Showing posts with label digital single market. Show all posts
Showing posts with label digital single market. Show all posts

Tuesday, 11 January 2022

A democratic alternative to the Digital Services Act's handshake between States and online platforms to tackle disinformation

 



 

By Paul De Hert* and Andrés Chomczyk Penedo**

 

* Professor at Vrije Universiteit Brussel (Belgium) and associate professor at Tilburg University (The Netherlands)

** PhD Researcher at the Law, Science, Technology and Society Research Group, Vrije Universiteit Brussel (Belgium). Marie Skłodowska-Curie fellow at the PROTECT ITN. The author has received funding from the European Union’s Horizon 2020 research and innovation programme under the Marie Skłodowska-Curie grant agreement No 813497

 

 

 

1. Dealing with online misinformation: who is in charge?

 

Misinformation and fake news are raising concerns for the digital age, as discussed by Irene Khan, the United Nations Special Rapporteur on the promotion and protection of the right to freedom of opinion and expression (see here). For example, during the last two years, the COVID19 crisis caught the world by surprise and considerable discussions about the best course of action to deal with the pandemic were held. In this respect, different stakeholders spoke up but not all of them were given the same possibilities to express their opinion. Online platforms, but also traditional media, played a key role in managing this debate, particularly using automated means (see here).

 

A climate of polarization developed, in particular on the issue of vaccination but also around other policies such as vaccination passports, self-tests, treatment of the virus in general, or whether the health system should focus on ensuring immunity through all available strategies (see here). Facebook, YouTube, and LinkedIn, just to name a few, stepped in and started delaying or censoring posts that in one way or another were perceived as harmful to governmental strategies (see here). While the whole COVID19 crisis deserves a separate discussion, it serves as an example of how digital platforms are, de facto, in charge of managing online freedom of expression and, from a practical point of view, have the final say in what is permissible or not in an online environment.

 

The term 'content’ has been paired with adjectives such as clearly illegal, illegal and harmful, or legal but harmful, just to name the most relevant ones. However, what does exactly each of these categories entail, and why are we discussing these categories? What should be the legal response, if any, to a particular piece of content and who should address it? While content and its moderation is not a new phenomenon, as Irene Khan points in her previously mentioned report, technological developments, such as the emergence and consolidation of platforms, demand new responses.

 

With this background, the European Union is currently discussing at a surprisingly, very quick speed the legal framework for this issue through the Digital Services Act (the DSA, previously summarised here). The purpose of this contribution is to explore how misinformation and other categories of questionable content are tackled in the DSA and to highlight the option taken in the DSA to transfer government-like powers (of censorship) to the private sector. A more democratic alternative is sketched. A first one is based on the distinction between manifestly illegal content and merely illegal content to distribute better the workload between private and public enforcement of norms. A second alternative consists in community-based content moderation as an alternative or complementary strategy next to platform-based content moderation

 

 

2. What is the DSA?

 

The DSA (see here for the full text of the proposal and here for its current legislative status) is one of the core proposals in the Commission’s 2019-2024 priorities, alongside the Digital Markets Act (discussed here), its regulatory ‘sibling’. It intends to refresh the rules provided for in the eCommerce Directive and deal with certain platform economy-related issues under a common European Union framework. It covers topics such as: intermediary service providers liability - building up from the eCommerce Directive regime and expanding it -, due diligence obligations for a transparent and safe online environment -including notice and takedown mechanisms, internal complaint-handling systems, traders traceability, and advertising practices-, risk management obligations for very large online platforms and the distribution of duties between the European Commission and the Member States. Many of the these topics might demand further regulatory efforts beyond the scope of the DSA, such as political advertisement which would be complemented by sector-specific rules as, for example, the proposal for a Regulation on the Transparency and Targeting of Political Advertising (see here).

 

As of late November 2021, the Council has adopted a general approach to the Commission’s proposal (see here) while the European Parliament is still dealing with the discussion of possible amendments and changes to that text (see here). Nevertheless, as with many other recent pieces of legislation (see here), it is expected that its adoption is sooner rather than later in the upcoming months.

