Showing posts with label Digital Services Act. Show all posts
Showing posts with label Digital Services Act. Show all posts

Monday, 29 June 2026

The End of Immunity for Internet Service Providers? C-188/24 WebGroup Czech Republic and NKL Associates and C-190/24 Coyote System, judgment 16 June 2026



 

Lorna Woods, Professor Emerita, University of Essex

Photo credit: TodayTesting.com, via Wikimedia Commons   

This recent CJEU judgment has been flagged in some quarters as upholding the French rules requiring age verification for porn sites. In others, it has been seen as stripping intermediary immunity from social media sites. Based on the e-Commerce Directive, however, is this just a transient discussion, fading away as the Digital Services Act (DSA) becomes the relevant law?

 

The Facts

 

The national cases in Case C-188/24 concern French rules requiring porn operators to implement technical age verification mechanisms to prevent minors from accessing those sites.  The companies were each the subject of a formal notice pursuant to Decree No 2021/1306 implementing Law No 2020-936 and Article 227-24 of the Criminal Code which prohibits any person from broadcasting a pornographic message likely to be seen by a minor. The rules in Coyote System concern the restriction on the broadcasting of information to drivers about roadside checks (eg in relation to speed or drunk driving). The relevant implementing measures were also derived from the French criminal code. These measures were subject to judicial challenge before the French Conseil d’État. The companies in question were not established in France and questioned the applicability of the French rules.

 

The Issues

 

The first question the CJEU had to address was whether the measures fell within the coordinated field of the  e-Commerce Directive (Directive 2000/31) and would therefore be caught by Article 3, which provides for the country of origin principle (COOP). Recital 22 which states that ‘information society services should be supervised at the source of the activity’. This means that services in general comply with the domestic law of the State in which they are established and do not have to comply with the laws of the States in which their services are capable of being accessed.  Article 3(3) excludes certain areas from the coordinated field and Article 3(4) et seq provide for limited grounds of derogation from the COOP and provide conditions with which the receiving State must comply to access the derogation.   The COOP applies only to laws falling within the coordinated field. Here the relevant laws were not sector specific measures targeting information society services in particular, but the general criminal law. The referring court questioned whether the provisions in issue fell within the coordinated field and referred the issue to the CJEU.

 

The ban on transmission in Coyote System was, according to the applicant, contravening the prohibition on general monitoring found in Article 15 e-Commerce Directive. This application of this article is dependent on the information society services in question falling within one of the categories of service found in Articles 12-14 e-Commerce Directive (mere conduit, caching services or hosting services respectively). The Court thus then had to consider whether the service in Coyote System was a hosting service within the meaning of Article 14 e-Commerce Directive. Article 14(1) provides:

 

Where an information society service is provided that consists of the storage of information provided by a recipient of the service, Member States shall ensure that the service provider is not liable for the information stored at the request of a recipient of the service, on condition that:

 

(a) the provider does not have actual knowledge of illegal activity or information and, as regards claims for damages, is not aware of facts or circumstances from which the illegal activity or information is apparent; or

(b) the provider, upon obtaining such knowledge or awareness, acts expeditiously to remove or to disable access to the information.

 

Judgment

 

The Coordinated Field

 

The Court emphasised that the coordinated field

 

covers all requirements laid down by the legal systems of the Member States relating to the taking up or pursuit of the activity of an information society service, … that definition does not make the coordinated field subject to the condition that only matters harmonised by that directive are covered. [para 52]

 

Following the Advocate General (at para 56 of his Opinion), it remarked that Article 3 is of particular importance precisely for the areas of law not harmonised. The mere fact that the laws apply generally cannot remove them from the coordinated field. Moreover, the Directive excludes certain areas from the scope of the Directive, so the question of exclusion had been taken into account in the Directive. Taking a different approach would undermine the purpose of the Directive.

 

The Court confirmed that requiring age verification sets the conditions for access to the information society services and is a requirement concerning the pursuit of an activity within Article 2(h)(i) (see Case C-649/18 A (Advertising and sale of medicinal products online)). For the roadside broadcasts, the Court took the view that the prohibition constituted a requirement relating to the content of the service. Both sets of measures therefore fall within the coordinated field.

 

The COOP and Derogation

 

The key question for the application of the COOP was whether the measures restricted the free movement of the services. This question the Court answered in the affirmative before considering whether the derogation in Article 3(4) could be used.

 

The derogation has substantive and procedural conditions. Substantively, the measure must be necessary in the interests of one of more of: public policy; protection of public health; public security; or protection of consumers. Further, those measures should be taken against an information society service which actually prejudices those objectives or presents a serious and grave risk to those objectives. Finally, the measures must be proportionate to the objectives. In procedural terms, the recipient Member State must first have issued an unsuccessful request to the host Member State to fix the issue and, secondly, notified the Commission.  A failure to comply renders the obligations unenforceable (Case C-390/18 Airbnb Ireland – following long established case law).

 

General rules applying without distinction do not satisfy the second of the substantive conditions. The rules, however, provided for the issuing of individual notices which satisfy this requirement [para 90]. The third substantive element – that of proportionality – was satisfied in relation to the protection of human dignity and the rights of the child as regards the broadcasting of pornography [para 94] and, without much elaboration, the prohibition on rebroadcasting is also proportionate [para 96]. 

 

So in principle, the national rules could meet the substantive criteria but it was for the referring court to determine whether the procedural rules were satisfied.

