Showing posts with label EU General Court. Show all posts
Showing posts with label EU General Court. Show all posts

Monday, 7 September 2026

How the New Appeal Filtering Mechanism in the EU Courts Affects Judicial Review of CSDP Missions


 


Antje Kunst*

Photo credit: Lucalupe, via WikimediaCommons

 

Introduction

In 2024, a new procedural requirement was introduced whereby appeals against General Court judgments delivered in proceedings brought under Article 272 TFEU (jurisdiction to rule on arbitration clauses in contracts concluded by or on behalf of the EU), are subject to an appeal filtering mechanism established by Article 58a of the Statute of the CJEU.

Since 1 September 2024, parties seeking to appeal a General Court judgment in an action brought under Article 272 TFEU must demonstrate that their appeal raises ‘an issue that is significant with respect to the unity, consistency, or development of Union law’. By contrast, no such admissibility requirement applies to appeals against judgments of the General Court in actions brought under Article 263 TFEU (actions for annulment), which may be pursued by staff seconded to Common Security and Defence Policy (CSDP) missions or in actions brought under Article 270 TFEU (staff cases).

The implications of the appeal filtering mechanism are particularly significant for staff serving in CSDP missions as contracted staff. In the absence of a EU Staff Regulations framework comparable to that applicable to ordinary EU civil servants, such staff cannot bring employment-related disputes under Article 270 TFEU. Instead, they must rely on an arbitration clause contained in their employment contracts, with Article 272 TFEU providing the procedural basis for bringing such disputes before the EU courts.

This blog argues that extending the Article 58a appeal filter to cases brought under Article 272 TFEU does more than reduce the workload of the Court of Justice. The reform further restricts, for contracted staff serving in CSDP missions the opportunities to obtain judicial review by the Court of Justice, in an area where access to judicial review is already subject to constraints, including those arising from Article 275  TFEU and Article 24(1) TEU.

The amendment therefore raises a broader constitutional question: can the  objective of reducing the Court’s workload legitimately come at the expense of effective judicial protection and meaningful access to judicial remedies for contracted staff serving in CSDP missions? The reform also raises concerns about equal treatment. It creates a distinction between, on the one hand ordinary EU civil servants and seconded staff serving in CSDP missions who have the possibility of appealing to the Court of Justice, and, on the other hand, contracted staff, who are denied equivalent access to appellate review.

Key Aspects of the New Requirement

Pursuant to the 2024 amendment to Article 58a of the Statute an appeal against the General Court in proceedings concerning ‘the performance of a contract containing an arbitration clause, within the meaning of Article 272 of the [TFEU]’ may proceed only if the Court of Justice first grants leave to appeal.

The admissibility threshold for appeals by contracted staff serving in CSDP missions is demanding. An appellant must demonstrate that the appeal raises ‘an issue that is significant with respect to the unity, consistency or development of Union law’. It is therefore no longer sufficient to argue that the General Court committed an error in its interpretation of the law or assessment of the facts in the individual case. Instead, the appellant must establish that the issue extends the interests of the individual litigant and demonstrate why its resolution matters for the EU legal order as a whole.

The appeal therefore requires a form of ‘second-level’ justification: first, the appellant must identify alleged errors of law in the judgment, second, and critically, the appellant must explain why that error raises an issue significant for the unity, consistency or development of Union law. (see the Court Order of 29 April 2025 in SC v Eulex Kosovo (Case C-881/24), the first case to which the new appeal filter was applied). In this respect the test is comparable to the approach of the UK Supreme Court which filters appeals according to whether they raise an ‘arguable point of law of general public importance’.

The Court of Justice determines whether the conditions laid down in Article 58a of the Statute are satisfied by means of a reasoned order rather than a judgment. Where leave to appeal is refused, the judgment of the General Court becomes final, thereby bringing the litigation to an end without substantive review by the Court of Justice.

What raises a wider issue?

In employment disputes involving contracted staff of CSDP missions, appellants must identify a legal issue that extends beyond the particular employment relationship or factual circumstances of the CSDP mission concerned. This requirement may be met where an appeal raises, for example, a question  of EU law that could affect numerous contracted staff across different CSDP missions; where existing case-law is uncertain or inconsistent; or where clarification by the Court of Justice would contribute to  a coherent and consistent body of EU law applicable to all staff serving in the Union.

An appellant might be able to convince the Court that its interpretation of a fundamental right in a CSDP employment dispute could have implications beyond that specific context and provide guidance for future disputes in other areas of EU  law, such as EU restrictive measures, public procurement, competition or migration and asylum.  This may include disputes involving other EU bodies, missions or other actors subject to EU law. (see in this respect paras. 22 and 24 of the Court Order 29 April 2025 in SC v Eulex Kosovo (Case C-881/24))

Furthermore, an appellant might be able to successfully argue that the case raises a question of principle concerning the scope of the Court’s jurisdiction under Articles 24 (1) TEU and 275 TFEU, in particular whether and to what extent the Common Foreign Security Policy (CFSP) limitations on judicial review apply to employment-related decisions in CSDP missions. This question could have implications beyond the individual dispute, including for comparable cases involving other CSDP missions, EU bodies, or categories of EU personnel. It could also have broader implications for the principle of effective judicial protection under EU law, particularly where the contested measure affects fundamental rights or other rights protected by EU law.

Rationale for an appeal filter related to decisions of Boards of Appeal

The appeal filtering mechanism was first introduced in 2019 for appeals brought before the Court of Justice against judgments of the General Court concerning decisions of the Boards of Appeal (BoAs) of certain EU offices and agencies.

The EU legislature focussed primarily on the EU agencies with powers over intellectual property rights, plant variety rights, chemicals regulation and aviation safety (EUIPO, CPVO, ECHA and EASA). The rationale was that decisions in these areas had already undergone administrative review by a specialised BoA and judicial review by the General Court, while a significant number of appeals were manifestly inadmissible or unfounded (see here).

In practice, this admissibility requirement has constituted a substantial threshold, with the Court of Justice permitting only a limited number of appeals to proceed beyond the initial filtering stage.

Rationale for an appeal filter related to Article 272 TFEU disputes

The 2024 extension of the Article 58a filtering mechanism to appeals concerning Article 272 disputes was justified primarily by considerations of judicial efficiency. The legislator’s rationale was that such disputes most frequently require the General Court to apply, to the substance of the dispute, the national law to which the arbitration clause refers. (see here) Such appeals would generally be less likely to raise issues of EU law.

