{"id":10785,"date":"2026-03-27T09:00:00","date_gmt":"2026-03-27T09:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/03\/eu-chat-control-what-companies-need-to-know-now\/"},"modified":"2026-07-04T12:22:49","modified_gmt":"2026-07-04T12:22:49","slug":"eu-chat-control-what-companies-need-to-know-now","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/03\/27\/eu-chat-control-what-companies-need-to-know-now\/","title":{"rendered":"EU Chat Control: What Companies Need to Know Now"},"content":{"rendered":"<p style=\"display:inline-block;background:#69d8ed;color:#fff;padding:4px 14px;border-radius:20px;font-size:0.85em;margin-bottom:18px;\">6 min reading time<\/p>\n<p><strong>502 cryptographers warned that Signal threatened to exit the European market &#8211; and Germany\u2019s Federal Constitutional Court struck down parts of \u201con-device\u201d communications interception. Yet the EU continues negotiating chat surveillance rules. The CSAR Regulation is now in trilogue negotiations, and the ePrivacy exception permitting voluntary scanning expires on 4 April 2026. What does this mean for businesses relying on encrypted communication?<\/strong><\/p>\n<p>The debate is often framed as a battle between child protection and privacy. For cybersecurity teams, it\u2019s far more concrete: any legally mandated weakness in encryption systems affects everyone &#8211; including attackers.<\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li><strong>Council agreed on no mandatory scanning:<\/strong> On 26 November 2025, the Council of the EU adopted a position with <em>no mandatory detection orders<\/em>. Instead: risk assessment obligations and voluntary scanning. Germany led the blocking minority (Council of the EU press release).<\/li>\n<li><strong>Trilogues continue:<\/strong> The second trilogue is scheduled for 26 February 2026, the third for 4 May, and the fourth for 29 June. The ePrivacy exception for voluntary scanning expires on 4 April 2026.<\/li>\n<li><strong>Federal Constitutional Court, \u201cTrojaner II\u201d ruling (June 2025):<\/strong> Declared parts of \u201con-device\u201d communications interception unconstitutional and void. Mass, indiscriminate surveillance of encrypted communications would almost certainly fail under this standard.<\/li>\n<li><strong>Signal\u2019s threat remains active:<\/strong> Meredith Whittaker, Signal\u2019s president, announced the company will exit the European market if client-side scanning becomes mandatory (confirmed via X post, May 2024).<\/li>\n<li><strong>502 internationally renowned cryptographers and security researchers<\/strong> deem client-side scanning \u201ctechnically unfeasible\u201d and warn of new vulnerabilities exploitable by hackers and hostile states.<\/li>\n<\/ul>\n<p>According to Telecom Reseller, use of SOCKS5 proxies in Europe has surged nearly 1,770% &#8211; a clear signal that technically savvy users and enterprises are already taking preventive action. Anyone designing corporate communication infrastructure today must consider the possibility that encrypted messaging services will come under regulatory pressure. This doesn\u2019t affect chat apps alone: end-to-end encrypted email services, zero-knowledge cloud storage, and VPN providers could also be implicated. The CSAR Regulation deliberately defines \u201chosting services\u201d and \u201cinterpersonal communications services\u201d very broadly.<\/p>\n<p>Another issue many companies overlook: legal liability. If a platform provider implements scanning after a detection order enters into force &#8211; and due to a software bug or compromised update &#8211; leaks confidential corporate data to unauthorized third parties, who bears responsibility? The provider that implemented the scanning mechanism? Or the legislator who mandated it? This question remains legally unresolved &#8211; and won\u2019t be clarified until the first incident occurs\u2026 far too late for affected businesses.<\/p>\n<p>This article contextualises what has been agreed, what remains pending, and what <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/24\/post_id-5563\/\">German companies must prepare for<\/a>.<\/p>\n<h2>What the Council agreed  &#8211;  and what it didn\u2019t<\/h2>\n<p>After three years of negotiations, the Council of the EU adopted a common position on the CSAR Regulation (Regulation on Combating Child Sexual Abuse) on 26 November 2025. At its core: <strong>mandatory detection orders have been dropped.<\/strong> Platform providers must conduct risk assessments and may voluntarily scan &#8211; but no one will be legally compelled to inspect messages before encryption.