Showing posts with label data controllers. Show all posts
Showing posts with label data controllers. Show all posts

Wednesday, 10 December 2025

Image Rights and False Claims, Data Protection and Intermediary Immunity: the case of Russmedia

 


 

Lorna Woods, Professor Emerita, University of Essex

 

Image credit: US Department of Defense

 

This Grand Chamber judgment of the Court of Justice in X v Russmedia Digital and Inform Media Press (Case C-492/23) handed down on 2 December 2025 concerns the scope of data protection rights and intermediary immunity in the context of the non-consensual use of someone’s image.  The judgment identifies:

- when someone has responsibilities under the GDPR,

- the relationship between those regulatory obligations and intermediary immunity, and

- the steps an data controller could take to satisfy those GDPR obligations.

 

It has been described as reshaping the obligations of online operators in the EU, while others have questioned how far the points in the judgments may be generalised to other situations.

 

Judgment

 

The Facts

 

Russmedia owns an online marketplace on which advertisements may be published. An unidentified user posted an advertisement falsely representing X as offering sexual services. The advert included X’s photographs (though there is no suggestion that these were intimate images) and phone number, all without her consent. Once notified, Russmedia removed the advert within an hour but the advertisement had been shared across several third party websites and remained accessible. X sued in the national courts in respect of her image rights, rights to reputation and data protection rights. The Romanian courts struggled with the question of whether Russmedia could claim the benefit of intermediary immunity (under the e-Commerce Directive (Directive 2000/31), provisions now replaced by the Digital Services Act (DSA)) and the extent of the obligations under the GDPR.

 

Is Russmedia subject to Obligations under the GDPR?

 

Obligations under GDPR arise when (1) personal data are (2) processed by (3) a data controller.

 

The CJEU commenced its analysis by noting the the information contained in the advert about X was personal data for the purposes of the GDPR and moreover that claims about a person’s sex life (implied in the advert) constituted “sensitive” personal data as protected by Article 9 GDPR, and that remained the case whether or not the claim was true.  Classification of the data as special category data means that there is a higher threshold to show lawful processing of those data. 

 

The Court further noted that “the operation of loading personal data on a webpage constitutes processing” for the purposes of the GDPR (para 54) and therefore covered the publication of the advert.

 

While this puts the advert within the scope of the GDPR, its obligations apply to data controllers and processors, so the question was whether, given Russmedia had no control over the content of the advert, was it a controller or joint controller? The Court reiterated previous jurisprudence to say (para 58) that:

 

any natural or legal person who exerts influence over the processing of such data, for his or her own purposes, and who participates, as a result, in the determination of the purposes and means of that processing, may be regarded as a controller in respect of such processing.

 

It noted also that there may be more than one entity which is a controller in respect of processing – this is the idea of joint controllers, although they may not have equal responsibility depending on the facts (para 63).  Joint decision making is not necessary for there to be joint controllers.

 

While the test for “controller” requires that the person processing the data does so for their own purposes, the Court added that this could include the situation “where the operator of an online marketplace publishes the personal data concerned for commercial or advertising purposes which go beyond the mere provision of a service which he or she provides to the user advertiser”  (para 66).  The Court in this case pointed to the fact that the terms of use give Russmedia “considerable freedom to exploit the information  published on that marketplace” including “the right to use published content, distribute it, transmit it, reproduce it, modify it, translate it, transfer it to partners and remove it at any time” (para 67). Russmedia is therefore not publishing solely on behalf of the user placing the advert. The Court also noted that Russmedia make the data in the advert accessible, allows the placing of anonymous adverts and sets the parameters for the dissemination of adverts (likely to contain personal data).

 

As a result of finding that the advert publishing platform was a joint controller the GDPR obligations bite in relation to the advert and must be able to demonstrate that the advert is published lawfully, which includes the requirement for consent for sensitive data (para 84 and 93) and the requirement for accuracy.  The CJEU notes that once published online and accessible to any Internet user, such data may be copied and reproduced on other websites, so that it may be difficult, if not impossible, for the data subject to obtain their effective deletion from the Internet.  The adds to the seriousness of the risks facing the data subject.

 

The GDPR also requires the implementation of technical and organisational measures – and this should be considered in the design of the service so that such data controllers can identify adverts containing sensitive data before they are published and to verify that such sensitive data is published in compliance with the principles of the GDPR (para 106).  Further, the controller must ensure that there are safety measures in place so that adverts containing sensitive data and not copied and unlawfully published elsewhere (para 122).