A CSDP employment dispute is an atypical Article 272 TFEU dispute

A CSDP employment dispute will rarely require the application of national law (see  JF v EUCAP Somalia) and is not a typical Article 272 TFEU dispute. Disputes involving contracted staff of CSDP missions often involve mission-specific instruments, such as Standard Operating Procedures (SOPs) and Operation Plans (OPLANs), as well as the analogous application of certain provisions of the EU Staff Regulations (see the judgment in Montanari v Eucap Sahel Niger). They may also involve the application of general principles of EU law and fundamental rights to contractual disputes (see JF v EUCAP Somalia), as well as questions concerning the scope of the Court of Justice’s jurisdiction in the CFSP context (see H v Council and Others, even if a seconded CSDP staff case ). This makes it particularly important to ensure that restrictions on access to an appeal before the Court of Justice do not prevent the development of authoritative guidance on questions affecting 1300 civilian staff working in CSDP missions, especially since only contracted staff, and not their seconded colleagues, are required to seek permission to appeal when challenging General Court judgments.

Where the EU Staff Regulations do not apply to such staff, the case law has established that the applicable legal framework derives primarily from the employment contract and mission specific instruments such as SOPs, supplemented, where relevant, by the analogous application of certain provisions of the EU Staff Regulations as well as certain general principles of EU law and the Charter of Fundamental Rights, as illustrated by JF v EUCAP Somalia.

Precisely because the legal framework governing CSDP contracted staff remains fragmented and continues to evolve, there is a strong argument that effective appellate review is of particular importance in this area.

Moreover, an appeal to the Court of Justice is not necessarily merely a second level of review. It may provide an important opportunity for the Court to give authoritative clarification of unresolved jurisdictional and constitutional questions concerning the scope of judicial protection in the CFSP context.

Conclusion

The appeal-filtering mechanism introduced by Article 58a of the Statute of the Court of Justice places international contracted staff serving in CSDP missions at a significant disadvantage compared with other categories of EU personnel in terms of access to appellate judicial review. EU staff subject to the EU Staff Regulations may bring claims under Article 270 TFEU, while seconded CSDP staff can bring actions under Article 263 TFEU. By contrast, international contracted staff whose disputes fall under Article 272 TFEU face an additional – and potentially insurmountable – hurdle when challenging a General Court judgment before the Court of Justice.

This disadvantage is all the more significant because the legal framework governing employment within CSDP missions remains fragmented and continues to develop. Restricting access to the Court of Justice therefore risks limiting not only the right of individuals to effective judicial protection, but also the development of a coherent and authoritative body of case law on employment within CSDP missions.

The Court of Justice can do little to remedy the disadvantage created by Article 58a of the Statute itself; addressing this issue is a matter for the EU legislature that should not be delayed.

 

*Antje Kunst is an international lawyer and barrister of Garden Court North Chambers, admitted to the Bar of England and Wales, and the Bar of Berlin, advising and representing individuals in a wide range of matters related to fundamental rights within the CFSP and other fields including staff cases. She has appeared in numerous cases before both the Court of Justice and the General Court of the Court of Justice of the European Union.  She acted as Counsel for JF in JF v EUCAP Somalia, Case 194/20. She represents SC in SC v Eulex Kosovo, Case C-881/22, and obtained the Court Order of 29 April 2025.

 

Sunday, 7 December 2025

The Digital Service’s Act Main Character: the EU Commission finally fines X

 


 

Steve Peers, Professor of Law, Royal Holloway University of London

Photo credit: Animated Heaven, via Wikimedia Commons

 

Introduction

The EU’s Digital Services Act (DSA) was conceived before Elon Musk bought Twitter (soon renaming it X); but they were literally born simultaneously, with the DSA being published in the EU’s Official Journal on the same day that Musk completed his takeover. Since then, Musk’s behaviour running X (see my review of a book on the takeover and the aftermath) has exemplified many of the reasons why the EU (and other jurisdictions) contemplated regulating social media in the first place: in particular arguments about the legality of its content and the fairness of its algorithms.

A Twitter user coined the phrase ‘today’s main character’ to describe a poster who becomes the centre of attention for a day – usually due to an absurd or obnoxious post that prompts many negative responses. For the DSA, X has been its main character since its creation, with much of the public debate about the potential use of the Act focussing on how it might apply to the controversial social network.

This debate has now come to a head. Last week, following its preliminary findings back in July 2024, the EU Commission adopted a final decision imposing a fine to enforce the DSA for the first time: €120 million for three breaches of the Act by X. This initial decision is likely to impact upon the broader debate over the Act’s implementation, and – due to Musk’s influence in the current Trump administration – also play a role in the fast-deteriorating relations between the EU and the US.

This blog post first provides an overview of the DSA, then examines the legal issues arising from this specific enforcement decision, and concludes with an assessment of the broader context of this decision: the enforcement of the DSA more generally, and the relations between the EU and the USA.

 

Background: overview of the Digital Services Act

Adoption of the DSA

Although the critics of the EU Commission fining X are quick to argue that the EU is undemocratic, EU legislation needs the support of elected Member State governments and elected Members of the European Parliament (MEPs) to be adopted. In fact, the Act received unanimous support from Member States and a large majority of MEPs.  

In any event, even without the Act, Member States would likely regulate social media – perhaps more quickly and more stringently than the EU has applied the Act in some cases. And even if the whole EU ceased to exist, as Elon Musk and Russian government mouthpieces demand, those countries would still be regulating Big Tech, with national equivalents of the Digital Markets Act and the GDPR, for instance. Indeed, despite leaving the EU, the UK has its own national versions of all three laws: the Online Safety Act, the Digital Markets, Competition and Consumers Act, and the UK GDPR, which sits alongside the Data (Use and Access) Act. While UK regulators may be famously timid about enforcing these laws, Australia – a long way from the EU – was not dissuaded from banning under-16 year olds from social media.

But until Musk and his sympathisers manage to destroy the EU, we have the DSA. It contains rules that govern online platforms generally, regardless of size, but its most prominent rules concern a special regulatory regime for the biggest platforms, defined as ‘very large online platforms’ (VLOPs) and ‘very large online search engines’ (VLOSEs), which subjects them to greater regulation. The Act gives the EU Commission power to designate such platforms and search engines (on the basis that 10% of the EU population visit them monthly) and to enforce the provisions of the DSA against them.