<\/p>\n<p>Germany, alongside a blocking minority, halted an earlier draft that <em>did<\/em> include mandatory scanning. Justice Minister Stefanie Hubig clearly articulated the government\u2019s stance: mass, suspicionless chat surveillance violates the fundamental principles of a constitutional democracy. The German Data Protection Conference, chaired by Meike Kamp &#8211; Berlin\u2019s Data Protection Commissioner &#8211; explicitly urged the federal government to reject chat control.<\/p>\n<div class=\"evm-stat evm-stat-highlight\" style=\"text-align:center;background:#f0f9fa;border-radius:12px;padding:32px 24px;margin:32px 0;\">\n<div style=\"font-size:48px;font-weight:700;color:#69d8ed;letter-spacing:-0.03em;\">502<\/div>\n<div style=\"font-size:15px;color:#444;margin-top:8px;\">Cryptographers and security researchers signed an open letter opposing client-side scanning<\/div>\n<div style=\"font-size:12px;color:#888;margin-top:8px;\">Source: CyberInsider, 2025<\/div>\n<\/div>\n<p>But the agreement contains a <strong>review clause:<\/strong> Within three years, the European Commission must assess whether mandatory detection orders are \u201cnecessary and feasible.\u201d Privacy experts and the Electronic Frontier Foundation warn of the risk of progressive scope creep &#8211; the backdoor for mandatory scanning remains explicitly preserved in the legal text.<\/p>\n<p>The trilogue between the Council, Parliament, and Commission began in December 2025. The second meeting took place on 26 February; the third is scheduled for 4 May. A critical date: the <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/20\/post_id-5461\/\">ePrivacy exception<\/a> currently permitting voluntary scanning legally expires on 4 April 2026. Without extension or new legislation, the legal basis vanishes.<\/p>\n<h2>Why backdoors don\u2019t work technically<\/h2>\n<p>Client-side scanning means analysing messages directly on the user\u2019s device &#8211; before they are encrypted. It appears to be a compromise: encryption remains intact, and scanning happens upstream. In practice, it\u2019s precisely the opposite: the scanning code installed on every device becomes a highly attractive target for attackers.<\/p>\n<p>502 scientists with recognised expertise in cryptography and security engineering warned in an open letter that such measures are technically unfeasible &#8211; and would undermine the security and privacy of all European citizens. Signatories include Cas Cremers (Helmholtz CISPA), Bart Preneel (KU Leuven), Carmela Troncoso (EPFL), and Ren\u00e9 Mayrhofer (JKU Linz).<\/p>\n<p>The argument boils down to one sentence: <strong>There is no backdoor accessible only to \u201cgood actors.\u201d<\/strong> Any mechanism granting law enforcement access also grants it to hackers, spyware vendors, and hostile intelligence services. History proves it: the NSA\u2019s Clipper chip &#8211; a 1990s encryption system built with integrated state access &#8211; failed in 1994 when Matt Blaze of AT&#038;T Bell Labs demonstrated its key escrow mechanism was manipulable.<\/p>\n<p>The same debate is unfolding simultaneously in Canada. Bill C-8 &#8211; nearly identical to the failed C-26 &#8211; authorises the Canadian government to order telecom operators to lower encryption standards via administrative decree. The term \u201csystemic vulnerability\u201d is undefined in the bill &#8211; a gap that may be intentional or negligent, but either way dangerous. The University of Toronto\u2019s Citizen Lab has formally warned of the cybersecurity consequences. The pattern is global: governments attempt to impose backdoors in encryption systems; cryptographers sound the alarm; courts rein them in &#8211; and pressure begins anew.<\/p>\n<p>For CISOs and IT leaders across DACH (Germany, Austria, Switzerland), the conclusion is pragmatic: chat control is not approved &#8211; but neither is it ruled out. The Council\u2019s review clause keeps mandatory scanning on the table. Anyone designing communication infrastructure today must factor in this uncertainty &#8211; with an architecture flexible enough to migrate, if necessary, to alternative providers or decentralised systems. This isn\u2019t alarmism. It\u2019s risk management.<\/p>\n<blockquote style=\"border-left:4px solid #69d8ed;margin:32px 0;padding:20px 24px;background:#fafafa;border-radius:0 8px 8px 0;font-size:1.1em;line-height:1.6;color:#333;\"><p>\n\u00abMass, indiscriminate surveillance &#8211; which subjects millions of EU citizens to blanket suspicion &#8211; is disproportionate.