Showing posts with label Twitter. Show all posts
Showing posts with label Twitter. Show all posts

Sunday, 7 December 2025

The Digital Service’s Act Main Character: the EU Commission finally fines X

 


 

Steve Peers, Professor of Law, Royal Holloway University of London

Photo credit: Animated Heaven, via Wikimedia Commons

 

Introduction

The EU’s Digital Services Act (DSA) was conceived before Elon Musk bought Twitter (soon renaming it X); but they were literally born simultaneously, with the DSA being published in the EU’s Official Journal on the same day that Musk completed his takeover. Since then, Musk’s behaviour running X (see my review of a book on the takeover and the aftermath) has exemplified many of the reasons why the EU (and other jurisdictions) contemplated regulating social media in the first place: in particular arguments about the legality of its content and the fairness of its algorithms.

A Twitter user coined the phrase ‘today’s main character’ to describe a poster who becomes the centre of attention for a day – usually due to an absurd or obnoxious post that prompts many negative responses. For the DSA, X has been its main character since its creation, with much of the public debate about the potential use of the Act focussing on how it might apply to the controversial social network.

This debate has now come to a head. Last week, following its preliminary findings back in July 2024, the EU Commission adopted a final decision imposing a fine to enforce the DSA for the first time: €120 million for three breaches of the Act by X. This initial decision is likely to impact upon the broader debate over the Act’s implementation, and – due to Musk’s influence in the current Trump administration – also play a role in the fast-deteriorating relations between the EU and the US.

This blog post first provides an overview of the DSA, then examines the legal issues arising from this specific enforcement decision, and concludes with an assessment of the broader context of this decision: the enforcement of the DSA more generally, and the relations between the EU and the USA.

 

Background: overview of the Digital Services Act

Adoption of the DSA

Although the critics of the EU Commission fining X are quick to argue that the EU is undemocratic, EU legislation needs the support of elected Member State governments and elected Members of the European Parliament (MEPs) to be adopted. In fact, the Act received unanimous support from Member States and a large majority of MEPs.  

In any event, even without the Act, Member States would likely regulate social media – perhaps more quickly and more stringently than the EU has applied the Act in some cases. And even if the whole EU ceased to exist, as Elon Musk and Russian government mouthpieces demand, those countries would still be regulating Big Tech, with national equivalents of the Digital Markets Act and the GDPR, for instance. Indeed, despite leaving the EU, the UK has its own national versions of all three laws: the Online Safety Act, the Digital Markets, Competition and Consumers Act, and the UK GDPR, which sits alongside the Data (Use and Access) Act. While UK regulators may be famously timid about enforcing these laws, Australia – a long way from the EU – was not dissuaded from banning under-16 year olds from social media.

But until Musk and his sympathisers manage to destroy the EU, we have the DSA. It contains rules that govern online platforms generally, regardless of size, but its most prominent rules concern a special regulatory regime for the biggest platforms, defined as ‘very large online platforms’ (VLOPs) and ‘very large online search engines’ (VLOSEs), which subjects them to greater regulation. The Act gives the EU Commission power to designate such platforms and search engines (on the basis that 10% of the EU population visit them monthly) and to enforce the provisions of the DSA against them.

While some claim that the DSA was adopted only to punish US tech firms, the list of designated VLOPs and VLOSEs includes also Chinese companies (AliExpress, TikTok, Temu, Shein), EU companies (Booking.com, Zalando, and two porn sites), and a Canadian site, Pornhub. Overall, nearly half of the companies designated as operating VLOPs and VLOSEs are non-American (although some of the American companies operate more than one platform).

Content of the DSA

For VLOPs, enforcement of the DSA involves a number of measures, including requests for information, a start of an investigation into possible breach of the Act, a preliminary finding of a breach, and a final decision finding a breach – which can result in a fine (of up to 6% of worldwide annual turnover) and orders to change practices. A VLOP or VLOSE can also agree avoid a fine by agreeing binding commitments to change its practices with the Commission (in effect, a settlement) before it reaches a final decision. If a finding of breach is not complied with, the Commission can impose very high fines – up to 5% of worldwide annual turnover per day.

While many critics of X excitedly demand that the EU Commission ban it, the Act imposes a very high threshold before a ban can be imposed – essentially a refusal to remove illegal content, with additional safeguards including involvement of a court. The case law has not yet fleshed out the relationship between the DSA and Member States’ laws on overlapping issues, or clarified whether there can be private enforcement of the DSA (ie individuals challenging the VLOPs and VLOSEs in court for breach of the Act, rather than the Commission enforcing it) in parallel.

Substantively, the Act’s requirements on VLOPs and VLOSEs (in its Articles 33-43) start with risk assessment: they must ‘diligently identify, analyse and assess any systemic risks in the Union stemming from the design or functioning of their service and its related systems, including algorithmic systems, or from the use made of their services’. Systemic risks are further defined as including ‘dissemination of illegal content through their services’, ‘negative effects’ upon various human rights, ‘actual or foreseeable negative effects on civic discourse and electoral processes, and public security’, and ‘actual or foreseeable negative effects in relation to gender-based violence, the protection of public health and minors and serious negative consequences to the person’s physical and mental well-being’.  

Very large platforms and search engines are also obliged to (as further defined): mitigate these risks; comply with a decision requiring a response to a crisis; perform independent audits; offer a recommender system not based on profiling, at least as an option; make public a repository of advertising data; provide access to their data to researchers; explain their algorithms to regulators; establish independent compliance bodies; provide further public data on their operations; and pay an annual supervisory fee to the EU Commission.

The DSA in the EU courts

Even before the first fine was imposed to enforce the DSA last week, its application in practice has been frequently litigated. First of all, Amazon, Zalando and several porn sites have challenged their designation as VLOPs. Zalando lost its challenge in the EU General Court in September, but has appealed to the EU’s Court of Justice (appeal pending). More recently Amazon also lost its challenge in the EU General Court against designation as a VLOP, but it still has time to appeal that judgment to the Court of Justice (Amazon had won an interim measures ruling in this case – delaying its obligation to publish information about its advertisers – but that interim measure was overturned by the Court of Justice, following a successful appeal by the Commission).

