In April 2025, the European Commission quietly reignited one of the most contentious debates in digital policy. The ProtectEU strategy, presented as a comprehensive approach to enhancing internal security, includes provisions that could fundamentally alter how encryption works across the European Union.
At its core, this is about "lawful access"—a term that sounds reasonable until you understand what it actually means: requiring service providers to decrypt communications when legally ordered. In practice, this could mean building weaknesses into the encryption that protects everything from your WhatsApp messages to your online banking.
The stakes couldn't be higher. We're watching a familiar battle play out again: law enforcement agencies argue they need access to encrypted communications to fight serious crime and terrorism. Privacy advocates, security experts, and tech companies counter that weakening encryption makes everyone less safe—including the very people these measures claim to protect.
This isn't a new fight. The EU has grappled with encryption policy for years, with previous attempts like the 2020 Council resolution on encryption and the controversial CSAR proposal. But ProtectEU signals a renewed, coordinated push that could eventually lead to binding legislation.
Here are seven critical aspects of this revived push that every EU citizen, business owner, and digital rights advocate needs to understand.
The ProtectEU strategy is the European Commission's comprehensive framework for enhancing the EU's internal security. Presented in April 2025, it aims to improve law enforcement's ability to access digital evidence across borders—including data protected by encryption.
Key Takeaway: ProtectEU is a non-legislative strategy, meaning it sets policy priorities and may lead to future legislation, but it doesn't immediately change any laws.
The strategy addresses several interconnected areas:
What makes ProtectEU particularly significant is its explicit focus on "lawful access" to encrypted communications. The Commission frames this as a necessary tool for investigating serious crimes, including terrorism, child sexual abuse, and organized crime.
This builds on previous EU efforts. The 2020 Council resolution on encryption called for "lawful and targeted access" to encrypted data, and the Commission has been exploring technical solutions ever since. ProtectEU represents the latest—and potentially most consequential—iteration of this push.
The strategy references the need to balance security and privacy. However, the inclusion of lawful access provisions has raised concerns that this balance tilts toward surveillance.
Here's where things get technical—and controversial.
"Lawful access" sounds straightforward: law enforcement should be able to access communications when they have legal authorization, such as a warrant. The problem is that end-to-end encryption (E2EE) is specifically designed so that no one—not even the service provider—can access the content of communications.
Key Takeaway: You cannot have both true end-to-end encryption and guaranteed law enforcement access. It's technically contradictory.
To enable lawful access to E2EE communications, you would need to:
Each of these approaches fundamentally undermines the security guarantees that make E2EE valuable.
The Commission emphasizes that any measures would be subject to strict safeguards: judicial oversight, proportionality tests, and limitations on when and how access can be granted. These are important protections, but they don't address the core technical problem: a backdoor that only "good guys" can use doesn't exist.
Security researchers have consistently demonstrated that any intentional vulnerability can be exploited by malicious actors. Once a backdoor exists, it becomes a target. And in a world where state-sponsored hackers, criminal organizations, and even rogue employees pose threats, the risk of misuse is significant.
Critics argue that "lawful access" is simply a euphemism for "backdoor"—a way to make an inherently dangerous proposition sound reasonable.
The fundamental problem with encryption backdoors is simple: they don't discriminate.
A backdoor built into a messaging app doesn't just let law enforcement read a suspect's messages. It creates a vulnerability that anyone with sufficient technical skill—or enough money to buy exploits—can potentially use.
Key Takeaway: There is no way to guarantee that a backdoor will only be accessible to authorized parties. Once it exists, it can be stolen, misused, or exploited.
Consider the track record:
The global cybersecurity ecosystem depends on trust. When users can't trust that their communications are truly private, they may turn to less secure alternatives or avoid digital services altogether. ENISA's 2022 survey found that 65% of EU businesses rely on encryption for data protection—weakening it would undermine the digital economy.
Perhaps the most persistent misconception is that backdoors only affect criminals. In reality, they affect everyone who uses encrypted services: journalists protecting sources, activists in authoritarian regimes, businesses protecting trade secrets, and ordinary citizens communicating with family.
The European Data Protection Supervisor (EDPS) has been unequivocal: weakening encryption could violate fundamental rights under the EU Charter of Fundamental Rights.
Key Takeaway: The EDPS has warned that any weakening of encryption could violate fundamental rights under the EU Charter, including the right to privacy and data protection.
The numbers tell a clear story about public opinion:
The European Parliament has repeatedly opposed mandatory backdoors:
Civil society organizations have been equally vocal. The Internet Society, EDRi (European Digital Rights), and dozens of other groups have warned that ProtectEU's lawful access provisions threaten the privacy and security of all EU citizens.
The human rights implications extend beyond privacy. Encryption protects freedom of expression, freedom of association, and the ability to access information—all fundamental rights enshrined in the EU Charter. Weakening encryption would disproportionately affect vulnerable groups: journalists, activists, minorities, and citizens in countries with poor human rights records.
