Corporate messenger in a private network — the only way to protect your chats
The EU is currently discussing the Chat Control regulation, a law aimed at protecting civil liberties. The next discussion is scheduled for September, after which chat scanning will become mandatory for all messengers, email services, social networks, and hosting providers — extending even to correspondence protected by end-to-end encryption.
Which services will be scanned:
|
Service |
Is scanning required? |
|---|---|
|
|
|
|
Messengers (WhatsApp, Viber, Telegram, etc.) |
|
|
Web hosting |
|
|
Social networks (Facebook, Instagram, etc.) |
|
|
File storage |
|
|
Cloud services |
|
|
Video conferencing services (Skype, Zoom, Microsoft Teams, etc.) |
|
|
Corporate messenger and video conferencing on private servers |
Companies will be required to scan absolutely all private messages — text, voice, photos, video, and files. However, some messengers use end-to-end encryption, meaning only the sender and recipient can see a message — not even the company itself can read it. To make the law work for these services too, a technology called client-side scanning has been proposed: software on your device analyzes content before it’s encrypted and sent, or after it’s decrypted on the other end — effectively a built-in surveillance tool on your device.
The image is created based on the source
This law threatens the privacy of communications and creates a risk of hacking and data theft. Businesses, where the confidentiality of company and employee data is critical, could be especially affected.
However, if a corporate messenger runs within a private network deployed on the company’s own servers, no one can access it from the outside. In this case, deploying is fully compliant with the law while giving you complete control over your privacy, since all users are verified employees — there are no unauthorized users or people who haven’t confirmed their personal data.
|
Criteria |
Cloud Messaging Providers |
On-Premise / Private Network Deployments |
|---|---|---|
|
Regulatory Scope |
Directly named: email, messaging, and cloud services including E2E-encrypted platforms (e.g. WhatsApp, Signal) |
Outside the regulation’s stated scope. It’s about providers serving end users, not internally deployed infrastructure |
|
Annual Risk Assessment |
Mandatory: providers must assess exposure to risks year over year |
No equivalent obligation: no classification as “service providers” to third parties |
|
Risk Classification |
Applies directly, driving downstream compliance obligations |
Not applicable — the system of control is built for externally-facing services, not for corporate ones |
|
Content Scanning |
Mandatory: reputational and regulatory exposure for those who opt out |
Not addressed — relevant only if the deployment itself functions as a service to external users, who are not employees of the enterprise |
|
Identity & Age Verification |
Explicitly required under the current draft |
Age verification is not required, since third parties don’t have access to the system, and employee data is stored by the employer |
|
Privacy Law Exemption |
These providers get a permanent exemption from the EU’s main e-privacy law — meaning they’re legally allowed to scan private messages, something normally not permitted |
Not affected — this exemption only applies to public communication services, not internal company systems |
|
End-to-End Encryption Integrity |
Nominally preserved, but scanning before/after encryption remains possible at provider discretion |
Governed by internal security policy, not by this regulation |
Protect your team communication with TrueConf!








Follow us on social networks