File 00 · The record

Private messaging is being legislated against. These are the receipts.

Everything below is a real instrument: a regulation, a statute, a court order, or a measured network block. Each entry says what it does, what it does not do, and links to the source so you can read it without us in the way.

How to read this

A proposal is not a law. Four of the things most often described as European surveillance law have never been adopted. They are marked Proposed and nothing else.

Most blocks have no order behind them. Where a government published nothing, the entry says so and cites the network measurement instead of pretending there is a document.

Nothing here compels decryption. Not one instrument on this page has ever produced the contents of an end-to-end encrypted message. What they reach is reachability, metadata and identity.

Europe

Four years of argument about scanning private messages, and the thing that finally passed carved encryption out of itself.

01European UnionIn force

In force 31 July 2026 · expires 3 April 2028

Chat Control 1.0: Regulation (EU) 2026/1881

Suspends the confidentiality rules in the ePrivacy Directive so that messaging and webmail providers may voluntarily scan for child sexual abuse material and report it. It replaced an identical 2021 regulation that Parliament let expire on 3 April 2026, leaving a four-month gap with no legal basis at all.

What it does not do

It compels nobody to scan anything, and Article 1(3) puts end-to-end encrypted communications outside its scope entirely. In the operative text, not a recital. Article 1(2) excludes audio. Recital 32: "Nothing in this Regulation should be interpreted as prohibiting or weakening end-to-end encryption."

This is the law people mean when they say the EU is reading your messages. It permits scanning; it does not require it, and it cannot reach an encrypted one.

EUR-Lex · full adopted text
02European UnionProposed

Proposed 11 May 2022 · still not adopted

Chat Control 2.0: the permanent CSA Regulation

Would create a standing EU regime of detection, removal and blocking orders aimed at child sexual abuse material, reaching interpersonal communication services. It is the only live European proposal that could ever mandate detection inside a private messenger.

What it does not do

After four years it imposes no obligation on anyone, because it has never been adopted. The fifth trilogue was held on 11 May 2026 and produced no agreement; whether detection is mandatory or voluntary, and how encryption is treated, are exactly the points still unresolved.

Anyone telling you what "Chat Control requires" is describing a contested draft. Three institutions hold three different versions of it.

European Parliament · legislative train
03European UnionIn force

Applies from 18 August 2026

e-Evidence: Regulation (EU) 2023/1543

Lets a judge in one member state send a production or preservation order straight to a service provider in another, for electronic evidence including message content. It covers messaging providers, not only telephone companies.

What it does not do

Recital 20 says it "should not lay down any obligation for service providers to decrypt data," and Recital 19 rules out any general retention duty. It works case by case, on a judicial order. The opposite of bulk collection, though the two are constantly conflated.

EUR-Lex · Regulation 2023/1543
04European UnionIn force

In force 20 May 2024 · wallets due end of 2026

European Digital Identity Wallet: Regulation (EU) 2024/1183

Every member state must offer a free digital identity wallet holding government-verified identity data, and public bodies and large regulated services must accept it. The deadline for the wallets themselves is the end of 2026.

What it does not do

Article 5a(15) makes use voluntary for people and forbids disadvantaging anyone who declines. Article 5b(9) bars a service from refusing a pseudonym where no law requires identification, and Article 5a(14) stops the wallet provider itself building a profile of where you used it.

The mandate runs on governments and on the services that must accept the wallet. Never on the individual. That is the opposite of how it is usually reported.

EUR-Lex · Regulation 2024/1183

United Kingdom

The scanning power everybody argues about has never been used. The one that matters is older, quieter, and secret by statute.

05United KingdomIn force

In force 10 January 2024 · never used

Online Safety Act 2023, section 121: technology notices

Lets Ofcom order a service to deploy accredited technology to detect child sexual abuse material. And for that purpose it reaches private messages, not just public ones. This is the UK power that could compel client-side scanning inside an encrypted messenger.

What it does not do

No notice has ever been issued and none currently can be. Technology counts as "accredited" only against minimum accuracy standards the Secretary of State has to approve and publish, and none exist. Ofcom's own statutory report, February 2026: "this part of the online safety regime is not active."