The porn companies’ legal challenges to their designations as VLOPs are still pending (see the summary of the arguments made by Pornhub, XNXX and XVideos; a challenge by Stripchat is also still pending even though the Commission has dropped its designation as a VLOP); their applications for interim measures as regards publishing advertisers’ information have been dismissed (see the General Court orders re Pornhub and XVideos, and the failed appeals to the Court of Justice as regards Pornhub and XVideos).  

Of these cases, the recent Amazon judgment has broad implications for the DSA as a whole, considered further below.

Secondly, the Commission’s decisions on fees for regulation (for 2023) have also been challenged. These challenges were all successful in the EU General Court (see the judgments as regards Tiktok and Meta), although the Commission has appealed both the Tiktok and Meta judgments to the Court of Justice (appeals pending). In the meantime, Tiktok, Meta and Google have brought a further round of legal challenges (all still pending) to the regulation fees imposed for 2024.

We can also now expect X to challenge the enforcement decision against it. (If it also requests interim measures, at least that aspect of the case will be decided soon).

Other enforcement of the DSA

In addition to the new decision enforcing the DSA against X, other Commission enforcement actions under the DSA have been adopted or are pending against VLOPs. Leaving aside requests for information (such as the one recently sent to Shein as regards reports of sales of child-like sex dolls):

-          The Commission has accepted binding commitments from AliExpress on various issues, but at the same time also adopted a preliminary finding that its risk assessment as regards illegal products was insufficient;

-          It has opened proceedings against porn sites for inadequate protection of children;

-          It has adopted a preliminary finding that Meta (Facebook and Instagram) is in breach as regards researchers’ access to data, and as regards flagging illegal content and allowing for appeals against content moderation decisions; an investigation as regards deceptive advertising, political data, and misinformation on Meta is still underway; and

-          It has adopted a preliminary finding that Temu has breached the DSA as regards illegal products, and an investigation continues as regards other issues

Finally, the Commission has been particularly active as regards TikTok. It has accepted a commitment to suspend the ‘TikTok Lite’ programme, which was apparently designed to (further) encourage social media addiction by children, having used the threat of issuing an intention to impose interim measures under the DSA earlier on in this case. A new decision, following a preliminary finding, accepts further commitments regarding information on advertisers – also a great irritant to Amazon and the porn companies, as can be seen in the litigation summarised above, as well as an issue in the X case, discussed below. TikTok has deadlines to implement the various commitments it has made, and there are specific powers to monitor whether it is complying with them under the DSA. The Commission has also adopted a preliminary finding against TikTok as regards researchers’ access to data, and further investigations against Tiktok are still underway.

Overall, it can be seen that to date the majority of enforcement actions under the DSA have been initiated against companies that are not American. Also, to date all the offers of binding commitments that have been accepted, in place of fines and enforcement orders, have come from Chinese companies. The potential of negotiating binding commitments instead of an enforcement order is, however, open to a VLOP based anywhere.  

 

The non-compliance decision against X

What did the decision address?

First and foremost, the non-compliance decision against X only concerns certain issues, namely deceptive practices as regards X’s ‘blue ticks’,* researchers’ access to data, and the repository of advertisers. The Commission complaint about ‘blue ticks’ is that they are a ‘deceptive practice’ banned by the DSA (note that this rule applies to platforms generally, not just VLOPs), in that they purport to indicate that an account has been verified, when it has not been. Under Musk, X has earned revenue from the blue ticks by selling them to anyone willing to pay for them, although the sale of the ticks, and the monetisation programme (ie giving money to X users whose posts lead to large numbers of reactions) are apparently not the subject of the non-compliance decision as such. The preference given to blue ticks in the X algorithm is not the subject of the decision as such either.

(*Disclosure: I applied for and obtained a ‘blue tick’ from Twitter prior to Musk’s purchase, when a proper verification system applied. I did not pay for the tick under Musk, and it was initially removed as a result. However, it was reinstated involuntarily – not at my request, and without my paying for it, or monetising my posts – as part of a process of reducing the social opprobrium of having a blue tick under Musk, in which the ticks were reinstated for some accounts. I initially hid the reinstated tick, but the facility to do that was removed. It remains there today; I have not used X since August 2024, due to my objection to Musk encouraging violent racial conflict in the UK, except for a handful of posts encouraging others to leave the platform. I have retained my account there to reduce the risk of anyone impersonating me, which has happened several times.)

The Commission has not yet made a final decision – or even a preliminary finding – as regards other issues involved in its opening of proceedings against X, namely the dissemination of illegal content and the effectiveness of rules against disinformation.

How can the decision be enforced?

X now has 60 days to inform the Commission about measures it will take to enforce the non-compliance decision as regards blue ticks. It has 90 days to submit an action plan to address the other two issues, and the Commission must respond to the action plan two months after that. In the event of non-compliance with the decision, as noted above the DSA gives the Commission the power to impose much higher fines. The method of calculation of last week’s fine is not explained in the press release. (The non-compliance decision itself may explain the calculation, but like most DSA decisions of the Commission, it has unfortunately not been made public; Article 80 of the DSA requires the main content of this decision to be published though)

If X challenges the decision in the EU courts, it can request an interim measures ruling suspending all or part of the decision; the EU General Court will decide on that (subject to appeal to the Court of Justice), as it has done in several DSA cases already, as detailed above. The final judgment of the EU courts can annul the Commission’s non-compliance decision in whole or part, and the DSA (Article 81) gives the EU courts unlimited jurisdiction to cancel, increase or reduce the fine. As for the collection of the fine (and any further fines that might be imposed on X for continued breach of the DSA), Article 299 TFEU sets out the process of enforcing fines imposed by EU bodies; although if X removes all its assets from the EU to the US, it might try to prevent collection by using US law that blocks the enforcement of foreign judgments on ‘free speech’ grounds (perhaps the SPEECH Act, although that concerns defamation; other routes may be available, or fresh routes adopted in light of the Commission decision).

This brings us neatly to the question of whether the non-compliance decision is arguably invalid on ‘free speech’ (or other) grounds.

Is the decision legal?

