My bookmarksSign up free
No longer in force

Regulation (EU) 2021/1232 of the European Parliament and of the Council of 14 July 2021 on a temporary derogation from certain provisions of Directive 2002/58/EC as regards the use of technologies by providers of number-independent interpersonal communications services for the processing of personal and other data for the purpose of combating online child sexual abuse (Text with EEA relevance)

Regulation (EU) 2021/1232 of the European Parliament and of the Council of 14 July 2021 on a temporary derogation from certain provisions of Directive 2002/58/EC as regards the use of technologies by providers of number-independent interpersonal communications services for the processing of personal and other data for the purpose of combating online child sexual abuse (Text with EEA relevance)

Regulation (EU) 2021/1232 · Regulation · 10 articles

RepealedRepealed 2026-04-03Status inferred from the source text; the official notice prevails.This legislation has been repealed. Do not cite it as law in force.

Data as of 2026-07-04 · Compiled from an official source version. Later amendments or repeals may not be reflected; the official text prevails. · Read the official text ↗

Subject matter and scope

Article 1

1.   This Regulation lays down temporary and strictly limited rules derogating from certain obligations laid down in Directive 2002/58/EC, with the sole objective of enabling providers of certain number-independent interpersonal communications services (‘providers’) to use, without prejudice to Regulation (EU) 2016/679, specific technologies for the processing of personal and other data to the extent strictly necessary to detect online child sexual abuse on their services and report it and to remove online child sexual abuse material from their services. 2.   This Regulation does not apply to the scanning of audio communications.

Definitions

Article 2

For the purposes of this Regulation, the following definitions apply: (1) ‘number-independent interpersonal communications service’ means a number-independent interpersonal communications service as defined in Article 2, point (7), of Directive (EU) 2018/1972; (2) ‘online child sexual abuse material’ means: (a) child pornography as defined in Article 2, point (c), of Directive 2011/93/EU; (b) pornographic performance as defined in Article 2, point (e), of Directive 2011/93/EU; (3) ‘solicitation of children’ means any intentional conduct constituting a criminal offence under Article 6 of Directive 2011/93/EU; (4) ‘online child sexual abuse’ means online child sexual abuse material and solicitation of children.