While some claim that the DSA was adopted only to punish US tech firms, the list of designated VLOPs and VLOSEs includes also Chinese companies (AliExpress, TikTok, Temu, Shein), EU companies (Booking.com, Zalando, and two porn sites), and a Canadian site, Pornhub. Overall, nearly half of the companies designated as operating VLOPs and VLOSEs are non-American (although some of the American companies operate more than one platform).

Content of the DSA

For VLOPs, enforcement of the DSA involves a number of measures, including requests for information, a start of an investigation into possible breach of the Act, a preliminary finding of a breach, and a final decision finding a breach – which can result in a fine (of up to 6% of worldwide annual turnover) and orders to change practices. A VLOP or VLOSE can also agree avoid a fine by agreeing binding commitments to change its practices with the Commission (in effect, a settlement) before it reaches a final decision. If a finding of breach is not complied with, the Commission can impose very high fines – up to 5% of worldwide annual turnover per day.

While many critics of X excitedly demand that the EU Commission ban it, the Act imposes a very high threshold before a ban can be imposed – essentially a refusal to remove illegal content, with additional safeguards including involvement of a court. The case law has not yet fleshed out the relationship between the DSA and Member States’ laws on overlapping issues, or clarified whether there can be private enforcement of the DSA (ie individuals challenging the VLOPs and VLOSEs in court for breach of the Act, rather than the Commission enforcing it) in parallel.

Substantively, the Act’s requirements on VLOPs and VLOSEs (in its Articles 33-43) start with risk assessment: they must ‘diligently identify, analyse and assess any systemic risks in the Union stemming from the design or functioning of their service and its related systems, including algorithmic systems, or from the use made of their services’. Systemic risks are further defined as including ‘dissemination of illegal content through their services’, ‘negative effects’ upon various human rights, ‘actual or foreseeable negative effects on civic discourse and electoral processes, and public security’, and ‘actual or foreseeable negative effects in relation to gender-based violence, the protection of public health and minors and serious negative consequences to the person’s physical and mental well-being’.  

Very large platforms and search engines are also obliged to (as further defined): mitigate these risks; comply with a decision requiring a response to a crisis; perform independent audits; offer a recommender system not based on profiling, at least as an option; make public a repository of advertising data; provide access to their data to researchers; explain their algorithms to regulators; establish independent compliance bodies; provide further public data on their operations; and pay an annual supervisory fee to the EU Commission.

The DSA in the EU courts

Even before the first fine was imposed to enforce the DSA last week, its application in practice has been frequently litigated. First of all, Amazon, Zalando and several porn sites have challenged their designation as VLOPs. Zalando lost its challenge in the EU General Court in September, but has appealed to the EU’s Court of Justice (appeal pending). More recently Amazon also lost its challenge in the EU General Court against designation as a VLOP, but it still has time to appeal that judgment to the Court of Justice (Amazon had won an interim measures ruling in this case – delaying its obligation to publish information about its advertisers – but that interim measure was overturned by the Court of Justice, following a successful appeal by the Commission).

The porn companies’ legal challenges to their designations as VLOPs are still pending (see the summary of the arguments made by Pornhub, XNXX and XVideos; a challenge by Stripchat is also still pending even though the Commission has dropped its designation as a VLOP); their applications for interim measures as regards publishing advertisers’ information have been dismissed (see the General Court orders re Pornhub and XVideos, and the failed appeals to the Court of Justice as regards Pornhub and XVideos).  

Of these cases, the recent Amazon judgment has broad implications for the DSA as a whole, considered further below.

Secondly, the Commission’s decisions on fees for regulation (for 2023) have also been challenged. These challenges were all successful in the EU General Court (see the judgments as regards Tiktok and Meta), although the Commission has appealed both the Tiktok and Meta judgments to the Court of Justice (appeals pending). In the meantime, Tiktok, Meta and Google have brought a further round of legal challenges (all still pending) to the regulation fees imposed for 2024.

We can also now expect X to challenge the enforcement decision against it. (If it also requests interim measures, at least that aspect of the case will be decided soon).

Other enforcement of the DSA

In addition to the new decision enforcing the DSA against X, other Commission enforcement actions under the DSA have been adopted or are pending against VLOPs. Leaving aside requests for information (such as the one recently sent to Shein as regards reports of sales of child-like sex dolls):

-          The Commission has accepted binding commitments from AliExpress on various issues, but at the same time also adopted a preliminary finding that its risk assessment as regards illegal products was insufficient;

-          It has opened proceedings against porn sites for inadequate protection of children;

-          It has adopted a preliminary finding that Meta (Facebook and Instagram) is in breach as regards researchers’ access to data, and as regards flagging illegal content and allowing for appeals against content moderation decisions; an investigation as regards deceptive advertising, political data, and misinformation on Meta is still underway; and

-          It has adopted a preliminary finding that Temu has breached the DSA as regards illegal products, and an investigation continues as regards other issues

Finally, the Commission has been particularly active as regards TikTok. It has accepted a commitment to suspend the ‘TikTok Lite’ programme, which was apparently designed to (further) encourage social media addiction by children, having used the threat of issuing an intention to impose interim measures under the DSA earlier on in this case. A new decision, following a preliminary finding, accepts further commitments regarding information on advertisers – also a great irritant to Amazon and the porn companies, as can be seen in the litigation summarised above, as well as an issue in the X case, discussed below. TikTok has deadlines to implement the various commitments it has made, and there are specific powers to monitor whether it is complying with them under the DSA. The Commission has also adopted a preliminary finding against TikTok as regards researchers’ access to data, and further investigations against Tiktok are still underway.

Overall, it can be seen that to date the majority of enforcement actions under the DSA have been initiated against companies that are not American. Also, to date all the offers of binding commitments that have been accepted, in place of fines and enforcement orders, have come from Chinese companies. The potential of negotiating binding commitments instead of an enforcement order is, however, open to a VLOP based anywhere.  

 

The non-compliance decision against X

What did the decision address?