What are the legal issues as regards last week’s non-compliance decision? As noted above, the recent judgment in the Amazon case addresses two of the issues in the non-compliance decision (advertising repositories and access to data), while also addressing broader criticisms of the Act, some of which may be relevant if X challenges the finding as regards ‘deceptive practices’, or takes this opportunity to challenge the legality of the Act more generally (as Amazon did when challenging the legality of its designation as a VLOP; on such challenges, see Article 277 TFEU).

Amazon’s legal challenge to its VLOP designation did not advance the obviously untenable argument that fewer than 10% of the EU population uses Amazon monthly (conversely, Zalando and the porn sites are arguing about the calculation of the numbers). Rather, Amazon argued that the entire system of special rules for VLOPs in the DSA was invalid, because it violated a number of human rights set out in the EU Charter of Fundamental Rights. All of these arguments were rejected by the EU General Court.

First of all, the Court rejected the argument that the VLOP regime breached the freedom to conduct a business (Article 16 of the Charter). In the Court’s view, although the regime interfered with the freedom to conduct a business, because it imposed significant costs on VLOPs and also had a considerable impact on their organisation or required complex technical solutions, that freedom was not absolute, and the interference with it was justified. According to Article 52(1) of the Charter, limitations on Charter rights have to be prescribed by law, have public interest objectives, respect the essence of the right and be proportionate. Here the limits were admittedly prescribed by law (being set out in the Act) and respected the essence of the right (as Amazon could still carry out its core business); Amazon instead argued mainly that the limits were disproportionate, as online shops did not present systemic risks, the objectives could be satisfied by less onerous means, and the costs were significant. However, the Court believed that there was a systemic risk of illegal content in online marketplaces; other means of designating VLOPs were not necessarily more proportionate; making advertising repositories open to the public was justified in the interests of consumer protection; and the arguments about economic impact made by Amazon as regards recommender systems, researchers’ access to data and advertiser repositories were unconvincing.

Secondly, Amazon’s argument that its right to property was infringed (Article 17 of the Charter) was dismissed at the outset, as it had not identified any of its property rights that were affected by the DSA: an administrative burden did not constitute interference with a property right. Thirdly, the Court rejected the argument that the VLOP regime breached the general right to equal treatment (Article 20 of the Charter), by treating larger companies differently from smaller ones, on the grounds that larger companies presented bigger risks.

Fourthly, Amazon’s arguments about freedom of expression (Article 11 of the Charter) were rejected too. This argument was only made as regards applying the DSA rules on recommender systems to Amazon. On this point, the Court reiterated that the Charter freedom of expression rules must be interpreted consistently with the freedom of expression set out in Article 10 of the European Convention on Human Rights (ECHR), referring also to the case law of the European Court of Human Rights (ECtHR). The Court did not see how the freedom of expression of third-party sellers might be affected by the DSA rules, but it accepted that Amazon’s freedom of expression was limited by having to offer a recommender system not based on profiling.

However, limitations of the right could be justified: the limitation here was prescribed by law; it did not affect the essence of the right (as Amazon could still offer a profiling-based recommender system as an option); it had an objective of general interest (consumer protection); and it was proportionate by only requiring the offer of one non-profiling based recommender system as an option – taking account of ECtHR case law that allows more interference with commercial expression than political expression.

Finally, Amazon complained about a breach of the right to privacy (Article 7 of the Charter). This was a remarkable thing for a company with a business model based on surveillance of its customers to argue about, but the Court considered its arguments seriously nonetheless. Again it followed the ECtHR case law on the corresponding rule (Article 8 ECHR), which states that businesses could invoke the right to privacy. Here the argument concerned the DSA rules on ad repositories and researchers’ access to data. Again the EU court agreed that the DSA interfered with the right, but ruled that it could be justified: it was prescribed by law, did not infringe the essence of the right, and complied with the principle of proportionality, particularly because of the limits built in to the obligations (for instance, no obligation to disclose the personal data of advertising recipients, or about the success of advertising; controls on which researchers can access the data).

How does this judgment (noting that Amazon could still appeal it to the Court of Justice) apply to a legal challenge that X might make to last week’s non-compliance decision? First of all, the judgment in principle disposes of many arguments that X might make about two aspects of the non-compliance decision, as regards ad repositories and researchers’ access to data – although X might try different arguments, or contend that the nuances of its case are different.

While the main US response to the EU Commission’s decision has been to claim that the EU is engaged in censorship, note that Amazon did not even argue that the DSA rules on ad repositories or researchers’ access to data infringed freedom of expression, and remember that X is only being investigated for the dissemination of illegal content and the effectiveness of rules against disinformation. Obviously a freedom of expression argument might be made in respect of those issues, but, as noted above, X has not been subjected to a final decision or even a preliminary finding in respect of them.

Furthermore, according to the Amazon judgment, a VLOP challenging a Commission decision under the DSA can only challenge the validity of those parts of the DSA that are the legal basis for the decision made against them: so X cannot, at this point, specifically attack the validity of the DSA rules on risk assessment or risk mitigation, since there is no decision that it has breached them yet.  X can attack the validity of the DSA system for VLOPs generally, which includes the rules on risk assessment and risk mitigation. Although Amazon has already tried this and failed, X might try to argue its case differently; but it looks like a long shot, given that a non-compliance decision is inherently more narrowly focussed than designation as a VLOP.

Another key point to remember in this debate is that, as the Amazon judgment confirms, the human rights standards applied by the EU courts are those of the EU Charter, interpreted (where relevant) in light of the corresponding ECHR rights, and the ECtHR case law on those rights. The ECHR approach to rights differs in some respects from that of the US courts, arguably providing greater protection for the right to privacy (although not enough for Amazon to win its arguments on this point), but lesser protection for the right to free speech (allowing more leeway for interference with the right). But that is the nature of doing business in another jurisdiction. US law may take the view that (hypothetical) X user ‘ZyklonB1488’, regularly posting ‘Next year in Auschwitz!’ at Jewish people, has the right to set out his stall in the marketplace of ideas. But other legal systems may legitimately take the view that he does not.