Scope of the derogation

Article 3

1.   Articles 5(1) and 6(1) of Directive 2002/58/EC shall not apply to the confidentiality of communications involving the processing by providers of personal and other data in connection with the provision of number-independent interpersonal communications services provided that: (a) the processing is: (i) strictly necessary for the use of specific technology for the sole purpose of detecting and removing online child sexual abuse material and reporting it to law enforcement authorities and to organisations acting in the public interest against child sexual abuse and of detecting solicitation of children and reporting it to law enforcement authorities or organisations acting in the public interest against child sexual abuse; (ii) proportionate and limited to technologies used by providers for the purpose set out in point (i); (iii) limited to content data and related traffic data that are strictly necessary for the purpose set out in point (i); (iv) limited to what is strictly necessary for the purpose set out in point (i); (b) the technologies used for the purpose set out in point (a)(i) of this paragraph are in accordance with the state of the art in the industry and are the least privacy-intrusive, including with regard to the principle of data protection by design and by default laid down in Article 25 of Regulation (EU) 2016/679 and, to the extent that they are used to scan text in communications, they are not able to deduce the substance of the content of the communications but are solely able to detect patterns which point to possible online child sexual abuse; (c) in respect of any specific technology used for the purpose set out in point (a)(i) of this paragraph, a prior data protection impact assessment as referred to in Article 35 of Regulation (EU) 2016/679 and a prior consultation procedure as referred to in Article 36 of that Regulation have been conducted; (d) with regard to new technology, meaning technology used for the purpose of detecting online child sexual abuse mat erial that has not been used by any provider in relation to services provided to users of number-independent interpersonal communications services (‘users’) in the Union before 2 August 2021, and with regard to technology used for the purpose of identifying possible solicitation of children, the provider reports back to the competent authority on the measures taken to demonstrate compliance with written advice issued in accordance with Article 36(2) of Regulation (EU) 2016/679 by the competent supervisory authority designated pursuant to Chapter VI, Section 1, of that Regulation (‘supervisory authority’) in the course of the prior consultation procedure; (e) the technologies used are sufficiently reliable in that they limit to the maximum extent possible the rate of errors regarding the detection of content representing online child sexual abuse and, where such occasional errors occur, their consequences are rectified without delay; (f) the technologies used to detect patterns of possible solicitation of children are limited to the use of relevant key indicators and objectively identified risk factors such as age difference and the likely involvement of a child in the scanned communication, without prejudice to the right to human review. (g) the providers: (i) have established internal procedures to prevent abuse of, unauthorised access to, and unauthorised transfers of, personal and other data; (ii) ensure human oversight of and, where necessary, human intervention in the processing of personal and other data using technologies falling under this Regulation; (iii) ensure that material not previously identified as online child sexual abuse material, or solicitation of children, is not reported to law enforcement authorities or organisations acting in the public interest against child sexual abuse without prior human confirmation; (iv) have established appropriate procedures and redress mechanisms to ensure that users can lodge complaints with them within a reasonable timeframe for the purpose of presenting their views; (v) inform users in a clear, prominent and comprehensible way of the fact that they have invoked, in accordance with this Regulation, the derogation from Articles 5(1) and 6(1) of Directive 2002/58/EC concerning the confidentiality of users’ communications for the sole purpose set out in point (a)(i) of this paragraph, the logic behind the measures they have taken under the derogation and the impact on the confidentiality of users’ communications, including the possibility that personal data are shared with law enforcement authorities and organisations acting in the public interest against child sexual abuse; (vi) inform users of the following, where their content has been removed or their account has been blocked or a service offered to them has been suspended: (1) the avenues for seeking redress from them; (2) the possibility of lodging a complaint with a supervisory authority; and (3) the right to a judicial remedy; (vii) by 3 February 2022, and by 31 January every year thereafter, publish and submit to the competent supervisory authority and to the Commission a report on the processing of personal data under this Regulation, including on: (1) the type and volumes of data processed; (2) the specific ground relied on for the processing pursuant to Regulation (EU) 2016/679; (3) the ground relied on for transfers of personal data outside the Union pursuant to Chapter V of Regulation (EU) 2016/679, where applicable; (4) the number of cases of online child sexual abuse identified, differentiating between online child sexual abuse material and solicitation of children; (5) the number of cases in which a user has lodged a complaint with the internal redress mechanism or with a judicial authority and the outcome of such complaints; (6) the numbers and ratios of errors (false positives) of the different technologies used; (7) the measures applied to limit the error rate and the error rate achieved; (8) the retention policy and the data protection safeguards applied pursuant to Regulation (EU) 2016/679; (9) the names of the organisations acting in the public interest against child sexual abuse with which data has been shared pursuant to this Regulation; (h) where suspected online child sexual abuse has been identified, the content data and related traffic data processed for the purpose set out in point (a)(i), and personal data generated through such processing are stored in a secure manner, solely for the purposes of: (i) reporting, without delay, the suspected online child sexual abuse to the competent law enforcement and judicial authorities or organisations acting in the public interest against child sexual abuse; (ii) blocking the account of, or suspending or terminating the provision of the service to, the user concerned; (iii) creating a unique, non-reconvertible digital signature (‘hash’) of data reliably identified as online child sexual abuse material; (iv) enabling the user concerned to seek redress from the provider or pursue administrative review or judicial remedies on matters related to the suspected online child sexual abuse; or (v) responding to requests issued by competent law enforcement and judicial authorities in accordance with the applicable law to provide them with the necessary data for the prevention, detection, investigation or prosecution of criminal offences as set out in Directive 2011/93/EU; (i) the data are stored no longer than strictly necessary for the relevant purpose set out in point (h) and, in any event, no longer than 12 months from the date of the identification of the suspected online child sexual abuse; (j) every case of a reasoned and verified suspicion of online child sexual abuse is reported without delay to the competent national law enforcement authorities or to organisations acting in the public interest against child sexual abuse. 2.   Until 3 April 2022, the condition set out in paragraph 1, point (c), shall not apply to providers that: (a) were using a specific technology before 2 August 2021 for the purpose set out in paragraph 1, point (a)(i), without having completed a prior consultation procedure in respect of that technology; (b) start a prior consultation procedure before 3 September 2021; and (c) duly cooperate with the competent supervisory authority in connection with the prior consultation procedure referred to in point (b). 3.   Until 3 April 2022, the condition set out in paragraph 1, point (d), shall not apply to providers that: (a) were using a technology as referred to in paragraph 1, point (d), before 2 August 2021 without having completed a prior consultation procedure in respect of that technology; (b) start a procedure as referred to in paragraph 1, point (d), before 3 September 2021; and (c) duly cooperate with the competent supervisory authority in connection with the procedure referred to in paragraph 1, point (d).