 

Are the GDPR Obligations Affected by Intermediary Immunity?

 

While the immunity provisions in the e-Commerce Directive are far-reaching, the e-Commerce Directive specified that it was not to apply to the Data Protection Directive (the legislation in  force at the time the e-Commerce Directive was drafted) and that included the immunities; the Court concluded that this meant the e-Commerce Directive could not interfere with the GDPR. It also specified that GDPR requirements here cannot be classified as general monitoring (which is prohibited by the e-Commerce Directive (and now the DSA)).

 

 

Conclusions, Implications and Questions

 

The ruling in this case does not match existing industry practice. It is not a bolt out of the blue, however, but builds on existing jurisprudence (eg Fashion ID (Case C-40/17)).  While the obligations required of Russmedia in this case may indicate, to some, a landmark shift in the Court’s approach, the judgment does rely on the specific facts in the case and, specifically, the point that “sensitive” data, which effectively requires explicit consent, is in issue. In principle, this could be relevant to other forms of sensitive content, notably non-consensual intimate images (NCII). Certainly, it re-emphasises data protection as a route for victims’ redress, if not preventing harm in the first place.

 

The ruling clarifies that a range of activities typically carried out by platforms - structuring, categorizing, and monetizing user content, can amount to determining “the purposes and means of processing personal data”, the test for responsibility as a controller under the GDPR (article 4 GDPR). In taking this approach, it differed from the Opinion of its Advocate-General (AG’s Opinion, para 120).  The Court noted that the definition of controller in the GDPR is broad – and this is to support the protection of individuals’ fundamental rights to privacy and data protection. Once a body is a controller, that body must be able to demonstrate compliance with the data protection principles, and take appropriate technical and organisational measures to ensure data processing is carried out in accordance with the GDPR. 

 

Here, some of the points that the Court relied on to determine that Russmedia was a joint controller could well be relevant to other services and not just online marketplaces. For example, many sites have broad terms of service similar to those the Court highlighted here; other services also allow anonymous posting and a key feature of many services is the making available of that content for advertising revenue purposes, as well as controlling how content is promoted. (Note the decision of the court in YouTube and Cyanado (Joined Cases C-682/18 and C-683/18), which suggested that automated content curation did not mean that a service is not neutral, is not directly relevant here as it relates to the conditions for maintaining intermediary immunity – and see Russmedia, AG’s Opinion, para 155)  It is unclear how many of these criteria need to be present for a service to constitute a controller in relation to the personal data in third party content it publishes (though the Court seems to list them as alternatives, suggesting any of them would suffice), or whether less far-reaching terms of service may be sufficient to stop a platform being a joint controller.  Where these conditions are satisfied, its impact need not be limited to advertising but to organic content containing third party personal data too.

 

The Court’s confirmation that the clear wording of the e-Commerce Directive, excluding the Data Protection Directive (the predecessor legislation to the GDPR) from its scope, meant that an intermediary cannot escape its own data protection responsibilities does not affect immunity from liability in respect of unlawful content.  Note that this decision was based on the wording of the e-Commerce Directive. This language has not been carried over to the DSA, which is expressed to operate without prejudice to, inter alia, the GDPR. It is not clear if or how this would change the Court’s interpretation. Immunity provisions from the e-Commerce Directive have been carried across to the DSA (albeit with a “carve out” in respect of consumer law in Article 6(3) DSA). While the EDPB has published guidance on the interplay of the GDPR and the DSA, it has looked at the question of the impact of the DSA requirements on data protection rather than the impact of data protection on the DSA.

 

The judgment suggests that services should design checks into their services to ensure compliance with the data protection obligations including pre-publication checks as to whether sensitive data is included and to check the identity of the person posting the material. Of course, while some sorts of posts (eg NCII) clearly constitute sensitive personal data, the outer edges of this category might not be clear cut. The Court here noted that the category should be interpreted broadly (para 52). It could be that some of the obligations could be passed on to the user uploading the advert through terms of service, though this might be capable of being abused by some users.  Further, the CJEU expects the site to prevent third party scraping so far as is possible – the judgment does not introduce strict liability in this regard.  What technical measures would be sufficient in practice remains uncertain.   This is very different from the reactive response required to maintain immunity under the e-Commerce Directive – and which has been the dominant framing until now. Assuming the position on immunity does not change, services may have to implement new systems, probably including automated tools and may ultimately affect choice of business model for some services.