First and foremost, the non-compliance decision against X only concerns certain issues, namely deceptive practices as regards X’s ‘blue ticks’,* researchers’ access to data, and the repository of advertisers. The Commission complaint about ‘blue ticks’ is that they are a ‘deceptive practice’ banned by the DSA (note that this rule applies to platforms generally, not just VLOPs), in that they purport to indicate that an account has been verified, when it has not been. Under Musk, X has earned revenue from the blue ticks by selling them to anyone willing to pay for them, although the sale of the ticks, and the monetisation programme (ie giving money to X users whose posts lead to large numbers of reactions) are apparently not the subject of the non-compliance decision as such. The preference given to blue ticks in the X algorithm is not the subject of the decision as such either.

(*Disclosure: I applied for and obtained a ‘blue tick’ from Twitter prior to Musk’s purchase, when a proper verification system applied. I did not pay for the tick under Musk, and it was initially removed as a result. However, it was reinstated involuntarily – not at my request, and without my paying for it, or monetising my posts – as part of a process of reducing the social opprobrium of having a blue tick under Musk, in which the ticks were reinstated for some accounts. I initially hid the reinstated tick, but the facility to do that was removed. It remains there today; I have not used X since August 2024, due to my objection to Musk encouraging violent racial conflict in the UK, except for a handful of posts encouraging others to leave the platform. I have retained my account there to reduce the risk of anyone impersonating me, which has happened several times.)

The Commission has not yet made a final decision – or even a preliminary finding – as regards other issues involved in its opening of proceedings against X, namely the dissemination of illegal content and the effectiveness of rules against disinformation.

How can the decision be enforced?

X now has 60 days to inform the Commission about measures it will take to enforce the non-compliance decision as regards blue ticks. It has 90 days to submit an action plan to address the other two issues, and the Commission must respond to the action plan two months after that. In the event of non-compliance with the decision, as noted above the DSA gives the Commission the power to impose much higher fines. The method of calculation of last week’s fine is not explained in the press release. (The non-compliance decision itself may explain the calculation, but like most DSA decisions of the Commission, it has unfortunately not been made public; Article 80 of the DSA requires the main content of this decision to be published though)

If X challenges the decision in the EU courts, it can request an interim measures ruling suspending all or part of the decision; the EU General Court will decide on that (subject to appeal to the Court of Justice), as it has done in several DSA cases already, as detailed above. The final judgment of the EU courts can annul the Commission’s non-compliance decision in whole or part, and the DSA (Article 81) gives the EU courts unlimited jurisdiction to cancel, increase or reduce the fine. As for the collection of the fine (and any further fines that might be imposed on X for continued breach of the DSA), Article 299 TFEU sets out the process of enforcing fines imposed by EU bodies; although if X removes all its assets from the EU to the US, it might try to prevent collection by using US law that blocks the enforcement of foreign judgments on ‘free speech’ grounds (perhaps the SPEECH Act, although that concerns defamation; other routes may be available, or fresh routes adopted in light of the Commission decision).

This brings us neatly to the question of whether the non-compliance decision is arguably invalid on ‘free speech’ (or other) grounds.

Is the decision legal?

What are the legal issues as regards last week’s non-compliance decision? As noted above, the recent judgment in the Amazon case addresses two of the issues in the non-compliance decision (advertising repositories and access to data), while also addressing broader criticisms of the Act, some of which may be relevant if X challenges the finding as regards ‘deceptive practices’, or takes this opportunity to challenge the legality of the Act more generally (as Amazon did when challenging the legality of its designation as a VLOP; on such challenges, see Article 277 TFEU).

Amazon’s legal challenge to its VLOP designation did not advance the obviously untenable argument that fewer than 10% of the EU population uses Amazon monthly (conversely, Zalando and the porn sites are arguing about the calculation of the numbers). Rather, Amazon argued that the entire system of special rules for VLOPs in the DSA was invalid, because it violated a number of human rights set out in the EU Charter of Fundamental Rights. All of these arguments were rejected by the EU General Court.

First of all, the Court rejected the argument that the VLOP regime breached the freedom to conduct a business (Article 16 of the Charter). In the Court’s view, although the regime interfered with the freedom to conduct a business, because it imposed significant costs on VLOPs and also had a considerable impact on their organisation or required complex technical solutions, that freedom was not absolute, and the interference with it was justified. According to Article 52(1) of the Charter, limitations on Charter rights have to be prescribed by law, have public interest objectives, respect the essence of the right and be proportionate. Here the limits were admittedly prescribed by law (being set out in the Act) and respected the essence of the right (as Amazon could still carry out its core business); Amazon instead argued mainly that the limits were disproportionate, as online shops did not present systemic risks, the objectives could be satisfied by less onerous means, and the costs were significant. However, the Court believed that there was a systemic risk of illegal content in online marketplaces; other means of designating VLOPs were not necessarily more proportionate; making advertising repositories open to the public was justified in the interests of consumer protection; and the arguments about economic impact made by Amazon as regards recommender systems, researchers’ access to data and advertiser repositories were unconvincing.

Secondly, Amazon’s argument that its right to property was infringed (Article 17 of the Charter) was dismissed at the outset, as it had not identified any of its property rights that were affected by the DSA: an administrative burden did not constitute interference with a property right. Thirdly, the Court rejected the argument that the VLOP regime breached the general right to equal treatment (Article 20 of the Charter), by treating larger companies differently from smaller ones, on the grounds that larger companies presented bigger risks.

Fourthly, Amazon’s arguments about freedom of expression (Article 11 of the Charter) were rejected too. This argument was only made as regards applying the DSA rules on recommender systems to Amazon. On this point, the Court reiterated that the Charter freedom of expression rules must be interpreted consistently with the freedom of expression set out in Article 10 of the European Convention on Human Rights (ECHR), referring also to the case law of the European Court of Human Rights (ECtHR). The Court did not see how the freedom of expression of third-party sellers might be affected by the DSA rules, but it accepted that Amazon’s freedom of expression was limited by having to offer a recommender system not based on profiling.

However, limitations of the right could be justified: the limitation here was prescribed by law; it did not affect the essence of the right (as Amazon could still offer a profiling-based recommender system as an option); it had an objective of general interest (consumer protection); and it was proportionate by only requiring the offer of one non-profiling based recommender system as an option – taking account of ECtHR case law that allows more interference with commercial expression than political expression.