European Data Protection Board guidelines

Article 4

By 3 September 2021, and pursuant to Article 70 of Regulation (EU) 2016/679, the Commission shall request the European Data Protection Board to issue guidelines for the purpose of assisting the supervisory authorities in assessing whether processing falling within the scope of this Regulation, for existing and new technologies used for the purpose set out in Article 3(1), point (a)(i), of this Regulation, complies with Regulation (EU) 2016/679.

Effective judicial remedies

Article 5

In accordance with Article 79 of Regulation (EU) 2016/679 and Article 15(2) of Directive 2002/58/EC, users shall have the right to an effective judicial remedy where they consider that their rights have been infringed as a result of the processing of personal and other data for the purpose set out in Article 3(1), point (a)(i), of this Regulation.

Supervisory authorities

Article 6

The supervisory authorities designated pursuant to Chapter VI, Section 1, of Regulation (EU) 2016/679 shall monitor the processing falling within the scope of this Regulation in accordance with their competences and powers under that Chapter.

Public list of organisations acting in the public interest against child sexual abuse

Article 7

1.   By 3 September 2021, providers shall communicate to the Commission a list of the names of organisations acting in the public interest against child sexual abuse to which they report online child sexual abuse under this Regulation. Providers shall communicate any changes to that list to the Commission on a regular basis. 2.   By 3 October 2021, the Commission shall make public a list of the names of organisations acting in the public interest against child sexual abuse communicated to it under the paragraph 1. The Commission shall keep that public list up to date.

Statistics

Article 8

1.   By 3 August 2022, and on an annual basis thereafter, the Member States shall make publicly available and submit to the Commission reports with statistics on the following: (a) the total number of reports of detected online child sexual abuse that have been submitted by providers and organisations acting in the public interest against child sexual abuse to the competent national law enforcement authorities, differentiating, where such information is available, between the absolute number of cases and those cases reported several times and the type of provider on whose service the online child sexual abuse was detected; (b) the number of children identified through actions pursuant to Article 3, differentiated by gender; (c) the number of perpetrators convicted. 2.   The Commission shall aggregate the statistics referred to in paragraph 1 of this Article and shall take them into account when preparing the implementation report pursuant to Article 9.

Implementation report

Article 9

1.   On the basis of the reports submitted pursuant to Article 3(1), point (g)(vii), and the statistics provided pursuant to Article 8, the Commission shall, by 3 August 2023, prepare a report on the implementation of this Regulation and submit and present it to the European Parliament and to Council. 2.   In the implementation report, the Commission shall consider, in particular: (a) the conditions for the processing of personal data and other data set out in Article 3(1), point (a)(ii), and points (b), (c) and (d); (b) the proportionality of the derogation provided for by this Regulation, including an assessment of the statistics submitted by the Member States pursuant to Article 8; (c) developments in technological progress regarding the activities covered by this Regulation, and the extent to which such developments improve accuracy and reduce the numbers and ratios of errors (false positives).

