In case you don't know what 1.0 does:
What is it?
A temporary derogation from the ePrivacy Directive that allowed (but did not require) providers to scan private messages of unsuspected users for potential child sexual abuse material.
Is scanning mandatory?
No — voluntary. In practice used mainly by unencrypted US services such as Gmail, Facebook/Instagram Messenger, Skype, Snapchat, iCloud Mail, and Xbox.
Does it touch encrypted messages?
No. End-to-end encrypted communications were never scanned but providers could deploy client-side scanning under this law.
Status today
Back in force. After expiring on 4 April 2026, it was reinstated on 9 July 2026 when Parliament failed to reach the absolute majority of 361 MEPs needed to reject the Council's fast-tracked "new" law. Only 314 MEPs voted to reject it, so suspicionless mass scanning is permitted to continue until 2028.