Applying this to the sole remaining issue in the Commission’s non-compliance decision – the deceptiveness of X’s blue tick system – this is not directly connected to the content of what blue tick holders (still less anyone else) may post on X. Any effect on freedom of expression of last week’s decision is therefore marginal – although again, free speech arguments would be stronger as regards future decisions the Commission might make in respect of X as regards other issues still under investigation (or Meta – subject to some broadly similar investigations, as summarised above), especially because ‘illegal content’ is the one breach of the DSA that might (subject to many conditions and safeguards) lead to a ban on the whole platform. And to the extent that the non-compliance decision on blue ticks does interfere with freedom of expression, there is a strong argument that the interference is justified both on the ground of consumer protection (cf the scams featuring impersonations of consumer advocate Martin Lewis) and (as Article 52 of the Charter also provides for) on the ground of ‘the need to protect the rights and freedoms of others’ (ie anyone being impersonated, including myself!).

 

Context: enforcing the DSA

Last week’s decision is a definitive sign that the Commission is willing to enforce the DSA, even to the extent of adopting non-compliance decisions. The world is full of ‘light-touch’ regulators – perhaps one of Britain’s more unappealing exports. Usually, the Commission is not seen as such; but its obvious stalling on taking a final decision regarding X, for 17 months since its provisional findings, may have given the impression that – on the DSA, at least – the lion had turned pussycat.

The non-compliance decision should be viewed alongside with the Amazon judgment, which it likely also takes account of. VLOPs now know not only that the Commission is willing to act to enforce the DSA, but also that the EU courts (subject to possible appeal) back up at least some key provisions of the Act. Also, the recent judgment may explain TikTok’s simultaneous willingness to agree on its compliance with the ad repository rules; and the Commission’s willingness (again) to accept commitments, combined with the recent judgment, shows VLOPs that it may be less hassle to negotiate commitments with the Commission, rather than embark upon court action that is unlikely to succeed.  The context also includes a dog that did not bark: the Commission did not propose any amendment to the DSA (or the Digital Markets Act) in its recent proposal for an ‘omnibus’ bonfire of some provisions of EU tech laws.

Having said that, it is striking that the Commission is moving forward on non-compliance decisions and preliminary findings other than on the issues relating more closely to content on social media networks (cf the ongoing investigations into Meta and X), which raise not only the more difficult legal issues (given their greater impact upon freedom of expression) but also have the greater political impact (given the subject-matter, and the closeness of both zillionaire owners to the US government). And this brings us nicely to the impact of the decision upon US/EU relations.  

 

Context: EU-USA relations

Coincidentally, the non-compliance decision was released the day after the US government published a foreign policy review that was intrinsically hostile to the EU, and hyperpartisan in its support of right wing populist parties in Member States. In that context, the decision against X is just a drop in the rapidly-widening Atlantic Ocean. Famously, US diplomat Dean Acheson was ‘present at the creation’ of the post-war alliance; the Trump administration’s goal seems to be to preside over its destruction.

Yet, as noted already, supporters of Trump are nevertheless enraged by the decision, despite its limited impact. Even though, as explained above, the DSA was approved by elected governments and MEPs, does not solely apply to US companies and is not solely enforced against US companies, and the recent decision has at best a marginal impact upon freedom of expression, the response is the same: “They’re eating our free speech!”

Of course, it’s hard to take concerns about free speech from the Trump administration seriously: these are folks who want to expel legal migrants for criticism of a foreign government, and whose leader, between naps, frequently insults and threatens journalists who are insufficiently North Korean in their adoration of him. If these people are genuine free speech defenders, then I’m Alexander Hamilton.

As hypocritical and inaccurate as the Trumpian reactions to the decision are, they were presumably anticipated by the Commission before it took its decision. Even if the EU courts rule in the Commission’s favour in the event of a legal challenge, its MAGA critics will likely remain just as irrational (“They’re eating the snails!”). Yet the Commission took the decision anyway.

The choice to go ahead with the decision regardless can be understood either as a calculated risk that the US will not punish the EU for it – at least no more than it was inclined to punish the EU anyway, for various other reasons – or that even if the US does punish the EU for the decision, it is worth exercising its regulatory powers anyway. Perhaps this is a response to the perception that the Commission had seemed unwilling to stand up to Trump to date. Or maybe the assumption is that Trump is unlikely to pay much attention to this matter for long, particularly if the EU can devise a way to distract him: something like a shiny gold award for ‘best European’, for ending the war between Narnia and Freedonia, may work.  

Whatever happens, the Commission’s decision was certainly a gamble, in the current context of fraught EU/US relations, with far broader trade and security issues at stake. Time will tell whether this assertion of regulatory strength is worth it in light of the reaction it may trigger.

 

Friday, 27 September 2024

So long, no thanks to all the fash: review of Character Limit: How Elon Musk Destroyed Twitter, by Kate Conger and Ryan Mac



Professor Steve Peers, Royal Holloway University of London

Photo credit: mikemacmarketing, image via vpnsrus

 

Full disclosure first: After exactly ten and a half years, I stopped posting on X (formerly Twitter) on August 10, 2024. I could not accept the owner’s view that those encouraging race riots in Britain online should not be punished, his promotion of those who held such views, or his racist memes about the British justice system that sought to bring them to account. I was not alone: X lost 30% of its UK users in the last year, and 20% of its US users. How did the supposed ‘global public square’ end up in this position?

The answer is obviously the owner, Elon Musk; and the new book by Kate Conger and Ryan Mac, Character Limit, recounts the story in detail. They divide the book into three acts. In Act One, dominated by former boss Jack Dorsey – depicted here as a diffident dude phoning in his governance from tropical islands – the story is retold until Musk makes his bid for Twitter. Act Two recounts the process of that bid, culminating in his purchase of the company. Act Three covers the subsequent developments: the frantic cost cutting, the frenzied management style, the fast-disappearing advertisers. The book ends in late 2023, with a short epilogue from early 2024 in which the authors astutely note that Musk has replaced Trump on the platform – in effect taking his place as Twitter’s main character. Musk’s personality – a fragile, petty, vicious, paranoid, narcissistic man-child – drives the narrative of the book. Musk’s legion of fanboys are frequently referred to, largely murmuring offstage like a Greek chorus manifesting as a Simpsons meme.

The book is highly readable – compelling the reader to turn its pages in much the same way that legal academic books don’t. It’s a highly personalised retelling of events, and one can easily imagine a Netflix version of its cinematic story – with its ending scene matching Hearst’s deathbed sled revelations, or Zuckerberg’s obsessive page refreshing, with Musk’s very public suggestion that advertisers “go fuck yourself”.

