2026: the year the EU chose surveillance over protection
By the Archibou team
The European Union had achieved something historic. A framework that protects its citizens' personal data, restores control over digital life, and inspires the world. The GDPR became a global gold standard — California, Brazil, Japan, India all drew inspiration from it.
But 2026 may mark the end of this European exception.
This year, three major events are unfolding simultaneously. A member of the European Parliament investigating spyware was hacked — and institutions did nothing. The European Council is reviving ChatControl, a bill designed to scan all private conversations. The European Commission is preparing a "Digital Omnibus" that weakens the GDPR, the best shield we have.
This is no coincidence. It is a pattern. And if we do not react, we will silently transition from a Europe that protects to a Europe that surveils.
The Pegasus scandal: an MEP hacked, and no one acts
Stelios Kouloglou is a Greek member of the European Parliament and an investigative journalist. He served on the PEGA Committee — the special committee created by the European Parliament to investigate spyware and its abuses in Europe.
His phone was infected with Pegasus twice: October 2022 and March 2023, precisely during the most sensitive phases of his committee's work. Pegasus is spyware developed by the Israeli company NSO Group. It allows its operator — a state, a government, we don't know which — to access everything on the phone: messages, photos, microphone, camera, location, history. Fifteen years of data, according to Kouloglou.
This is a severe violation on multiple levels: international law, diplomatic protection, sovereignty of European institutions, privacy. The GDPR itself is trampled by a foreign actor breaching the communications of a European parliamentarian.
European and national institutions have all the tools to act: directives, treaties, conventions, GDPR, national criminal law. They could denounce, investigate, demand accountability, sanction. The PEGA Committee's recommendations were clear and detailed.
Result: nothing. The European Commission ignored the recommendations. No sanctions. No public inquiry. No protections put in place for other MEPs. No consequences for NSO or its clients. Citizen Lab and MEP Hannah Neumann sum it up: "The responsible country spied on a member of the European Parliament while they were investigating spyware abuse. It shows total disregard for parliamentarians' role and for European democracy."
A terrible message is sent: you can spy on European parliamentarians with impunity. The legal tools exist — but political will does not.
Source: The Record from Recorded Future News — "Spyware found on phone of European Parliament member probing it", Suzanne Smalley, July 3, 2026
Source: Citizen Lab — original report
ChatControl: mass surveillance disguised as child protection
On the same day, the European Council revived the provisional regulation known as "ChatControl," barely three months after the European Parliament rejected it in March 2026. The text aims to authorize major platforms (WhatsApp, Signal, Messenger, etc.) to voluntarily scan all electronic communications to detect child sexual abuse material.
The previous temporary regulation expired on April 3, 2026. Without an agreement on the permanent framework (CSAR — Child Sexual Abuse Regulation), member states decided to extend surveillance until April 2028. But since an expired regulation cannot be extended, the Council used a "procedural subterfuge" (according to Next.ink): starting from an empty new proposal, copy-pasting the dead text, only adapting the dates.
This is not the only democratic breach. According to Politico, European Parliament President Roberta Metsola herself is behind the maneuver to circumvent her own Parliament's vote. Several MEPs believe she bypassed their authority.
A technical aside, but essential
End-to-end encryption is not software or an option — it's a mathematical formula applied to data. It transforms the content of a message, photo, or document into unreadable code that only the recipient can decrypt with their key. No one else — not the operator, not the state, not a hacker — can access it. It's the same principle that secures passwords, banking operations, and medical records.
Some voices advocate for a "compromise": allow platforms to scan messages, but entrust control to sworn officials — judges, police, independent authorities. This compromise does not exist mathematically.
You cannot create an "exception" in a mathematical formula. Either it encrypts, and no one can read the content. Or it allows a third party to read it, and it is broken — for everyone. There is no "small hole reserved for the good guys." Once a backdoor exists, it can be exploited by anyone: an authoritarian state, a hacker, a malicious employee.
This is why cryptographers, computer scientists, and human rights defenders are unanimous: wanting to "scan messages without breaking encryption" is wanting a square circle. Either you protect the formula, or you weaken it — and you weaken it for everyone, irreversibly.
Source: Next.ink — "ChatControl: nouvelle tentative de prolonger la surveillance des messageries", Martin Clavey, July 3, 2026
Source: Politico — "President vs Parliament: Roberta Metsola overrides MEPs' bid to force child abuse law"
The Digital Omnibus: dismantling the GDPR
The European Commission is preparing a vast "simplification" of the digital legislative framework, dubbed the "Digital Omnibus." Behind the stated goal of cutting red tape, the proposed changes to the GDPR are anything but minor.
