The European debate on so-called Chat Control has once again put the privacy of communications at the center of the conversation. The official aim is to combat online child sexual abuse, a necessary and socially unquestionable objective. But the debate also raises an uncomfortable question: how to pursue serious crimes on the internet without disproportionately weakening the legitimate privacy of citizens, businesses, and professionals.
And while Europe debates that balance, something much simpler happens in day-to-day life: we continue sending passwords, logins, tax data, banking information, or confidential documentation via WhatsApp, Telegram, email, or internal chats.
Many security breaches do not start with a sophisticated attack. They start with a message sent in a hurry.
What is happening now with so-called Chat Control
The term Chat Control is commonly used to refer to the European debate on measures to detect, report, and remove online child sexual abuse material. To avoid confusion, it is worth updating the context properly: this is not a general privacy rule, but a very specific file related to the temporary derogation of certain confidentiality rules for electronic communications to allow voluntary activities to detect online child sexual abuse.
As of this review, the relevant file is procedure 2025/0429(COD), on the amendment of Regulation (EU) 2021/1232. That regulation had allowed, on a temporary and limited basis, certain providers of number-independent interpersonal communications services to use specific technologies to detect, report, and remove online child sexual abuse material.
The previous regime expired on April 3, 2026. Afterwards, the Council of the European Union adopted its position on July 2, 2026 to reactivate a transitional measure until April 3, 2028, while the permanent framework continues to be negotiated. The key update is that, in the European Parliament’s official voting list for Thursday, July 9, 2026, the item “Amending Regulation (EU) 2021/1232 as regards the extension of its period of application” (C10-0178) appears. In other words, we are no longer talking only about a previous vote or the Council’s position: as of July 9, the matter is explicitly on the European Parliament’s voting agenda.
For that reason, the current reading should focus on this stage of the file: the attempt to reactivate the temporary regime in a context of political and legal urgency. The stated objective is to protect minors and avoid a prolonged legal vacuum, but the debate still requires sufficient safeguards for privacy, proportionality, and data protection.
| Concept | What it means |
| Regulation (EU) 2021/1232 | Temporary regime related to the use of technologies by certain providers to combat online child sexual abuse, through a limited derogation from ePrivacy rules. |
| Procedure 2025/0429(COD) | Legislative file to amend Regulation 2021/1232 and extend or reactivate its application while the permanent framework is negotiated. |
| Status as of July 9, 2026 | The Council adopted its position on July 2, 2026. The European Parliament’s official voting list includes the item for Thursday, July 9, 2026. |
| Underlying debate | How to pursue serious crimes without normalizing generalized scanning systems or excessively affecting legitimate private communications. |
The fight against online child sexual abuse is a legitimate, necessary, and socially unquestionable purpose. The legal and technical question is not whether these crimes should be prosecuted, but how to do so without disproportionately affecting legitimate private communications.
Public security and privacy should not be set against each other
This debate should not be framed as a war between security and privacy. A mature digital society needs both: effective tools to pursue serious crimes and strong safeguards to protect legitimate communications.
The European Data Protection Supervisor has warned, in relation to the extension of Regulation 2021/1232, that the temporary rules to combat online child sexual abuse material must address shortcomings and avoid indiscriminate scanning. That nuance is important.
Privacy is not opacity. Encryption is not suspicious behavior. In many cases, it is simply a basic security measure.
A company that protects clients’ tax data. A firm that exchanges confidential documentation. A professional who shares temporary access. A consultancy that receives personal information. All these cases have something in common: they handle data that should not be circulating as plain text.
The everyday risk: sending sensitive data as if it were normal messages
The problem is not only in major European rules. It is also in an everyday practice that we have all seen at some point.
A client sends a password via WhatsApp. A supplier shares access via Telegram. An employee forwards personal information by email. A company sends tax data in plain text because “it’s faster.”
The message is sent, it stays stored, it can sync to other devices, be forwarded, screenshotted, or be exposed if an account is compromised. Then, when the problem appears, the question is usually the same: “How did they access my data?”.
Sometimes there has not been a complex hack. There has been a prior bad practice: sharing sensitive information without a sufficient layer of protection.
| Information sent for convenience | Common risk | More prudent practice |
| Passwords or temporary keys | They remain stored, forwarded, or visible in a compromised account. | Password manager, temporary link, or encrypted message. |
| Tax or accounting data | Exposure of personal or business information. | Secure document channel and encryption where appropriate. |
| Access to platforms | Misuse or loss of control over the account. | Individual access, MFA, and key rotation. |
| Banking information | Risk of fraud, impersonation, or social engineering. | Verification via a separate channel and minimal exposure. |
| Clients’ personal data | Non-compliance with internal data protection protocols. | Data minimization, permissions, and appropriate technical measures. |
Convenience is understandable. Nobody wants to complicate a simple task. But in cybersecurity, fast can become expensive when we are talking about passwords, access, tax data, or business information.
Why Advixy is incorporating Layergram into its protocols
At Advixy, we work daily with sensitive information from companies, professionals, and clients: tax documentation, corporate data, access credentials, business information, internal communications, and personal data.
