Showing posts with label Internet regulation. Show all posts
Showing posts with label Internet regulation. Show all posts

Monday, 29 June 2026

The End of Immunity for Internet Service Providers? C-188/24 WebGroup Czech Republic and NKL Associates and C-190/24 Coyote System, judgment 16 June 2026



 

Lorna Woods, Professor Emerita, University of Essex

Photo credit: TodayTesting.com, via Wikimedia Commons   

This recent CJEU judgment has been flagged in some quarters as upholding the French rules requiring age verification for porn sites. In others, it has been seen as stripping intermediary immunity from social media sites. Based on the e-Commerce Directive, however, is this just a transient discussion, fading away as the Digital Services Act (DSA) becomes the relevant law?

 

The Facts

 

The national cases in Case C-188/24 concern French rules requiring porn operators to implement technical age verification mechanisms to prevent minors from accessing those sites.  The companies were each the subject of a formal notice pursuant to Decree No 2021/1306 implementing Law No 2020-936 and Article 227-24 of the Criminal Code which prohibits any person from broadcasting a pornographic message likely to be seen by a minor. The rules in Coyote System concern the restriction on the broadcasting of information to drivers about roadside checks (eg in relation to speed or drunk driving). The relevant implementing measures were also derived from the French criminal code. These measures were subject to judicial challenge before the French Conseil d’État. The companies in question were not established in France and questioned the applicability of the French rules.

 

The Issues

 

The first question the CJEU had to address was whether the measures fell within the coordinated field of the  e-Commerce Directive (Directive 2000/31) and would therefore be caught by Article 3, which provides for the country of origin principle (COOP). Recital 22 which states that ‘information society services should be supervised at the source of the activity’. This means that services in general comply with the domestic law of the State in which they are established and do not have to comply with the laws of the States in which their services are capable of being accessed.  Article 3(3) excludes certain areas from the coordinated field and Article 3(4) et seq provide for limited grounds of derogation from the COOP and provide conditions with which the receiving State must comply to access the derogation.   The COOP applies only to laws falling within the coordinated field. Here the relevant laws were not sector specific measures targeting information society services in particular, but the general criminal law. The referring court questioned whether the provisions in issue fell within the coordinated field and referred the issue to the CJEU.

 

The ban on transmission in Coyote System was, according to the applicant, contravening the prohibition on general monitoring found in Article 15 e-Commerce Directive. This application of this article is dependent on the information society services in question falling within one of the categories of service found in Articles 12-14 e-Commerce Directive (mere conduit, caching services or hosting services respectively). The Court thus then had to consider whether the service in Coyote System was a hosting service within the meaning of Article 14 e-Commerce Directive. Article 14(1) provides:

 

Where an information society service is provided that consists of the storage of information provided by a recipient of the service, Member States shall ensure that the service provider is not liable for the information stored at the request of a recipient of the service, on condition that:

 

(a) the provider does not have actual knowledge of illegal activity or information and, as regards claims for damages, is not aware of facts or circumstances from which the illegal activity or information is apparent; or

(b) the provider, upon obtaining such knowledge or awareness, acts expeditiously to remove or to disable access to the information.

 

Judgment

 

The Coordinated Field

 

The Court emphasised that the coordinated field

 

covers all requirements laid down by the legal systems of the Member States relating to the taking up or pursuit of the activity of an information society service, … that definition does not make the coordinated field subject to the condition that only matters harmonised by that directive are covered. [para 52]

 

Following the Advocate General (at para 56 of his Opinion), it remarked that Article 3 is of particular importance precisely for the areas of law not harmonised. The mere fact that the laws apply generally cannot remove them from the coordinated field. Moreover, the Directive excludes certain areas from the scope of the Directive, so the question of exclusion had been taken into account in the Directive. Taking a different approach would undermine the purpose of the Directive.

 

The Court confirmed that requiring age verification sets the conditions for access to the information society services and is a requirement concerning the pursuit of an activity within Article 2(h)(i) (see Case C-649/18 A (Advertising and sale of medicinal products online)). For the roadside broadcasts, the Court took the view that the prohibition constituted a requirement relating to the content of the service. Both sets of measures therefore fall within the coordinated field.

 

The COOP and Derogation

 

The key question for the application of the COOP was whether the measures restricted the free movement of the services. This question the Court answered in the affirmative before considering whether the derogation in Article 3(4) could be used.

 

The derogation has substantive and procedural conditions. Substantively, the measure must be necessary in the interests of one of more of: public policy; protection of public health; public security; or protection of consumers. Further, those measures should be taken against an information society service which actually prejudices those objectives or presents a serious and grave risk to those objectives. Finally, the measures must be proportionate to the objectives. In procedural terms, the recipient Member State must first have issued an unsuccessful request to the host Member State to fix the issue and, secondly, notified the Commission.  A failure to comply renders the obligations unenforceable (Case C-390/18 Airbnb Ireland – following long established case law).

 

General rules applying without distinction do not satisfy the second of the substantive conditions. The rules, however, provided for the issuing of individual notices which satisfy this requirement [para 90]. The third substantive element – that of proportionality – was satisfied in relation to the protection of human dignity and the rights of the child as regards the broadcasting of pornography [para 94] and, without much elaboration, the prohibition on rebroadcasting is also proportionate [para 96]. 

 

So in principle, the national rules could meet the substantive criteria but it was for the referring court to determine whether the procedural rules were satisfied.

 

General Monitoring

 

Hosting

 

As noted above, the possibility of relying on Article 15 depends on whether the service in issue – here the service in Coyote System - is a host within the scope of Article 14 [see para 105]. The Court noted that the definition of hosting did not automatically preclude a service which also has elements of broadcasting from being a host, referring to long-standing caselaw as well as more recent (Case C-360/10 SABAM; Case C-682/18 YouTube and Cyanado and Case C-401/19 Poland v Parliament and Council). Conversely, just because a service includes the storage of information does it mean that the service is a host for the purposes of Article 14. The Court reiterated the limitations arising from Recital 42 – that the services should be of a mere technical, automatic and passive nature. This implies, according to the Court’s case law (Case C-324/09 L’Oréal and Case C-682/18 YouTube and Cyanado), “the information society service provider has neither knowledge of nor control over the information which is transmitted or stored” [para 108].  The Court underlined that “those two conditions requiring knowledge and control should be understood as being alternative to and independent of each other” [para 110].  The Court then held that

 

if, beyond the mere categorisation and indexation of information for the purpose of improving its accessibility, the algorithm used determines, in the interest of the operator or its service, under what conditions, how and in which order of priority that information is or is not be broadcast, that operator exercises control over that information, with the result that the service it offers cannot be classified as an ‘information society service … that consists of the storage of information provided by a recipient of the service’ [para 112].

 

Impact on Article 14(3) and Article 15

 

If a service exercises control over content, it does not fall within Article 14 and therefore the restrictions imposed on Member States by Article 15 are not applicable to such are service. The questions were for the national court to determine.

 

On the assumption that the service were found to be neutral, the national court must decide whether the prohibition on rebroadcasting the information on roadside checks is permitted by Article 14(3) which concerns orders requiring a neutral host to terminate any infringement on the part of the recipient of the service due to, inter alia, the presence of illegal information stored on its website or on its platform by removing or blocking access to that information.

 

Considering Article 15, the Court referred to Recital 47 e-Commerce Directive, which clarifies that Article 15 does not apply to monitoring in specific cases. Referring to the test laid down in Glawischnig-Piesczek (Case C-18/18), paras 46 and 47, the Court noted in this case that the information targeted by the prohibitions “is circumscribed in such a way that its rebroadcasting may be automatically prevented by the operator concerned” [para 121].