 

General Monitoring

 

Hosting

 

As noted above, the possibility of relying on Article 15 depends on whether the service in issue – here the service in Coyote System - is a host within the scope of Article 14 [see para 105]. The Court noted that the definition of hosting did not automatically preclude a service which also has elements of broadcasting from being a host, referring to long-standing caselaw as well as more recent (Case C-360/10 SABAM; Case C-682/18 YouTube and Cyanado and Case C-401/19 Poland v Parliament and Council). Conversely, just because a service includes the storage of information does it mean that the service is a host for the purposes of Article 14. The Court reiterated the limitations arising from Recital 42 – that the services should be of a mere technical, automatic and passive nature. This implies, according to the Court’s case law (Case C-324/09 L’Oréal and Case C-682/18 YouTube and Cyanado), “the information society service provider has neither knowledge of nor control over the information which is transmitted or stored” [para 108].  The Court underlined that “those two conditions requiring knowledge and control should be understood as being alternative to and independent of each other” [para 110].  The Court then held that

 

if, beyond the mere categorisation and indexation of information for the purpose of improving its accessibility, the algorithm used determines, in the interest of the operator or its service, under what conditions, how and in which order of priority that information is or is not be broadcast, that operator exercises control over that information, with the result that the service it offers cannot be classified as an ‘information society service … that consists of the storage of information provided by a recipient of the service’ [para 112].

 

Impact on Article 14(3) and Article 15

 

If a service exercises control over content, it does not fall within Article 14 and therefore the restrictions imposed on Member States by Article 15 are not applicable to such are service. The questions were for the national court to determine.

 

On the assumption that the service were found to be neutral, the national court must decide whether the prohibition on rebroadcasting the information on roadside checks is permitted by Article 14(3) which concerns orders requiring a neutral host to terminate any infringement on the part of the recipient of the service due to, inter alia, the presence of illegal information stored on its website or on its platform by removing or blocking access to that information.

 

Considering Article 15, the Court referred to Recital 47 e-Commerce Directive, which clarifies that Article 15 does not apply to monitoring in specific cases. Referring to the test laid down in Glawischnig-Piesczek (Case C-18/18), paras 46 and 47, the Court noted in this case that the information targeted by the prohibitions “is circumscribed in such a way that its rebroadcasting may be automatically prevented by the operator concerned” [para 121].

 

 

Comment

 

Coordinated Field and COOP

 

The Court has taken a typical approach here, a broad approach to the areas covered: criminal law rules and public policy rules can fall within the scope of the directive, provided they impose requirements on the access or conduct of an information society service. Furthermore, none of the criminal law in general, public policy and public security measures appear on any of the exclusions from the scope of the directive. The Court’s ruling makes explicit that this absence from the exclusions is deliberate. This position is in the interests of ensuring that a service is not subject to multiple regulation, but it can lead to unevenness and gaps in protection from the viewpoint of a person expecting the rules of the member state in which they reside to apply to services providers providing services in that self-same Member State. This is especially the case when the aspect potentially taking the national rule outside the derogation regime is about its form, not its substance.  The COOP principle has long given rise to concerns about forum shopping and a race to the bottom (as can be seen also in the broadcasting sector and the Audiovisual Media Services Directive) but has been re-affirmed as a central tenet of the EU regime (see eg Case C-769/22 Commission v Hungary (Values of the European Union)). 

 

It is also worth noting that the Court in principle accepted that both sets of rules in the cases referred were aimed at achieving legitimate aims and were proportionate. The Court drew on the fact that the AVMSD requires age verification in relation to pornography to reach this latter assessment. In so doing, the Court engaged in a joining up the dots activity between different piece of EU digital legislation. 

 

In this ruling, the Court underlined both the importance of the right to human dignity and the rights of the child.

 

Impact on Article 14

 

The headline news from this ruling is the impact on Article 14 and the test for neutral intermediary. The hosting safe harbour in Article 14 was always meant for neutral, passive intermediaries – entities whose activity is “purely technical, automatic and passive”, implying that the provider “has no knowledge of or control over” the information stored (Recital 42 e-Commerce Directive). This has been the standard position since the early case law – for example L’Oreal.  What this means, and in particular the impact of automated tools, has been the subject of some discussion. In a different context (copyright infringement), the Court even if an operator automatically indexes infringing content to recommended videos based on each users’ use did not necessarily mean that the host had specific knowledge of the infringing content, and the Court determined that this sort of specific knowledge was what was required. This could be seen as quite a generous view towards the hosting services and the scope of immunity. It might almost be said that there was an assumption that platforms would benefit from Article 14 (provided they responded to notices). In Coyote there is a shift of focus.

 

The first point to note is the Court’s statement that hosting services do not automatically benefit from Article 14. While this is not new – and, indeed, can be seen the Court’s previous jurisprudence – the reminder feels significant, especially in the light of the rest of the ruling. The Court here confirmed that a service has to satisfy both the knowledge and the control tests, a point not laboured in previous judgments. The Court (at para 110) makes this really clear: if a service exercises control, even if it has no knowledge, it will fall outside the intermediary immunity provision.

 

Whereas Cyanado dealt with knowledge, System Coyote looks at control. Significantly, the Court held that algorithmic curation constitutes “control”.  The Court (following its Advocate General) held (para 111):

 

it is, inter alia, by means of the algorithm used that such an operator exercises control over the information stored. So long as it has predetermined, by means of that algorithm, the conditions under which such information may or may not be broadcast, it is irrelevant that that operator does not itself carry out additional interventions which have the effect of promoting, modifying or deleting information stored with a view to it being broadcast.

