EU's active war against data-privacy - Markus Hölsä
Markus Hölsä
Disobey 2026 · Main Stage
Overview
Markus Hölsä's talk, "EU's Active War Against Data Privacy," delivers a stark warning about the European Union's escalating legislative efforts that, under the guise of security and child protection, are actively eroding the fundamental right to privacy for its citizens. Hölsä, an experienced cyber and information security expert, dissects the mechanisms through which the EU is pursuing mandatory client-side scanning, bypassing end-to-end encryption, and establishing a surveillance infrastructure that could have far-reaching implications beyond its stated goals.

Key moments
- 0:00 Speaker introduction and talk's core premise
- 1:20 Understanding EU's 'Protect EU' security strategy
- 2:00 High-Level Group's challenges with encryption and data
- 3:00 What is the Child Sexual Abuse Regulation (CSAR)?
- 4:00 EU's actions actively erode fundamental privacy rights
- 5:00 Concerns about transparency in HLG 'going dark' meetings
- 7:30 HLG's shift from 'secure' to 'security by design'
- 9:30 Chat control mandates bypassing end-to-end encryption
EU's Active War Against Data Privacy
Speakers: Markus Hölsä
Conference: Disobey
YouTube: https://www.youtube.com/watch?v=qnZwbSbbOdY
Overview
Markus Hölsä's talk, "EU's Active War Against Data Privacy," delivers a stark warning about the European Union's escalating legislative efforts that, under the guise of security and child protection, are actively eroding the fundamental right to privacy for its citizens. Hölsä, an experienced cyber and information security expert, dissects the mechanisms through which the EU is pursuing mandatory client-side scanning, bypassing end-to-end encryption, and establishing a surveillance infrastructure that could have far-reaching implications beyond its stated goals.
The presentation meticulously uncovers the political machinations, lobbying efforts, and concerning narratives employed by proponents of these measures. Hölsä argues that while the stated aim is to combat heinous crimes like child sexual abuse material (CSAM) and money laundering, the proposed solutions—particularly the Child Sexual Abuse Regulation (CSAR), often referred to as "Chat Control"—represent a dangerous precedent. He highlights the inherent paradox of these initiatives: while the EU pledges to strengthen security, democracy, and fundamental rights, the practical application of these laws threatens to undermine the very principles they claim to uphold.
This talk is crucial for anyone concerned with digital rights, cybersecurity, and the future of privacy in the digital age. It serves as an urgent call to action, urging citizens and experts alike to recognize the profound societal and technical risks posed by legislation that seeks to implement pervasive surveillance capabilities. Hölsä's deep dive into the specifics of the proposed technologies, the political actors involved, and the lobbying landscape provides invaluable insight into a critical battleground for internet freedom.
Background
▶ Watch: Speaker introduction and talk's core premise (0:00)
The genesis of the EU's current legislative thrust against digital privacy can be traced to its "Protect EU" internal security strategy, which ostensibly aims to strengthen legislation, cooperation, and investments to safeguard security, democracy, and fundamental rights. However, Markus Hölsä contends that several key initiatives under this umbrella are, in practice, doing the opposite. Two primary legislative efforts are central to this discussion: the work of the High-Level Group (HLG) and the Child Sexual Abuse Regulation (CSAR), commonly known as "Chat Control."
The High-Level Group was established to address "significant challenges" faced by EU law enforcement in accessing digital data. Hölsä identifies three main points of contention from the law enforcement perspective:
- Encryption: The widespread adoption of end-to-end encryption by communication services makes it difficult for authorities to intercept and read communications.
- Absence of Data Retention Obligations: Many companies are not legally required to store user data, which limits the information available to investigators.
- Difficulties with Over-The-Top (OTT) Services: Services like WhatsApp, Signal, or Skype, which provide communication over the internet, operate outside traditional telecom networks, making them harder to supervise and extract information from.