 

 

Comment

 

Coordinated Field and COOP

 

The Court has taken a typical approach here, a broad approach to the areas covered: criminal law rules and public policy rules can fall within the scope of the directive, provided they impose requirements on the access or conduct of an information society service. Furthermore, none of the criminal law in general, public policy and public security measures appear on any of the exclusions from the scope of the directive. The Court’s ruling makes explicit that this absence from the exclusions is deliberate. This position is in the interests of ensuring that a service is not subject to multiple regulation, but it can lead to unevenness and gaps in protection from the viewpoint of a person expecting the rules of the member state in which they reside to apply to services providers providing services in that self-same Member State. This is especially the case when the aspect potentially taking the national rule outside the derogation regime is about its form, not its substance.  The COOP principle has long given rise to concerns about forum shopping and a race to the bottom (as can be seen also in the broadcasting sector and the Audiovisual Media Services Directive) but has been re-affirmed as a central tenet of the EU regime (see eg Case C-769/22 Commission v Hungary (Values of the European Union)). 

 

It is also worth noting that the Court in principle accepted that both sets of rules in the cases referred were aimed at achieving legitimate aims and were proportionate. The Court drew on the fact that the AVMSD requires age verification in relation to pornography to reach this latter assessment. In so doing, the Court engaged in a joining up the dots activity between different piece of EU digital legislation. 

 

In this ruling, the Court underlined both the importance of the right to human dignity and the rights of the child.

 

Impact on Article 14

 

The headline news from this ruling is the impact on Article 14 and the test for neutral intermediary. The hosting safe harbour in Article 14 was always meant for neutral, passive intermediaries – entities whose activity is “purely technical, automatic and passive”, implying that the provider “has no knowledge of or control over” the information stored (Recital 42 e-Commerce Directive). This has been the standard position since the early case law – for example L’Oreal.  What this means, and in particular the impact of automated tools, has been the subject of some discussion. In a different context (copyright infringement), the Court even if an operator automatically indexes infringing content to recommended videos based on each users’ use did not necessarily mean that the host had specific knowledge of the infringing content, and the Court determined that this sort of specific knowledge was what was required. This could be seen as quite a generous view towards the hosting services and the scope of immunity. It might almost be said that there was an assumption that platforms would benefit from Article 14 (provided they responded to notices). In Coyote there is a shift of focus.

 

The first point to note is the Court’s statement that hosting services do not automatically benefit from Article 14. While this is not new – and, indeed, can be seen the Court’s previous jurisprudence – the reminder feels significant, especially in the light of the rest of the ruling. The Court here confirmed that a service has to satisfy both the knowledge and the control tests, a point not laboured in previous judgments. The Court (at para 110) makes this really clear: if a service exercises control, even if it has no knowledge, it will fall outside the intermediary immunity provision.

 

Whereas Cyanado dealt with knowledge, System Coyote looks at control. Significantly, the Court held that algorithmic curation constitutes “control”.  The Court (following its Advocate General) held (para 111):

 

it is, inter alia, by means of the algorithm used that such an operator exercises control over the information stored. So long as it has predetermined, by means of that algorithm, the conditions under which such information may or may not be broadcast, it is irrelevant that that operator does not itself carry out additional interventions which have the effect of promoting, modifying or deleting information stored with a view to it being broadcast.

 

In other words, when a service which stores information uses an algorithm to determine – in its own interest or that of its service – under what conditions, in what manner, and in what order of priority information is or is not disseminated it has control (see para 112). It does not matter that this is automatic. So creating the algorithmic system is exercising control.  In focussing on control, the Court avoids outright conflict with its earlier position (for example in Cyanado), but it certainly signals a change in emphasis and (in line with thinking underpinning parts of the DSA) a recognition that the algorithm is not necessarily neutral.

 

Not all categorisation or prioritising satisfies the control test. Simple categorisation and indexing of information to improve its accessibility do not on their own constitute control. Essentially, the Court is trying to draw the line between a neutral index, or chronological feed, and something more editorial (and it is telling to remember that the services themselves have claimed first amendment rights – is relating to their speech – in relation to how results are provided). 

 

Nonetheless, this ruling will affect a wide range of services based on curating user generated content, from social networks, video-sharing services and – of course – services that rebroadcast user reports (eg about police checks), as well as recommended products on a marketplace. The judgment could be read as stripping most (if not all) of the large social media platforms of their immunity (though this does not mean they will automatically be liable in all cases – that will depend on national law and the facts in individual cases). It could also be said to follow a similar path to the Russmedia decision (Case C-492/23), discussed here, which also took a narrow view of immunity (hosting defence does not apply to liability under the GDPR).

 

Impact on Article 15

 

The prohibition on general monitoring only relates to those services covered by intermediary immunity. Although this follows the language of Article 15(1) there had been some dispute as to who could claim the protection of Article 15. The answer is now clear: fall outside Article 14 (or 12 or 13) and Article 15 does not apply. 

 

The Court also reiterates its position on the distinction between general and specific monitoring and highlighting the possibility of using automated techniques to identify particular types of content. This could be relevant for Member States’ ability to impose monitoring or filtering obligations (in services of some public interest) – these (in relation to copyright infringements, e.g. SABAM, above) had been thought problematic in the relatively early days of the e-Commerce Directive, and platforms have often challenged such obligations as constituting general monitoring. The Court’s discussion here is focussed tightly on content; it does not discuss behavioural monitoring or profiling (which might be techniques by services to reduce the incidence of illegal content or behaviour across their services). It will be interesting to see how this line of case law joins up with the jurisprudence under the e-Privacy directive on collection of metadata and intrusions into communications privacy (see eg Case C-746/18 Prokurator).

 

Impact on DSA

 

Article 6 DSA, which replaces Article 14 e-Commerce Directive, provides that hosting providers are not liable for information stored at the request of a recipient of the service, provided that they do not have actual knowledge of illegal activity or content, unless the recipient acts under the authority  “or control” of the provider. It has been assumed given the similarity in the text, that the case law on Article 14 is relevant for understanding Article 6 DSA, including as regards the threshold condition of neutral. The wording of the relevant recitals in the DSA differ, however, from the text in the e-Commerce Directive (noted above) – and the Court has relied heavily on that text in its interpretation of Article 14.  Indeed, Article 14 itself does not refer to control. Recital 22 DSA specifies:

[i]n order to benefit from the exemption from liability for hosting services, the provider should, upon obtaining actual knowledge or awareness of illegal activities or illegal content, act expeditiously to remove or to disable access to that content. … The provider can obtain such actual knowledge or awareness of the illegal nature of the content, inter alia, through its own-initiative investigations or through notices submitted to it by individuals or entities in accordance with this Regulation in so far as such notices are sufficiently substantiated to allow a diligent economic operator to reasonably identify, assess and, where appropriate, act against the illegal content. However, such actual knowledge or awareness cannot be considered to be obtained solely on the ground that the provider is aware, in a general sense, of the fact that its service is also used to store illegal content. Furthermore, the fact that the provider automatically indexes information uploaded to its service, that it has a search function or that it recommends information on the basis of profiles or preferences of the recipients of the service is not a sufficient ground for considering that provider to have ‘specific’ knowledge of illegal activities carried out on that platform or of illegal content stored on it. [emphasis added]

 

At first glance, the recital seems to contradict the ruling in Coyote System. The wording of the recital seems to follow the approach the Court adopted in Cyanado and like that judgment deals with the question of knowledge. We have noted earlier, the Court’s sidestep in this case, to talk about control. The recital says nothing about control and is therefore not inconsistent with the approach in Coyote System.  Of course, this means that there is no reference to “control” in the text of the DSA because Article 6, like its predecessor Article 14, is silent on the point. It is far from clear, however, that the change in wording in the recital was intended to mark a change in meaning from Article 14 resulting in an expansion of the scope of immunity. Rather it seems an intention to align the DSA with the case law on Article 14 e-Commerce Directive. Presumably, there will be much litigation on this point as well as the linked question as to where the boundary between control and “mere categorisation and indexation of information” [para 112].


Thursday, 6 June 2024

EU Media Freedom Act: the convolutions of the new legislation

 



Samira Asmaa Allioui, research and tutorial fellow at the Centre d'études internationales et européennes de l'Université de Strasbourg

 

Photo credit: Bin im Garten, via Wikimedia Commons

 

Journalists are under pressure in different ways. Throughout the last few years, media freedom and especially media pluralism are in peril.