 

3. Unpacking Mis/Disinformation (part1): illegal content as defined by Member States

 

We started by discussing misinformation and fake news. If we look at the DSA proposal, the term 'fake news' is missing in all its sections. However, the concept of misinformation appears as disinformation in Recitals 63, 68, 69, and 71. Nevertheless, both terms are nowhere to be found in the Articles of the DSA proposal.

 

In literature, the terms are used interchangeably or are distinguished, with disinformation defined as the intentional and purposive spread of misleading information, and misinformation as ‘unintentional behaviors that inadvertently mislead’ (see here). But that distinction does not help in recognizing either mis- or disinformation, from other categories of content.

 

Ó Fathaigh, Helberger, and Appelman (see here) have pointed that disinformation, in particular, is a complex concept to tackle and that very few scholars have tried to unpack its meaning. Despite the different policy and scholarly efforts, a single unified definition of mis- or disinformation is still lacking, and the existing ones can be considered as too vague and uncertain to be used as legal definitions. So, where shall we start looking at these issues? A starting point, so we think, is the notion of content moderation, which according to the DSA proposal, is defined as follows:

 

'content moderation' means the activities undertaken by providers of intermediary services aimed at detecting, identifying, and addressing illegal content or information incompatible with their terms and conditions, provided by recipients of the service, including measures taken that affect the availability, visibility, and accessibility of that illegal content or that information, such as demotion, disabling of access to, or removal thereof, or the recipients' ability to provide that information, such as the termination or suspension of a recipient's account (we underline);

 

Under this definition, content moderation is an activity that is delegated to providers of intermediary services, particularly online platforms, and very large online platforms. Turning to the object of the moderation, we can ask what is exactly being moderated under the DSA? As mentioned above, moderated content is usually associated with certain adjectives, particularly illegal and harmful. The DSA proposal only defines illegal content:

 

‘illegal content’ means any information, which, in itself or by its reference to an activity, including the sale of products or provision of services is not in compliance with Union law or the law of a Member State, irrespective of the precise subject matter or nature of that law;

 

So far, this definition should not provide much of a challenge. If the law considers something as, it makes sense that it is similarly addressed in the online environment as in the physical realm. For example, a pair of fake sneakers constitute a trademark infringement, regardless of if the pair is being sold via eBay or by a street vendor in Madrid’s Puerta del Sol. In legal practice, regulating illegal content is not black and white. A distinction can be made between clearly illegal content and situations where further exploration must be conducted to determine the illegality of certain content. This is how it is framed in the German NetzDG, for example. In some of the DSA proposal articles, mainly Art. 20, we can see the distinction between manifestly illegal content and illegal content. However, this distinction is not picked up again in the rest of the DSA proposal.

 

What stands is that the DSA proposal does not expressly cover disinformation but concentrates on the notion of illegal content. If Member State law defines and prohibit mis- or disinformation -which Ó Fathaigh, Helberger and Appelman have reviewed and found to be inconsistent across the EU- , then this would fall under the DSA category of illegal content. Rather than creating legal certainty, this further reinforces legal uncertainty and pegs the notion of illegal content to be dependent on each Member State's provisions. But where does this leave disinformation that is not regulated in in Member State laws? The DSA does not like it, but its regulation is quasi hidden.

 

 

4. Unpacking Mis/Disinformation (part2): harmful content non defined by the DSA

 

The foregoing brings us to the other main concept dealing with content in the DSA, viz. harmful content. To say that this is a (second) 'main' concept might confuse the reader, since the DSA does not define it or regulate it at great lengths.  The DSA’s explanatory memorandum states that `[t]here is a general agreement among stakeholders that ‘harmful’ (yet not, or at least not necessarily, illegal) content should not be defined in the Digital Services Act and should not be subject to removal obligations, as this is a delicate area with severe implications for the protection of freedom of expression’.

 

As such, how can we define harmful content? This question is not new by any means as we can trace back policy documents from the European Union dating back to 1996 (see here) dealing with this problem. Since then, little has changed in the debate surrounding harmful content as the core idea remains untouched: harmful content refers to something that, depending on the context, could affect somebody due to it being unethical or controversial (see here).