The assurance that it will not break encryption is a minister's statement from a 2023 Lords debate, not a carve-out in the text of the Act.

legislation.gov.uk · OSA 2023 s.121
06United KingdomIn force

In force since 2016

Investigatory Powers Act 2016, section 253: technical capability notices

The Home Secretary may order a communications operator to build and keep the capability to help execute warrants, expressly including "the removal by a relevant operator of electronic protection." It applies to companies outside the UK, and section 255(8) makes the existence of a notice secret.

What it does not do

It does not authorise interception on its own, a separate warrant is still needed, and a judicial commissioner must approve the notice. But section 43(6) is the sharp edge: once a notice applies, the steps you are expected to take include every step you could have taken had you built the capability. "We cannot decrypt" becomes "you should have been able to."

The government neither confirms nor denies that any notice has ever been served on anyone. That is the official position, given in a written answer in June 2025.

legislation.gov.uk · IPA 2016 s.253
07United KingdomBefore a court

Ongoing · substantive hearing listed December 2026

Apple and the Home Office, at the Investigatory Powers Tribunal

Apple withdrew Advanced Data Protection for new UK users on 21 February 2025, after a reported technical capability notice. It filed a fresh tribunal claim disclosed on 3 August 2026, and a separate challenge to the notices regime itself, brought by Privacy International and Liberty, is listed for hearing in December 2026.

What it does not do

Apple did not remove end-to-end encryption. iMessage and FaceTime stay encrypted end to end worldwide, fifteen iCloud data categories remain encrypted by default, and what was lost is the option of extending that to ten more. The Tribunal has published one judgment, and it says in terms that it should not be taken as confirming the reporting is accurate.

Nobody outside the process knows what was ordered. Everything public about it is reporting the government will not confirm.

Investigatory Powers Tribunal · published judgment
08United KingdomIn force

Operative 25 July 2025 · eight fines to date

Online Safety Act age checks, and what enforcement looks like

Services that let children encounter pornography or content about suicide, self-harm or eating disorders must use "highly effective age assurance." Eight companies have been fined for failing to, from £50,000 to £1.35m, and around two dozen investigations are open.

What it does not do

No method is mandated. Ofcom lists seven, several of which never show an ID document to the site. No UK site has been blocked by court order; Ofcom said plainly in July 2026 that it has no power to block a site for not paying a fine. The services that vanished blocked themselves.

The Guardian · the £1m fine, and what triggered it

United States

No backdoor mandate has ever been enacted. The pressure arrives through the app store, the courtroom and the liability rule instead.

09United StatesBefore a court

Decided 27 June 2025

Free Speech Coalition v. Paxton: the Supreme Court on age checks

The Court upheld a Texas law requiring age verification on sites where at least a third of the content is sexual material harmful to minors, applying intermediate rather than strict scrutiny. Twenty-six states now have adult-content age-verification laws in force, and after this ruling none is enjoined.

What it does not do

It reaches only speech that is obscene as to minors. The Court did not bless age gates on social media, on app stores, or on any speech lawful for adults and children alike. For those, strict scrutiny survives.

Supreme Court · full opinion (PDF)
10Texas, United StatesIn force

Enforceable since 4 June 2026

Texas S.B. 2420: the App Store Accountability Act

Every app-store account holder, adult or child, must have their age verified before the account is created, and under-18s must be tied to a verified parent account that approves each individual download. It was enjoined in December 2025, the Fifth Circuit stayed that injunction in June 2026, and on 6 July 2026 the Supreme Court declined to vacate the stay.

What it does not do

The Supreme Court order was an emergency-docket denial, not a ruling that the law is constitutional; the merits were argued in the Fifth Circuit on 4 August 2026 and are undecided. Louisiana has a similar law live since 1 July 2026; Alabama's starts 1 January 2027; Utah's is deferred to May 2027.

This is the first American law under which installing an encrypted messenger means proving who you are. At the store, before you ever open the app.

Supreme Court · docket 25A1390
11United StatesProposed

Reported out of committee 26 June 2025 · no floor vote since

STOP CSAM Act: where shipping encryption becomes evidence

Creates a civil action against services that host child sexual abuse material "intentionally, knowingly, or recklessly," with $300,000 in liquidated damages, no limitation period, and the Section 230 shield removed for those claims.