 

In other words, when a service which stores information uses an algorithm to determine – in its own interest or that of its service – under what conditions, in what manner, and in what order of priority information is or is not disseminated it has control (see para 112). It does not matter that this is automatic. So creating the algorithmic system is exercising control.  In focussing on control, the Court avoids outright conflict with its earlier position (for example in Cyanado), but it certainly signals a change in emphasis and (in line with thinking underpinning parts of the DSA) a recognition that the algorithm is not necessarily neutral.

 

Not all categorisation or prioritising satisfies the control test. Simple categorisation and indexing of information to improve its accessibility do not on their own constitute control. Essentially, the Court is trying to draw the line between a neutral index, or chronological feed, and something more editorial (and it is telling to remember that the services themselves have claimed first amendment rights – is relating to their speech – in relation to how results are provided). 

 

Nonetheless, this ruling will affect a wide range of services based on curating user generated content, from social networks, video-sharing services and – of course – services that rebroadcast user reports (eg about police checks), as well as recommended products on a marketplace. The judgment could be read as stripping most (if not all) of the large social media platforms of their immunity (though this does not mean they will automatically be liable in all cases – that will depend on national law and the facts in individual cases). It could also be said to follow a similar path to the Russmedia decision (Case C-492/23), discussed here, which also took a narrow view of immunity (hosting defence does not apply to liability under the GDPR).

 

Impact on Article 15

 

The prohibition on general monitoring only relates to those services covered by intermediary immunity. Although this follows the language of Article 15(1) there had been some dispute as to who could claim the protection of Article 15. The answer is now clear: fall outside Article 14 (or 12 or 13) and Article 15 does not apply. 

 

The Court also reiterates its position on the distinction between general and specific monitoring and highlighting the possibility of using automated techniques to identify particular types of content. This could be relevant for Member States’ ability to impose monitoring or filtering obligations (in services of some public interest) – these (in relation to copyright infringements, e.g. SABAM, above) had been thought problematic in the relatively early days of the e-Commerce Directive, and platforms have often challenged such obligations as constituting general monitoring. The Court’s discussion here is focussed tightly on content; it does not discuss behavioural monitoring or profiling (which might be techniques by services to reduce the incidence of illegal content or behaviour across their services). It will be interesting to see how this line of case law joins up with the jurisprudence under the e-Privacy directive on collection of metadata and intrusions into communications privacy (see eg Case C-746/18 Prokurator).

 

Impact on DSA

 

Article 6 DSA, which replaces Article 14 e-Commerce Directive, provides that hosting providers are not liable for information stored at the request of a recipient of the service, provided that they do not have actual knowledge of illegal activity or content, unless the recipient acts under the authority  “or control” of the provider. It has been assumed given the similarity in the text, that the case law on Article 14 is relevant for understanding Article 6 DSA, including as regards the threshold condition of neutral. The wording of the relevant recitals in the DSA differ, however, from the text in the e-Commerce Directive (noted above) – and the Court has relied heavily on that text in its interpretation of Article 14.  Indeed, Article 14 itself does not refer to control. Recital 22 DSA specifies:

[i]n order to benefit from the exemption from liability for hosting services, the provider should, upon obtaining actual knowledge or awareness of illegal activities or illegal content, act expeditiously to remove or to disable access to that content. … The provider can obtain such actual knowledge or awareness of the illegal nature of the content, inter alia, through its own-initiative investigations or through notices submitted to it by individuals or entities in accordance with this Regulation in so far as such notices are sufficiently substantiated to allow a diligent economic operator to reasonably identify, assess and, where appropriate, act against the illegal content. However, such actual knowledge or awareness cannot be considered to be obtained solely on the ground that the provider is aware, in a general sense, of the fact that its service is also used to store illegal content. Furthermore, the fact that the provider automatically indexes information uploaded to its service, that it has a search function or that it recommends information on the basis of profiles or preferences of the recipients of the service is not a sufficient ground for considering that provider to have ‘specific’ knowledge of illegal activities carried out on that platform or of illegal content stored on it. [emphasis added]

 

At first glance, the recital seems to contradict the ruling in Coyote System. The wording of the recital seems to follow the approach the Court adopted in Cyanado and like that judgment deals with the question of knowledge. We have noted earlier, the Court’s sidestep in this case, to talk about control. The recital says nothing about control and is therefore not inconsistent with the approach in Coyote System.  Of course, this means that there is no reference to “control” in the text of the DSA because Article 6, like its predecessor Article 14, is silent on the point. It is far from clear, however, that the change in wording in the recital was intended to mark a change in meaning from Article 14 resulting in an expansion of the scope of immunity. Rather it seems an intention to align the DSA with the case law on Article 14 e-Commerce Directive. Presumably, there will be much litigation on this point as well as the linked question as to where the boundary between control and “mere categorisation and indexation of information” [para 112].


Thursday, 28 May 2026

Amazon, systemic risk, and the Digital Services Act: What the General Court did and did not decide

 



 

Catalin Gabriel Stanescu, Associate Professor of Private Law at the University of Southern Denmark. His research focuses on consumer law, digital regulation, financial vulnerability, and the political economy of private law.

 

Photo credit: David Dixon, via Wikimedia Commons

 

The DSA Observatory recently published a thoughtful post on the General Court’s judgment in Amazon v Commission, which rejected Amazon’s argument that it should not have been listed as a ‘very large online platform’ (VLOP) under the Digital Services Act (DSA), and, in doing so, critiqued a working paper of mine on ‘systemic risk’ under the Digital Services Act. For me, it was a valuable engagement. The judgment does influence how arguments about systemic risk under the DSA can be framed. However, it does not support the broader claim that a financial-law analogy about the definition of ‘systemic risk’ has been displaced. When read carefully, Amazon takes a narrower approach: it rejects one specific application of the financial analogy, while preserving a more structural comparison between financial supervision and the DSA’s systemic-risk regime.