 

In this respect, the discussion on this kind of content does not tackle a legal problem but rather an ethical, political, or religious one. As such, it is a valid question to be asked if laws and regulations should even mingle in this scenario. In other words, does it make sense to talk about legal but harmful content when we discuss new regulations? Should our understanding of illegal and harmful content be construed in the most generous way to accommodate for the most amount of situations possible to avoid this issue? And more importantly, if the content seems to be legal, does it make sense to add the adjective of ‘harmful’ rather than using, for example, ‘controversial’? Regardless of the terminology used, this situation leaves us with three types of content categories: (i) manifestly illegal content; (ii) illegal, both harmful and not, content; (iii) legal but harmful content. Each of them demands a different approach, which shall be the topic of our following sections.

 

 

5. Illegal content moderation mechanisms in the DSA (content type 1 & 2)

 

The DSA puts forward a clear, but complex, regime for dealing with all kinds of illegal content. As a starting point, the DSA proposal provides for a general no monitoring regime for all intermediary service providers (Art. 7) with particular conditions for mere conduits (Art. 3), caching (Art. 4), and hosting service providers (Art. 5). However, voluntary own-initiative investigations are allowed and do not compromise this liability exemption regime (Art. 6). In any case, once a judicial or administrative order mandates the removal of content, this order has to be followed to avoid incurring liability (Art. 8). In principle, public bodies (administrative agencies and judges) have control over what is illegal and when something should be taken down.

 

However, beyond this general regime, there are certain stakeholder-specific obligations spread out across the DSA proposal also dealing with illegal content that challenge the foregoing state-controlled mechanism. In this respect, we can point out the mandatory notice and takedown procedure for hosting providers with a fast lane for trusted flaggers notices (Arts. 14 and 19, respectively), in addition to the internal complaint-handling system for online platforms paired with the out-of-court dispute settlement (Arts. 17 and 18, respectively) and, in the case of very large online platforms, these duties should be adopted following a risk assessment process (Art. 25). With these set of provisions, the DSA grants a considerable margin to certain entities to act as law enforcers and judges, without a government body having a say in if something was illegal and its removal was a correct decision.

 

6. Legal but harmful content moderation mechanisms in the DSA (content type 3)

 

But what about our third type of content, legal but harmful content, and its moderation? Without dealing with the issue of content moderation directly, the DSA transfers the delimitation of this concept to providers of online intermediary services, mainly online platforms. In other words, a private company can limit apparently free speech within its boundaries. In this respect, the DSA proposal grants all providers of intermediary services the possibility of further limiting what content can be uploaded and how it shall be governed via the platform’s terms and conditions and, by doing so, these digital services providers are granted substantial power in regulating digital behavior as they see fit:

 

‘Article 12 Terms and conditions

 

1. Providers of intermediary services shall include information on any restrictions that they impose concerning the use of their service in respect of information provided by the recipients of the service, in their terms and conditions. That information shall include information on any policies, procedures, measures, and tools used for content moderation, including algorithmic decision-making and human review. It shall be set out in clear and unambiguous language and shall be publicly available in an easily accessible format.

 

2. Providers of intermediary services shall act in a diligent, objective, and proportionate manner in applying and enforcing the restrictions referred to in paragraph 1, with due regard to the rights and legitimate interests of all parties involved, including the applicable fundamental rights of the recipients of the service as enshrined in the Charter.’

 

In this respect, the DSA consolidates a content moderation model heavily based around providers of intermediary services, and in particular, very large online platforms, acting as lawmakers, law enforcers, and judges at the same time. They are lawmakers as the terms and conditions lay down what is permitted as well as forbidden in the platform. While there isn't a general obligation to patrol the platform, they must react to notices from users and trusted flaggers and enforce the terms if necessary. And, finally, they act as judges by attending to the replies from the user who uploaded illegal content and dealing with the parties involved in the dispute, notwithstanding the alternative means provided for in the DSA.

 

Rather than using the distinction between manifestly illegal content and ordinary illegal content and refraining from regulating other types of content, the DSA creates a governance model for moderation of all content in the same manner. While administrative agencies and judges can request content to be taken down, under Art. 8, the development of the further obligations mentioned above poses the following question: who is the main responsible to define what is illegal and what is legal? Are the existing institutions subject to checks and balances or rather private parties, particularly BigTech and very large online platforms?

