Skip to main content

EU CSAM Interim

Regulation (EU) 2021/1232 + Regulation (EU) 2024/1307 + Regulation (EU) 2026/1881 (CSAM Interim Derogation)

Temporary legal bridge allowing certain number-independent interpersonal communications providers to voluntarily detect, report, and remove child sexual abuse material notwithstanding ePrivacy constraints, pending the permanent CSAR framework. Now carried by Regulation (EU) 2026/1881, which succeeded the expired Regulation (EU) 2021/1232 and applies until April 3, 2028.

Jurisdiction

European Union

Enacted

Jul 14, 2021

Effective

Aug 2, 2021

Enforcement

National data protection authorities; ePrivacy regulation enforcement varies by member state

In force again. Regulation (EU) 2021/1232, as extended by Regulation (EU) 2024/1307, expired on April 3, 2026 after the European Parliament declined a further extension on March 26, 2026, leaving a gap of roughly four months. A replacement instrument, Regulation (EU) 2026/1881, was adopted on July 24, 2026, published in the Official Journal on July 28, 2026, and entered into force on the third day following publication (July 31, 2026). It applies until April 3, 2028. It is a fresh regulation rather than an amendment extending the 2021 text.

EUR-Lex (Regulation (EU) 2026/1881)

Why It Matters

Bridge law keeping voluntary scanning alive while permanent CSAR fight continues. Expires April 2026.

Recent Developments

Regulation (EU) 2021/1232 lapsed on April 3, 2026 after Parliament declined to extend it, creating a period in which voluntary CSAM detection in private communications had no ePrivacy derogation. The Council moved to reinstate an interim measure on July 2, 2026 and Parliament supported a narrower replacement on July 6, 2026. Regulation (EU) 2026/1881 was then adopted on July 24, 2026 and published in the Official Journal on July 28, 2026, restoring the derogation through April 3, 2028. Its recitals record that the co-legislators could not agree on the Commission proposal of December 19, 2025 before the April 3, 2026 expiry. The derogation does not extend to the scanning of audio communications.

At a Glance

Applies to

Social PlatformOnline PlatformGeneral Chatbot

Harms addressed

Who Must Comply

  • Providers of number-independent interpersonal communications services in EU

Safety Provisions

  • Enables voluntary CSAM detection/reporting/removal by number-independent interpersonal communications services (NIICS)
  • Strict necessity/proportionality; GDPR still applies
  • Harmonized reporting on voluntary measures
  • Exclusion of audio communications
  • Mandatory DPIA for detection technologies
  • Compulsory human review before reporting

Compliance & Enforcement

Key Dates

Apr 3, 2026

Regulation (EU) 2021/1232 (as extended by 2024/1307) expired, ending the first derogation

Jul 31, 2026

Replacement derogation, Regulation (EU) 2026/1881, entered into force

Apr 3, 2028

Regulation (EU) 2026/1881 ceases to apply

Penalties

Penalties vary by jurisdiction

View on map

European Union

Focus Areas

Child safety
Active safeguards required

Cite This

APA

European Union. (2021). Regulation (EU) 2021/1232 + Regulation (EU) 2024/1307 + Regulation (EU) 2026/1881 (CSAM Interim Derogation).

Related Regulations

In Effect EU

EU DSA Minors Guidelines

Commission guidelines under DSA Article 28(1) establishing measures for online platforms to protect minors, including age assurance, default privacy settings, anti-addictive design restrictions, recommender system safeguards, and protections against grooming and exploitation.

Pending EU

EU CSAR (Proposed)

Proposed permanent framework replacing interim derogation. Parliament position (Nov 2023) limits detection to known/new CSAM, excludes E2EE services. Council has not agreed General Approach.

In Effect DE

DE JuSchG §24a (KidD)

Requires providers of certain telemedia services to implement provider-side precautionary measures ("Vorsorgemaßnahmen") with regulator-facing evaluability via published BzKJ criteria.

In Effect FR

FR SREN

France's 2024 "digital space" law strengthening national digital regulation and enforcement levers via ARCOM across platform safety and integrity issues.

In Effect IE

Ireland OSMR

Establishes Coimisiún na Meán (Media Commission) with binding duties for video-sharing platforms. One of the cleaner examples of explicit self-harm/suicide/eating-disorder content duties in platform governance.

In Effect GB

UK OSA Minimum Standards of Accuracy

Statutory minimum standards of accuracy that terrorism-content and CSEA-content detection technology must meet before Ofcom can accredit it and require its use through a technology notice under Chapter 5 of Part 7 of the Online Safety Act 2023. Accreditation is an audit-based assessment across four principles (technical performance, fairness, robustness, maintainability), each scored from evidence submitted by the technology developer.

Last updated August 30, 2026. Verify against primary sources before relying on this information.