\u00bb<br \/>\n<cite style=\"display:block;margin-top:12px;font-size:0.8em;color:#888;font-style:normal;\"> &#8211;  Meike Kamp, Berlin Data Protection Commissioner \/ Chair of the German Data Protection Conference (BfDI, October 2025)<\/cite>\n<\/p><\/blockquote>\n<h2>BVerfG \u201cTrojaner II\u201d: The constitutional limit<\/h2>\n<p>On 24 June 2025, Germany\u2019s Federal Constitutional Court issued its \u201cTrojaner II\u201d ruling (1 BvR 180\/23), declaring parts of \u201con-device\u201d communications interception unconstitutional and void. The court set clear limits on state interference with encrypted communication.<\/p>\n<p>Key conclusions: On-device interception may not be applied to offences punishable by less than three years\u2019 imprisonment. Its use is restricted to communications that could also be intercepted using traditional telephone surveillance methods (the principle of synchronicity). Both the secrecy of telecommunications (Article 10 of the Basic Law) and the fundamental right to informational self-determination &#8211; the right to confidentiality and integrity of IT systems &#8211; are affected.<\/p>\n<p>This is directly relevant to the chat control debate. If the Federal Constitutional Court already deems targeted on-device interception disproportionate for minor offences, then <strong>mass, indiscriminate surveillance<\/strong> of all encrypted messages would fail even more decisively under the same standard. The fundamental right to informational self-determination &#8211; established in the 2008 \u201cdata retention\u201d ruling &#8211; protects the integrity of end-user devices &#8211; and client-side scanning precisely violates that integrity.<\/p>\n<p>This ruling has direct economic consequences for Germany. Companies using end-to-end encrypted communication &#8211; including, per Bitkom, 58% of all firms with more than 20 employees &#8211; operate on a constitutionally protected foundation. A European regulation mandating client-side scanning would be immediately challenged in Germany. The question is not <em>whether<\/em>, but <em>when<\/em>, such a regulation would land before the Federal Constitutional Court &#8211; or the Court of Justice of the EU.<\/p>\n<h2>What this means for businesses<\/h2>\n<p>The consequences are not theoretical. If detection orders become mandatory in a future version of the regulation, they will affect <strong>all encrypted platforms:<\/strong> Microsoft Teams, Slack, Signal, WhatsApp &#8211; and any end-to-end encrypted email solution.<\/p>\n<p>Compliance teams face three concrete risks. First: internal communications &#8211; contract negotiations, M&#038;A processes, personnel files, source code &#8211; would be automatically scanned, with a documented false-positive rate in detection. False positives could transmit confidential corporate data to authorities without the company\u2019s knowledge or consent.<\/p>\n<p>Second: divergent requirements between the EU and the United States make a uniform global encryption architecture impossible. Companies would need to manage separate communication channels for EU and non-EU contexts.<\/p>\n<p>Third: <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/25\/copilot-as-a-security-risk-when-the-ai-assistant-leaks-corporate-secrets\/\">Loss of trust.<\/a> Meredith Whittaker, Signal\u2019s president, has warned the company will exit the European market if client-side scanning becomes mandatory. For businesses relying on Signal as a secure channel &#8211; many, especially in cybersecurity &#8211; this would mean immediate infrastructure loss.<\/p>\n<div style=\"display:flex;flex-wrap:wrap;gap:12px;margin:32px 0;\">\n<div style=\"flex:1;min-width:160px;text-align:center;background:#f0f9fa;border-radius:10px;padding:24px 20px;border-top:3px solid #69d8ed;\">\n<div style=\"font-size:clamp(1.5em,5vw,2.4em);font-weight:800;color:#69d8ed;line-height:1;\">4 April<\/div>\n<div style=\"font-size:0.85em;margin-top:8px;color:#444;\">ePrivacy exception expires<\/div>\n<\/div>\n<div style=\"flex:1;min-width:160px;text-align:center;background:#f0f9fa;border-radius:10px;padding:24px 20px;border-top:3px solid #69d8ed;\">\n<div style=\"font-size:clamp(1.5em,5vw,2.4em);font-weight:800;color:#69d8ed;line-height:1;\">4 May<\/div>\n<div style=\"font-size:0.85em;margin-top:8px;color:#444;\">Third trilogue scheduled<\/div>\n<\/div>\n<div style=\"flex:1;min-width:160px;text-align:center;background:#f0f9fa;border-radius:10px;padding:24px 20px;border-top:3px solid #69d8ed;\">\n<div style=\"font-size:clamp(1.5em,5vw,2.4em);font-weight:800;color:#69d8ed;line-height:1;\">29 June<\/div>\n<div style=\"font-size:0.85em;margin-top:8px;color:#444;\">Fourth trilogue (likely the final one)<\/div>\n<\/div>\n<\/div>\n<div style=\"text-align:center;font-size:12px;color:#888;margin-top:-20px;margin-bottom:24px;\">Sources: Factually.co, EDRi, Council of the EU 2025-2026<\/div>\n<h2>What IT security teams must do now<\/h2>\n<p><strong>First: document your messaging infrastructure.