On December 15, 2023, the European Council and the European Parliament struck a deal on rules to safeguard media freedom, media pluralism and editorial independence in the European Union. The EU Media Freedom Act (EMFA) promised increased transparency about media ownership and safeguards against government surveillance and the use of spyware against journalists. The agreement comes after numerous revisions of the Audiovisual Media Services Directive (AMSD) and new regulations such as the Digital Market Act (DMA) and Digital Services Act (DSA). As a reminder, the EMFA builds on the DSA.

The aim of this contribution is to present an overview of the EMFA and specifically to analyse to what extent its rules still contribute to the limitation of freedom of speech, the erosion of trust, the breach of democratic processes, disinformation, and legal uncertainty.

The EMFA requires EU countries to respect editorial freedom, no spyware, no political interference, stable funding for public media, protection of online media and transparent state advertising.  It established a European watchdog: a new independent European Board for Media Services to fight interference from inside and outside the EU.

Nevertheless, this new EU legislation tries to set boundaries for the journalists’ actions through Article 18 EMFA on the protection of media content on very large online platforms (VLOPs), and the potential detrimental effects of introducing something akin to a media exemption. But the most significant ambiguity is addressed by Article 2 of the EMFA on the definition of ‘media service’ which appears to be the problem everyone acknowledges. This raises the question of who the EMFA is protecting. Are democracy and the possibility for people to get impartial and unbiased information really strengthened? Not forgetting that for the European Parliament elections, there is a potential danger of political interference by extra-European countries that will try to take advantage of democratic elections to influence the media illegally, by creating fake social media accounts and by launching a massive propaganda campaign to disseminate conflict-ridden content.

 

THE ACCURACY OF INFORMATION

The EMFA focuses on two main points regarding VLOPs. First, it asserts that platforms limit users’ access to reliable content when they apply their terms and conditions to media companies that practice editorial responsibility and create news conforming with journalistic standards. First, the Regulation takes aim at VLOPs’ gatekeeping power over access to media content. To do so, the EMFA aims to remould the relationship between media and platforms. Media service providers that exercise editorial responsibility for their content have a primary role in the dissemination of information and in the exercise of freedom of information online. In exercising this editorial responsibility, they are expected to intervene diligently and provide reliable information that complies with fundamental rights, in accordance with the regulatory or self-regulatory requirements to which they are subject in the Member States.

Secondly, it asserts that the quality of the media may fight against disinformation. To consider this problem, the EMFA’s objective is to adjust the connection between platforms and media. According to Article 2 EMFA, ‘media service’ means ‘a service as defined by Articles 56 and 57 [TFEU], where the principal purpose of the service or a dissociable section thereof consists in providing programmes or press publications, to the general public, under the editorial responsibility of a media service provider, by any means, in order to inform, entertain or educate’  A ‘media service’ has some protections under the Act.  According to Joan Barrata, the media definition under EMFA is an overly “limited” definition, which is not “aligned” with international and European human rights standards, and “discriminatory”, as it excludes “certain forms of media and journalistic activity”. The DSA classifies platforms or search engines that have more than 45 million users per month in the EU as VLOPs or Very Large Online Search Engines (VLOSEs). As an illustration, according to Article 18 EMFA, media service providers will be afforded special transparency and contestation rights on platforms. In addition to that, according to Article 19 EMFA, media service providers will have the opportunity to engage in a constructed dialogue with platforms on concepts such as disinformation. Under the agreement, VLOPs will have to inform media service providers that they plan to remove or restrict their content and give them 24 hours to answer (except in the event of a crisis as defined in the DSA).

Article 18 of the EMFA enforces a 24-hour content moderation exemption for media, effectively making platforms host content by force. By making platforms host content by force, this rule prevents large online platforms from deleting media content that violates community guidelines. Nevertheless, not only it could threaten marginalised groups, but it could also undermine equality of speech and fuel disinformation. This is a vicious circle between the speaker planting false information on social media, the media platform spreading the false speech thanks to amplifying algorithms or human-simulating bots, and the recipients who view the claims and spread them.

According to the EMFA provides that, before signing up to a social media platform, platforms must create a “special/privileged communication channel” to consider content restrictions with “media service providers”, defined as “a natural or legal person whose professional activity is to provide a media service and who has editorial responsibility for the choice of the content of the media service and determines the manner in which it is organised “. In other words, instead of being forced to host any content, online platforms should provide special privileged treatment to certain media outlets.

However, not only does this strategy impede platforms’ autonomy in enforcing their terms of use (nudity, disinformation, self-harm) but it also imperils the protection of marginalised groups who are frequently the main targets of disinformation and hate speech. Politics remains fertile ground for hate speech as well as disinformation. Online platforms and social media have played a key role in amplifying the spread of hate speech and disinformation. As proof, recent reports reveal the widespread abuse of these platforms by political parties and governments. Indeed, it turns out that more than 80 countries around the world have engaged in political disinformation campaigns.

This could also permit misleading information to remain online which allows sufficient time to see the information transmitted and disseminated, hindering one of the key objectives of EMFA - to give more reliable sources of information to citizens.


ABUSIVE REGULATORY INTERVENTION AND DETERIORATION OF TRUST

Primarily, one can only be concerned about any regulatory intervention by governments on issues such as freedom of expression or media freedom. Through their EU Treaty competencies in security and defence matters, EU Member States seem to be winning because their options to spy on reporters have been reaffirmed. However, according to the final text (April 11, 2024), the European Parliament added important guarantees to allow the use of spyware, which will only be possible on a case-by-case basis and subject to authorization from an investigating judicial authority as regards serious offenses punishable by a sufficiently long custodial sentence.

Furthermore, it must be emphasized that even in these cases the subjects will have the right to be informed after the surveillance and will be able to challenge it in court. It is also specified that the use of spyware against the media, journalists and their families is prohibited. In the same vein, the rules specify that journalists should not be prosecuted for having protected the confidentiality of their sources.

The law restricts possible exceptions to this for national security reasons which fall within the competence of member states or in cases of investigations into a closed list of crimes, such as murder, child abuse or terrorism. Only in such situations or cases of neglect, the law makes it very clear that this must be duly justified, on a case-by-case basis, in accordance with the Charter of Fundamental Rights, in circumstances where no other investigative tool would be adequate.

In this regard, the law therefore allows for new concrete guarantees at EU level in this regard. Any journalist concerned would have the right to seek effective judicial protection from an independent court in the Member State concerned. In addition to that, each Member State will have to designate an independent authority responsible for handling complaints from journalists concerning the use of spyware against them. These independent authorities provide, within three months of the request, an opinion on compliance with the provisions of the law on media freedom.

Some governments in Europe have tried to interfere in the work of journalists recently which is a blatant demonstration of how far politicians can go against media using national security as an excuse. To avoid an erosion of trust, media service providers must be totally transparent about their ownership structures. That is why, in its final version (April 2024), the EMFA enhances transparency of media ownership, responding to rising concerns in the EU about this issue. The EMFA broadens the scope of the requirements of transparency, providing for rules guaranteeing the transparency of media ownership and preventing conflicts of interest (Article 6) as well as the creation of a coordination mechanism between national regulators in order to respond to propaganda from hostile countries outside the EU (Article 17).

To do that, there is a need to deepen safeguards to shield all media against economic capture by private owners to avoid media capture. It can be worse when no official intervention can mean non-transparent and selective support for pro-government media. As a matter of fact, it demonstrates that a combination of political pressure and corruption can be risky for the free press.

Secondly, the EMFA’s content moderation provisions could ruin public trust in media and endanger the integrity of information channels. Online platforms moderate illegal content online. Moderation provisions include: a solution-orientated conversation between the parties (VLOPs, the media and civil society) to avoid unjustified content removals; obligatory annual reporting (reports on content moderation which must include information about the moderation initiative, including information relating to illegal content, complaints received under complaints-handling systems, use of automated tools and training measures) by very large online platforms (VLOPs); any complaint lodged under complaints-handling systems by media service providers must be processed with priority; and additional protection against the unjustified removal by VLOPs of media content produced according to professional standards. These platforms will need to take every precaution to communicate the reasons for suspending content to media service providers before the suspension becomes effective. The process consists of a series of safeguards to ensure that this rapid alert procedure is consistent with the European Commissions’ priorities such as the fight against disinformation. In this regard, the Electronic Frontier Foundation states that « By creating a special class of privileged self-declared media providers whose content cannot be removed from big tech platforms, the law not only changes company policies but risks harming users in the EU and beyond ».