There’s a detailed account of sources, but in the journalistic tradition some of them are off the record interviews. One thing this academic would have liked to have seen would have been some broader analysis of why things developed as they did: was this all an inevitable consequence of the political and social media dynamics of the last few years, or an example of the (not so) great man theory of history?

If the latter, what explains Musk’s behaviour exactly? Drug use is mentioned – in a passage appearing so heavily lawyered that it has its own sharp and useless look about it. Nevertheless, the reader will notice Musk’s obvious extreme mood swings and erratic behaviour. At first, the prospect of saving Twitter financially may be have been taken seriously: the authors usefully remind the reader that Twitter often lost money even before Musk’s takeover (it also had controversies about hate speech already, and the previous management was planning to cut staff before Musk did). But that motivation is hard to take seriously for long, as advertisers (Twitter’s main source of income) started fleeing from the outset, with no lessons learned from their exit. Rather, it seems that the main incentive was Musk’s personal obsession with Twitter, also mentioned at several points; the political objectives that many have suggested are not much explored.

Having said that, this is a very readable book, for those interested in the fate of this well-known social network over the last decade. And one striking feature for this reader is the role of the law in all this.

It’s obvious throughout that Musk cares nothing, and knows less, about the law; he shares these traits with such luminaries as Donald Trump, Boris Johnson, and Dominic Cummings. Although he has an early victory when a jury inexplicably clears him of defaming a critic of his Thai cave rescue attempt as a ‘pedo’, other litigation and regulatory struggles are a constant theme. Musk is only compelled to complete his purchase of Twitter due to litigation brought by its board (bound, as the authors frequently point out, by their fiduciary duty to shareholders) to enforce the deal Musk signed without undertaking prior due diligence. Compliance with an FTC consent order regarding privacy is an ongoing issue. Massive staff cuts lead to litigation over employment law and executive compensation. Twitter stops paying Thorn – a specialist in detecting online child abuse material. Conflict with a Brazilian judge over Twitter’s refusal to take down tweets backing Bolsonaro’s coup attempt leads to well-known consequences (although they occur after the book’s finale). Refusal to pay rent sparks legal challenges worldwide. And having cancelled the cleaners and crammed staff into less space in Twitter’s headquarters to save on office costs, the washrooms are soon overused. As cockroaches scuttle from the drains, desperate staff bring toilet paper from home or flee to nearby coffee shop loos to avoid those in Twitter offices. Cory Doctorow famously developed a thesis about the ‘enshittification’ of online businesses; he probably never expected it to be quite so literal.

I think it’s possible that future brushes with the law will concern in particular the EU’s Digital Services Act (DSA) – which, in a remarkable coincidence, was published in the EU’s Official Journal on the same day that Musk completed his takeover of Twitter. X is already the subject of the first preliminary findings of a breach of the Act on some issues, and investigations into further issues – including illegal content, the one thing that could get X suspended in the EU – are ongoing. I wonder if the risk assessments required by the Act should take specific account of the personal behaviour of the owner of a very large online platform – given Musk’s direct role in spreading disinformation and the negative effect of his posts on civic discourse, electoral process and gender-based violence. Recently, Musk threatened to give Taylor Swift a baby; but regulators gonna regulate.

A particular issue throughout the book – and an implied obligation under the DSA – is content moderation. It raises a series of inherent contradictions. Reflecting the sometimes conflicting human rights of freedom of expression and equality, the DSA requires very large online platforms to ensure free speech while considering the need to limit it. As for users, the book makes clear that content moderation repels free speech advocates while attracting opponents of hate speech; it costs money but its absence loses revenue, as advertisers are alarmed to see their ads appearing next to Nazis. But it is also clear from the book that Musk’s supposed free speech fundamentalism is hypocritical, as he bans and fires critics while acceding to censorship demands of the Indian government. As so often with authoritarians, there is an in-group which the law protects but does not bind – and an out-group which it binds but does not protect.

One final thought about the consequences of unlimited speech, returning to the reason why I stopped posting on the platform. When defending the ‘rights’ of those encouraging race riots in Britain, Musk and his fans compared those supporting limits on such speech to communists and Nazis. Let’s put this in historical context. After I flew to Vienna for a holiday after departing X, I visited the Sigmund Freud museum and was struck by the fact that his four sisters, staying behind in Vienna after he fled to London, all died in 1942-3. Their deaths were not caused by those who tried to censor Nazis, but by the Nazis themselves. And the postwar allies were not confused about this: Julius Streicher was tried, convicted and executed at Nuremberg for publishing the extremely anti-semitic Der Sturmer. Incitement played a role in the Holocaust. Words have consequences; and the real extremists are those who demand that the advocacy of hatred and violence should not be effectively limited.

Tuesday, 11 January 2022

A democratic alternative to the Digital Services Act's handshake between States and online platforms to tackle disinformation

 



 

By Paul De Hert* and Andrés Chomczyk Penedo**

 

* Professor at Vrije Universiteit Brussel (Belgium) and associate professor at Tilburg University (The Netherlands)

** PhD Researcher at the Law, Science, Technology and Society Research Group, Vrije Universiteit Brussel (Belgium). Marie SkÅ‚odowska-Curie fellow at the PROTECT ITN. The author has received funding from the European Union’s Horizon 2020 research and innovation programme under the Marie SkÅ‚odowska-Curie grant agreement No 813497

 

 

 

1. Dealing with online misinformation: who is in charge?

 

Misinformation and fake news are raising concerns for the digital age, as discussed by Irene Khan, the United Nations Special Rapporteur on the promotion and protection of the right to freedom of opinion and expression (see here). For example, during the last two years, the COVID19 crisis caught the world by surprise and considerable discussions about the best course of action to deal with the pandemic were held. In this respect, different stakeholders spoke up but not all of them were given the same possibilities to express their opinion. Online platforms, but also traditional media, played a key role in managing this debate, particularly using automated means (see here).