Finally, Amazon complained about a breach of the right to privacy (Article 7 of the Charter). This was a remarkable thing for a company with a business model based on surveillance of its customers to argue about, but the Court considered its arguments seriously nonetheless. Again it followed the ECtHR case law on the corresponding rule (Article 8 ECHR), which states that businesses could invoke the right to privacy. Here the argument concerned the DSA rules on ad repositories and researchers’ access to data. Again the EU court agreed that the DSA interfered with the right, but ruled that it could be justified: it was prescribed by law, did not infringe the essence of the right, and complied with the principle of proportionality, particularly because of the limits built in to the obligations (for instance, no obligation to disclose the personal data of advertising recipients, or about the success of advertising; controls on which researchers can access the data).

How does this judgment (noting that Amazon could still appeal it to the Court of Justice) apply to a legal challenge that X might make to last week’s non-compliance decision? First of all, the judgment in principle disposes of many arguments that X might make about two aspects of the non-compliance decision, as regards ad repositories and researchers’ access to data – although X might try different arguments, or contend that the nuances of its case are different.

While the main US response to the EU Commission’s decision has been to claim that the EU is engaged in censorship, note that Amazon did not even argue that the DSA rules on ad repositories or researchers’ access to data infringed freedom of expression, and remember that X is only being investigated for the dissemination of illegal content and the effectiveness of rules against disinformation. Obviously a freedom of expression argument might be made in respect of those issues, but, as noted above, X has not been subjected to a final decision or even a preliminary finding in respect of them.

Furthermore, according to the Amazon judgment, a VLOP challenging a Commission decision under the DSA can only challenge the validity of those parts of the DSA that are the legal basis for the decision made against them: so X cannot, at this point, specifically attack the validity of the DSA rules on risk assessment or risk mitigation, since there is no decision that it has breached them yet.  X can attack the validity of the DSA system for VLOPs generally, which includes the rules on risk assessment and risk mitigation. Although Amazon has already tried this and failed, X might try to argue its case differently; but it looks like a long shot, given that a non-compliance decision is inherently more narrowly focussed than designation as a VLOP.

Another key point to remember in this debate is that, as the Amazon judgment confirms, the human rights standards applied by the EU courts are those of the EU Charter, interpreted (where relevant) in light of the corresponding ECHR rights, and the ECtHR case law on those rights. The ECHR approach to rights differs in some respects from that of the US courts, arguably providing greater protection for the right to privacy (although not enough for Amazon to win its arguments on this point), but lesser protection for the right to free speech (allowing more leeway for interference with the right). But that is the nature of doing business in another jurisdiction. US law may take the view that (hypothetical) X user ‘ZyklonB1488’, regularly posting ‘Next year in Auschwitz!’ at Jewish people, has the right to set out his stall in the marketplace of ideas. But other legal systems may legitimately take the view that he does not.

Applying this to the sole remaining issue in the Commission’s non-compliance decision – the deceptiveness of X’s blue tick system – this is not directly connected to the content of what blue tick holders (still less anyone else) may post on X. Any effect on freedom of expression of last week’s decision is therefore marginal – although again, free speech arguments would be stronger as regards future decisions the Commission might make in respect of X as regards other issues still under investigation (or Meta – subject to some broadly similar investigations, as summarised above), especially because ‘illegal content’ is the one breach of the DSA that might (subject to many conditions and safeguards) lead to a ban on the whole platform. And to the extent that the non-compliance decision on blue ticks does interfere with freedom of expression, there is a strong argument that the interference is justified both on the ground of consumer protection (cf the scams featuring impersonations of consumer advocate Martin Lewis) and (as Article 52 of the Charter also provides for) on the ground of ‘the need to protect the rights and freedoms of others’ (ie anyone being impersonated, including myself!).

 

Context: enforcing the DSA

Last week’s decision is a definitive sign that the Commission is willing to enforce the DSA, even to the extent of adopting non-compliance decisions. The world is full of ‘light-touch’ regulators – perhaps one of Britain’s more unappealing exports. Usually, the Commission is not seen as such; but its obvious stalling on taking a final decision regarding X, for 17 months since its provisional findings, may have given the impression that – on the DSA, at least – the lion had turned pussycat.

The non-compliance decision should be viewed alongside with the Amazon judgment, which it likely also takes account of. VLOPs now know not only that the Commission is willing to act to enforce the DSA, but also that the EU courts (subject to possible appeal) back up at least some key provisions of the Act. Also, the recent judgment may explain TikTok’s simultaneous willingness to agree on its compliance with the ad repository rules; and the Commission’s willingness (again) to accept commitments, combined with the recent judgment, shows VLOPs that it may be less hassle to negotiate commitments with the Commission, rather than embark upon court action that is unlikely to succeed.  The context also includes a dog that did not bark: the Commission did not propose any amendment to the DSA (or the Digital Markets Act) in its recent proposal for an ‘omnibus’ bonfire of some provisions of EU tech laws.

Having said that, it is striking that the Commission is moving forward on non-compliance decisions and preliminary findings other than on the issues relating more closely to content on social media networks (cf the ongoing investigations into Meta and X), which raise not only the more difficult legal issues (given their greater impact upon freedom of expression) but also have the greater political impact (given the subject-matter, and the closeness of both zillionaire owners to the US government). And this brings us nicely to the impact of the decision upon US/EU relations.  

 

Context: EU-USA relations

Coincidentally, the non-compliance decision was released the day after the US government published a foreign policy review that was intrinsically hostile to the EU, and hyperpartisan in its support of right wing populist parties in Member States. In that context, the decision against X is just a drop in the rapidly-widening Atlantic Ocean. Famously, US diplomat Dean Acheson was ‘present at the creation’ of the post-war alliance; the Trump administration’s goal seems to be to preside over its destruction.

Yet, as noted already, supporters of Trump are nevertheless enraged by the decision, despite its limited impact. Even though, as explained above, the DSA was approved by elected governments and MEPs, does not solely apply to US companies and is not solely enforced against US companies, and the recent decision has at best a marginal impact upon freedom of expression, the response is the same: “They’re eating our free speech!”

Of course, it’s hard to take concerns about free speech from the Trump administration seriously: these are folks who want to expel legal migrants for criticism of a foreign government, and whose leader, between naps, frequently insults and threatens journalists who are insufficiently North Korean in their adoration of him. If these people are genuine free speech defenders, then I’m Alexander Hamilton.

