If you use Gmail for work, someone can read inside it. And it's legal.

Da luglio 2026 l'Unione Europea ha rimesso in vigore, dopo un percorso travagliato, la norma che permette a Gmail e ad altri provider di scansionare volontariamente le comunicazioni non cifrate. Non è un allarme, ma un caso concreto per capire una domanda che vale per qualunque strumento digitale usi ogni giorno: sai davvero chi può leggere i tuoi dati, e a quali condizioni?

test

A rule that expired, then came back

In early April 2026 the exemption informally known as "Chat Control 1.0" had expired: the European Parliament had rejected its extension. The Council put it back on the table through an emergency procedure, and on July 9 Parliament voted again. A majority of those present were against reinstating it, but the vote fell short of the threshold needed to block it entirely. Result: the rule remains in force until April 2028.
It's an exemption from the ePrivacy directive, not an obligation: it authorizes providers like Gmail, iCloud Mail, or Instagram to voluntarily scan unencrypted content in search of child sexual abuse material, without risking legal action for doing so. No one is required to — but several, Google chief among them, have already been doing it for years through automated systems.

Who's in, who's out

The detail worth knowing if you run a business using these tools: apps with true end-to-end encryption — WhatsApp, Signal, Telegram — were explicitly excluded from this scope by Parliament. Gmail, iCloud Mail, and similar services were not, because technically the content passes through, and remains readable, server-side.
This isn't an abstract technical distinction. It's the difference between a tool that guarantees by design that no outsider can read what you write, and one that can, under certain conditions, by decision of an institution a thousand kilometers away.

Why this is about your digital decisions, not just your inbox

I'm not telling this story to alarm anyone. The rule was created for a legitimate purpose and doesn't affect your work email any differently than anyone else's. I'm telling it because it's a concrete example of something true for any "convenient" tool we use daily: it has rules, those rules can change, and almost no one explains them to you before you choose the tool.
When a client asks me to choose an email provider, a management system, a platform for their customers, the question "where does the data live, and who can read it" is as much a part of the choice as "does it work well." It's work that usually stays invisible — but it's the difference between a tool that holds up for years and one that creates a problem when you least expect it.

Domande frequenti

Domanda
What is the "Chat Control 1.0" exemption?
Risposta

It's a temporary exception to the EU's ePrivacy directive, in place since 2021, that allows providers like Gmail or iCloud Mail to voluntarily scan unencrypted content to detect child abuse material. It's an authorization, not a requirement.

Domanda
Is Gmail among the services that can be scanned?
Risposta

Yes. Gmail doesn't use end-to-end encryption between sender and recipient, so the content is technically readable server-side and falls within the exemption's scope, which remains valid until April 2028.

Domanda
Are WhatsApp or Telegram subject to the same rule?
Risposta

No. Apps with true end-to-end encryption were explicitly excluded by the European Parliament in July 2026: the provider itself can't read the content, so it can't scan it.

Domanda
Should I stop using Gmail for work?
Risposta

That's not the point of this piece. The useful question isn't "which tool to avoid," but "do I actually know who can read the data passing through my tools, and under what conditions." It's a question worth asking about any digital tool you use for work, not just Gmail.