 

A climate of polarization developed, in particular on the issue of vaccination but also around other policies such as vaccination passports, self-tests, treatment of the virus in general, or whether the health system should focus on ensuring immunity through all available strategies (see here). Facebook, YouTube, and LinkedIn, just to name a few, stepped in and started delaying or censoring posts that in one way or another were perceived as harmful to governmental strategies (see here). While the whole COVID19 crisis deserves a separate discussion, it serves as an example of how digital platforms are, de facto, in charge of managing online freedom of expression and, from a practical point of view, have the final say in what is permissible or not in an online environment.

 

The term 'content’ has been paired with adjectives such as clearly illegal, illegal and harmful, or legal but harmful, just to name the most relevant ones. However, what does exactly each of these categories entail, and why are we discussing these categories? What should be the legal response, if any, to a particular piece of content and who should address it? While content and its moderation is not a new phenomenon, as Irene Khan points in her previously mentioned report, technological developments, such as the emergence and consolidation of platforms, demand new responses.

 

With this background, the European Union is currently discussing at a surprisingly, very quick speed the legal framework for this issue through the Digital Services Act (the DSA, previously summarised here). The purpose of this contribution is to explore how misinformation and other categories of questionable content are tackled in the DSA and to highlight the option taken in the DSA to transfer government-like powers (of censorship) to the private sector. A more democratic alternative is sketched. A first one is based on the distinction between manifestly illegal content and merely illegal content to distribute better the workload between private and public enforcement of norms. A second alternative consists in community-based content moderation as an alternative or complementary strategy next to platform-based content moderation

 

 

2. What is the DSA?

 

The DSA (see here for the full text of the proposal and here for its current legislative status) is one of the core proposals in the Commission’s 2019-2024 priorities, alongside the Digital Markets Act (discussed here), its regulatory ‘sibling’. It intends to refresh the rules provided for in the eCommerce Directive and deal with certain platform economy-related issues under a common European Union framework. It covers topics such as: intermediary service providers liability - building up from the eCommerce Directive regime and expanding it -, due diligence obligations for a transparent and safe online environment -including notice and takedown mechanisms, internal complaint-handling systems, traders traceability, and advertising practices-, risk management obligations for very large online platforms and the distribution of duties between the European Commission and the Member States. Many of the these topics might demand further regulatory efforts beyond the scope of the DSA, such as political advertisement which would be complemented by sector-specific rules as, for example, the proposal for a Regulation on the Transparency and Targeting of Political Advertising (see here).

 

As of late November 2021, the Council has adopted a general approach to the Commission’s proposal (see here) while the European Parliament is still dealing with the discussion of possible amendments and changes to that text (see here). Nevertheless, as with many other recent pieces of legislation (see here), it is expected that its adoption is sooner rather than later in the upcoming months.

 

3. Unpacking Mis/Disinformation (part1): illegal content as defined by Member States

 

We started by discussing misinformation and fake news. If we look at the DSA proposal, the term 'fake news' is missing in all its sections. However, the concept of misinformation appears as disinformation in Recitals 63, 68, 69, and 71. Nevertheless, both terms are nowhere to be found in the Articles of the DSA proposal.

 

In literature, the terms are used interchangeably or are distinguished, with disinformation defined as the intentional and purposive spread of misleading information, and misinformation as ‘unintentional behaviors that inadvertently mislead’ (see here). But that distinction does not help in recognizing either mis- or disinformation, from other categories of content.

 

Ó Fathaigh, Helberger, and Appelman (see here) have pointed that disinformation, in particular, is a complex concept to tackle and that very few scholars have tried to unpack its meaning. Despite the different policy and scholarly efforts, a single unified definition of mis- or disinformation is still lacking, and the existing ones can be considered as too vague and uncertain to be used as legal definitions. So, where shall we start looking at these issues? A starting point, so we think, is the notion of content moderation, which according to the DSA proposal, is defined as follows:

 

'content moderation' means the activities undertaken by providers of intermediary services aimed at detecting, identifying, and addressing illegal content or information incompatible with their terms and conditions, provided by recipients of the service, including measures taken that affect the availability, visibility, and accessibility of that illegal content or that information, such as demotion, disabling of access to, or removal thereof, or the recipients' ability to provide that information, such as the termination or suspension of a recipient's account (we underline);

 

Under this definition, content moderation is an activity that is delegated to providers of intermediary services, particularly online platforms, and very large online platforms. Turning to the object of the moderation, we can ask what is exactly being moderated under the DSA? As mentioned above, moderated content is usually associated with certain adjectives, particularly illegal and harmful. The DSA proposal only defines illegal content:

 

‘illegal content’ means any information, which, in itself or by its reference to an activity, including the sale of products or provision of services is not in compliance with Union law or the law of a Member State, irrespective of the precise subject matter or nature of that law;

 

So far, this definition should not provide much of a challenge. If the law considers something as, it makes sense that it is similarly addressed in the online environment as in the physical realm. For example, a pair of fake sneakers constitute a trademark infringement, regardless of if the pair is being sold via eBay or by a street vendor in Madrid’s Puerta del Sol. In legal practice, regulating illegal content is not black and white. A distinction can be made between clearly illegal content and situations where further exploration must be conducted to determine the illegality of certain content. This is how it is framed in the German NetzDG, for example. In some of the DSA proposal articles, mainly Art. 20, we can see the distinction between manifestly illegal content and illegal content. However, this distinction is not picked up again in the rest of the DSA proposal.

 

What stands is that the DSA proposal does not expressly cover disinformation but concentrates on the notion of illegal content. If Member State law defines and prohibit mis- or disinformation -which Ó Fathaigh, Helberger and Appelman have reviewed and found to be inconsistent across the EU- , then this would fall under the DSA category of illegal content. Rather than creating legal certainty, this further reinforces legal uncertainty and pegs the notion of illegal content to be dependent on each Member State's provisions. But where does this leave disinformation that is not regulated in in Member State laws? The DSA does not like it, but its regulation is quasi hidden.

 

 

4. Unpacking Mis/Disinformation (part2): harmful content non defined by the DSA

 

The foregoing brings us to the other main concept dealing with content in the DSA, viz. harmful content. To say that this is a (second) 'main' concept might confuse the reader, since the DSA does not define it or regulate it at great lengths.  The DSA’s explanatory memorandum states that `[t]here is a general agreement among stakeholders that ‘harmful’ (yet not, or at least not necessarily, illegal) content should not be defined in the Digital Services Act and should not be subject to removal obligations, as this is a delicate area with severe implications for the protection of freedom of expression’.