Hölsä critically notes that the HLG's meetings have been shrouded in secrecy, with participant lists heavily redacted. Only police forces and secret services are known to be represented, while the EU data protection supervisor holds only observer status, and NGOs are excluded. This lack of transparency, he argues, directly contradicts the democratic principle of openness and fuels suspicion about the group's true intentions. The HLG has also proposed a redefinition of "secure by design" from its traditional meaning—products designed to protect users—to "security by design," where products are designed to meet the needs of law enforcement and EU policy requirements. This shift fundamentally alters the purpose of security, turning it into an enforcement tool rather than a user protection mechanism.
Parallel to the HLG's efforts, the CSAR initiative, championed by EU Commissioner for Internal Affairs Ulva Johansson, aims to combat child sexual abuse material (CSAM). Initially, Chat Control 1.0 proposed voluntary scanning by large providers of mainly unencrypted services. However, under Danish leadership in 2025, the proposal evolved into Chat Control 2.0, advocating for mandatory scanning of messages, specifically requiring a bypass of end-to-end encryption. This move, as highlighted by Hölsä, represents a significant escalation from voluntary, unencrypted scanning to mandatory, encrypted-service surveillance.
Another relevant legislative area mentioned is the tightening of anti-money laundering (AML) laws, which are already in effect. These laws mandate verification for users of banks, crypto asset service providers, and crowdfunding platforms, requiring them to report suspicious activity and limiting anonymous cash payments (banning those over €3,000 in commercial transactions and over €10,000 in business transactions, and prohibiting anonymous crypto payments). While not the main focus, Hölsä uses AML laws as another example of how EU regulations, despite their stated goals, are actively eroding privacy and anonymity, forming a broader pattern of surveillance.
Key Findings
▶ Watch: High-Level Group's challenges with encryption and data (2:00)
Markus Hölsä's presentation exposes several critical findings that underscore the EU's aggressive pivot towards pervasive digital surveillance, often under the guise of public safety:
- Redefinition of "Security by Design": The High-Level Group's proposed shift from "secure by design" (protecting users) to "security by design" (meeting law enforcement needs) is a fundamental conceptual change. This redefinition implies that devices sold in the EU would be mandated to include backdoors or client-side scanning capabilities, fundamentally compromising user privacy and security for the sake of surveillance.
- Mandatory Client-Side Scanning and Encryption Bypass: The core of Chat Control 2.0 is the requirement for mandatory scanning of all private messages and files, even those protected by end-to-end encryption. This necessitates client-side scanning technologies that would inspect messages either before they are encrypted when sending or after they are decrypted when receiving. This directly contradicts the security assurances of end-to-end encryption and represents an unprecedented level of surveillance "without initial suspicion."
- Politically Motivated Misinformation and Microtargeting: Commissioner Ulva Johansson, a key proponent of Chat Control, has made several factually incorrect statements, such as claiming it's possible to scan encrypted messages "without breaking the encryption" or that Signal "already scans all the chats." Furthermore, the EU Home Affairs division ran microtargeted ads on social media, funded by taxpayer money, specifically targeting citizens in eight EU countries (Belgium, Czech Republic, Finland, Netherlands, Portugal, Slovenia, Sweden) that did not support Chat Control. These ads excluded users associated with tags often linked to far-right movements, indicating a manipulative attempt to influence public opinion by selectively presenting information. The European Data Protection Supervisor (EDPS) issued a reprimand for this activity.
- Influence of Non-Profits and Lobbying Networks: Hölsä reveals a complex network of organizations actively lobbying for Chat Control. Thorn, co-founded by actors Ashton Kutcher and Demi Moore, developed "Safer," an AI-driven CSAM detection software that is not free and has actively lobbied for the legislation, spending approximately €600,000 since 2020. The Oak Foundation, led by former US official Douglas Griffith, serves as a central financial power, providing multi-million dollar grants to advocacy groups. WeProtect, initially a governmental initiative, transformed into a "putatively independent foundation" actively campaigning for Chat Control, with Ulva Johansson's right-hand man, Labrador Jimenez, on its policy board. The Brave Movement, launched just weeks before Johansson's regulation was unveiled and backed by a €10.3 million grant from the Oak Foundation, strategically mobilized CSAM survivors from opposing countries to lobby MEPs in Brussels.