What it does not do

It mandates no backdoor, no key escrow and no client-side scanning, and it says outright that using end-to-end encryption cannot be an independent basis for liability. But the next subsection makes that same choice admissible to show "motive, intent, preparation, plan". So the encryption is not illegal, it is exhibit A.

The two federal bills that would have actually mandated a backdoor are dead. EARN IT was never reintroduced in this Congress; the Lawful Access to Encrypted Data Act has been dead since 2020.

govinfo · S.1829 as reported
12United StatesBreach

Disclosed October 2024 · still active February 2026

Salt Typhoon: the wiretap system was the way in

State-sponsored attackers reached the lawful-intercept systems that American carriers are legally required to build and maintain. The FCC recorded that a top security agency confirmed at least eight communications companies were infiltrated; a ninth followed weeks later, and the FBI confirmed in February 2026 that the threat is not over.

What it does not do

The figures you see of 200 companies across 80 countries describe the wider espionage campaign, not the carriers whose intercept systems were compromised. For those, the defensible number is at least nine.

In November 2025 the FCC rescinded its own ruling that carriers must secure those systems, finding it had misread the statute. The duty to build the wiretap remains; the duty to protect it was withdrawn.

FCC · fact sheet (PDF)
13United StatesIn force

Lapsed 12 June 2026 · collection continues to March 2027

FISA Section 702 expired, and nothing stopped

The House declined to extend Section 702 on 11 June 2026 and the authority lapsed at midnight. It permitted warrantless collection of foreign targets' communications from US providers, sweeping in Americans' messages along the way.

What it does not do

Expiry did not end the surveillance. Certifications valid when issued run for up to a year, and the court approved the current set in March 2026. So collection continues unchanged until roughly 17 March 2027.

Brennan Center · Section 702 resource page

Elsewhere

Most of the world does not legislate against encrypted messengers. It switches them off, usually with nothing published to challenge.

14RussiaNetwork block

Signal 9 August 2024 · Viber 13 December 2024

Russia blocked the messengers, then built its own

Signal has been blocked since August 2024 and Viber since December 2024, both still unavailable. A state-backed national messenger, MAX, is being pushed into the space they left.

What it does not do

These are network-level blocks, not decryption orders. No Russian instrument obtained the contents of anything. It removed the ability to reach the service at all.

OONI · measurement explorer, Russia
15PakistanNetwork block

Continuous since 15 November 2024

Signal made unusable for twenty-one months, with no order at all

Pakistani networks let the name lookup succeed and the connection open, then reset the encrypted handshake to Signal's chat, storage, voice and contact-discovery servers. Measurement on 7 August 2026 recorded 315 tests and zero successes.

What it does not do

There is no published order, no gazette entry, no regulator confirmation and no block page. The app simply fails with a connection error. Nothing was decrypted; the block defeats reachability, not encryption.

The country's own lawful-interception stack is documented as unable to see inside HTTPS. It gets metadata, and the power to switch you off.

OONI · measurement explorer, Pakistan
16TanzaniaNetwork block

Telegram since 31 August 2024 · Signal since October 2025

Two encrypted messengers, blocked indefinitely, with nothing to appeal

Telegram has been unreachable on Tanzanian networks since August 2024 and Signal since around the October 2025 election, both across eight autonomous systems and both still blocked.

What it does not do

No order was ever published for either. There is no legal basis to challenge, no appeal route and no announced end date. Which is also why neither has been lifted.

OONI · measurement explorer, Tanzania
17NepalNetwork block

4 September 2025 · reversed after five days

Twenty-six platforms cut off for not appointing a local officer

Nepal ordered internet providers to deactivate twenty-six platforms that had not registered locally and named a resident grievance officer within seven days. WhatsApp and Signal were both on the list. It was reversed on 8 September, after protests in which more than nineteen people died.

What it does not do

The order demanded no scanning and no decryption. It conditioned access on having a legal presence in the country. Which a service built to hold no keys and no user records cannot supply without ceasing to be that service.

Telegram had already been blocked separately since July 2025 and was not restored with the rest.

Kathmandu Post · the full list of 26
18IndiaNetwork block

16–23 June 2026

A nation of 1.4 billion switched off Telegram for a week, for an exam

India blocked Telegram nationwide across more than seventy-five networks to stop question papers leaking before a medical entrance exam on 21 June. The block was lifted two days after the exam.