MEDIA COMPANIES AND PLATFORMS BARGAINING CONTENT

Yet the EMFA still does not deal with the complex issue of who would oversee controlling the self-declarations (Article 18(1) EMFA). More precisely, according to Article 18 EMFA “Providers of [VLOPs] shall provide a functionality allowing recipients of their services to declare” that they are media service providers. This self-declaration can be done, mainly, according to three criteria: if public service media providers fulfill the definition of Article 2 EMFA; if public service media providers “declare that they are editorially independent from Member States, political parties, third countries and entities owned or controlled by third countries”; and if public service media providers “declare that they are subject to regulatory requirements for the exercise of editorial responsibility in one or more Member States” or adhere “to a co-regulatory or self-regulatory mechanism governing editorial standards that is widely recognised and accepted in the relevant media sector in one or more Member States”. According to Article 18(4), when a VLOP decides to suspend its services regarding the content provided by a self-declared media service provider, “on the grounds that such content is incompatible with its terms and conditions”, it must “communicate to the media service provider concerned a statement of reasons” accompanying that decision “prior to such a decision to suspend or restrict visibility taking effect”.

Aside from that, Article 18 EMFA  splits the rules implemented by the Digital Services Act (DSA), a horizontal instrument that aims to create and ensure a more trustworthy online environment by putting in place a multilevel framework of responsibilities targeted at different types of services and by proposing a set of asymmetric obligations harmonized at EU level with the aim of ensuring regulatory oversight of the EU transparency, online space and accountability. Those rules covering all services and all types of illegal content, including goods or services are set by the DSA. This implies that media regulators will be enrolled in the cooperation mechanisms that will be set up for the aspects falling under their mandate. The inception of a specific “structured cooperation” mechanism is intended to contribute to strengthening robustness, legal certainty, and predictability of cross-border regulatory cooperation. This entails enhanced coordination and more precisely collective deliberation between national regulatory authorities (NRAs) which can bring significant added value to the application of the EMFA. This implies that media regulators will be involved in the cooperation mechanisms that will be set up for the aspects falling under their remit, even if it is still unclear how this will look in practice.

Above all, how will the new legislation be applied in practice and how will it work to ensure that it neither undermines the equality of speech and democratic debate nor endangers vulnerable groups? Excluding the fact that Article 18 of the EMFA incorporates safeguards about AI-generated content, details about which remain undisclosed as of now (see also Hajli et al on ‘Social Bots and the Spread of Disinformation in Social Media’ and Vaccari and Chadwick on ‘Deepfakes and Disinformation’), there is clearly reason to be concerned about the use of generative AI to promote disinformation and deep fakes. In an era where new technologies dominate, voluntary guidelines are not enough. Stronger measures are urgently needed to balance free speech and to have control over AI systems. It is admitted that while AI can be an excellent tool for journalists, it can also be used for bad purposes.

 

INEQUALITY BETWEEN MEDIA PROVIDERS: THE ATTRIBUTION OF A SPECIAL STATUS

In terms of platforms and media companies negotiating content, since not all media providers (media companies negotiating content) will receive a special status, it creates inequality. Platforms will have to guarantee that most of the reported information is publicly accessible. The main privilege resulting from this special status is that VLOP providers are more restricted in the way they moderate the content, but not in the sense of a ban on acting against this content but rather in the form of advanced transparency and information towards the information provider concerned. This effectively leads to an uncertain negotiation situation in which influential media and platforms negotiate over what content remains visible. This is especially true since the media have financial interests in seeking a rapid means of communication and in ensuring that their content remains visible even if it is at the expense of small providers.


CONCLUSION

As a conclusion, the risk to tamper with public opinion by disguising disinformation and propaganda as legitimate media content is still reflected in Article 18’s self-proclamation mechanism. In top of that, the risk of establishing two categories of freedom of speech arises from the fragmentation of legislation, not aligning with the DSA. Then, our capacity to create informed decisions could be undermined by Article 18 EMFA, an article that allows self-proclaimed media entities to operate with insufficient oversight. Furthermore, our democratic processes risk to be severely damaged by the unregulated spread of disinformation. Finally, the opacity of Article 18 in the determination of the authenticity of self-proclaimed media engenders problems of compliance enforcement.

The elements recalled here highlight the underside of the new legislation and corroborates that efforts must be made in the future to remedy the critical situation of press freedom within the EU.

 

Saturday, 20 April 2024

‘Trusted’ rules on trusted flaggers? Open issues under the Digital Services Act regime





Alessandra Fratini and Giorgia Lo Tauro, FratiniVergano European Lawyers

Photo credit:  Lobo Studio Hamburg, via Wikimedia Commons

 

1 Introduction

The EU’s Digital Services Act (DSA) institutionalises the tasks and responsibilities of ‘trusted flaggers’, key actors in the online platform environment, that have existed, with roles and functions of variable scope, since the early 2000. The newly applicable regime fits with the rationale and aims pursued by the DSA (Article 1): establishing a targeted set of uniform, effective and proportionate mandatory rules at Union level to safeguard and improve the functioning of the internal market (recital 4 in the preamble), with the objective of ensuring a safe, predictable and trusted online environment, within which fundamental rights are effectively protected and innovation is facilitated (recital 9), and for which responsible and diligent behaviour by providers of intermediary services is essential (recital 3). This article, after retracing the main regulatory initiatives and practices at EU level that paved the way for its adoption, looks at the DSA’s trusted flaggers regime and at some open issues that remain to be tested in practice.

 

2 Trusted reporters: the precedents paving the way to the DSA

The activity of flagging can be generally recognised as that of third parties reporting harmful or illegal content to intermediary service providers that hold that content in order for them to moderate it. In general terms, it refers to flaggers that have “certain privileges in flagging”, including “some degree of priority in the processing of notices, as well as access to special interfaces or points of contact to submit their flags”. This, in turn, poses issues in terms of both the flaggers’ responsibility and their trustworthiness since, as rightly noted, “not everyone trusts the same flagger.”

In EU law, the notion of trusted flaggers can be traced back to Directive 2000/31 (the ‘e-Commerce Directive’), the foundational legal framework for online services in the EU. The Directive exempted intermediaries from liability for illegal content they managed if they fulfilled certain conditions: under Articles 12 (‘mere conduit’), 13 (‘caching’) and 14 (‘hosting’) – now replaced by Articles 4-6 DSA – intermediary service providers were liable for the information stored at the request of the recipient of the service if, once become or made aware of any illegal content, such content was not removed or access to it was not disabled “expeditiously” (also recital 46). The Directive encouraged mechanisms and procedures for removing and disabling access to illegal information to be developed on the basis of voluntary agreements between all parties concerned (recital 40).

This conditional liability regime encouraged intermediary services providers to develop, as part of their own content moderation policies, flagging systems that would allow them to rapidly treat notifications so as not to trigger liability. The systems were not imposed as such by the Directive, but adopted as a result of the liability regime provided therein.

Following the provisions of Article 16 of the Directive, which supports the drawing up of codes of conduct at EU level, in 2016 the Commission launched the EU Code of Conduct on countering illegal hate speech online, signed by the Commission and several service providers, with others joining later on. The Code is a voluntary commitment made by signatories to, among others, review the majority of the flagged content within 24 hours and remove or disable access to content assessed as illegal, if necessary, as well as to engage in partnerships with civil society organisations, to enlarge the geographical spread of such partnerships and enable them to fulfil the role of a ‘trusted reporter’ or equivalent. Within the context of the Code, trusted reporters are entrusted to provide high quality notices, and signatories are to make information about them available on their websites.