- "Revolving Door" Incidents: Hölsä exposes instances of individuals moving directly between key EU positions and lobbying organizations. A notable example is Akatan Delaney, a Europol official who worked on an AI pilot for CSAM detection, who then moved to Thorn and continued to attend Europol meetings as a lobbyist for Thorn's products. Similarly, Brave Movement's European campaign manager, Jessica Ary, previously worked within the EU Commission on the very same legislative file before moving to lobby for its passage. These incidents raise serious questions about conflicts of interest and undue influence.
- Narrative Shift from CSAM to "All Crimes": Europol Director Catherine De Bolle explicitly stated that "anonymity is not a fundamental right" and advocated for "front door" access to data, not just for CSAM but for "all crimes under the sun." Minutes from high-level meetings confirm Europol's request for unfiltered access to data harvested under the CSAM proposal and for the AI technology to be applied to other crimes. This reveals a clear intent to expand surveillance beyond child protection, transforming a specific crime-fighting tool into a general-purpose mass surveillance apparatus.
- Compromised "Chat Control 2.0": Despite initial opposition from several member states, notably Germany (whose 19% population share is critical for blocking qualified majorities), a "compromise" Chat Control 2.0 was endorsed. While it initially appeared to make scanning non-mandatory for service providers, Hölsä warns that the legislation is designed to allow technology to mature, implying that mandatory scanning will be enforced once the technical capabilities are deemed "ripe." This compromise also introduces mandatory child age verification for all service providers, with unclear implications for children's access to the internet.
These findings collectively paint a picture of a concerted, well-funded, and politically astute campaign to implement widespread digital surveillance within the EU, leveraging emotional appeals and opaque processes to bypass democratic scrutiny and erode fundamental privacy rights.
Technical Deep Dive
▶ Watch: EU's actions actively erode fundamental privacy rights (4:00)
The technical core of the proposed Chat Control legislation revolves around client-side scanning and the use of artificial intelligence (AI) for content detection. This approach aims to bypass the protective barrier of end-to-end encryption, a cornerstone of modern secure communication, without explicitly "breaking" the encryption itself.
The proposed mechanism for Chat Control can be broken down into three key technical directives:
- Automatic Scanning of All Private Communications: The legislation intends to force providers of messaging services (e.g., WhatsApp, Signal), email services, hosting services, and even personal cloud storage (e.g., Apple iCloud) to automatically scan all private chat messages and files. Crucially, this scanning is to occur "in general, and without initial suspicion." This means that every user's private communications would be subject to automated scrutiny, regardless of any prior indication of wrongdoing.
- Installation of Surveillance Functionalities on User Devices: To overcome end-to-end encryption, the EU proposes compelling communication providers to install surveillance functionalities directly on user devices. This is the essence of client-side scanning. The technology would operate either before messages are encrypted (when sending) or after they are decrypted (when receiving). This ensures that the content is visible in plaintext at some point on the user's device, allowing for analysis before it is secured by encryption or after it has been unlocked.
- AI-Driven Detection Tools and Centralized Databases: The automated search relies on specific technologies, primarily involving AI. These AI models would be trained to detect "suspicious content," specifically child sexual abuse material (CSAM). The detected information and potential matches would then be correlated with centralized databases maintained by a proposed "EU center on child sexual abuse." Hölsä notes that the control and review of these databases and the flagged content would largely fall to private security companies and local law enforcement, raising concerns about data governance, accountability, and potential for abuse.
The operational flow of this scanning technology is envisioned as follows:
- A court issues a detection order for a specific service provider (e.g., Microsoft, Apple, Facebook).
- Upon receiving this order, the service provider is legally obligated to activate the client-side scanning technology for users under that order.
- The technology then scans for suspicious content (primarily CSAM, though Europol seeks expansion to "all crimes") and flags potential hits.