My paper’s central claim was not that the DSA should be read as banking law in another guise. Nor was it that systemic risk under the DSA must be defined by interbank contagion or by the existence of a closed system of interconnected undertakings. What I proposed was that the DSA relocates into digital governance a supervisory rationality already familiar from EU financial law: a mode of regulation built around ex ante risk assessment, differentiated obligations for systemically significant actors, and a recalibrated proportionality analysis where institutions are acting under conditions of complexity, uncertainty, and potentially large-scale harm. That remains, in my view, the right level at which to compare the two regimes.    

The General Court’s judgment, however, establishes an important limitation. Amazon contended that marketplaces could not generate “systemic” risks because, unlike financial institutions, they do not form part of an interconnected system. In paragraph 69, the Court summarized Amazon’s submission that marketplaces are not interdependent, do not constitute a system, and therefore cannot give rise to systemic risks in the manner of financial institutions. The Court rejected this argument in paragraph 70. It held that the DSA is not concerned with systemic risks posed by marketplaces due to their participation in a “system” in that sense. Instead, the DSA aims to mitigate systemic risks to society as a whole, insofar as those risks may affect a significant portion of the European Union’s population. Consequently, the Court found that the independence of marketplaces from one another does not prevent them from generating some of the risks identified in Article 34(1) DSA (ie the risks which VLOPs are obliged to assess).

This is a significant point. Under the DSA, interconnectedness in the financial-law sense is not a necessary criterion for defining systemic risk. Instead, the Court places decisive emphasis on reach, scale, and disproportionate societal impact. This approach is evident not only from paragraph 70, but also from the Court’s reliance on recitals 75 and 76 DSA, which highlight the reach of very large online platforms, their role in facilitating public debate and economic transactions, and the potential for disproportionate impact once they reach a significant share of the Union’s population. The same reasoning appears later when the Court notes that marketplaces above the Article 33 DSA threshold for designating VLOPs may pose risks to society that differ in scale and impact from those posed by smaller platforms. On this point, the Observatory’s interpretation is correct: Amazon shifts the analysis away from a narrow contagion model.

What does not follow, however, is the stronger conclusion that the judgment rejects the relevance of financial systemic-risk thinking altogether. The Observatory interprets Amazon as attributing a more autonomous meaning to systemic risks under the DSA and as introducing a break with the reliance on financial systemic-risk regulation as a reference point. I believe this interpretation overstates the case. The Court rejected Amazon’s specific application of the analogy, but did not assert that the DSA lacks structural affinity with systemic-risk governance as developed in other areas of EU law.

This distinction is important because the DSA’s regime retains a recognizably systemic-risk structure.

First, the regime is actor-specific. In the present context, Articles 34 to 43 DSA apply only to platforms designated as VLOPs, while more broadly it also includes very large online search engines (VLOSEs). The Court accepts this differentiation as resting on the legislative judgement that platforms of such scale may generate risks with a disproportionate impact in the Union. In paragraphs 52 and 53, the Court summarizes the obligations imposed on VLOPs: risk assessment, potential adaptation of service design, independent audit, profiling-free recommender options, advertising repositories, data access for researchers, internal compliance functions, transparency reports, and supervisory fees. In paragraphs 63 to 65 and 77, the Court accepts the legislative premise that VLOPs may cause societal risks that differ in scope and impact from those caused by smaller platforms, and that marketplaces above the threshold may give rise to the risks listed in Article 34(1). This is not merely a semantic distinction regarding the meaning of what qualifies as “systemic.” It is a sorting mechanism that imposes heightened obligations on actors deemed systemically significant due to their scale. This feature is central to the financial-law genealogy discussed in my paper.

Second, the regime is preventive. The obligations upheld in Amazon are not limited to sanctioning completed infringements, but are intended to identify, assess, and mitigate risks before harm occurs. The Court’s summary of Articles 34 to 43 confirms this preventive orientation. This is why the financial-law comparison remains relevant at the level of supervisory logic. In both contexts, the law acts proactively rather than waiting for collapse or completed harm before intervening. My paper identified this preventive approach as a central element of systemic-risk governance in EU law, both in finance and under the DSA. Nothing in Amazon contradicts this analysis.

Third, and most importantly, Amazon strongly supports the argument that systemic-risk governance is accompanied by a relatively flexible form of proportionality review. The Court explicitly recognizes that Article 33(1), by subjecting VLOPs to Articles 34 to 43, interferes with the freedom to conduct a business under Article 16 of the Charter, as these obligations may entail significant costs, substantial organizational effects, and complex technical solutions. Nevertheless, the Court upholds this interference because the legislature possesses broad discretion when making political, economic, and social choices and undertaking complex assessments. In this context, only measures that are “manifestly inappropriate” can be deemed unlawful. The Court further emphasizes that the freedom to conduct a business is not absolute and must be balanced with the objective of ensuring a high level of consumer protection under Article 38 of the Charter. It concludes that the legislature did not commit a manifest error in treating marketplaces above the threshold as capable of generating the risks identified in Article 34(1), and that Article 33(1) DSA was not shown to be manifestly inappropriate for achieving the Regulation’s objectives.

This aspect of the judgment is at least as significant as paragraph 70. Even if one accepts that DSA systemic risk is not linked to interconnectedness in the financial sense, the Court’s reasoning still supports a model of anticipatory, differentiated, and intrusive supervision, constitutionally sustained through broad institutional discretion and limited judicial review. This is precisely the dimension of systemic-risk governance that my paper sought to highlight. EU financial-law jurisprudence exhibits the same pattern: preventive intervention, differentiated obligations for systemically significant actors, and a proportionality review tailored to technical complexity and predictive judgment. At this level, the comparison is not only valid but also illuminating.