Subsequently, in 2017 the Commission adopted the Communication on tackling illegal content online, to provide guidance on the responsibilities of online service providers in respect of illegal content online. The Communication suggested criteria based on respect for fundamental rights and of democratic values to be agreed by the industry at EU level through self-regulatory mechanisms or within the EU standardization framework. It also recognised the need to strike a reasonable balance between ensuring a high quality of notices coming from trusted flaggers, the scope of additional measures that companies would take in relation to trusted flaggers and the burden in ensuring these quality standards, including the possibility of removing the privilege of a trusted flagger status in case of abuses.

Building on the progress made through the voluntary arrangements, the Commission adopted Recommendation 2018/334 on measures to effectively tackle illegal content online. The Recommendation establishes that cooperation between hosting service providers and trusted flaggers should be encouraged, in particular, by providing fast-track procedures to process notices submitted by trusted flaggers, and that hosting service providers should be encouraged to publish clear and objective conditions for determining which individuals or entities they consider as trusted flaggers. Those conditions should aim to ensure that the individuals or entities concerned have the necessary expertise and carry out their activities as trusted flaggers in a diligent and objective manner, based on respect for the values on which the Union is founded.

While the 2017 Communication and 2018 Recommendation are the foundation of the trusted flaggers regime institutionalized by the DSA, further initiatives took place in the run-up to it.

In 2018, further to extensive consultations with citizens and stakeholders, the Commission adopted a Communication on tackling online disinformation, which acknowledged once again the role of trusted flaggers to foster credibility of information and shape inclusive solutions. Platform operators agreed on a voluntary basis to set self-regulatory standards to fight disinformation and adopted a Code of Practice on disinformation. The Commission’s assessment in 2020 revealed significant shortcomings, including inconsistent and incomplete application of the Code across platforms and Member States and lack of an appropriate monitoring mechanism. As a result, the Commission issued in May 2021 its Guidance on Strengthening the Code of Practice on Disinformation, containing indications on the dedicated functionality for users to flag false and/or misleading information (p. 7.6). The Guidance also aimed at developing the existing Code of Practice towards a ‘Code of Conduct’ as foreseen in (now) Article 45 DSA.

Further to the Guidance, in 2022 the Strengthened Code of Practice on Disinformation was signed and presented by 34 signatories who had joined the revision process of the 2018 Code. For signatories that are VLOPs, the Code aims to become a mitigation measure and a Code of Conduct recognized under the co-regulatory framework of the DSA (recital 104).

Finally, in the context of provisions/mechanisms defined before the DSA, it is worth mentioning Article 17 of Directive 2019/790 (the ‘Copyright Directive’), which draws upon Article 14(1)(b) of the e-Commerce Directive on the liability limitation for intermediaries and acknowledges the pivotal role of rightholders when it comes to flagging unauthorised use of their protected works. Under Article 17(4), in fact, “[i]f no authorisation is granted, online content-sharing service providers shall be liable for unauthorised acts of communication to the public, including making available to the public, of copyright-protected works and other subject matter, unless the service providers demonstrate that they have: (a) made best efforts to obtain an authorisation, and (b) made, in accordance with high industry standards of professional diligence, best efforts to ensure the unavailability of specific works and other subject matter for which the rightholders have provided the service providers with the relevant and necessary information; and in any event (c) acted expeditiously, upon receiving a sufficiently substantiated notice from the rightholders, to disable access to, or to remove from their websites, the notified works or other subject matter, and made best efforts to prevent their future uploads in accordance with point (b)” (emphasis added).

 

3 Trusted flaggers under the DSA

The DSA has given legislative legitimacy to trusted flaggers, granting a formal (and binding) recognition to a practice that far developed on a voluntary basis.

According to the DSA, a trusted flagger is an entity that has been granted such status within a specific area of expertise by the Digital Service Coordinator (DSC) in the Member State in which it is established, because it meets certain legal requirements. Online platform providers must process and decide upon - as a priority and with undue delay - notices from trusted flaggers concerning the presence of illegal content on their online platform. That requires that online platform providers take the necessary technical and organizational measures with regard to their notice and action mechanisms. Recital 61 exposes the rationale and scope of the regime: notices of illegal content submitted by trusted flaggers, acting within their designated area of expertise, are treated with priority by providers of online platforms.

The regime is mainly outlined in Article 22.

Eligibility requirements

Article 22(2) sets out the three cumulative conditions to be met by an applicant wishing to be awarded the status of trusted flagger: 1) expertise and competence in detecting, identifying and notifying illegal content; 2) independence from any provider of online platforms; and 3) diligence, accuracy and objectivity in how it operates. Recital 61 clarifies that only entities - being them public in nature, non-governmental organizations or private or semi-public bodies - can be awarded the status, not individuals. Therefore, (private) entities only representing individual interests, such as brands or copyright owners, are not excluded from accessing the trusted flagger status. However, the DSA displays a preference for industry associations representing their member interests applying for the status of trusted flagger, which appears to be justified by the need to ensure that the added-value of the regime (the fast-track procedure) be maintained, with the overall number of trusted flaggers awarded under the DSA remaining limited. As clarified by recital 62, the rules on trusted flaggers should not be understood to prevent providers of online platforms from giving similar treatment to notices submitted by entities or individuals that have not been awarded trusted flagger status, from otherwise cooperating with other entities, in accordance with the applicable law. The DSA does not prevent online platforms from using mechanisms to act quickly and reliably against content that violates their terms and conditions.

The status’ award

Under Article 22(2), the trusted flagger status shall be awarded by the DSC of the Member State in which the applicant is established. Different from the voluntary trusted flagger schemes, which are a matter for individual providers of online platforms, the status awarded by a DSC must be recognized by all providers falling within the scope of the DSA (recital 61). Accordingly, the DSC shall communicate to the Commission and to the European Board for Digital Services details of the entities to which they have awarded the status of trusted flagger (and whose status they have suspended or revoked - Article 22(4)), and the Commission shall publish and keep up to date such information in a publicly available database (Article 22(5)).

Under Article 49(3), Member States were to designate their DSCs by 17 February 2024; the Commission makes available the list of designated DSCs on its website. The DSCs, who are responsible for all matters relating to supervision and enforcement of the DSA, shall ensure coordination in its supervision and enforcement throughout the EU. The European Board for Digital Services, among other tasks, shall be consulted on Commission’s guidelines on trusted flaggers, to be issued “where necessary”, and for matters “dealing with applications for trusted flaggers” (Article 22(8)).

The fast-track procedure

Article 22(1) requires providers of online platforms to deal with notices submitted by trusted flaggers as a priority and without undue delay. In doing so, it refers to the generally applicable rules on notice and action mechanisms under Article 16. On the priority to be granted to trusted flaggers’ notices, recital 42 invites providers to designate a single electronic point of contact, that “can also be used by trusted flaggers and by professional entities which are under a specific relationship with the provider of intermediary services”. Recital 62 explains further that the faster processing of trusted flaggers’ notices depends, amongst other, on “actual technical procedures” put in place by providers of online platforms. The organizational and technical measures that are necessary to ensure a fast-track procedure for processing trusted flaggers’ notices remain a matter for the providers of online platforms.

Activities and ongoing obligations of trusted flaggers

Article 22(3) requires trusted flaggers to regularly (at least once a year) publish detailed reports on the notices they submitted, make them publicly available and send them to the awarding DSCs. The status of trusted flagger may be revoked or suspended if the required conditions are not consistently upheld and/or the applicable obligations are not correctly fulfilled by the entity. The status can only be revoked by the awarding DSC following an investigation, either on the DSC’s own initiative or on the basis of information received from third parties, including providers of online platforms. Trusted flaggers are thus granted the possibility to react to, and fix where possible, the findings of the investigation (Article 22(6)).

On the other hand, if trusted flaggers detect any violation of the DSA provisions by the platforms, they have the right to lodge a complaint with the DSC of the Member State where they are located or established, according to Article 53. Such a right is granted not only to trusted flaggers but to any recipient of the service, to ensure effective enforcement of the DSA obligations (also recital 118).