What it does not do

The order was issued under section 69A of the IT Act, which makes such orders confidential by rule. So there is no public document to read, and nothing to challenge.

OONI · finding, India
19AustraliaIn force

Took effect 10 December 2025

Under-16s off social media: and a $54.6m case against Telegram

Australia requires platforms to take reasonable steps to stop under-16s holding accounts; about 4.7 million accounts were restricted in the first weeks. In July 2026 the regulator began Federal Court proceedings against Telegram seeking up to $54.6m.

What it does not do

The rules expressly exclude services whose sole or primary purpose is messaging, email or calling. WhatsApp and Messenger are both on the published not-restricted list. And every failure pleaded against Telegram concerns public channels and terms of service, not private encrypted chats. No decryption is sought.

legislation.gov.au · the Rules (section 5 lists what is excluded)

What happens to the ID

Every age check is a promise to hold your identity safely. These are the times that promise was tested.

20DiscordBreach

20 September 2025 · around 58 hours of access

Government-ID photos, taken through a support vendor

An attacker reached a third-party customer-service system and, in Discord's own words, around 70,000 users "may have had government-ID photos exposed," along with names, emails, IP addresses and support-ticket contents.

What it does not do

The 2.1 million figure that circulated came from the extortionists, and Discord calls it incorrect. Full card numbers, passwords and on-platform messages were not exposed.

The IDs were not held by the platform you trusted. They were held by a contractor of a contractor.

Discord · security incident update
21Tea Dating AdviceBreach

25 July 2025

Verification selfies that were promised to be deleted

A misconfigured legacy storage bucket exposed around 72,000 images, of which roughly 13,000 were selfies and photo IDs submitted for identity verification.

What it does not do

The often-repeated "72,000 IDs" is wrong. Most of the images were ordinary in-app content, and only users who joined before February 2024 were affected.

The app's own privacy policy had said verification photos were "stored only temporarily and… deleted immediately." They were still there.

TechCrunch · reporting on the exposure
22AU10TIX · identity vendorBreach

Credentials live from around December 2022 to at least June 2024

The ID checker behind TikTok, Uber and X left the door open for eighteen months

An employee's credentials for AU10TIX, the identity-verification company those services use, were taken by malware around December 2022 and posted publicly. When researchers tested them in June 2024 they still worked, opening an administrative console that held images of customers' identity documents.

What it does not do

No victim count has ever been confirmed, and there is no evidence that any document was actually taken. What is established is the exposure, not the theft.

This is the layer every age-check law depends on and none of them regulates. Not the site you visited. The contractor it sends your passport to.

404 Media · the investigation

The other side of the record

A record that only accuses is a pitch. These two cut the other way, and they belong here for the same reason as everything else.

23United StatesIn force

18 December 2024

The US cyber-defence agency told Americans to use end-to-end encryption

After the telecom intrusions, CISA published mobile communications guidance whose first best practice reads: "Use only end-to-end encrypted communications. Adopt a free messaging application for secure communications that guarantees end-to-end encryption, such as Signal or similar apps."

What it does not do

It was written for highly targeted people in senior government and political roles, though the guidance says it is applicable to all audiences. It is advice, not law.

CISA · mobile communications best practices (PDF)
24United KingdomIn force

Cancelled 21 July 2026

The UK digital ID scheme was cancelled

Announced in September 2025, stripped of its mandatory element in January 2026, and cancelled outright on 21 July 2026. The £1.8bn was redirected to a cut in electricity VAT.

What it does not do

No bill was ever introduced, and "BritCard" was a think-tank name the government never used. There is now no UK identity credential for an account to be bound to.

A gov.uk explainer page still says digital ID will be a legal requirement for right-to-work checks. It was superseded and never corrected. Old pages outlive the policies they describe.

gov.uk · the announcement that cancelled it

None of this was decided by a company, and none of it can be undone by one.

The pattern across every jurisdiction is the same. Nobody has taken the contents of an encrypted message. What they take is the ability to reach a service, the record of who you spoke to, and the identity you had to show to get in. Which is why the design matters more than the promise: a service that never holds your keys has nothing to hand over, a service on the open web has no store to be removed from, and a message anchored on a public chain has no owner who can quietly delete it.

Found something wrong, out of date, or overstated? It should be corrected. The whole value of this page is that it survives being checked.