yet public services face ongoing blocking and operators must integrate with state filtering systems. The material reflects the regulatory situation on 24 September 2026.

Habr•Policy & Regulation

Troubleshooting Erroneous TSPU Blocks: How Admins Can Collaborate with Russian Regulators

A Moneta client outage traced back to erroneous filtering on Russia's TSPU system rather than internal infrastructure or DDoS protection. Engineers used curl, traceroute, nping, and custom Python scripts to confirm TCP payload-based blocking after the handshake. The team submitted a request via the VTS personal account, received partial acceptance status, then escalated to DCOA and SSOP to obtain the specific TSPU site number. Detailed network traces and active traffic were required for diagnostics. The case highlights coordination challenges between operators, DCOA, and SSOP when erroneous blocks occur on information resources.

AntiMalware•Policy & Regulation

Security Vision Unveils Self-Assessment Portal for Unified Information Security Evaluation Across Corporate Holdings

Security Vision has launched a new Self-Assessment portal designed to consolidate information security self-evaluations for entire corporate groups and holdings. The platform addresses common challenges where subsidiaries maintain inconsistent compliance records, with some requirements fulfilled while others remain unresolved for years in scattered emails and spreadsheets. Security Vision SA covers the complete workflow from defining requirements and distributing questionnaires to calculating results and tracking remediation actions. Parent organizations gain a consolidated view of subsidiary compliance status along with detailed breakdowns by individual systems. The system supports requirement templates, version control, scheduled assessments, automated metric-based answers, and conversion of gaps into actionable plans with assigned owners and deadlines. Additional features include internal policy document management and interactive dashboards for analysis. The first public demonstration is scheduled for the SOC Forum on October 27-28.

Habr•Policy & Regulation

Russian Websites Remain Dependent on Foreign SSL Certificates and Analytics Despite Sanctions

A Russian security researcher developed an open-source tool to scan websites for dependencies on foreign services that could be cut off abruptly. The scan of 50 major Russian sites including banks, retailers, telecoms, airlines, delivery services, online schools and government portals revealed that servers have largely been migrated domestically. However, critical components such as SSL certificates, analytics platforms and fonts remain tied to overseas providers. 43 out of 50 sites still use foreign SSL certificates, primarily from Belgian GlobalSign and American Let's Encrypt, while only four rely on the Russian NUC certificate from the Ministry of Digital Development. The study also highlights legal obligations under Roskomnadzor rules effective since March 2023 requiring prior notification for cross-border personal data transfers. Many sites continue using Google Analytics, Google Fonts and reCAPTCHA without realizing the compliance and resilience risks. The tool assigns letter grades from A to F based on the number of foreign dependencies detected.