As hypocritical and inaccurate as the Trumpian reactions to the decision are, they were presumably anticipated by the Commission before it took its decision. Even if the EU courts rule in the Commission’s favour in the event of a legal challenge, its MAGA critics will likely remain just as irrational (“They’re eating the snails!”). Yet the Commission took the decision anyway.

The choice to go ahead with the decision regardless can be understood either as a calculated risk that the US will not punish the EU for it – at least no more than it was inclined to punish the EU anyway, for various other reasons – or that even if the US does punish the EU for the decision, it is worth exercising its regulatory powers anyway. Perhaps this is a response to the perception that the Commission had seemed unwilling to stand up to Trump to date. Or maybe the assumption is that Trump is unlikely to pay much attention to this matter for long, particularly if the EU can devise a way to distract him: something like a shiny gold award for ‘best European’, for ending the war between Narnia and Freedonia, may work.  

Whatever happens, the Commission’s decision was certainly a gamble, in the current context of fraught EU/US relations, with far broader trade and security issues at stake. Time will tell whether this assertion of regulatory strength is worth it in light of the reaction it may trigger.

 

Tuesday, 7 October 2025

The General Court of the European Union upholds the Data Privacy Framework

 


 

Dr Samira Allioui, Research fellow, Centre d'études internationales et européennes, Université de Strasbourg

Photo credit: Ibrahim Rustanov, via Wikimedia Commons

French Member of Parliament Philippe Latombe, who also sits on the board of the French data protection authority, the Commission Nationale de l’Informatique et des Libertés, brought an action, in his personal capacity, in the General Court of the European Union calling for the annulment of the Data Privacy Framework. On Wednesday, September 3, the General Court of the European Union dismissed MP Philippe Latombe's appeal against the Data Privacy Framework adequacy decision, the agreement governing data transfers between the EU and the United States, at the heart of a long legal saga. Since Latombe's case was brought as an action for annulment and not as a preliminary question by a national court, he not only had to prove that the deal was substantively wrong, but also that he was directly affected in order to be entitled to bring an action at all.

The DPF is the successor to the EU-U.S. Privacy Shield (the Privacy Shield), after the adequacy decision on the EU side adopted in light of the Privacy Shield was declared invalid in 2020 by the CJEU following litigation by privacy advocate Maximilian Schrems, acting through not-for-profit NOYB (none of your business), in the landmark case of Schrems II. The Privacy Shield was the successor to the EU-U.S. Safe Harbor Framework, which was declared invalid in 2015 in Schrems I. In response, the United States established the Data Protection Review Court (DPRC). The European Commission approved the DPF in July 2023.

Personal data transferred from the European Union to third countries is no longer subject to the GDPR in those countries. This requires compliance with certain safeguards prior to transfer, with the aim of ensuring adequate data protection in the destination country. An adequacy decision is one of the mechanisms for ensuring this protection, and the GDPR provides for a Commission decision recognizing, after a thorough examination, that the law of a third country offers guarantees deemed adequate.

It is clear that even though American law has since evolved towards greater oversight of intelligence services, one particular issue has long been a problem in US-EU relations: access to effective remedies in the United States, allowing Europeans affected by transatlantic transfers to challenge the processing of their data. This issue was already the subject of progress in 2022 with Executive Order 14086, which paved the way for a challenge mechanism. This allowed the European Commission to adopt a new adequacy decision in 2023, the very one that is being challenged in the Latombe case.

The new ruling

This new ruling is therefore part of a series of developments relating to transatlantic transfers. The fundamental issue is the adequacy of the safeguards provided abroad, and therefore the degree of requirement that the European Union must have vis-à-vis the states to which data are transferred. However, on this point, the reasoning followed by the General Court of the European Union contrasts sharply with the rulings handed down by the Court of Justice of the European Union in the Schrems I and II cases. In the Schrems II ruling, the Court insisted that "the third country must offer guarantees to ensure an adequate level of protection essentially equivalent to that guaranteed in the European Union," while also using the terms "essential equivalence" and "substantial equivalence" interchangeably. Only the latter expression—"substantial equivalent"—is adopted by the General Court, although it gives it a scope that appears to be weakened.

In its assessment of the adequacy of American law, the Court appears to be less demanding than the Court of Justice. In recent years, the latter has initiated a particularly demanding jurisprudential movement in matters of personal data protection, giving rise to numerous tensions with Member States, which themselves struggle to comply with the requirements of the Court of Justice. While the Schrems I and II judgments were perfectly in line with this trend, the Court's judgment seems to propose another direction, perhaps more favorable to national security issues.

In any case, in its analysis of the conditions to be met to conclude that foreign law is adequate, the Court draws its inspiration primarily from the ECtHR case of Big Brother Watch v. United Kingdom. On the contrary, the major decisions of the CJEU – we are thinking in particular of the La Quadrature du Net I case – dealing with the activities of intelligence services are not considered relevant by the Court. The latter were particularly demanding, where the ECtHR recognizes certain margins of appreciation for States, in particular due to the very sensitive nature of intelligence and national security issues.

The next developments?

Since this is a General Court ruling, it is likely that there will be an appeal to the CJEU. Let us assume, however, that the Court upholds the existing adequacy decision. Another fundamental question would inevitably arise. The General Court is not taking into account recent developments in US law, particularly since the return of President Donald Trump. However, some of the guarantees applicable in US law, highlighted by the General Court, already appear to be weakened. Let us give an example: the Privacy and Civil Liberties Oversight Board (PCLOB) which role is fundamental, particularly because it is involved in the appointment of members of the Data Protection Review Court, whose independence and impartiality are discussed at length in the General Court's ruling. However, President Donald Trump has terminated the terms of several PCLOB members, preventing it from functioning. The impact this could have on transatlantic data transfers has already been the subject of debate in the European Parliament and the United States. The saga surrounding transatlantic data transfers could thus, despite the Court's ruling, be the subject of new twists and turns.

Today, more than 2,800 US companies are DPF-certified, allowing them to continue relying on the adequacy decision (Article 45 of the GDPR) as the legal basis for their transatlantic transfers Data Privacy Framework. However, while this prevents massive disruptions to data flows, the stability of the framework is not guaranteed. It must be actively monitored, given regulatory or judicial events that may disrupt it.