The role of the DSCs

With the DSA it becomes mandatory for online platforms to ensure that notices submitted by the designated trusted flaggers are given priority. While online platforms maintain discretion as to entering into bilateral agreements with private entities or individuals they trust and whose notices they want to process with priority (recital 61), they must give priority to entities that have been awarded the trusted flagger status by the DSCs. From the platforms’ perspective, the DSA ‘reduces’ their burden in terms of decision-making responsibility by shifting it to the DSCs, but ‘increases’ their burden in terms of executive liability (for the implementation of measures ensuring the mandated priority). From the reporters’ perspective, the DSA imposes a set of (mostly) harmonised requirements to be awarded the status by a DSC, once and for all platforms, and to maintain such status afterward.

While the Commission’s guidelines are in the pipeline, some DSCs have proposed and adopted guidelines to assist potential applicants with the requirements for the award of the trusted flagger status. Among others, the French ARCOM published “Trusted flaggers: conditions and applications” on its website; the Italian AGCOM published for consultation its draft “Rules of Procedure for the award of the trusted flagger status under Article 22 DSA”; the Irish Coimisiún na Meán published the final version of its “Application Form and Guidance to award the trusted flagger status under Article 22 DSA”; as did the Austrian KommAustria, the Danish KFST and the Romanian ANCOM. The national guidelines have been developed following exchanges with the other authorities designated as DSCs (or about to be so) with the view to ensuring a consistent and harmonised approach in the implementation of Article 22. As a matter of fact, the published guidelines are largely comparable.

 

4 Open issues

While the DSA’s regime is in its early stages and no trusted flagger status has been awarded yet, some of its merits have been acknowledged already, such as the fact that it has standardised existing practices, harmonised eligibility criteria, complemented special regimes – such as the one set out in Article 17 Copyright Directive - confirmed the cooperative approach between stakeholders, and finally formalised the role of trusted flaggers as special entities in the context of notice and action procedures.

At the same time, the DSA’s regime leaves on the table some open issues, such as the respective role of trusted flaggers and other relevant actors in the context of tackling illegal/harmful content online, such as end users and reporters that reach bilateral agreements with the platforms, which remain to be addressed in practice for the system to effectively work.

The role of trusted flaggers vis-à-vis end users

While the DSA contains no specific provision on the role of trusted flaggers vis-à-vis end users, some of the national guidelines published by the DSCs require that the applicant entity, as part of the condition relating to due diligence in the flagging process, indicates whether it has mechanisms in place to allow end users to report illegal content to it. In general, applicants have to indicate how they select content to monitor (which may include end users’ notices) and how they ensure that they do not unduly concentrate their monitoring on any one side and apply appropriate standards of assessment taking all legitimate rights and interests into account. As a matter of fact, the organisation and management of the relationship with end users (onboarding procedures, collection and processing of their notices, etc.) are left to the trusted flaggers. For example, some organisations (such as those part of the INHOPE network, operating in the current voluntary schemes) offer hotlines to the public to report to them, including anonymously, illegal content found online.

Although it is clear from the DSA that end users retain the right to flag their notices directly to online platforms (Article 16) with no duty to notify trusted flaggers, as well as their right to autonomously lodge a complaint against platforms (Article 53) and to claim compensation for damages (Article 54), it remains unclear whether, in practice, it will be more convenient for end users to rely on specialised trusted flaggers for their notices to be processed more expeditiously – in other words, whether the regime provides sufficient incentives, at least for some end users, to go the trusted flaggers’ way. On the other hand, it remains unclear to what extent applicant entities will be actually ‘required’ to put in place effective mechanisms to allow end users to report illegal or harmful content to them – in other words, whether the due diligence requirements will imply the trusted flaggers’ review of end users’ notices, within their area of expertise.

From another perspective, in connection with the reporting of illegal content, trusted flaggers may come across infringements by the platforms, as any recipient of online services. In such cases, Article 53 provides the right to lodge a complaint with the competent DSC, with no difference being made between complaints lodged respectively by trusted flaggers and by end users. If ‘priority’ is to be understood as the main feature of the privileged status granted to trusted flaggers when flagging illegal content online to platforms, a question arises about the possibility of granting them a corresponding priority before the DSCs when they complain about an infringement by online platforms. And in this context, one may wonder whether lodging a complaint to the DSC on behalf of end users might also fall within the scope of action of trusted flaggers (to the extent of claiming platforms’ abusive practices such as shadow banning, recital 55).

The role of trusted flaggers vis-à-vis other reporters

The DSA requires online platforms to put in place notice and action mechanisms that shall be “easy to access and user-friendly” (Article 16) and to ensure an internal complaint-handling system to recipients of the service (Article 20). However, as noted above, these provisions concern all recipients, with no difference in treatment for trusted flaggers. Although their notices are granted priority by virtue of Article 22, which leaves platforms free to choose the most suitable mechanisms, the DSA says nothing about ‘how much priority’ should be guaranteed to trusted flaggers with respect to notices filed not only by end users, but (also - and especially) by other entities/individuals with whom platforms have agreements in place.

In this respect, guidance would be welcome as to the degree of prevalence that platforms are expected to give trusted flaggers’ notices compared to other trusted reporters’, as would a clarification as to whether the nature of the content may influence such prevalence. From the trusted flaggers’ perspective, there should be a rewarding incentive to engage in a role that comes with the price tag of ongoing obligations.

 

5 Concluding remarks

While the role of trusted flaggers is not new when it comes to tackling illegal content online, the tasks newly entrusted to the DSCs in this context are. This results in a different allocation of responsibilities for the actors involved, with the declared aims of ensuring harmonisation of best practices across sectors and territories in the EU and a better protection for users online. Some open issues, as the ones put forward above, appear at this stage to be relevant, in particular for ensuring that the trusted flaggers’ mechanism effectively works as an expeditious remedy against harmful and illegal content online. It is expected that the awaited Commission guidelines under Article 22(8) DSA will shed a clarifying light on those issues. In the absence, there is a risk that the costs-benefits analysis - with the costs being certain and the benefits in terms of actual priority uncertain - might make the “trusted flagger project” unattractive for a potential applicant.

Monday, 21 November 2022

The EU Commission’s proposal on Media Freedom Regulation


 


Lorna Woods, Professor of Internet Law, University of Essex

 

Photo credit: Bin im Garten, via Wikimedia Commons

 

In her 2021 State of the Union address, EU Commission President von der Leyen stated:

 

Media companies cannot be treated as just another business. Their independence is essential. Europe needs a law that safeguards this independence – and the Commission will deliver a Media Freedom Act in the next year.

 

The resulting Proposal sits against a network of existing rules – notably the long-standing Audiovisual Media Services Directive (AVMSD) and the e-Commerce Directive as well as the recently agreed Digital Services Act (DSA) and Digital Markets Act (DMA).  It will be accompanied by a Recommendation. The Proposal is a significant step; the Commission is entering new regulatory terrain here. This move indicates concerns not just about the state of the media but about public discourse more generally, but how has the Commission sought to transfer this high level concern into specific rules?

 

Outline of the Proposal

 

The Proposal can be said to be divided into roughly five elements (in addition to the definitions and scope), reflecting the fact that the concerns around media freedom have different aspects and need a response that itself is multifaceted. 

 

1 Media Freedoms

 

The first is about media freedom (and the recommendation is relevant for this issue too as it focuses on internal safeguards for editorial independence and ownership transparency). The Proposal introduces rights and obligations on media service providers in Chapter II. Specifically, it provides them the right to exercise their “economic activities in the internal market without restrictions other than those allowed under [EU] law” (Article 4(1)).  Article 4(2) then provides more detail. It specifies that Member States are prohibited from:

 

-          interfering with editorial policies and decisions by media service providers (Article 4(2)(a));

 

-          detaining, sanctioning, intercepting, subjecting to surveillance or search and seizure or inspecting media service providers, their employees, their families or their premises “on the ground that they refuse to disclose information on their sources, unless this is justified by an overriding requirement in the public interest” (Article 4(2)(b)); and

 

-          deploying spyware in any device or machine used by media service providers, their employees or their families other than in certain narrowly-defined circumstances (Article 4(2)(c)).