Entry into force and application

Article 10

This Regulation shall enter into force on the third day following that of its publication in the Official Journal of the European Union . It shall apply until 3 August 2024.

Other acts of the same type
Commission Implementing Regulation (EU) 2020/2016 of 9 December 2020 amending Annex II to Implementing Regulation (EU) No 577/2013 as regards the entries for the United Kingdom, Guernsey, the Isle of Man and Jersey (Text with EEA relevance)Commission Implementing Regulation (EU) 2020/2017 of 9 December 2020 amending Part 2 of the Annex to Implementing Regulation (EU) 2018/878 as regards the entry for United Kingdom in respect of Northern Ireland (Text with EEA relevance)Commission Implementing Regulation (EU) 2020/2018 of 9 December 2020 entering a name in the register of protected designations of origin and protected geographical indications (Mozzarella di Gioia del Colle (PDO))Commission Implementing Regulation (EU) 2020/2036 of 9 December 2020 amending Regulation (EU) No 965/2012 as regards the requirements for flight crew competence and training methods and postponing dates of application of certain measures in the context of the COVID-19 pandemicCommission Implementing Regulation (EU) 2020/2080 of 9 December 2020 concerning the classification of certain goods in the Combined NomenclatureCommission Implementing Regulation (EU) 2020/2095 of 9 December 2020 approving non-minor amendments to the product specification for a name entered in the register of protected designations of origin and protected geographical indications [‘Aceite de la Comunitat Valenciana’ (PDO)]Commission Implementing Regulation (EU) 2020/2149 of 9 December 2020 amending Council Regulation (EC) No 2368/2002 implementing the Kimberley Process certification scheme for the international trade in rough diamonds, in order to add Italy as a Union authority and to take into account the withdrawal of the United Kingdom from the UnionCommission Implementing Regulation (EU) 2020/2006 of 8 December 2020 operating deductions from fishing quotas available for certain stocks in 2020 on account of overfishing of other stocks in the previous years and amending Implementing Regulation (EU) 2020/1247Commission Implementing Regulation (EU) 2020/2007 of 8 December 2020 amending Implementing Regulation (EU) No 540/2011 as regards the extension of the approval periods of the active substances 1-decanol, 1,4-dimethylnaphthalene, 6-benzyladenine, acequinocyl, Adoxophyes orana granulovirus, aluminium sulfate, amisulbrom, Aureobasidium pullulans (strains DSM 14940 and DSM 14941), azadirachtin, Bacillus pumilus QST 2808, benalaxyl-M, bixafen, bupirimate, Candida oleophila strain O, chlorantraniliprole, disodium phosphonate, dithianon, dodine, emamectin, flubendiamide, fluometuron, fluxapyroxad, flutriafol, hexythiazox, imazamox, ipconazole, isoxaben, L-ascorbic acid, lime sulphur, orange oil, Paecilomyces fumosoroseus strain FE 9901, pendimethalin, penflufen, penthiopyrad, potassium phosphonates, prosulfuron, Pseudomonas sp. strain DSMZ 13134, pyridalyl, pyriofenone, pyroxsulam, quinmerac, S-abscisic acid, sedaxane, sintofen, sodium silver thiosulfate, spinetoram, spirotetramat, Streptomyces lydicus strain WYEC 108, tau-fluvalinate, tebufenozide, tembotrione, thiencarbazone, valifenalate, zinc phosphideCommission Regulation (EU) 2020/2008 of 8 December 2020 amending Regulations (EU) No 702/2014, (EU) No 717/2014 and (EU) No 1388/2014, as regards their period of application and other relevant adjustments (Text with EEA relevance)Commission Implementing Regulation (EU) 2020/2079 of 8 December 2020 approving amendments to the product specification for a spirit drink whose name is registered as a geographical indication (Münchener Kümmel)Council Regulation (EU) 2020/1998 of 7 December 2020 concerning restrictive measures against serious human rights violations and abuses

Source: EUR-Lex (Publications Office of the EU), © European Union, reuse permitted under Commission Decision 2011/833/EU.

What to look at next