The core disagreement with the Observatory is not whether Amazon alters the analytical landscape –it does – but rather concerns the appropriate level of abstraction for comparison. If the argument were that DSA systemic risk merely replicates bank-contagion logic, the judgment would be difficult to defend. However, that was not my position. My argument is that the DSA adopts a macroprudential style of governance: it identifies a subset of actors whose scale enables them to cause significant harm, subjects them to enhanced due diligence and supervision, and justifies these obligations through a preventive public-interest rationale. Amazon does not undermine this claim, it only refines it.

One further point should be noted. The judgment did not resolve all interpretive questions regarding Article 34 DSA. Specifically, it did not explicitly determine whether the list of risks to be assessed, set out in Article 34(1), is exhaustive. While the Observatory may reasonably infer from certain passages that this is the case, such an inference does not constitute a definitive holding. The repeated references to the risks “referred to in Article 34(1)(a) to (d)” are consistent with the narrower view that these were the risks relevant to the case at hand. On this issue, a cautious approach remains advisable.

In my view, the most accurate reading of Amazon is as follows. The judgment narrows the conceptual overlap between financial and digital systemic risk by rejecting interconnectedness as a necessary definitional criterion under the DSA. However, it reinforces the structural overlap at the level of governance. Under the DSA, systemic risk continues to justify a regime that is differentiated, preventive, supervisory, and constitutionally sustained through a broad margin of institutional discretion. Therefore, the financial analogy I proposed remains useful, provided it is applied at the appropriate level of abstraction. The DSA is not banking law for platforms, but it is law crafted in a distinctly macroprudential register.

 

Friday, 20 February 2026

Digital Services Act: summary and links

 


Professor Steve Peers, Royal Holloway University of London

Photo credit: Animated Heaven, via Wikimedia Commons

 

Introduction

The EU’s Digital Services Act (DSA) sets out rules for regulating online platforms and search engines. The following sets out a summary of what the Act does, and links to key resources. It draws upon (and updates) a blog post on the Commission’s first non-compliance decision under the Act. This post will be updated.

 

Overview of the Digital Services Act

The DSA contains rules that govern online platforms generally, regardless of size, but its most prominent rules concern a special regulatory regime for the biggest platforms, defined as ‘very large online platforms’ (VLOPs) and ‘very large online search engines’ (VLOSEs), which subjects them to greater regulation. The Act gives the EU Commission power to designate such platforms and search engines (on the basis that 10% of the EU population visit them monthly) and to enforce the provisions of the DSA against them.

The Commission’s list of designated VLOPs and VLOSEs includes US companies (including Meta, X, Google, LinkedIn), and also Chinese companies (AliExpress, TikTok, Temu, Shein), EU companies (Booking.com, Zalando, and two porn sites), and a Canadian site, Pornhub. Overall, nearly half of the companies designated as operating VLOPs and VLOSEs are non-American (although some of the American companies operate more than one platform).

For VLOPs, enforcement of the DSA involves a number of measures, including requests for information, a start of an investigation into possible breach of the Act, a preliminary finding of a breach, and a final decision finding a breach – which can result in a fine (of up to 6% of worldwide annual turnover) and orders to change practices. A VLOP or VLOSE can also agree avoid a fine by agreeing binding commitments to change its practices with the Commission (in effect, a settlement) before it reaches a final decision. If a finding of breach is not complied with, the Commission can impose very high fines – up to 5% of worldwide annual turnover per day.

The Act imposes a very high threshold before a ban can be imposed against a platform – essentially a refusal to remove illegal content, with additional safeguards including involvement of a court.

The case law has not yet fleshed out the relationship between the DSA and Member States’ laws on overlapping issues, or clarified whether there can be private enforcement of the DSA (ie individuals challenging the VLOPs and VLOSEs in court for breach of the Act, rather than the Commission enforcing it) in parallel.

Substantively, the Act’s requirements on VLOPs and VLOSEs (in its Articles 33-43) start with risk assessment: they must ‘diligently identify, analyse and assess any systemic risks in the Union stemming from the design or functioning of their service and its related systems, including algorithmic systems, or from the use made of their services’. Systemic risks are further defined as including ‘dissemination of illegal content through their services’, ‘negative effects’ upon various human rights, ‘actual or foreseeable negative effects on civic discourse and electoral processes, and public security’, and ‘actual or foreseeable negative effects in relation to gender-based violence, the protection of public health and minors and serious negative consequences to the person’s physical and mental well-being’.  

Very large platforms and search engines are also obliged to (as further defined): mitigate these risks; comply with a decision requiring a response to a crisis; perform independent audits; offer a recommender system not based on profiling, at least as an option; make public a repository of advertising data; provide access to their data to researchers; explain their algorithms to regulators; establish independent compliance bodies; provide further public data on their operations; and pay an annual supervisory fee to the EU Commission.

 

The DSA in the EU courts

Challenges to designation

Amazon, Zalando and several porn sites have challenged their designation as VLOPs.