 

There are questions about how this ruling impacts the DSA. How does a pre-check system differ from general monitoring. General monitoring is prohibited under Article 8 DSA (though specific monitoring is not)? The CJEU stated that systems to ensure GDPR compliance could not be classified as “general monitoring” (para 132) – but did not explain this statement any further. There is an argument to say that all content will need to be scanned to identify that which contains sensitive personal data – and by contrast to checking against a database of known CSAM images, for example, which might be considered specific monitoring, this is a more open ended obligation. It is unclear whether there are other routes to pre-check which do not involve content scanning.  The requirements to check whether the person posting the personal data is the person to which the data relates (or is otherwise lawfully processing) may make, for example, anonymity difficult to maintain and it is unclear what level of identity verification would be acceptable.  There are also questions about how this system of pre-checks affects the neutrality of the platform and consequently the possibility for the platform to claim immunity (in respect of other claims relating to the content) under Article 6 DSA.

 

The position in the UK may be slightly different, however. Section 6(1) European Union (Withdrawal) Act provides that decisions of the CJEU post-dating 31 December 2020 do not bind UK courts although they may have regard to such judgments. The provisions which would have had the effect of removing the status of binding precedent from decisions of the CJEU made on or before that date have now not been brought into force (but they remain on the statute book), as the Labour Government revoked the relevant commencement regulations.  Furthermore, old case law from the Northern Irish courts (pre-dating Brexit), CG v. Facebook, suggested the the e-Commerce Directive (the relevant law at the time) could apply to data protection claims.

Friday, 13 June 2014

Reforming EU data protection law: the Council takes its first baby steps


Steve Peers

The EU’s controversial data protection rules, currently in the form of a Directive dating back to 1995, would be reformed profoundly if a Regulation proposed by the Commission is adopted. Talks on this proposal have been underway since January 2012, with no immediate end in sight. However, in June, for the first time the Council (consisting of Member States’ justice ministers) has agreed its position on part of the proposal. Of course, the Council still has to agree its position on the rest of the text, and then negotiate with the European Parliament, which adopted its position on the entire text this spring. But at least this recent partial Council deal offers the first opportunity to assess the direction of negotiations.

Furthermore, this is a good occasion to assess whether the new legislation might impact upon the application of the controversial Google Spain judgment.

The partial Council deal

The Council deal only concerns the question of how the new EU rules will apply to non-EU countries. However this issue is of great importance in light of the ever-growing use of the Internet and social media, since the EU rules are potentially liable to apply worldwide.

To place the deal in context, it is necessary to look at four different things: (a) the current rules in the 1995 Directive, as interpreted by the CJEU; (b) the 2012 proposal; (c) the Council’s position; and (d) the EP’s position.

In each case, I will look at two different aspects which were addressed by the Council deal. First, when do the standard EU data protection rules apply, even where the company processing data is based outside the EU? Secondly, when do the special rules on external relations apply?

The current rules

Currently Article 4 of the 1995 Directive states firstly that the standard rules apply to a data controller established in a Member State. According to the CJEU in Google Spain, that concept applies at least where a non-EU company has established a subsidiary in a Member State, and that subsidiary carries out activities linked to the business model of the parent company. The current rules go on to say that if the controller is established on the territory of more than one Member State, it must comply with the national law of each of those States.

Furthermore, the standard rules in the 1995 Directive apply where a Member State’s national law applies by virtue of public international law, and where the controller is not established on EU territory, but uses equipment located on a Member State’s territory, unless that equipment is used only for the purposes of transit. This raises the question of whether the use of ‘cookies’,  for instance, amounts to the use of equipment on a national territory, since those cookies are installed on a Member State’s computer.

As for external transfers, the current rules provide (Article 25) that in principle data can only be transferred if there is an ‘adequate level of protection’ in the third country concerned. The Commission can adopt decisions either finding that there is, or is not, an adequate level of protection. By way of derogation (Article 26), Member States must nonetheless allow (unless their national law provides otherwise) external transfers to take place if: the data subject has given unambiguous consent; the transfer is necessary to perform a contract with the data controller or to implement pre-contractual measures which the data subject requested; the transfer is necessary to conclude or perform a contract in the interest of the data subject as a third party; the transfer is ‘necessary or legally required on important public interest grounds’ or related to legal claims; the transfer is in the data subject’s ‘vital interests’; or the transfer is from a register which provides information to the public or to persons with a legitimate interest.