Plus, if Mr. Latombe can still appeal the General Court's decision to the CJEU, it is uncertain whether the CJEU would follow the General Court's reasoning. It should be recalled here that the CJEU has in the past held that adequacy decisions must be assessed on the basis of the legal and factual situation at the time of the appeal, while in Latombe, the General Court departed from this standard and stated that decisions must be assessed on the basis of the situation at the time of their adoption (i.e., under the previous administration). Finally, the European Commission could, in theory, decide to suspend or repeal the DPF if it considers in the future that US law no longer provides sufficient protection for European Economic Area personal data.

Friday, 28 February 2025

Hamoudi v Frontex, an EU Courts pushback case: Shifting the burden of proof and a duty to assist the Court (a duty of candour?)


 


Antje Kunst*

* Antje Kunst is an international lawyer and barrister of Garden Court North Chambers, admitted to the Bar of England and Wales, and the Bar of Berlin, advising and representing individuals in a wide range of matters related to fundamental rights within the CFSP and other fields. She has appeared in numerous cases before both the Court of Justice and the General Court, within the Court of Justice of the European Union.  

Photo credit: Rock Cohen, via Wikimedia Commons

 

Introduction

On 4 February 2025 the Grand Chamber held a hearing on the appeal of Hamoudi v Frontex in Case C-136/24 against the General Court (GC)’s Order of 13 December 2023. This appeal is taking place alongside the separate challenge in WS v Frontex (see analysis of that case and summary of the hearing).  

The case of Hamoudi v. Frontex concerns Syrian asylum seeker Alaa Hamoudi, who alleges that on 28 April 2020, he and 21 other individuals were subjected to a pushback operation in the Aegean Sea. He claims that upon arriving from Turkey by boat, he entered Greek territory on the island of Samos to seek asylum. Local police intercepted him, confiscated his mobile phone, and later that day, Greek authorities forced him and the others back out to sea. The following day, a vessel from the Turkish coast guard took them aboard. Hamoudi also alleges that on 29 April 2020, while at sea, a private surveillance aircraft operated by Frontex, equipped with a camera, flew over the scene twice.

In February 2022 OLAF issued a highly damaging report on Frontex which addresses incidents of illegal pushbacks involving Frontex assets like Frontex Surveillance Aircraft, in particular in the Aegean Sea, in late April 2020. This report was not made publicly available (see here more on this fact).

In March 2022, Mr. Hamoudi brought an action pursuant to Article 340.2 TFEU  against Frontex, seeking €500,000 compensation for non-material in damage in respect of violations of his fundamental rights, including the prohibition of collective expulsion and the principle of non-refoulement under the EU Charter of Fundamental Rights.

The GC dismissed the action by Court Order stating it "manifestly lacked any foundation in law." (para. 62 of the Court Order). The GC found that the appellant’s own written statement taken by an NGO more than a year and a half after the events, a Bellingcat article, and four screenshots from third-party video recordings of the pushback were “manifestly insufficient” to conclusively prove Hamoudi’s presence or involvement in the incident.  It further noted that the claimant could not be identified in the images. Further his own written statement lacked credibility (paras. 40 and 41 of the Court Order).

Hamoudi appealed this decision on 19 February 2024, contending that the General Court erred in its legal assessment and mischaracterized the facts.

Relevance of two ECtHR expulsion cases

In January 2025, in two groundbreaking judgments A.R.E. and G.R.J. v. Greece the European Court of Human Rights (ECtHR) unanimously confirmed Greece's “systematic practice” of pushbacks of third-country nationals from Greece back to Turkey. Both ECtHR cases are very similar in terms of facts to the Hamoudi case.  The G.R.J.  case which was referred to by the judges during the hearing concerns like in the Hamoudi case a pushback from the island of Samos to Turkey in 2020.

Significantly the parties were asked to comment on the relevance of these two judgments seemingly with a view to consider the ECtHR’s finding on the existence of a “systematic practice” of pushbacks by Greece. The Court might likely to be inspired by the ECtHR approach in these types of cases, if not align its case law with the Strasbourg Court’s large case law on expulsion. Both Courts have engaged in the past in a judicial dialogue, referring to each other’s case law, aiming for consistency in protecting human rights of individuals.

Assisting the court in reaching the correct result

Pushbacks are difficult to prove, in particular when they happen at night and mobile phones are confiscated or destroyed (as happened to the appellant and applicants in ECtHR cases (e.g., in  A.R.E.  para. 266).

In proceedings before the ECtHR, respondent states often deny the facts rather than disclosing relevant records, surveillance footage, or photos and videos documenting the events, as elaborated here. In Hamoudi, Frontex representatives, during the hearing before the Grand Chamber, claimed it was unclear whether Frontex had been present at the scene of the events, noting that "they had not been monitoring the situation from afar through their binoculars" (see here).

The question arises: Is it acceptable for an EU agency like Frontex to present such arguments, displaying a stance similar to that of states before the ECtHR? Or does it, instead, have a duty to assist the Court? Article 24 of the Court’s Statute provides that the Court “may require the parties to produce all documents and to supply all information which the Court considers desirable.” This provision establishes not only a procedural obligation for the parties to cooperate fully with the Court but also an implicit duty to assist the Court in reaching an accurate outcome. The Court here relies on the transparency and good faith of the parties to uncover the relevant facts and produce it before the Court.

In UK public law there is a duty of candour vis-à-vis the Court. The duty of candour requires a public authority "not to seek to win [a] litigation at all costs but to assist the court in reaching the correct result and thereby to improve standards in public administration." (see also here)

This principle is not unknown in member states. In Germany for example pursuant to §99 Administrative Court Procedure Code and §138 Code of Civil Procedure , public authorities must act truthfully and fully cooperate with the administrative courts.

Arguably as an EU agency, Frontex, and based on Article 24 of the Court’s Statute it has a duty to assist the Court in reaching the correct result by providing information and disclosing evidence exclusively within its possession, even if that evidence may be unfavourable to its case. In other words, it is not acceptable for Frontex to adopt the same approach as states in these types of cases.

Furthermore, contrary to what the EU Agency presented before the Court, Frontex also “sits on evidence” -not only the member states- related to its activities collecting evidence when it carries out its assistance and surveillance activities acting under a clear mandate to protect the fundamental rights of individuals in distress at sea, in accordance with Articles 80(2) and 80(3) of the Frontex Regulation.