Several measures are raising concerns among data protection authorities, the French Senate, and organizations like noyb:
Redefinition of "personal data." The Commission proposes narrowing the GDPR's core definition to exclude pseudonymized data — transformed but potentially re-identifiable — as long as the processing entity states it does not "aim" to identify individuals. The European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) consider that this change "goes beyond recent CJEU case law and a targeted GDPR amendment" and would constitute a regression. The CNIL shares this analysis. Direct consequence: an operator could argue that data no longer falls under the GDPR, even if technical means of identification exist within its ecosystem. The GDPR's scope would be reduced by regulation, without legislative oversight.
AI training as "legitimate interest." The text states that training AI models (large language models, image and video generation) relies on personal data and can be carried out on the basis of "legitimate interest" — without explicit consent from individuals. For noyb, this is a "slippery slope": if scraping the entire Internet without consent becomes a legitimate interest, there are hardly any processing activities that would not qualify. Paul Nemitz, one of the GDPR's architects, sums it up: "Nothing will remain of data protection, because AI is everywhere."
Transfer of enforcement powers to an Irish one-stop shop. The new cookie regime would shift enforcement competence from the CNIL to the Irish authority (where most major US platforms are established). The CNIL estimates that France would lose 90% of cookie fine revenue — nearly 900 million euros since 2020. The French Senate considers that "the e-Privacy directive and the GDPR operate under very different logics" and that this transfer "would reduce the effectiveness of remedies."
Taken individually, some changes might be defensible, the Senate rapporteurs acknowledge. But their cumulative effect risks, according to the French Association of Data Protection Officers (AFCDP), "emptying the GDPR of its substance" and weakening its standing as an international standard.
Source: French Senate Information Report No. 626 (2025-2026) — "European Digital Omnibus: a risk for the protection of citizens' digital rights," May 13, 2026
Source: Next.ink — "La Commission européenne prévoit d'affaiblir le RGPD au profit des entreprises d'IA," Martin Clavey, November 10, 2025
The tipping point dashboard
These three stories are not coincidences. They tell the same trajectory:
| Protection weakened | Surveillance strengthened |
|---|---|
| The GDPR is dismantled so AIs and tech giants access data without consent | ChatControl mandates scanning all private conversations |
| PEGA Committee recommendations against spyware are ignored | Phones of investigating MEPs are hacked, with no consequences |
| Protection mechanisms (CNIL, right to object, consent) are hollowed out | Mass surveillance becomes the norm, without real democratic debate |
| Europe abandons its role as global data protection benchmark | Europe catches up with US and Chinese models of generalized surveillance |
In short: Europe is trading its model — trust, fundamental rights, privacy — for that of others: surveillance in the name of security, data as free raw material for AI.
It claims to "protect children" with ChatControl, but lets member states hack parliamentarians with Pegasus without consequences. It claims to "simplify the GDPR for innovation," but the only winners are Big Tech and governments that want to surveil you.
Why we must fight
The slope is slippery, and we don't feel it happening.
The GDPR is not perfect, but it is the only tool we have to say "no, my data is not for sale." ChatControl is not yet definitively adopted, but if it passes, end-to-end encryption is dead in Europe. Spyware is not new, but if institutions look the other way, it will become the norm — even against the highest representatives of European democracy.
What is at stake: - Your privacy: your messages, your location, your photos, your opinions - Your digital safety: no encryption = no protection for the most vulnerable - Your democracy: if MEPs investigating abuses are hacked and their work is ignored, what is Parliament for? - Your freedom: a society where everything is surveilled is a society where self-censorship thrives
And all of this happens in silence — because it is technical, because it is European, because "the GDPR is complicated." But that is precisely why it is essential that as many people as possible understand.
At Archibou, we believe in the GDPR and privacy protection
At Archibou, we believe that privacy and intimate life protection is not an option — it is a fundamental right. We built our offering on this conviction: the GDPR is not a checkbox or a legal burden to endure. It is a compass.
Our software is designed to respect everyone's data — by default, by design, by choice. Not because we are required to, but because it is the only way to build trustworthy digital services.
2026 is a pivotal year. And we do not intend to watch this train pass by without saying a word.
✊
Archibou — Digital services in the service of privacy and intimate life protection.