A Member State may authorise an external transfer to a country with an inadequate level of protection if the data controller can offer ‘adequate safeguards’, in particular arising from contractual clauses. The Commission can decide that certain standard contractual clauses offer such protection. 

The 2012 proposal

The 2012 proposal (Article 3) suggests that the new Regulation should apply first of all where a controller or processor is established in the EU. Secondly, it should apply where the data controller is not established in the EU, but the data subjects reside in the Union, and the data controller either offers them goods or services, or monitors their behaviour. Thirdly, as before, it would apply where a Member State’s national law applies by virtue of public international law. The provision concerning the ‘use of equipment’ would be dropped.
As regards external transfers, the 2012 proposal maintains the basic structure of the current rules, but elaborates upon it. So there are more details on what the Commission has to take into account when assessing the adequacy of a third State, including judicial redress and supervisory authorities. Adequacy decisions taken pursuant to the 1995 Directive would remain in force.

External transfers would be permitted on the basis of binding corporate rules, or standard contractual rules adopted by the Commission or a national supervisory authority, or individually negotiated contractual rules authorised by a national supervisory authority. Otherwise transfers would require approval by a supervisory authority. Pre-existing authorisations by a supervisory authority would remain valid.

A new clause would elaborate upon the content of binding corporate rules that would be adopted unilaterally. These would require the approval of a supervisory authority.

Finally, further derogations would be permitted. Compared to the current rules, these would be optional, not mandatory. The new proposal would clarify that consent could only be given after the data subject had been warned of the risks, and that transfers in the data subject’s interest could only be given if the data subject were unable to consent. There would be a new ground of external transfers in the data controller’s or processor’s legitimate interest, subject to safeguards being in place. The concept of the ‘public interest’ justifying such transfers would be further clarified in national or EU law.

The Council position

As regards the standard rules, the Council would amend the Commission proposal to clarify that the rules will apply whether or not the data controller offers goods or services for payment. However, as regards monitoring of behaviour, the rules will only apply if the data controller monitors behaviour within the EU.

For external transfers, the Council would add further detail to the rules regarding the assessment of the adequacy of third states, including a specific reference to participation in regional or multilateral data protection treaties. The Council also wants to give an advisory role to the planned new European Data Protection Board in this process. The Council would require the Commission to monitor the application of its adequacy decisions, and empower it to revoke them. However, the Commission would no longer have the power to adopt a decision specifying that a third State had inadequate protection.

The Council would also permit external transfers to take place on the basis of a code of conduct or a certification mechanism. Transfers in the private interest of the data processor or controller would be subject to a possible override in the data subject’s interests. The Commission would lose powers to define the public interests reasons for transfers, and Member States would gain more powers on this point.  

The EP position

The EP would amend the Commission proposal so that, where the controller or processor is established within the EU, it would not matter where the data was processed. Also, the standard rules would apply to the offering of goods or services or monitoring by data controllers or data processors, and would apply to any sort of monitoring of data subjects, not only the monitoring of behaviour. Unlike the Council, the EP would not limit the monitoring clause to behaviour within the EU. However, like the Council, the EP would apply the rules even if goods or services are not offered for payment.

As for external transfers, the EP agrees with the Council that the Commission should monitor its adequacy decisions, and that there should be a role for the new Board.  However, the EP wants to apply a ‘sunset clause’ to pre-existing adequacy decisions, and retain the power for the Commission to adopt ‘inadequacy’ decisions.

Similarly, pre-existing authorisations of contractual clauses would expire soon after the new rules were adopted, although the EP agrees with the Council that a form of certification process should justify external transfers. For binding corporate rules, the EP wants to ensure consultation of workers where their data is involved, and apply the rules to sub-contractors (the Council approaches the latter issue by referring to groups of companies). As regards the derogations, the EP would reject the idea of transfers in the legitimate interests of controllers.

Finally, the EP has proposed a new ‘Snowden clause’ which would mean that national courts could not recognise the decisions of non-EU courts which ordered the disclosure of personal data. However, this rule would be ‘without prejudice’ to mutual assistance treaties or any other international agreements between a non-EU state and the EU or any Member State.