- These flagged hits are reported to the police.
- A human reviewer within the police force or a designated entity then reviews the flagged content to determine its credibility.
- If deemed credible, the information is reported, potentially leading to further investigation or charges.
A critical technical and ethical flaw highlighted by Hölsä is the concept of scanning "without initial suspicion." Unlike traditional warrants that require probable cause for specific individuals, this framework mandates universal, proactive scanning of all users. This dramatically increases the potential for false positives, where innocent content or misinterpretations by AI algorithms could lead to individuals being wrongly suspected and reported to the police. The speaker emphasizes that even if the AI flags something, a human review is still needed, but the initial suspicion is generated by an automated, fallible system.
Furthermore, the very premise that client-side scanning can occur "without breaking the encryption" is a point of contention. As Ulva Johansson's quote suggests, proponents claim this is possible. However, the cybersecurity community widely refutes this. For content to be scanned on the client side, it must be accessible in an unencrypted state. This creates a fundamental vulnerability: if the content can be read by a scanning tool, it can theoretically be accessed by other malicious actors or exploited. This effectively creates a backdoor on every device, compromising the very security that end-to-end encryption is designed to provide. The "front door" that Europol's Catherine De Bolle advocates for is, in technical reality, a backdoor to user privacy.
The technical immaturity of this proposed system is also a significant factor. Hölsä points out that the current technology proposed for universal, reliable client-side scanning, particularly for encrypted communications, "doesn't actually exist yet really" in a robust and scalable form without significant privacy implications. The EU's strategy appears to be to push through the legislation and then allow technology to "run its course" until it is "ripe for implementing," at which point they will enforce its mandatory adoption. This implies a future where privacy-preserving technologies are systematically undermined by state-mandated surveillance tools embedded directly into personal devices and services.
Demo / Proof of Concept
▶ Watch: Concerns about transparency in HLG 'going dark' meetings (5:00)
Markus Hölsä's presentation focused on a critical analysis of the legislative, political, and technical implications of the EU's proposed privacy-eroding measures. As such, the talk did not include a live technical demonstration or a proof of concept of the client-side scanning technologies discussed. Instead, the speaker's objective was to expose the mechanisms and consequences of these proposals through detailed explanation and evidence from official documents and public statements.
Defensive Implications
▶ Watch: Chat control mandates bypassing end-to-end encryption (9:30)
The implications of the EU's legislative proposals, particularly Chat Control, are profound for both individual users and organizations that prioritize digital privacy and security. Defenders—whether they are cybersecurity professionals, privacy advocates, or concerned citizens—must understand these threats and take proactive steps.
- Advocate Against Client-Side Scanning: The most critical defensive action is to actively oppose the implementation of client-side scanning. This technology fundamentally undermines end-to-end encryption, creating a systemic vulnerability that can be exploited by malicious actors, not just law enforcement. Users and organizations should engage with their elected representatives (MEPs) and support organizations like fightcontrol.eu.it, as highlighted by Hölsä, to voice strong opposition. The "gene is out of the bottle" analogy is apt: once such a pervasive surveillance technology is introduced, it is exceptionally difficult to remove or limit its scope.
- Understand the Scope Creep: Defenders must be vigilant about the narrative shift from combating CSAM to enabling surveillance for "all crimes under the sun." This expansion of scope, openly articulated by Europol, indicates that the technology, once in place, will likely be leveraged for a much broader range of investigative purposes. This broadens the attack surface for privacy and increases the potential for abuse against journalists, dissidents, or minorities, depending on the political climate.
- Prioritize Privacy-Preserving Technologies: For individuals, continuing to use and support services that genuinely offer strong end-to-end encryption and have a proven track record of fighting for user privacy is crucial. While the EU seeks to mandate client-side scanning, the choice of technology providers and their commitment to privacy will remain important.
- Demand Transparency and Accountability: The secrecy surrounding the High-Level Group's meetings and the "revolving door" incidents involving lobbyists and EU officials highlight a lack of transparency. Defenders should demand greater transparency in legislative processes, particularly when fundamental rights are at stake. Independent oversight of any proposed "EU center on child sexual abuse" and its centralized databases, especially given the involvement of private security companies, is paramount.