 

According to the Q&A document, this is to “protect them from unjustified, disproportionate and discriminatory national measures”.  There are provisions dealing specifically with “public service media providers”, reflecting their “societal role as a public good” (Recital 14) but also their “institutional proximity to the State, which puts them at peculiar risk of interference (Recital 18): they are obliged to provide “in an impartial manner a plurality of information and opinions to their audiences, in accordance with their public service mission” (Article 5(1)), although what “plurality” means for these purposes is not defined. It seems that public service media cannot be self-declared as such – the definition of “public service media provider” requires the media service either to be “entrusted with a public service mission under national law” or receives national funding for the fulfilment of such a mission (Art 2(3)). 

 

There are some ownership transparency obligations on media service providers who “provid[e] news and current affairs content”. They must provide the provider’s name and contact details, and details relating to certain shareholders and beneficial owners (Article 6(1)). They must also “take measures that they deem appropriate with a view to guaranteeing the independence of individual editorial decisions” (Article 6(2)).

 

The proposal also sets out the right of the audience (“recipients of media services”) the right to “receive a plurality of news and current affairs content, produced with respect for editorial freedom of media service providers, to the benefit of the public discourse” (Article 3(1)). Recital 11, however, clarifies that this right “does not entail any correspondent obligation on any given media service provider to adhere to standards not set out explicitly by law.”

 

2. VLOPS

 

Secondly, there are obligations on Very Large Online Platforms (VLOPs), which are in addition to those in the DSA. These provide additional rights to media service providers on VLOPs. Specifically, VLOPs must provide certain mechanisms to deal with the media (including applications of the requirements of the Platform to Business Regulation – see Article 17 MFA, and Articles 11 P2B Regulation).

 

3. Media Regulation and Institutions

 

A third element concerns the institutional set up of media regulation. There are provisions around cooperation of national regulators. The Proposal expands the scope of the existing European Regulators Group for Audiovisual Media Services (ERGA), replacing it with the European Board for Media Services (EBMS) which - with the European Commission - is to ensure the consistent application of the MFA and the wider EU media law framework (perhaps in a similar fashion to the EDPB in relation to the GDPR). Specifically, the EBMS will

 

-          advise the Commission on the implementation of the Regulation, for example, providing expertise on regulatory, technical, or practical aspects concerning the identification of audiovisual media services of general interest under Article 7a of the AVMSD;

-          mediate between the regulatory bodies of the Member States;

-          assess areas of interest such as the functioning of media markets and the potential impact of national measures; and

-          take a position if the functioning of the internal market appears to be affected.

 

4. Media markets

 

A fourth element deals with the market and includes requirements for Member States to put in place rules for assessing media market concentrations (Articles 20-22). In addition for setting rules for when concentrations must be notified, Member States should also set out criteria for assessing the impact of a concentration on media pluralism and editorial independence, an assessment which is distinct from that under competition law.

 

5. Resources and Audience measurement

 

Finally, there are rules relating to measurements of audience and to criteria for allocating resources to media outlets. The Commission notes that ‘opaque and unfair allocation of economic resources’ contribute not only to an uneven playing field but also to internal market barriers. The “opacity of and biases inherent to proprietary systems of audience measurement skew advertising revenue flows”, and the way state advertising revenue is allocated is also problematic. The Proposal therefore mandates transparent, non-discriminatory and objective measures and allocation of resources.

 

Comment

 

Competence

 

The Proposal builds on the Commission’s Rule of Law Report 2020 and the European Democracy Action Plan, and seems to aim at some worthy objectives. Despite this, the Proposal is not framed as directly protecting democracy.   The Proposal frames issues as media companies facing

 

“obstacles hindering their operation and impacting investment conditions in the internal market such as different national rules and procedures related to media freedom and pluralism”.

 

This would seem to be aimed at tackling concerns around competence and the fact that culture is typically for Member States, not the EU. To be sure, there are often special ownership and merger regimes for media undertakings, but these are often based on not on economic considerations but on non-market concerns. The emphasis on the impact that disparate rules have on media undertakings is used to justify the use of Article 114 TFEU as the legal basis for the proposal. This re-emphasises that this in not a specific piece of media policy, fields in which the EU has limited competence and has no competence to harmonise (Article 167 TFEU), but market regulation.  The Commission has pushed the extent of its harmonising powers before; while the AVMSD may have started off dealing with restrictions on cross-border advertising, it has also got a distinct cultural aspect (eg EU quotas). In this proposal, it is not clear how the measures listed actually map on to addressing the internal market problems identified in the Explanatory Memorandum. The extent to which a harmonising measure has to deal directly with the eradication of barriers to trade and the degree to which it may be directed at other policy issues has been the subject of a certain amount of jurisprudence, as the examples of Titanium Dioxide case (Case 300/89), Tobacco Advertising I (Case C-376/98), Swedish Match (Case C-210/03) and Vodafone (Case C-58/08) illustrate, and a cottage industry in legal commentary. On first glance, this proposal lies quite close to the boundary.  It is noteworthy that the justification given in recital 6 – that the audience should be able to receive cross boarder information flows – is linked to the satisfaction of the requirement in Article 11 of the Charter on Fundamental Rights. Yet, the Charter in itself is not a legal base for harmonising legislation. It is likely that this issue of competence may lead to legal challenge in the measure is enacted.

 

Place in the Digital Regulation Landscape

 

There will be a question of the interplay between this measure and others impacting on publicly available content. The measure is to a large part aware of this and cross refers to some of these relevant measures. It replicates some definitions from the AVMSD, albeit slightly tweaked. For instance the definition of ‘programme’ is in its base element the same that in the ADMSD (Art 1(b)) but excludes the reference in the AVMSD to “including feature-length films, video clips, sports events, situation comedies, documentaries, children's programmes and original drama”.  It is also notable that the definition of “media service” moves the focus of the service on to the provision  of programmes or press publications (Article 2(1), emphasis added); traditionally publications might have been thought to be goods! The definition of audiovisual media service remains the same as in the AVMSD. The terms “editorial decision” (Art 2(8)) and “editorial responsibility” (art 2(9)) seem to be aimed at drawing the boundary of these terms in the same place as the analogous terms in the AVMSD, though the language has been revised to reflect the broader scope of the Proposal.

 

The Proposal also notes the currently limited scope for the ERGA to take action; currently it is limited to audio-visual media services only.   The development of EBMS, however, follows the approaches taken in the DSA and also found in the EU’s approach to disinformation. Extending ERGA’s remit beyond audiovisual media services brings into question the historic difference in approach between broadcasting (and subsequently video on demand) and the print media, even in their online formats. It has long been accepted that regulation of broadcast entities is legitimate (even if different justifications might be given for that regulation) whereas the press has typically been subject to self-regulation. Giving ERGA (or the EBMS as it would become under the Proposal) a role starts to challenge that settlement.  It is worth reminding ourselves that the national regulatory bodies making up ERGA must meet certain independence requirements (and ERGA itself emphasises the importance of independence – as well as adequate resources!) – these independent bodies might start to have oversight over the press (in the areas covered by the proposal).  Again, this is a sensitive topic.

 

Media Independence

 

The Proposal does contain some important provisions that should benefit the maintenance of media independence – though of course the inclusion of these provisions recognises the distinctive nature of the media and the important role they play in an informed, democratic society. There are specific provisions on editorial independence and for public service media providers Member States will be under an obligation to ensure they have “have adequate and stable financial resources to fulfill their public service remit. These resources shall be such that editorial independence is preserved.” (Article 5).