<\/strong> Which encrypted channels does your company use? Signal, WhatsApp, Teams? Who communicates what &#8211; and with whom? This inventory forms the foundation for any future adjustments.<\/p>\n<p><strong>Second: review your encryption policy.<\/strong> Which communications use end-to-end encryption &#8211; and which rely solely on transport-layer encryption? Under mandatory detection orders, E2EE communications would be affected, but transport-only encryption would not. Understanding your own architecture is decisive.<\/p>\n<p><strong>Third: <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/12\/nis2-in-deutschland-was-unternehmen-jetzt-wissen-und-umsetzen-muessen\/\">actively track regulatory developments.<\/a><\/strong> Trilogue negotiations will continue at least through June 2026. Every company with a compliance department should monitor EDRi\u2019s document collection and Council press releases.<\/p>\n<p><strong>Fourth: evaluate alternative communication channels.<\/strong> If Signal does exit the European market, teams will need alternatives offering comparable security. Wire (Swiss provider), Threema (also Swiss), and Matrix\/Element (decentralised and open-source) are strong candidates &#8211; all with distinct regulatory compliance profiles.<\/p>\n<p>The chat control debate reveals a fundamental pattern: any regulation that weakens encryption weakens <em>everyone<\/em> &#8211; not just the intended target group. The Federal Constitutional Court set constitutional boundaries with \u201cTrojaner II.\u201d The 502 cryptographers set technical boundaries. Whether politics respects those boundaries depends on decisions made in the coming months.<\/p>\n<p>One thing is clear: encryption is neither a luxury nor an obstacle to criminal investigations. It is the foundation of confidential business communication, whistleblower protection, journalistic source confidentiality, and trust in digital infrastructure. Every attempt to weaken it undermines the entire system &#8211; confirmed by 502 scientists, confirmed by the Federal Constitutional Court, and proven by the history of the Clipper chip. The question is not <em>whether<\/em> encryption must be protected. The question is whether Europe understands this &#8211; before it\u2019s too late.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>What is the EU\u2019s chat control?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The CSAR Regulation (Regulation on Combating Child Sexual Abuse) aims to compel platform providers to search for illegal content on their services. Critics warn of mass surveillance of encrypted communications. The Council\u2019s current text no longer includes mandatory detection orders &#8211; but does contain a review clause.<\/p>\n<\/details>\n<details>\n<summary><strong>Has chat control already been approved?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">No. The Council adopted its position in November 2025; the trilogue with Parliament and the Commission began in December 2025. A final agreement is expected no earlier than summer 2026.<\/p>\n<\/details>\n<details>\n<summary><strong>Would Signal leave the EU?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Meredith Whittaker, Signal\u2019s president, has announced the company will exit the European market if client-side scanning becomes mandatory. As the Council\u2019s current text imposes no such obligation, Signal remains in the market &#8211; for now.<\/p>\n<\/details>\n<details>\n<summary><strong>What does the Federal Constitutional Court say about surveillance of encrypted communications?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The \u201cTrojaner II\u201d ruling, issued in June 2025, declared parts of on-device communications interception unconstitutional. Mass, indiscriminate surveillance would fail even more clearly under this standard &#8211; as it infringes both the secrecy of telecommunications and the fundamental right to informational self-determination.<\/p>\n<\/details>\n<details>\n<summary><strong>What does chat control mean for businesses?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">If mandatory detection orders are imposed, all encrypted platforms (Teams, Slack, Signal) would need to implement client-side scanning. False positives could send confidential corporate data to authorities without the company\u2019s knowledge or consent.<\/p>\n<\/details>\n<details>\n<summary><strong>What is client-side scanning?