Even if we set aside the security and human rights concerns, there's a practical problem: encryption backdoors are incredibly difficult to implement effectively.
Key Takeaway: Law enforcement faces real challenges with encrypted data, but backdoors are not the solution—they create more problems than they solve.
The scale of the challenge is significant:
These are real problems that deserve serious solutions. But mandatory decryption isn't the answer.
Alternative approaches that don't require backdoors:
The problem with client-side scanning:
Some have proposed client-side scanning as an alternative—scanning messages on the sender's device before encryption. While this avoids breaking encryption in transit, it raises its own privacy concerns. It effectively turns every device into a surveillance tool and could be abused for purposes beyond the stated goals.
The technical complexity of implementing backdoors also creates practical problems for businesses. Companies would need to build and maintain separate systems for different jurisdictions, comply with conflicting legal requirements, and bear the costs of implementing and securing these systems.
The EU is not monolithic, and encryption policy reveals deep divisions among member states.
Key Takeaway: Member states are split on encryption policy, with some supporting lawful access and others prioritizing privacy—this division will shape what happens next.
Countries historically supporting lawful access:
Countries prioritizing privacy:
The European Parliament has been a consistent opponent of mandatory backdoors, passing resolutions in 2017 and 2020 affirming the importance of strong encryption.
To navigate these divisions, the Commission plans to establish a High-Level Group on Lawful Access to facilitate dialogue between stakeholders—law enforcement, tech companies, civil society, and member states.
Tech companies and civil society remain strongly opposed. The Internet Society has warned that backdoors would undermine the security of the internet, while EDRi has called the proposals "a direct threat to fundamental rights."
The ProtectEU strategy is non-legislative, meaning it doesn't immediately change any laws. But it sets the stage for future legislative proposals.
Key Takeaway: The strategy is just the beginning—any binding measures would require separate legislative proposals, which would face scrutiny from the European Parliament and Council.
Key milestones to watch:
Lessons from previous attempts:
Potential impact on businesses:
Companies operating in the EU could face: - Increased costs: Building and maintaining backdoor systems - Legal risks: Conflicting requirements across jurisdictions - Reputational damage: Customers may lose trust in services with weakened encryption
The European Commission's ProtectEU strategy represents a renewed push in a long-running battle over encryption. The core tension remains unresolved: how do we balance legitimate law enforcement needs with the security and privacy that strong encryption provides?
Key Takeaway: Strong encryption is essential for the digital economy, fundamental rights, and global cybersecurity—any attempt to weaken it must meet an extremely high bar.
What we know:
What we don't know:
The debate is far from over. The Commission's push signals renewed focus, but it faces strong opposition from the European Parliament, privacy advocates, and the tech industry. Any legislative proposal would face an uphill battle.
For now, the most important thing is to stay informed and engaged. Encryption isn't just a technical issue—it's a fundamental question about the kind of society we want to live in.
What is the ProtectEU strategy?
ProtectEU is the European Commission's April 2025 strategy to enhance EU internal security by improving law enforcement's ability to access digital evidence, including encrypted data. It's a non-legislative strategy that sets policy priorities.
Does ProtectEU mandate encryption backdoors?
Not directly. ProtectEU includes a "lawful access" framework that could require service providers to decrypt communications when legally ordered, but it doesn't immediately change any laws. Any binding measures would require separate legislation.
Why is encryption important?
Encryption protects the confidentiality of digital communications and data. It's essential for privacy, security, and the digital economy. 85% of EU citizens consider it important, and 65% of EU businesses rely on it.
What are the risks of encryption backdoors?
Backdoors create vulnerabilities that can be exploited by hackers, foreign governments, and malicious actors. There's no way to guarantee exclusive access—once a backdoor exists, it can be stolen or misused.
Who opposes encryption backdoors?
The European Parliament (which passed resolutions against them in 2017 and 2020), the European Data Protection Supervisor, civil society organizations like the Internet Society and EDRi, and most tech companies.
What alternatives to backdoors exist?
Targeted hacking, metadata analysis, international cooperation, and endpoint security are alternatives that don't require weakening encryption for everyone.
Has the EU attempted this before?
Yes. The 2020 Council resolution on encryption called for lawful access, and the CSAR proposal included detection orders that raised similar concerns. Previous attempts have faced significant opposition.
What happens next with ProtectEU?
The Commission plans to establish a High-Level Group on Lawful Access. Any binding legislation would require approval from the European Parliament and Council, where it would face scrutiny.
How does ProtectEU affect businesses?
Businesses could face increased costs, legal risks, and conflicting requirements across jurisdictions if backdoor mandates are implemented. It could also undermine customer trust.
What is the European Data Protection Supervisor's stance?
The EDPS has warned that weakening encryption could violate fundamental rights under the EU Charter of Fundamental Rights.
Want to learn more about how encryption affects your digital rights? Subscribe to our newsletter for updates on EU digital policy and join the conversation using #ProtectEncryption.