EU CSAM Interim
Regulation (EU) 2021/1232 + Regulation (EU) 2024/1307 + Regulation (EU) 2026/1881 (CSAM Interim Derogation)
Temporary legal bridge allowing certain number-independent interpersonal communications providers to voluntarily detect, report, and remove child sexual abuse material notwithstanding ePrivacy constraints, pending the permanent CSAR framework. Now carried by Regulation (EU) 2026/1881, which succeeded the expired Regulation (EU) 2021/1232 and applies until April 3, 2028.
Jurisdiction
European Union
Enacted
Jul 14, 2021
Effective
Aug 2, 2021
Enforcement
National data protection authorities; ePrivacy regulation enforcement varies by member state
In force again. Regulation (EU) 2021/1232, as extended by Regulation (EU) 2024/1307, expired on April 3, 2026 after the European Parliament declined a further extension on March 26, 2026, leaving a gap of roughly four months. A replacement instrument, Regulation (EU) 2026/1881, was adopted on July 24, 2026, published in the Official Journal on July 28, 2026, and entered into force on the third day following publication (July 31, 2026). It applies until April 3, 2028. It is a fresh regulation rather than an amendment extending the 2021 text.
EUR-Lex (Regulation (EU) 2026/1881)Why It Matters
Bridge law keeping voluntary scanning alive while permanent CSAR fight continues. Expires April 2026.
Recent Developments
Regulation (EU) 2021/1232 lapsed on April 3, 2026 after Parliament declined to extend it, creating a period in which voluntary CSAM detection in private communications had no ePrivacy derogation. The Council moved to reinstate an interim measure on July 2, 2026 and Parliament supported a narrower replacement on July 6, 2026. Regulation (EU) 2026/1881 was then adopted on July 24, 2026 and published in the Official Journal on July 28, 2026, restoring the derogation through April 3, 2028. Its recitals record that the co-legislators could not agree on the Commission proposal of December 19, 2025 before the April 3, 2026 expiry. The derogation does not extend to the scanning of audio communications.
At a Glance
Applies to
Harms addressed
Requires
Who Must Comply
- Providers of number-independent interpersonal communications services in EU
Obligations fall on:
Safety Provisions
- Enables voluntary CSAM detection/reporting/removal by number-independent interpersonal communications services (NIICS)
- Strict necessity/proportionality; GDPR still applies
- Harmonized reporting on voluntary measures
- Exclusion of audio communications
- Mandatory DPIA for detection technologies
- Compulsory human review before reporting
Compliance & Enforcement
Key Dates
Apr 3, 2026
Regulation (EU) 2021/1232 (as extended by 2024/1307) expired, ending the first derogation
Jul 31, 2026
Replacement derogation, Regulation (EU) 2026/1881, entered into force
Apr 3, 2028
Regulation (EU) 2026/1881 ceases to apply
Penalties
Penalties vary by jurisdiction
View on map
European Union
Focus Areas
Cite This
APA
European Union. (2021). Regulation (EU) 2021/1232 + Regulation (EU) 2024/1307 + Regulation (EU) 2026/1881 (CSAM Interim Derogation).
Related Regulations
EU DSA Minors Guidelines
Commission guidelines under DSA Article 28(1) establishing measures for online platforms to protect minors, including age assurance, default privacy settings, anti-addictive design restrictions, recommender system safeguards, and protections against grooming and exploitation.
EU CSAR (Proposed)
Proposed permanent framework replacing interim derogation. Parliament position (Nov 2023) limits detection to known/new CSAM, excludes E2EE services. Council has not agreed General Approach.
DE JuSchG §24a (KidD)
Requires providers of certain telemedia services to implement provider-side precautionary measures ("Vorsorgemaßnahmen") with regulator-facing evaluability via published BzKJ criteria.
FR SREN
France's 2024 "digital space" law strengthening national digital regulation and enforcement levers via ARCOM across platform safety and integrity issues.
Ireland OSMR
Establishes Coimisiún na Meán (Media Commission) with binding duties for video-sharing platforms. One of the cleaner examples of explicit self-harm/suicide/eating-disorder content duties in platform governance.
UK OSA Minimum Standards of Accuracy
Statutory minimum standards of accuracy that terrorism-content and CSEA-content detection technology must meet before Ofcom can accredit it and require its use through a technology notice under Chapter 5 of Part 7 of the Online Safety Act 2023. Accreditation is an audit-based assessment across four principles (technical performance, fairness, robustness, maintainability), each scored from evidence submitted by the technology developer.
Last updated August 30, 2026. Verify against primary sources before relying on this information.