 

This requirement for sufficient funding brings into law a principle long found in the Council of Europe recommendations on this area. Indeed, EU state aid law has also long recognised the need for State support (and the definition for public service media to a large extent reflects the position under Article 106(2) TFEU). How this is to be calculated or assessed however is not specified in the Proposal (the Recitals merely noting that a multi- year funding model is desirable – see Recital 18) and may cause tensions given the different levels of resources available and funding models used across the various Member States.  The Recitals are anxious to emphasise that this obligation does “not affect the competence of Member States to provide for the funding of public service media”, though it would seem that there is a shift from the permissive regime envisaged by Protocol 29 and the mandatory rule envisaged here. Currently Member States may provide such funding (subject to competition law and state aid rules in particular); this Proposal suggests that in future Member States must do so.

 

Moreover the Proposal introduces obligations so that the senior management is to be appointed according to transparent, non-discriminatory and objective procedures. They will also have term limits and can only be dismissed if it is determined that they are no longer fulfilling their legal duties. The rules around non-dismissal are commonly found to ensure institutional independence in regulators but are here extended to the media (though the Commission has noted that concerns remain regarding the independence of some regulators - Rule of Law Report (3.3) despite the provisions introduced by the 2018 amendments to the AVMSD). 

 

The specific obligations in Article 4(2) follow the lines set doewn in standard freedom of expression case law concerning journalists – notably the protection of journalists sources, and the importance of journalists’ communications remaining confidential, as noted in Recital 16. In this, the prohibition of spyware in Article 4(2)(c) seems to be a specific response to recent scandals showing the use of these technologies.

 

Transparency

 

The lack of transparency in media ownership has been seen as an issue specifically in relation to assessing plurality of the media as well as for users to make assessments as to likely bias in the information and opinions published by a media outlet, a point recognised in Recital 19. This was an issue on which there was little action in the individual Member States. The Commission’s Rule of Law report also noted “The transparency of media ownership continues to present on average a medium risk across Member States, due to a lack of effectiveness of legal provisions and to the fact that information is provided only to public bodies, but not to the public” (3.3). Against this background, the requirements to give information to the public is a step forward; it might be questioned how effective it will be, however, in the case of highly complex corporate structures. Moreover, the transparency obligations are limited in to those providing news and current affairs content.  This term, however, is not defined in the proposal – nor is it defined in the AVMSD.  There is a question as to whether the rules apply only to those whose purpose is to provide news and current affairs, or whether it includes providers whose offering includes news and current affairs. If so, how big a proportion of the offering should news and current affairs constitute to trigger the obligation? This of course assumes we know what news and current affairs comprises; but does this term encompass, for example, celebrity gossip? Broader aspects are contained in the recommendation and are therefore not binding.

 

Rules on VLOPs

 

It is unclear what the obligations on VLOPs add to the the obligations in the Platform to Business Regulation (“P2B Regulation”) – which could apply to VLOPs anyway – indeed, may apply much more broadly than to VLOPs or how the relationship between the two measures might be managed. 

 

VLOPs are likely to satisfy the definition of “online intermediation service providers” within the meaning of the P2B Regulation and therefore owe certain obligations to “business users”. It seems also likely that media service providers using VLOPs (or other platforms) to reach their audiences would constitute such “business users”, though perhaps some citizen journalists might fall outside this definition.  Having said that, would “citizen journalists” fall within the definition of media service for the purpose of the Proposal; ‘services’ within the TFEU are limited to economic activity – as Recital 7 to the Proposal recognises. It specifically notes that

 

[t]his definition should exclude user-generated content uploaded to an online platform unless it constitutes a professional activity normally provided for consideration (be it of financial or of other nature).

 

This might adversely affect charitable foundations and the like by contrast with influencers. Note, however, that the recital specifically excludes ‘[c]orporate communication and distribution of informational or promotional materials for public or private entities”.

 

Article 17(3) deals with complaints lodged by media organisations “with priority” and “without undue delay”, yet Article 11 of P2B requires online intermediation service providers to handle complaints “swiftly and effectively”. It is hard to see what added benefit is from the requirement in Article 17 regarding “undue delay” adds – indeed, it might be seen to be a lower standard than “swiftly”. The obligation to give media entities priority does seem to suggest that their complaints be dealt with in some sort of differentiated way.  This could be justified by the public interest in news and its perishable nature; however, it seems less good if such claims – no matter their merit - are automatically dealt with over other serious claims. While there might be specified time limits for dealing with certain sorts of content (notably terrorism), prioritising journalism leaves the victim of revenge porn, for example, relatively unprotected. This may of course be the nature of a legislative measure dealing with one type of content; specifying time scales that are not comparative in nature (implicitly ‘with priority’ is whereas ‘swiftly’, for example, is not) could avoid that problem.  Insofar as the Proposal envisages a separate mechanism for media entities, there is a risk of confusion as to which mechanisms for dispute resolution – whether those in the DSA or those envisaged here – should be used.

 

There is also a concern about the definition of media services which receive the benefit of this special treatment as it covers what have been termed ‘self-declared media’. This recalls the debates in the DSA’s legislative process to create a media exemption, but which was ultimately rejected.  The concern is that a wide range of actors could self declare as media entities for the purpose of this clause – perhaps benefitting those who spread disinformation. 

 

VLOPs are also required to allow their users to customise the audiovisual media offer (subject to Art 7a AVMSD) (Article 19). It is not clear the extent to which this overlaps with Article 27 DSA, which provides for recommender system transparency, and Article 38 to allow recommender systems not based on profiling.

 

Media Concentration

 

In the Commission’s Rule of Law Report, it notes that the media market is at risk from high levels of concentration. This seems to be a consequence of the dominance of online platforms in digital advertising and the adverse impact that has had on the financial stability of many media entities, a situation worsened during COVID. Against this background some controls on media concentration are required – though that then leaves the question of how the media entities are expected to survive in an environment dominated by clickbait content especially when the market dominance of the platforms and similar services are taken into account. This Proposal does not include those services into account. While the DMA provides some controls, it is not clear how the two sets of provisions will work together and whether there would be gaps (think for example of a cross media merger involving a platform and a content provider).  Finally, these questions seem to be dealt with at national level; rules may differ between Member States. The EBMS and the Commission are envisaged as having advisory roles. While this may respect divisions of competence, there are question about equality of enforcement – it remains to be seen (in the light of the experience of the GDPR) how well the co-operation provisions (Article 13, Article 14) work.

 

Resources

 

The final section relates to the measuring of audiences (indirectly affecting resources) and the allocation of State advertising – which is an important source of revenue in many places. Recital 29 notes that state advertising can be used as a form of covert public subsidy. Article 2(15) defines “State advertising” to mean the “placement, publication or dissemination … of a promotional or self-promotional message, normally in return for payment of for any other consideration, for or on behalf or any national or regional public authority” – this includes state-owned enterprises or other state-controlled entities.  This is a broad definition although there are limits on those subject to the obligation. For example, there is a de minimis threshold of local authorities with less than 1 million inhabitants. Recital 10 excludes “emergency messages by public authorities which are necessary, for example, in cases of natural or sanitary disasters, accidents or other sudden incidents that can cause harm to individuals”.  Although the Proposal envisages that the reporting on advertising spend should be monitored, it does not specify by which body.

 

Enforcement

 

One final point to note is that the Proposal does not include a specific mechanism for enforcement; the presumption seems to be that national mechanisms should be relied on (see eg Article 4(3)) (and the Q&A doc notes that any claimed breaches can be brought before national courts since the proposal – as a regulation – is directly applicable). This may, for example, give a route to relief for those subject to spyware – though the route to CJEU itself through the national courts – especially when those courts form part of the regime deploying the spyware and therefore may be unlikely to provide adequate relief themselves - may be long. It is also unclear what the precise role of the EBMS is in ensuring the consistent application of the Proposal.

 

Conclusion

 

In conclusion, the Proposal marks a significant shift in the current status quo and attempts the important job of safeguarding media independence – independence which has come under increasing threat in recent years. In so doing, however, pushes at the edges of EU competence. Moreover, some of the measures proposed may prove controversial as they seek to support the media against authoritarian regimes seeking to control them, not least with some Member States. The passage of this proposal is unlikely therefore to be smooth or easy; whether it achieves its stated aims is yet another question.