-          Zalando lost its challenge in the EU General Court in September, but has appealed to the EU’s Court of Justice (appeal pending)

-          Amazon also lost its challenge in the EU General Court against designation as a VLOP, and has appealed to the CJEU (the Commission has cross-appealed)

-          Amazon had won an interim measures ruling in this case – delaying its obligation to publish information about its advertisers – but that interim measure was overturned by the Court of Justice, following a successful appeal by the Commission)

-          The porn companies’ legal challenges to their designations as VLOPs are still pending (see the summary of the arguments made by Pornhub, XNXX and XVideos; a challenge by Stripchat is also still pending even though the Commission has dropped its designation as a VLOP)

-          the porn companies’ applications for interim measures as regards publishing advertisers’ information have been dismissed (see the General Court orders re Pornhub and XVideos, and the failed appeals to the Court of Justice as regards Pornhub and XVideos)  

Summary of the Amazon judgment

Amazon argued that the entire system of special rules for VLOPs in the DSA was invalid, because it violated a number of human rights set out in the EU Charter of Fundamental Rights. All of these arguments were rejected by the EU General Court (now subject to appeal).

First of all, the Court rejected the argument that the VLOP regime breached the freedom to conduct a business (Article 16 of the Charter). In the Court’s view, although the regime interfered with the freedom to conduct a business, because it imposed significant costs on VLOPs and also had a considerable impact on their organisation or required complex technical solutions, that freedom was not absolute, and the interference with it was justified. According to Article 52(1) of the Charter, limitations on Charter rights have to be prescribed by law, have public interest objectives, respect the essence of the right and be proportionate. Here the limits were admittedly prescribed by law (being set out in the Act) and respected the essence of the right (as Amazon could still carry out its core business); Amazon instead argued mainly that the limits were disproportionate, as online shops did not present systemic risks, the objectives could be satisfied by less onerous means, and the costs were significant. However, the Court believed that there was a systemic risk of illegal content in online marketplaces; other means of designating VLOPs were not necessarily more proportionate; making advertising repositories open to the public was justified in the interests of consumer protection; and the arguments about economic impact made by Amazon as regards recommender systems, researchers’ access to data and advertiser repositories were unconvincing.

Secondly, Amazon’s argument that its right to property was infringed (Article 17 of the Charter) was dismissed at the outset, as it had not identified any of its property rights that were affected by the DSA: an administrative burden did not constitute interference with a property right. Thirdly, the Court rejected the argument that the VLOP regime breached the general right to equal treatment (Article 20 of the Charter), by treating larger companies differently from smaller ones, on the grounds that larger companies presented bigger risks.

Fourthly, Amazon’s arguments about freedom of expression (Article 11 of the Charter) were rejected too. This argument was only made as regards applying the DSA rules on recommender systems to Amazon. On this point, the Court reiterated that the Charter freedom of expression rules must be interpreted consistently with the freedom of expression set out in Article 10 of the European Convention on Human Rights (ECHR), referring also to the case law of the European Court of Human Rights (ECtHR) – ie the US First Amendment does not apply to the regulation of a company doing business in the European Union. The Court did not see how the freedom of expression of third-party sellers might be affected by the DSA rules, but it accepted that Amazon’s freedom of expression was limited by having to offer a recommender system not based on profiling.

However, limitations of the right could be justified: the limitation here was prescribed by law; it did not affect the essence of the right (as Amazon could still offer a profiling-based recommender system as an option); it had an objective of general interest (consumer protection); and it was proportionate by only requiring the offer of one non-profiling based recommender system as an option – taking account of ECtHR case law that allows more interference with commercial expression than political expression.

Finally, Amazon complained about a breach of the right to privacy (Article 7 of the Charter). This was a remarkable thing for a company with a business model based on surveillance of its customers to argue about, but the Court considered its arguments seriously nonetheless. Again it followed the ECtHR case law on the corresponding rule (Article 8 ECHR), which states that businesses could invoke the right to privacy. Here the argument concerned the DSA rules on ad repositories and researchers’ access to data. Again the EU court agreed that the DSA interfered with the right, but ruled that it could be justified: it was prescribed by law, did not infringe the essence of the right, and complied with the principle of proportionality, particularly because of the limits built in to the obligations (for instance, no obligation to disclose the personal data of advertising recipients, or about the success of advertising; controls on which researchers can access the data).

Regulation fees

The Commission’s decisions on fees for regulation (for 2023) have also been challenged. These challenges were all successful in the EU General Court (see the judgments as regards Tiktok and Meta), although the Commission has appealed both the Tiktok and Meta judgments to the Court of Justice (appeals pending).

In the meantime, Tiktok, Meta and Google have brought a further round of legal challenges (all still pending) to the regulation fees imposed for 2024.

Non-compliance decision

X, X.AI and Elon Musk have challenged the December 2025 non-compliance decision against X.

Infringement actions

The Commission is suing Spain for non-enforcement of its obligations to apply the DSA at national level.

 

Enforcement of the DSA

Non-compliance decisions

So far the EU Commission has adopted one final decision  of non-compliance, against X in December 2025, following its preliminary findings in July 2024

This decision includes a fine to enforce the DSA for the first time: €120 million for three breaches of the Act by X. It concerns certain issues, namely deceptive practices as regards X’s ‘blue ticks’,* researchers’ access to data, and the repository of advertisers.

The Commission has not yet made a final decision – or even a preliminary finding – as regards other issues involved in its opening of proceedings against X, namely the dissemination of illegal content and the effectiveness of rules against disinformation. In January 2026, the Commission opened proceedings against X as regards its recommender systems and ‘nudification’ apps.