That is why cybersecurity cannot be limited to large corporate systems. It must also apply to everyday actions: how a password is sent, how an access instruction is shared, or how data is transmitted that should not remain visible in an ordinary conversation.
In this context, we are incorporating Layergram into our internal security protocols.
Layergram is not a tool owned by Advixy nor is it presented as our own product: it is an independent open-source project, created by one of Advixy’s partners. Its basic version is free; there is also an optional paid tier with additional features, which is not necessary for the use we describe here. We know it closely and we are using it to strengthen a very specific part of day-to-day operations: sending sensitive information through common channels.
Its function is simple: add a layer of local encryption before sending certain messages via WhatsApp, Telegram, Signal, iMessage, email, or other channels. Layergram is not intended to replace existing messaging apps, but to work as an encryption layer independent of the transport channel.
How Layergram works in practice
Layergram starts from a very clear idea: you cannot always change the channel a client, supplier, or team uses. But you can prevent sensitive data from traveling as plain text.
The practical workflow is simple:
- You write in Layergram the sensitive content you want to protect.
- The tool encrypts it locally on the device.
- You copy the encrypted message.
- You send it through the usual channel: WhatsApp, Telegram, Signal, iMessage, email, or another.
- The recipient decrypts it with Layergram if they have the corresponding keys.
Layergram lets you keep the usual apps (WhatsApp, Telegram, Signal, iMessage, email, or social networks), and the message is encrypted locally with modern cryptography.
This is important because the goal is not for the client to abandon their usual messaging app or have to register on a new network. The goal is to reduce the exposure of sensitive messages when communication is already taking place through ordinary channels.
Does this mean all messages must be encrypted?
No. And this distinction is important.
Not all messages need an additional layer of encryption. A meeting confirmation, a greeting, or a general conversation do not carry the same level of risk as a password, tax data, an access instruction, or a client’s confidential information.
The key is knowing how to tell the difference.
In a consultancy, advisory firm, professional practice, or a company that handles sensitive information, that distinction should be part of the internal security culture. It is not enough to have data protection policies if, for convenience, access is then shared via WhatsApp without any additional protection.
Layergram does not turn a bad practice into a perfect practice. But it does help correct one of the most common habits: sending delicate data as if it were ordinary messages.
Sending passwords via WhatsApp: a practice that should stop being normalized
As a general rule, a password should not be sent via ordinary messaging.
The most prudent approach is to use password managers, individual access, temporary links, multi-factor authentication, and key rotation. However, the reality for many companies is different: due to urgency, lack of awareness, or convenience, passwords still circulate via WhatsApp, Telegram, or email.
When that happens, the risk is not only that someone reads the message at that moment. The risk is that the information remains stored, synced, copied, forwarded, or accessible from a compromised device.
That is why, if a password or access data is exceptionally shared, it is reasonable to avoid it traveling as plain text, limit its validity, and change it afterwards.
Security does not depend on a single tool. It depends on a way of working.
Encryption, GDPR, and good data protection practices
The GDPR does not require a specific tool to protect personal data. What it requires is adopting technical and organizational measures appropriate to the risk.
Article 25 sets out the principle of data protection by design and by default. Article 32 addresses security of processing and includes, where appropriate, measures such as pseudonymization and encryption of personal data, as well as the ability to ensure the confidentiality, integrity, availability, and resilience of systems.
This does not mean that using an encryption tool is enough to comply with the GDPR. It is not. Data protection requires internal policies, access control, training, data minimization, multi-factor authentication, permission reviews, and appropriate document channels.
But encryption can be part of a reasonable security strategy, especially when sensitive information is shared in day-to-day communications.
Encryption is not a way to hide: it is a way to protect
One of the most common mistakes in this debate is associating encryption with concealment. In reality, for businesses and professionals, encryption is a basic protection measure.
An advisory firm does not encrypt information because it wants to hide it improperly. It encrypts it because it has an obligation to protect it.
A firm does not protect a confidential document because it is suspicious. It protects it because it affects a client.
A company should not send internal access details in the clear because those access details can compromise systems, data, and responsibilities.
The debate should not be whether encryption is good or bad. The right question is different: what information should never circulate as plain text.
The practical lesson for businesses and professionals
The European debate on Chat Control is a reminder that the privacy of communications will remain one of the major regulatory topics of the coming years. But data protection does not start only in Brussels, nor in a directive, nor in a regulation.
It starts with every message we send.
Protecting minors against serious online crimes is necessary. Protecting legitimate privacy and the sensitive data of citizens, businesses, and professionals is also necessary. The issue is not choosing one or the other, but building proportionate, secure, and responsible solutions.
For Advixy, incorporating Layergram into its internal protocols is a practical decision: to reduce the exposure of sensitive information in everyday communications.
It is not about hiding information. It is about protecting data that should never circulate unprotected.
Further reading: Cybersecurity for businesses and freelancers and AI and accounting in 2026: how to use artificial intelligence in your business without getting in trouble with the Spanish tax authorities.