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Messages are analysed directly on the user\u2019s device before encryption. The scanning mechanism itself thus becomes an attack target. 502 cryptographers have warned this undermines security for all users.<\/p>\n<\/details>\n<details>\n<summary><strong>Are there Signal alternatives based in Switzerland?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Wire and Threema are Swiss-based providers offering end-to-end encryption. Matrix\/Element is decentralised and open-source. All three would be less directly exposed to an EU scanning mandate than US-headquartered providers.<\/p>\n<\/details>\n<p>The surge in proxy usage across Europe shows businesses and users aren\u2019t waiting for regulation to advance. According to Telecom Reseller, SOCKS5 proxy usage in Europe rose nearly 1,770% &#8211; a clear indicator that preventive action is already underway. The question is whether the EU will succeed in imposing a regulation that will be technically circumvented and constitutionally challenged &#8211; or whether it will honour the Council\u2019s agreed compromise: risk assessment instead of mass surveillance, prevention instead of backdoors.<\/p>\n<div style=\"background:#f0f8ff;border-radius:8px;padding:20px 24px;margin:24px 0;border-top:3px solid #69d8ed;\">\n<h2 style=\"margin-top:0;margin-bottom:12px;font-size:1.05em;\">Editorial reading recommendations<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/25\/copilot-as-a-security-risk-when-the-ai-assistant-leaks-corporate-secrets\/\">Copilot as a security risk: When AI assistants leak corporate secrets<\/a><\/li>\n<li>Passkeys 2026: Why passwords are disappearing<\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/24\/supply-chain-attack-on-trivy-when-the-security-scanner-itself-becomes-a-weapon\/\">Supply-chain attack against Trivy<\/a><\/li>\n<\/ul>\n<\/div>\n<div style=\"background:#f0f8ff;border-radius:8px;padding:20px 24px;margin:24px 0;border-top:3px solid #69d8ed;\">\n<p style=\"font-weight:700;color:#e6e3da;font-size:1.05em;margin:48px 0 16px;\">More from MBF Media Netzwerk<\/p>\n<div style=\"display:flex;flex-direction:column;gap:14px;margin-bottom:40px;\"><a href=\"https:\/\/www.cloudmagazin.com\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#0bb7fd;\">cloudmagazin<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">cloudmagazin   &#8211;   Cloud, SaaS, and IT infrastructure<\/span><\/a><a href=\"https:\/\/www.mybusinessfuture.com\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#aa8ac2;\">MyBusinessFuture<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">MyBusinessFuture   &#8211;   Digital transformation and Artificial Intelligence<\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#d65663;\">Digital Chiefs<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">Digital Chiefs   &#8211;   Strategic leadership for executives<\/span><\/a><\/div>\n<p style=\"text-align:right;font-style:italic;color:#888;margin-top:32px;\">Header Image Source: Pexels \/ Dan Nelson (px:4489171)<\/p>\n","protected":false},"excerpt":{"rendered":"6 min reading time 502 cryptographers warned that Signal threatened to exit the European market &#8211; and Germany\u2019s Federal Constitutional Court struck down parts of \u201con-device\u201d communications interception. Yet the EU continues negotiating chat surveillance rules. The CSAR Regulation is now in trilogue negotiations, and the ePrivacy exception permitting voluntary scanning expires on 4 April [&hellip;]","protected":false},"author":55,"featured_media":5580,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"chat control","_yoast_wpseo_title":"EU Chat Control: What Companies Need to Know Now","_yoast_wpseo_metadesc":"EU Chat Control: Keep your business compliant with new messaging regulations. Learn how to protect user privacy and avoid penalties\u2014read now.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[259],"tags":[],"class_list":["post-10785","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-strategie-governance-en"],"evm_reading_time_minutes":13,"wpml_language":"en","wpml_translation_of":9020,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/10785","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=10785"}],"version-history":[{"count":3,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/10785\/revisions"}],"predecessor-version":[{"id":19733,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/10785\/revisions\/19733"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/5580"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=10785"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=10785"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=10785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}