 

As such, how can we define harmful content? This question is not new by any means as we can trace back policy documents from the European Union dating back to 1996 (see here) dealing with this problem. Since then, little has changed in the debate surrounding harmful content as the core idea remains untouched: harmful content refers to something that, depending on the context, could affect somebody due to it being unethical or controversial (see here).

 

In this respect, the discussion on this kind of content does not tackle a legal problem but rather an ethical, political, or religious one. As such, it is a valid question to be asked if laws and regulations should even mingle in this scenario. In other words, does it make sense to talk about legal but harmful content when we discuss new regulations? Should our understanding of illegal and harmful content be construed in the most generous way to accommodate for the most amount of situations possible to avoid this issue? And more importantly, if the content seems to be legal, does it make sense to add the adjective of ‘harmful’ rather than using, for example, ‘controversial’? Regardless of the terminology used, this situation leaves us with three types of content categories: (i) manifestly illegal content; (ii) illegal, both harmful and not, content; (iii) legal but harmful content. Each of them demands a different approach, which shall be the topic of our following sections.

 

 

5. Illegal content moderation mechanisms in the DSA (content type 1 & 2)

 

The DSA puts forward a clear, but complex, regime for dealing with all kinds of illegal content. As a starting point, the DSA proposal provides for a general no monitoring regime for all intermediary service providers (Art. 7) with particular conditions for mere conduits (Art. 3), caching (Art. 4), and hosting service providers (Art. 5). However, voluntary own-initiative investigations are allowed and do not compromise this liability exemption regime (Art. 6). In any case, once a judicial or administrative order mandates the removal of content, this order has to be followed to avoid incurring liability (Art. 8). In principle, public bodies (administrative agencies and judges) have control over what is illegal and when something should be taken down.

 

However, beyond this general regime, there are certain stakeholder-specific obligations spread out across the DSA proposal also dealing with illegal content that challenge the foregoing state-controlled mechanism. In this respect, we can point out the mandatory notice and takedown procedure for hosting providers with a fast lane for trusted flaggers notices (Arts. 14 and 19, respectively), in addition to the internal complaint-handling system for online platforms paired with the out-of-court dispute settlement (Arts. 17 and 18, respectively) and, in the case of very large online platforms, these duties should be adopted following a risk assessment process (Art. 25). With these set of provisions, the DSA grants a considerable margin to certain entities to act as law enforcers and judges, without a government body having a say in if something was illegal and its removal was a correct decision.

 

6. Legal but harmful content moderation mechanisms in the DSA (content type 3)

 

But what about our third type of content, legal but harmful content, and its moderation? Without dealing with the issue of content moderation directly, the DSA transfers the delimitation of this concept to providers of online intermediary services, mainly online platforms. In other words, a private company can limit apparently free speech within its boundaries. In this respect, the DSA proposal grants all providers of intermediary services the possibility of further limiting what content can be uploaded and how it shall be governed via the platform’s terms and conditions and, by doing so, these digital services providers are granted substantial power in regulating digital behavior as they see fit:

 

‘Article 12 Terms and conditions

 

1. Providers of intermediary services shall include information on any restrictions that they impose concerning the use of their service in respect of information provided by the recipients of the service, in their terms and conditions. That information shall include information on any policies, procedures, measures, and tools used for content moderation, including algorithmic decision-making and human review. It shall be set out in clear and unambiguous language and shall be publicly available in an easily accessible format.

 

2. Providers of intermediary services shall act in a diligent, objective, and proportionate manner in applying and enforcing the restrictions referred to in paragraph 1, with due regard to the rights and legitimate interests of all parties involved, including the applicable fundamental rights of the recipients of the service as enshrined in the Charter.’

 

In this respect, the DSA consolidates a content moderation model heavily based around providers of intermediary services, and in particular, very large online platforms, acting as lawmakers, law enforcers, and judges at the same time. They are lawmakers as the terms and conditions lay down what is permitted as well as forbidden in the platform. While there isn't a general obligation to patrol the platform, they must react to notices from users and trusted flaggers and enforce the terms if necessary. And, finally, they act as judges by attending to the replies from the user who uploaded illegal content and dealing with the parties involved in the dispute, notwithstanding the alternative means provided for in the DSA.

 

Rather than using the distinction between manifestly illegal content and ordinary illegal content and refraining from regulating other types of content, the DSA creates a governance model for moderation of all content in the same manner. While administrative agencies and judges can request content to be taken down, under Art. 8, the development of the further obligations mentioned above poses the following question: who is the main responsible to define what is illegal and what is legal? Are the existing institutions subject to checks and balances or rather private parties, particularly BigTech and very large online platforms?

 

 

7. The privatization of content moderation: the second (convenient?) invisible handshake between the States and platforms

 

As seen with many other areas of the law, policymakers and regulators have slowly but steadily transferred government-like responsibilities into the private sector and mandated their compliance relying on a risk-based approach. For example, in the case of financial services, banks, and other financial services providers have turned into the long arm of financial regulators to tackle money laundering and tax evasion rather than relying on government resources to do this. This resulted in financial services firms having to process vast amounts of personal data to determine whether a transaction is illegal (either because it is laundering criminal proceedings or avoiding taxes) with nothing but their planning and some general guidelines; if they fail in this endeavor administrative fines (and in some cases, criminal sanctions) can be expected. The result has been an ineffective system to tackle this problem (see here) yet regulators keep on insisting on this approach.

 

A little shy of 20 years ago, Birnhack and Elkin denounced the existence of an invisible handshake between States and platforms for the protection and sake of national security after the 9/11 terror attacks (see here). At that time, this invisible handshake could be considered by some as necessary to deal with an international security crisis. Are we in the same situation as we speak when it comes to dealing with disinformation and fake news? This is a valid question. The EU policy makers seems to be impressed by voices such as Facebook’s whistleblower Frances Haugen who wants to align 'technology and democracy' by enabling platforms to moderate post. The underlying assumption seems to be that platforms are in the best position to moderate content following supposedly clear rules and that 'disinformation' can be identified (see here).

