ScanRecords

Companies / Meta (Facebook, Instagram, Messenger)

Meta (Facebook, Instagram, Messenger)

Scans under Chat Control — confirmed
Messenger · Instagram Direct

WhatsApp — end-to-end encrypted, and Meta’s own filing says the scanning runs only on surfaces that are not end-to-end encrypted. WhatsApp's record →

Which services the evidence names

Meta’s own filing under the derogation names the services and adds a limit of its own: the scanning runs on surfaces that are not end-to-end encrypted. The service names below are Meta’s wording, not ours.

Named Messenger, Instagram Direct — named in Meta EU CSAM derogation report, archived here: We run our media matching technology on images and video (media) across Messenger and Instagram Direct on surfaces that are not end-to-end encrypted.

Not named Facebook itself is also operated by Meta. The filing does not name it, and no other source we track names it as scanning under the derogation.

The Commission's report, which is what puts Meta in this group at all, names the provider and not the service. That is why the two lines above are separate.

What we watch for — Meta files the derogation's transparency reports today. We watch for the reports stopping, scanning language disappearing from these documents, and what replaces the legal basis when the derogation expires in April 2028.
Services
Messenger, Instagram Direct, Facebook (evidence names Messenger, Instagram Direct)
Status
Scans under Chat Control — confirmed
Held since
26 Jul 2026
Documents
4 tracked
App Store label
Tracked
Changes recorded
10 — latest 9 Sep 2026

Tracked documents

DocumentLast fetchedSizeHashSnapshot
Privacy Policy
www.facebook.com
9 Sep 2026 48,970 chars 8999ad3ac0be text · raw · wayback
Law Enforcement Guidelines
www.facebook.com
26 Jul 2026 5,340 chars c8a4ebebd7ba text · raw · wayback
Google Play Data Safety
play.google.com
26 Jul 2026 8,585 chars f70c2a1b4405 text · raw · wayback
EU CSAM derogation report (Regulation (EU) 2021/1232)
transparency.meta.com
28 Jul 2026 5,420 chars b79f73522a8d text · raw · wayback

text is the extracted record we hash and diff; raw is the page's original HTML kept verbatim as evidence — it renders without its styling here, by design.

App Store privacy label — Facebook

Apple requires every app to declare the data it collects. This is Meta (Facebook, Instagram, Messenger)'s current declaration, as shown on the App Store; ScanRecords records when it changes.

Data Used to Track You

  • Contact Info
  • Identifiers
  • Other Data

Data Linked to You

  • Health & Fitness
  • Purchases
  • Financial Info
  • Location
  • Contact Info
  • Contacts
  • User Content
  • Search History
  • Browsing History
  • Identifiers
  • Usage Data
  • Sensitive Info
  • Diagnostics
  • Other Data

What we searched for

A status that rests on absence is only as good as the search behind it. Every one of Meta (Facebook, Instagram, Messenger)'s 4 archived documents (68,319 characters) was searched for the same published vocabulary used on every company here — in English, German and French. The search is a plain function of the archived text and re-runs whenever that text changes, so it always describes the documents listed above. Re-run it against this archive yourself with tools/scan-terms.mjs.

TermHitsIn context
Regulation 2021/1232 2 “Processing under EU Regulation 2021/1232 Summary : This is a report made by Meta Platforms Ireland Limited (Meta Ireland) in accordance with EU Regula…” — derogation-report
“…ary : This is a report made by Meta Platforms Ireland Limited (Meta Ireland) in accordance with EU Regulation 2021/1232 on a temporary derogation from certain provisions of Directive 2002/58/EC as regards the use of technologies…” — derogation-report
derogation / Ausnahmeregelung / dérogation 7 “…de by Meta Platforms Ireland Limited (Meta Ireland) in accordance with EU Regulation 2021/1232 on a temporary derogation from certain provisions of Directive 2002/58/EC as regards the use of technologies by providers of number-ind…” — derogation-report
“…for the processing of personal and other data for the purpose of combating online child sexual abuse (EU CSAM Derogation). Article 3(1)(g)(vii) of the EU CSAM Derogation requires service providers to publish a report which relates…” — derogation-report
“…the purpose of combating online child sexual abuse (EU CSAM Derogation). Article 3(1)(g)(vii) of the EU CSAM Derogation requires service providers to publish a report which relates to its processing of personal data in reliance o…” — derogation-report
CSAM / CSAE 14 “…ices for the processing of personal and other data for the purpose of combating online child sexual abuse (EU CSAM Derogation). Article 3(1)(g)(vii) of the EU CSAM Derogation requires service providers to publish a report wh…” — derogation-report
“…a for the purpose of combating online child sexual abuse (EU CSAM Derogation). Article 3(1)(g)(vii) of the EU CSAM Derogation requires service providers to publish a report which relates to its processing of personal data in…” — derogation-report
“…service providers to publish a report which relates to its processing of personal data in reliance of the EU CSAM Derogation. This report is published for the purposes of compliance with this reporting obligation and provid…” — derogation-report
child sexual abuse / Kindesmissbrauch 5 “…nal communications services for the processing of personal and other data for the purpose of combating online child sexual abuse (EU CSAM Derogation). Article 3(1)(g)(vii) of the EU CSAM Derogation requires service providers to publish a…” — derogation-report
“…ng obligation and provides data relating to our use of technology for the detection, reporting and removal of child sexual abuse material (CSAM). Specifically, this report covers the period from January 1, 2024 to December 31, 2024 inclus…” — derogation-report
“…mission for the internal transfers to Meta Platforms Inc. as its processor. (4) The number of cases of online child sexual abuse identified, differentiating between online child sexual abuse material and solicitation of children: Between…” — derogation-report
NCMEC / CyberTipline 1 “…ich data has been shared pursuant to this Regulation: The National Center for Missing and Exploited Children (NCMEC). Date of report: January 30, 2025” — derogation-report

Found nowhere in these documents: Chat Control / Chatkontrolle · ePrivacy · PhotoDNA · hash matching / hash database · Internet Watch Foundation · scan / scanning / gescannt · automated detection / automatisierte Erkennung · classifier / machine learning detection · monitor content / review content

Record RSS ↗