Other enforcement actions

Other Commission enforcement actions under the DSA include:

-          The Commission has accepted binding commitments from AliExpress on various issues, but at the same time also adopted a preliminary finding that its risk assessment as regards illegal products was insufficient;

-          It has opened proceedings against porn sites for inadequate protection of children;

-          It has adopted a preliminary finding that Meta (Facebook and Instagram) is in breach as regards researchers’ access to data, and as regards flagging illegal content and allowing for appeals against content moderation decisions; an investigation as regards deceptive advertising, political data, and misinformation on Meta is still underway; and

-          It has adopted a preliminary finding that Temu has breached the DSA as regards illegal products, and an investigation continues as regards other issues

- It has accepted a commitment from TikTok to suspend the ‘TikTok Lite’ programme, which was apparently designed to (further) encourage social media addiction by children, having used the threat of issuing an intention to impose interim measures under the DSA earlier on in this case. A new decision, following a preliminary finding, accepts further commitments regarding information on advertisers The Commission has also adopted a preliminary finding against TikTok as regards researchers’ access to data, a preliminary finding of breach as regards addictive design, and further investigations against Tiktok are still underway.

- It has begun investigation of Shein for illegal content (child sex dolls), recommender systems and addictive design

Wednesday, 10 December 2025

Image Rights and False Claims, Data Protection and Intermediary Immunity: the case of Russmedia

 


 

Lorna Woods, Professor Emerita, University of Essex

 

Image credit: US Department of Defense

 

This Grand Chamber judgment of the Court of Justice in X v Russmedia Digital and Inform Media Press (Case C-492/23) handed down on 2 December 2025 concerns the scope of data protection rights and intermediary immunity in the context of the non-consensual use of someone’s image.  The judgment identifies:

- when someone has responsibilities under the GDPR,

- the relationship between those regulatory obligations and intermediary immunity, and

- the steps an data controller could take to satisfy those GDPR obligations.

 

It has been described as reshaping the obligations of online operators in the EU, while others have questioned how far the points in the judgments may be generalised to other situations.

 

Judgment

 

The Facts

 

Russmedia owns an online marketplace on which advertisements may be published. An unidentified user posted an advertisement falsely representing X as offering sexual services. The advert included X’s photographs (though there is no suggestion that these were intimate images) and phone number, all without her consent. Once notified, Russmedia removed the advert within an hour but the advertisement had been shared across several third party websites and remained accessible. X sued in the national courts in respect of her image rights, rights to reputation and data protection rights. The Romanian courts struggled with the question of whether Russmedia could claim the benefit of intermediary immunity (under the e-Commerce Directive (Directive 2000/31), provisions now replaced by the Digital Services Act (DSA)) and the extent of the obligations under the GDPR.

 

Is Russmedia subject to Obligations under the GDPR?

 

Obligations under GDPR arise when (1) personal data are (2) processed by (3) a data controller.

 

The CJEU commenced its analysis by noting the the information contained in the advert about X was personal data for the purposes of the GDPR and moreover that claims about a person’s sex life (implied in the advert) constituted “sensitive” personal data as protected by Article 9 GDPR, and that remained the case whether or not the claim was true.  Classification of the data as special category data means that there is a higher threshold to show lawful processing of those data. 

 

The Court further noted that “the operation of loading personal data on a webpage constitutes processing” for the purposes of the GDPR (para 54) and therefore covered the publication of the advert.

 

While this puts the advert within the scope of the GDPR, its obligations apply to data controllers and processors, so the question was whether, given Russmedia had no control over the content of the advert, was it a controller or joint controller? The Court reiterated previous jurisprudence to say (para 58) that:

 

any natural or legal person who exerts influence over the processing of such data, for his or her own purposes, and who participates, as a result, in the determination of the purposes and means of that processing, may be regarded as a controller in respect of such processing.

 

It noted also that there may be more than one entity which is a controller in respect of processing – this is the idea of joint controllers, although they may not have equal responsibility depending on the facts (para 63).  Joint decision making is not necessary for there to be joint controllers.

 

While the test for “controller” requires that the person processing the data does so for their own purposes, the Court added that this could include the situation “where the operator of an online marketplace publishes the personal data concerned for commercial or advertising purposes which go beyond the mere provision of a service which he or she provides to the user advertiser”  (para 66).  The Court in this case pointed to the fact that the terms of use give Russmedia “considerable freedom to exploit the information  published on that marketplace” including “the right to use published content, distribute it, transmit it, reproduce it, modify it, translate it, transfer it to partners and remove it at any time” (para 67). Russmedia is therefore not publishing solely on behalf of the user placing the advert. The Court also noted that Russmedia make the data in the advert accessible, allows the placing of anonymous adverts and sets the parameters for the dissemination of adverts (likely to contain personal data).

 

As a result of finding that the advert publishing platform was a joint controller the GDPR obligations bite in relation to the advert and must be able to demonstrate that the advert is published lawfully, which includes the requirement for consent for sensitive data (para 84 and 93) and the requirement for accuracy.  The CJEU notes that once published online and accessible to any Internet user, such data may be copied and reproduced on other websites, so that it may be difficult, if not impossible, for the data subject to obtain their effective deletion from the Internet.  The adds to the seriousness of the risks facing the data subject.

 

The GDPR also requires the implementation of technical and organisational measures – and this should be considered in the design of the service so that such data controllers can identify adverts containing sensitive data before they are published and to verify that such sensitive data is published in compliance with the principles of the GDPR (para 106).  Further, the controller must ensure that there are safety measures in place so that adverts containing sensitive data and not copied and unlawfully published elsewhere (para 122).

 

Are the GDPR Obligations Affected by Intermediary Immunity?

 

While the immunity provisions in the e-Commerce Directive are far-reaching, the e-Commerce Directive specified that it was not to apply to the Data Protection Directive (the legislation in  force at the time the e-Commerce Directive was drafted) and that included the immunities; the Court concluded that this meant the e-Commerce Directive could not interfere with the GDPR. It also specified that GDPR requirements here cannot be classified as general monitoring (which is prohibited by the e-Commerce Directive (and now the DSA)).