Comments

One important point should be addressed at the outset: what is the result of the recent EP election on the EP’s position? In the EU system, proposed legislation does not fall simply because there is an election for the EP, or because there will be a new Commission as from November. Rather, the newly elected EP traditionally holds a vote at an early stage to decide whether to reaffirm the positions taken by the previous legislature. Usually it reaffirms almost all of the prior legislature’s positions. It should be recalled that the EP’s position on the data protection Regulation was adopted by a huge majority, and so despite the increase in the number of populist MEPs, a majority in favour of approving the EP’s prior position on this proposal should in principle not be hard to find.

For its part, the incoming Commission will decide whether to withdraw some of its pending proposals, but is very rare for an incoming Commission to withdraw a proposal which is actively under discussion in the Council and EP, such as the data protection proposal.

Moving on to the substance of the issues, as regards the application of the standard rules, all three institutions agree to keep the rule on establishment, extending it to data processors also. The EP’s suggested amendment regarding the location of the data processing is merely a clarification, which is probably not necessary.

The three institutions all agree to drop the ‘use of equipment’ clause, to keep the clause on public international law, and to add a new clause regarding goods and services and monitoring. The EP and the Council also agree that the ‘goods and services’ clause will apply even where there is no payment made. The institutions differ as regards extending the new clause also to data controllers, and differ as regards the exact scope of the monitoring of behaviour.

As for the external transfers rules, all three institutions would keep the current basic structure. They differ as regards: the ‘Snowden clause’ (although this rule is very weak, in light of its exceptions for any international treaties); whether the Commission can adopt an ‘inadequacy decision’ (it has never done so); sunset clauses for prior authorisations; whether private interests can justify external transfers; and the process of determining when the public interest can justify them.

Taken as a whole, the impact of the new rules depends on how the current rules are interpreted. There is no reason to doubt that the ‘establishment’ clause would be interpreted the same way as it was in Google Spain, ie applying at least where a subsidiary’s activity is linked to a non-EU parent company’s business model. But there is no case law clarifying what the ‘use of equipment’ means, and so it is not easy to assess what removal of this clause will mean in practice.

Instead the focus will be on what it means to offer goods or services (whether or not for payment), and what it means to monitor an individual. These concepts are clarified in the preamble, which indicates that the ‘offering goods or services’ rule will apply where there a website seeks to sell its products or services, and its online activity is particularly directed towards EU citizens (in light of the currency or language used). So the intention is apparently not to cover a non-profit body like Wikipedia, or a social network or search engine which does not charge for its services (although some such entities would be covered by the ‘establishment’ rule).

What about ‘monitoring’? Here, the preamble suggests that the new clause applies when an individual’s Internet activities are tracked with a view to profiling him or her. There is no suggestion in the preamble that keeping records of a person’s use of social networks would count as monitoring.  But if that is not the intention, it would be better for the EU legislature to rule it out more expressly. In any event, it is difficult to see how the Council’s limitation regarding the monitoring of behaviour within the EU would work in practice, in light of the nature of the Internet.

As regards the external transfer clauses, their importance depends on whether the standard clauses apply. The greater the number of businesses covered by the standard rules, the less important the external transfer rules are – and vice versa.

It is clear that the external transfer clauses will remain broadly similar to the current rules, so any corporate or NGO strategies regarding these clauses would only need to be amended modestly, rather than be overhauled. The biggest issues may be the EP’s insistence on its ‘Snowden clause’ and its rejection of the idea that external transfers can take place in the data controller’s interest, although the former clause is weak and data controllers can usually pursue their interests by means of obtaining consent or establishing a contractual relationship.

Much of the most difficult work as regards the negotiation of the new rules remains to be done. In fact, it is rather peculiar to negotiate a new law by defining its territorial scope before agreeing on its main substance.

While a vast number of issues will arise in the forthcoming negotiations, the following are particularly relevant to the fallout from the Google Spain decision, in particular as regards its possible impact on social networks and Wikipedia: the interpretation of a ‘data processor’ (which would be particularly significant if the EP gets its way and the entire clause on territorial scope applies to data processors); the possible application of the ‘household exception’ to user-generated content; the exception for journalism; and the definition of the grounds for processing personal data (notably consent and the controller’s legitimate interests).



Barnard & Peers: chapter 9