Encryption

BadLawEuropean Union

EU Chat Control 1.0 (Scanning Derogation)

Regulation (EU) 2021/1232 · European Union
In force to April 2028 (readopted July 9; E2EE excluded)

The 'temporary' law behind mass scanning of Europe's messages since 2021. A majority of voting MEPs tried to block its July revival and fell short of the absolute majority needed to do it, so suspicionless scanning is law again through April 2028.

●●● High threatUpdated July 9, 2026Details →
BadIn progressEuropean Union

EU CSA Regulation (Chat Control 2.0)

2022/0155(COD) · European Union
Five trilogue rounds failed; talks resume September

The permanent plan to mandate scanning of private messages in Europe. Five trilogue rounds have failed on the same question: suspicionless scanning of encrypted communications.

●●● High threatUpdated June 29, 2026Details →
BadIn progressCanada

Canada Bill C-22 (Lawful Access Act)

Bill C-22 (45th Parliament) · Canada
Before the Senate

Canada's surveillance rebuild: providers ordered to install monitoring capability, encryption breakable on ministerial demand, and a year of everyone's metadata on file. Passed the Commons; the Senate is what remains.

●●● High threatUpdated June 18, 2026Details →
BadIntroducedUnited States

Michigan HB 4938 (ISP Filtering and VPN Ban)

Michigan HB 4938 · United States · Michigan
Parked in House Judiciary, no hearing

Would force ISPs to filter the internet statewide and block VPNs, proxies, and encrypted tunnels. Parked in committee, but it is the blueprint.

●●● High threatUpdated September 11, 2025Details →
BadIn progressUnited States

Cooper Davis and Devin Norring Act

S.2316 / H.R.4518 (119th) · United States
Referred to committee

Would make platforms report suspected drug activity in users' messages to the DEA, deputizing them as federal informants.

●●● High threatUpdated July 17, 2025Details →
BadIn progressUnited States

STOP CSAM Act

S.1829 / H.R.3921 (119th) · United States
Reported by committee

Would let platforms be sued for 'recklessly' hosting abuse material, which makes offering encryption itself the legal risk.

●●● High threatUpdated June 12, 2025Details →
BadLawUnited States

TAKE IT DOWN Act

S.146 (119th) · United States
Signed into law

The deepfake takedown law with a 48-hour clock, no encryption exception, and the FTC now sending warning letters.

●●○ Medium threatUpdated May 19, 2025Details →
GoodIn progressUnited States

ENCRYPT Act

H.R.2508 (119th) · United States
Referred to committee

A protective bill that would stop individual states from ordering companies to weaken or backdoor encryption.

●○○ Low threatUpdated March 31, 2025Details →
BadDormantUnited States

EARN IT Act

S.1207 / H.R.2732 (118th) · United States
Not before the 119th Congress

Strips platforms of liability protection in a way that pressures them to break end-to-end encryption.

●●● High threatUpdated January 3, 2025Details →
BadLawUnited Kingdom

UK Investigatory Powers Act 2016

UK Public General Act 2016 c. 25 · United Kingdom
In force; expanded by the 2024 Amendment Act

The Snoopers' Charter: bulk interception, state hacking, a year of everyone's browsing history on file, and secret orders that can compel companies to break their own encryption.

●●● High threatUpdated April 25, 2024Details →
BadArchivedUnited States

Lawful Access to Encrypted Data Act

S.4051 / H.R.7891 (116th) · United States
Introduced once in 2020 (116th Congress); not seen since

A recurring proposal to force companies to build law-enforcement access into encrypted devices and messages. Last introduced in 2020.

●●● High threatUpdated January 3, 2021Details →
BadLawAustralia

Australia TOLA (Assistance and Access Act)

Act No. 148 of 2018 · Australia
In force since December 2018

The first Western law built to compel tech companies to help break their own encryption: secret notices, criminal penalties for disclosure, and a 'systemic weakness' safeguard nobody can define.

●●● High threatUpdated December 8, 2018Details →

← All tracked bills