 

 

Conclusions, Implications and Questions

 

The ruling in this case does not match existing industry practice. It is not a bolt out of the blue, however, but builds on existing jurisprudence (eg Fashion ID (Case C-40/17)).  While the obligations required of Russmedia in this case may indicate, to some, a landmark shift in the Court’s approach, the judgment does rely on the specific facts in the case and, specifically, the point that “sensitive” data, which effectively requires explicit consent, is in issue. In principle, this could be relevant to other forms of sensitive content, notably non-consensual intimate images (NCII). Certainly, it re-emphasises data protection as a route for victims’ redress, if not preventing harm in the first place.

 

The ruling clarifies that a range of activities typically carried out by platforms - structuring, categorizing, and monetizing user content, can amount to determining “the purposes and means of processing personal data”, the test for responsibility as a controller under the GDPR (article 4 GDPR). In taking this approach, it differed from the Opinion of its Advocate-General (AG’s Opinion, para 120).  The Court noted that the definition of controller in the GDPR is broad – and this is to support the protection of individuals’ fundamental rights to privacy and data protection. Once a body is a controller, that body must be able to demonstrate compliance with the data protection principles, and take appropriate technical and organisational measures to ensure data processing is carried out in accordance with the GDPR. 

 

Here, some of the points that the Court relied on to determine that Russmedia was a joint controller could well be relevant to other services and not just online marketplaces. For example, many sites have broad terms of service similar to those the Court highlighted here; other services also allow anonymous posting and a key feature of many services is the making available of that content for advertising revenue purposes, as well as controlling how content is promoted. (Note the decision of the court in YouTube and Cyanado (Joined Cases C-682/18 and C-683/18), which suggested that automated content curation did not mean that a service is not neutral, is not directly relevant here as it relates to the conditions for maintaining intermediary immunity – and see Russmedia, AG’s Opinion, para 155)  It is unclear how many of these criteria need to be present for a service to constitute a controller in relation to the personal data in third party content it publishes (though the Court seems to list them as alternatives, suggesting any of them would suffice), or whether less far-reaching terms of service may be sufficient to stop a platform being a joint controller.  Where these conditions are satisfied, its impact need not be limited to advertising but to organic content containing third party personal data too.

 

The Court’s confirmation that the clear wording of the e-Commerce Directive, excluding the Data Protection Directive (the predecessor legislation to the GDPR) from its scope, meant that an intermediary cannot escape its own data protection responsibilities does not affect immunity from liability in respect of unlawful content.  Note that this decision was based on the wording of the e-Commerce Directive. This language has not been carried over to the DSA, which is expressed to operate without prejudice to, inter alia, the GDPR. It is not clear if or how this would change the Court’s interpretation. Immunity provisions from the e-Commerce Directive have been carried across to the DSA (albeit with a “carve out” in respect of consumer law in Article 6(3) DSA). While the EDPB has published guidance on the interplay of the GDPR and the DSA, it has looked at the question of the impact of the DSA requirements on data protection rather than the impact of data protection on the DSA.

 

The judgment suggests that services should design checks into their services to ensure compliance with the data protection obligations including pre-publication checks as to whether sensitive data is included and to check the identity of the person posting the material. Of course, while some sorts of posts (eg NCII) clearly constitute sensitive personal data, the outer edges of this category might not be clear cut. The Court here noted that the category should be interpreted broadly (para 52). It could be that some of the obligations could be passed on to the user uploading the advert through terms of service, though this might be capable of being abused by some users.  Further, the CJEU expects the site to prevent third party scraping so far as is possible – the judgment does not introduce strict liability in this regard.  What technical measures would be sufficient in practice remains uncertain.   This is very different from the reactive response required to maintain immunity under the e-Commerce Directive – and which has been the dominant framing until now. Assuming the position on immunity does not change, services may have to implement new systems, probably including automated tools and may ultimately affect choice of business model for some services.

 

There are questions about how this ruling impacts the DSA. How does a pre-check system differ from general monitoring. General monitoring is prohibited under Article 8 DSA (though specific monitoring is not)? The CJEU stated that systems to ensure GDPR compliance could not be classified as “general monitoring” (para 132) – but did not explain this statement any further. There is an argument to say that all content will need to be scanned to identify that which contains sensitive personal data – and by contrast to checking against a database of known CSAM images, for example, which might be considered specific monitoring, this is a more open ended obligation. It is unclear whether there are other routes to pre-check which do not involve content scanning.  The requirements to check whether the person posting the personal data is the person to which the data relates (or is otherwise lawfully processing) may make, for example, anonymity difficult to maintain and it is unclear what level of identity verification would be acceptable.  There are also questions about how this system of pre-checks affects the neutrality of the platform and consequently the possibility for the platform to claim immunity (in respect of other claims relating to the content) under Article 6 DSA.

 

The position in the UK may be slightly different, however. Section 6(1) European Union (Withdrawal) Act provides that decisions of the CJEU post-dating 31 December 2020 do not bind UK courts although they may have regard to such judgments. The provisions which would have had the effect of removing the status of binding precedent from decisions of the CJEU made on or before that date have now not been brought into force (but they remain on the statute book), as the Labour Government revoked the relevant commencement regulations.  Furthermore, old case law from the Northern Irish courts (pre-dating Brexit), CG v. Facebook, suggested the the e-Commerce Directive (the relevant law at the time) could apply to data protection claims.