- Educate and Raise Awareness: Many citizens may not fully grasp the technical implications of client-side scanning or the broader erosion of privacy. Cybersecurity professionals and privacy advocates have a responsibility to educate the public, policymakers, and media about the dangers inherent in these proposals, debunking misinformation (like the ability to scan encrypted messages without breaking encryption).
- Prepare for Potential Compliance Challenges: For businesses and service providers operating within the EU, these regulations could impose significant compliance burdens. Mandatory age verification, for instance, adds layers of complexity and raises new privacy concerns regarding how such data is collected, stored, and protected. Organizations must stay informed about the evolving legislative landscape and prepare for potential mandates that could force them to compromise their services' security and privacy architectures.
- Support International Standards and Collaboration: The fight for digital privacy is not confined to the EU. Supporting international efforts and collaborating with global privacy advocates can help establish stronger norms and prevent similar legislation from spreading globally.
Ultimately, the defensive stance requires a multi-faceted approach: political advocacy, technical vigilance, public education, and a steadfast commitment to the principles of privacy and security by design. The current legislative push represents a critical juncture for the future of digital rights in Europe.
Key Takeaways
- EU Legislation Erodes Privacy: The EU's "Protect EU" strategy, particularly through the High-Level Group and Child Sexual Abuse Regulation (Chat Control), is actively undermining fundamental privacy rights under the guise of security and child protection.
- "Security by Design" Redefined: The proposed redefinition of "secure by design" to mean products designed for law enforcement needs implies mandatory backdoors or client-side scanning on devices, fundamentally compromising user security.
- Mandatory Client-Side Scanning Threatens Encryption: Chat Control 2.0 advocates for mandatory client-side scanning of all private messages and files, even those end-to-end encrypted, requiring a bypass of encryption at the user device level "without initial suspicion."
- Deceptive Tactics and Lobbying: Proponents of Chat Control have employed misinformation, microtargeted advertising campaigns funded by taxpayers, and leveraged a complex network of non-profits (Thorn, Oak Foundation, WeProtect, Brave Movement) with significant lobbying budgets and "revolving door" personnel to push the legislation.
- Scope Creep to "All Crimes": Europol explicitly seeks to expand the use of client-side scanning and AI detection, initially for CSAM, to surveil for "all crimes under the sun," indicating a clear intent for mass surveillance beyond its stated initial purpose.
- Vigilance and Action are Crucial: Despite initial setbacks for Chat Control, "compromise" proposals continue to advance, with the intent to implement mandatory scanning once the technology matures. Citizens, privacy advocates, and cybersecurity professionals must remain vigilant and actively oppose these measures (e.g., through platforms like fightcontrol.eu.it) to protect digital rights.
About the Speaker(s)
Markus Hölsä is an experienced professional in the field of cyber and information security. He has worked on development projects as an expert in these areas and has served as a corporate cybersecurity trainer. Prior to his career in cybersecurity, Hölsä spent approximately 15 years as a fish farmer. He transitioned to cybersecurity after studying the field, driven by a passion for the subject, particularly concerning the EU and data privacy. His talk reflects this deep passion and expertise in dissecting complex legislative and technical issues related to digital rights.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A well-researched policy/advocacy talk that does the unglamorous work of mapping the lobbying networks, revolving-door incidents, and procedural maneuvering behind Chat Control — content that's genuinely harder to assemble than it looks. The technical framing is thin and the speaker's background is modest for the stage, but the investigative legwork carries it to a solid slot at a community-oriented con like Disobey.
Heather Calloway (CISO) — SOLID
Hölsä does real work here — the lobbying network mapping, the revolving door exposures, and the scope creep documentation are genuinely useful. But the talk is built for digital rights advocates, not security leaders or operators, and it never closes the institutional gap between 'this is happening' and 'here is what your organization needs to decide.'