 

Content moderation presents a challenge for States given the amount of content generated non-stop across different intermediary services, in particular, social media online platforms (see here). Facebook employs a sizable staff of almost 15,000 individuals as content moderators (see here) but also relies heavily on automated content moderation, authorized by the DSA proposal under Arts. 14 and 17, in particular, to mitigate mental health problems to those human moderators given the inhuman content they sometimes have to engage with. To put this in comparison, using the latest available numbers from the Council of Europe about the composition of judiciary systems in Europe (see here), the Belgian judiciary employs approximately 9200 individuals (-the entire judiciary dealing with issues about commercial law up to criminal cases-), a little more than half of Facebook’s content moderators.

 

As such, one can argue that courts could be easily overloaded with cases that demand a quick and agile solution for defining what is illegal or harmful content if platforms didn't act as a first-stage filter for content moderation. Governments would need to heavily invest in administrative or judicial infrastructure and human resources to deal with such demand from online users. This matter has been discussed by scholars (see here). The available options they see either (i) strengthening platform content moderation by requiring the adoption of judiciary-like governance schemes, such as social media councils as Facebook has done; or (ii) implementing e-courts with adequate resources and procedures suited to the needs of the digital age to upscale our existing judiciary.

 

8. The consequences of the second invisible handshake

 

The DSA seems to have, willingly or not, decided on the first approach. Via this approach, -the privatization of content moderation-, States do not have to deal with the lack of judicial infrastructure to deal with the amount of content moderation that digital society requires. As shown by our example, Facebook has an infrastructure, just on raw manpower available, that doubles that of a country’s judiciary, such as Belgium. This second invisible handshake between BigTech and States can be situated in the incapacity of States to deal with disinformation effectively with the current legal framework and institutions.

 

If the DSA proposal is adopted ‘as is’, then platforms would have a significant power over individuals. First, through the terms and conditions, they would in position to determine what is allowed to be said and what cannot be discussed, as provided for by Art. 12. Not only that but also any redress before decisions adopted by platforms would have to be first channeled through the internal complaint handling mechanisms, as provided for by Arts. 17 and 18, for example, rather than seeking judicial remedy. As it can be appreciated, the power scale has clearly shifted towards platforms, and by extension to governments, in detriment of end-users.

 

Besides this, the transfer of government-like powers to platforms contributes to avoiding making complicated and hard decisions that could cost political reputation. Returning to our opening example, the lack of a concrete decision from our governments regarding sensitive topics has left platforms in charge of choosing what is the best course of action to tackle a worldwide pandemic by defining when something is misinformation that can affect the public health and when something could help fight back something that is out of control. Not only that but if platforms wrongfully approach the issue, then they are exposed to fines for non-compliance with their obligations, although particularly very large online platforms can deal with the fines proposed under the DSA.

 

If the second invisible handshake is going to take place, the least we, as a society, deserve is that agreement is made transparent so that public scrutiny can oversight such practices and free speech can be safeguarded. In this respect, the DSA could have addressed the issue of misinformation and fake news in a more democratic manner. Two proposals:

 

 

9. Addressing disinformation more democratically to align 'technology and democracy'

 

Firstly, the distinction between manifestly illegal content and merely illegal content could have been extremely helpful in distributing the workload between the private and public sector in a manner that administrative authorities and judges would only take care of cases where authoritative legal interpretation is necessary. As such, manifestly illegal content, such as apology to crime or intellectual property infringements, could be handled directly by platforms and merely illegal content by courts or administrative agencies. In this respect, a clear modernization in legal procedures to deal with claims about merely illegal content would still be necessary to adjust the legal response time to the speed of our digital society. Content moderation is not alone in this respect but joins the ranks of other mass-related issues, such as consumer protection, where effective legal protection is missing due to the lack of adequate infrastructure to channel complaints.

 

Secondly, as for legal but harmful content, while providers of online intermediary services have a right to conduct their business as to how they see fit and therefore can select which content is allowed or not via terms and conditions, citizens do have a valid right to engage directly in the discussion of those topics and determine how to proceed with them. This is even more important as users themselves are the ones interacting on these platforms and that content is exploited by platforms to ensure that controversy remains on the table to ensure engagement (see here).

 

However, there is a possibility to deal with content moderation, particularly in the case of legal but harmful content, that avoids a second invisible handshake: community-based content moderation strategies (see here) where users have a more active role in the management of online content has proven to be successful in certain online platforms. While categories such as clearly illegal or illegal and harmful content do not provide much margin for societal interpretation, legal but harmful content could be tackled by citizens' involvement. In this respect, community-based approaches, while resource-intensive, allow for citizens to engage directly in the debate about the issue at hand.

 

While community-based content moderation also has its own risks, it could serve as a more democratic method than relying on platforms’ unilateral decisions and it might serve where judges and administrative agencies cannot go due to the legality of content. As noted by the Office of the United Nations High Commissioner for Human Rights, people, rather than technology, should be making the hard decisions but also States, as elective representatives of society, need to make decisions about what is illegal and what is legal (see here).

 

Our alternatives are only a part of a more complete program. Further work is needed at policy level to address fake news. Sadly, as it may be, the matter is not matured yet and ripe for regulation. While the phenomena of political actors actively spreading misleading information (the twittering lies told by political leaders) are well-known and discussed, the role of traditional news media, who are supposed to be the bearers of truth and factual accuracy, is less well understood. Traditional news media are in fact a part of the problem, and play a somewhat paradoxical role with respect to fake news and its dissemination. People learn about fake news, not via obscure accounts that Facebook and others can control, but through regular media that find it important for many reasons to report on disinformation. Tsfatie and others (see here) rightly ask for more analysis and collaborations between academics and journalists to develop better practices in this area.

 

We are also surprised by the lack of attention in the DSA proposal to the algorithmic and technological dimension that seems central to the issue of fake news. More work is needed on the consequences of algorithmic production of online content. More work too is needed to assess the performance of technological answers to technology.  How to organize a space of contestation in a digitally mediated and enforced world? Are the redress mechanisms in the DSA sufficient when the post has already been deleted, i.e. "delete first rectify after"?

 

Art credit: Frederick Burr Opper, via wikimedia commons