Impossible proof

The burden of proof imposed by the GC amounted to probatio diabolica, an impossible proof for Mr. Hamoudi.

There might be cases in which applicants are able to provide robust evidence related to their individual situation, such as photographs, video recordings, and witness testimonies. The possession of mobile phones with geolocation capabilities gives victims of pushback operations new means to provide proof of their presence in a certain area or to prove the involvement of Frontex.

In most cases, individuals like Hamoudi face serious practical difficulties in gathering evidence. The incident took place at night and under very stressful conditions, with Hamoudi being in the open sea in a boat. Hamoudi was unable, both physically and mentally, to gather any evidence. (see more on this here) Taking away mobile phones as happened to Mr. Hamoudi makes it impossible for the victim to use such evidence.  This is what the General Court failed to consider.

Applying the rules governing the burden of proof in Strasbourg expulsion cases

The appellant argues in his appeal that the General Court (GC) committed an error of law by failing to properly assess and apply the relevant rules governing the burden of proof. Specifically, the appellant contends that the GC did not consider the legal criteria established by the ECtHR in its expulsion case law, which aligns with the EU Court’s own established practice (e.g., in discrimination cases).

When adjudicating such cases, the ECtHR shifts the burden of proof to the state as elaborated here  where there is different access to information which advantages the state and leaves the applicant without evidence or when the defending State possesses information that could  corroborate or refute the applicant’s allegations. Despite what Frontex alleged at the hearing Frontex certainly has access to information regarding the events in question as also the OLAF report shows. This relates to information regarding its own compliance with its own fundamental rights obligations and the existence of the immaterial harm stemming from the events during the night in question.

The ECtHR expulsion case law provides that once an applicant has furnished prima facie evidence in support of his or her version of events, the burden of proof should shift to the respondent when (a) there is an absence of personalized treatment—such as not being interviewed or having personal details taken—which lies at the very core of the applicant’s complaint, as in the present case; and (b) this absence has contributed to the difficulty in adducing evidence of involvement in the event (see Case of N.D. and N.T. v. Spain, para. 85).

As analysed here in its recent rulings the ECtHR has explicitly acknowledged that the state’s complete denial of alleged facts places the applicant in an inherently difficult evidentiary position, in which they may be unable to establish the veracity of their account (A.R.E., para. 218; G.R.J., para. 183).

The consolidated case law of the ECtHR regarding the reversal of the burden of proof might serve as a compelling source of inspiration for the ECJ’s judges in this specific case, which bears significant similarities to the large number of expulsion cases the ECtHR has adjudicated, most recently in G.R.J.

The fact that this is an application for damages under Article 340(2) TFEU against an EU agency, rather than a human rights application before the ECtHR against a state, does not make a difference, as similar objectives are pursued. The judges might consider that the conditions to be met for being successful with claim for damages before the ECJ are significantly higher than a human rights application before the ECtHR. This applies particularly to the more extensive requirements for proving harm under the ECJ’s case law compared to the standards for establishing victim status under Strasbourg case law. In other words, and contrary to what Frontex appeared to imply during the hearing, the bar for establishing liability remains high and substantial.

Meet prima facie threshold

To meet the prima facie threshold under the ECtHR, regularly two key elements are required (a) an individual account which is specific, consistent, generally coherent, and credible and (b) general context evidence concerning the broader context relevant to applicants’ claims.  In G.R.J.  the ECtHR relied on such general context evidence: “[h]aving regard to the large number, diversity, and concordance of the relevant sources …the Court concludes that there is serious evidence to suggest that, at the time of the alleged events, there was a systematic practice of refoulement by the Greek authorities of third-country nationals from the Greek islands to Turkey.” G.R.J. , para. 190, unofficial translation. Contradictions in the respondent’s statements will be considered as well.

It appeared from the judges' questions during the hearing that the Court was indeed considering holding that the General Court had failed to consider shifting the burden of proof to the EU Agency. This is not surprising in view of its own well-established case law on the reversal of the burden of proof in similar cases of asymmetry of access to information, albeit in other areas (e.g., discrimination) and its approach to consider relevant case law of the ECtHR as a source of inspiration. In this regard, the Court has ample reasons to hold that the applicant has provided prima facie evidence of the violation and that the General Court should have considered shifting the burden of proof to Frontex.

The judges inquired about OLAF’s 2021 report on Frontex and its findings concerning the events of 28 and 29 April 2020. It mentioned the fact that the report refers to two Frontex officers confirming the credibility of the Bellingcat article admitting that the operation of which Mr. Hamoudi claims to be the victim of took place. In any event, if the case had been considered by the Strasbourg Court, it would have found that the specific and consistent account by Mr. Hamoudi, partially corroborated by OLAF’s findings and the Bellingcat article, constitutes prima facie evidence, thereby triggering a shift in the burden of proof.  The Court of Justice would be justified in following the Strasbourg case law and reaching this conclusion. This is also so because of the widely documented information on the general context and the myriad of contradictory statements about the events by Frontex outside the proceedings.

Refuting the appellant’s claims

Frontex stressed at the hearing that it could not “live up” to substantiating, refuting or corroborating the prima facie evidence of the appellant. It was in a situation of an impossible proof. This is wholly unconvincing. Frontex could simply review its records or surveillance footage to determine whether, at the relevant date and time, its surveillance aircrafts were operating over the area where the unlawful pushback of Mr. Hamoudi occurred. Frontex conducted two active operations in the region and is best placed to substantiate or refute the appellant’s claims. With an explicit to mandate to provide support to Greece in the Aegean Sea fully aware of Greece’s shady practices and under an explicit mandate to safeguard fundamental rights of individuals in distress at sea as per Article 80 (2) and 80 (3) of the Frontex Regulation it was monitoring the situation.

Conclusion

Enabling the EU Courts to focus on the legal assessment of alleged fundamental rights violations in such cases by providing as much factual information as possible serves the interests of all parties involved—including the Court itself.

Frontex has faced significant criticism over alleged pushback practices in the Aegean Sea, raising serious concerns about compliance with its fundamental rights obligations. It is in the Agency’s interest to be as transparent as possible, not to seek to win a litigation such as the Hamoudi case at all costs but to assist the court in reaching the correct result. By doing so, Frontex can contribute to reinforcing trust in the EU Agency’s commitment to human rights and accountability.