 

 

7. The privatization of content moderation: the second (convenient?) invisible handshake between the States and platforms

 

As seen with many other areas of the law, policymakers and regulators have slowly but steadily transferred government-like responsibilities into the private sector and mandated their compliance relying on a risk-based approach. For example, in the case of financial services, banks, and other financial services providers have turned into the long arm of financial regulators to tackle money laundering and tax evasion rather than relying on government resources to do this. This resulted in financial services firms having to process vast amounts of personal data to determine whether a transaction is illegal (either because it is laundering criminal proceedings or avoiding taxes) with nothing but their planning and some general guidelines; if they fail in this endeavor administrative fines (and in some cases, criminal sanctions) can be expected. The result has been an ineffective system to tackle this problem (see here) yet regulators keep on insisting on this approach.

 

A little shy of 20 years ago, Birnhack and Elkin denounced the existence of an invisible handshake between States and platforms for the protection and sake of national security after the 9/11 terror attacks (see here). At that time, this invisible handshake could be considered by some as necessary to deal with an international security crisis. Are we in the same situation as we speak when it comes to dealing with disinformation and fake news? This is a valid question. The EU policy makers seems to be impressed by voices such as Facebook’s whistleblower Frances Haugen who wants to align 'technology and democracy' by enabling platforms to moderate post. The underlying assumption seems to be that platforms are in the best position to moderate content following supposedly clear rules and that 'disinformation' can be identified (see here).

 

Content moderation presents a challenge for States given the amount of content generated non-stop across different intermediary services, in particular, social media online platforms (see here). Facebook employs a sizable staff of almost 15,000 individuals as content moderators (see here) but also relies heavily on automated content moderation, authorized by the DSA proposal under Arts. 14 and 17, in particular, to mitigate mental health problems to those human moderators given the inhuman content they sometimes have to engage with. To put this in comparison, using the latest available numbers from the Council of Europe about the composition of judiciary systems in Europe (see here), the Belgian judiciary employs approximately 9200 individuals (-the entire judiciary dealing with issues about commercial law up to criminal cases-), a little more than half of Facebook’s content moderators.

 

As such, one can argue that courts could be easily overloaded with cases that demand a quick and agile solution for defining what is illegal or harmful content if platforms didn't act as a first-stage filter for content moderation. Governments would need to heavily invest in administrative or judicial infrastructure and human resources to deal with such demand from online users. This matter has been discussed by scholars (see here). The available options they see either (i) strengthening platform content moderation by requiring the adoption of judiciary-like governance schemes, such as social media councils as Facebook has done; or (ii) implementing e-courts with adequate resources and procedures suited to the needs of the digital age to upscale our existing judiciary.

 

8. The consequences of the second invisible handshake

 

The DSA seems to have, willingly or not, decided on the first approach. Via this approach, -the privatization of content moderation-, States do not have to deal with the lack of judicial infrastructure to deal with the amount of content moderation that digital society requires. As shown by our example, Facebook has an infrastructure, just on raw manpower available, that doubles that of a country’s judiciary, such as Belgium. This second invisible handshake between BigTech and States can be situated in the incapacity of States to deal with disinformation effectively with the current legal framework and institutions.

 

If the DSA proposal is adopted ‘as is’, then platforms would have a significant power over individuals. First, through the terms and conditions, they would in position to determine what is allowed to be said and what cannot be discussed, as provided for by Art. 12. Not only that but also any redress before decisions adopted by platforms would have to be first channeled through the internal complaint handling mechanisms, as provided for by Arts. 17 and 18, for example, rather than seeking judicial remedy. As it can be appreciated, the power scale has clearly shifted towards platforms, and by extension to governments, in detriment of end-users.

 

Besides this, the transfer of government-like powers to platforms contributes to avoiding making complicated and hard decisions that could cost political reputation. Returning to our opening example, the lack of a concrete decision from our governments regarding sensitive topics has left platforms in charge of choosing what is the best course of action to tackle a worldwide pandemic by defining when something is misinformation that can affect the public health and when something could help fight back something that is out of control. Not only that but if platforms wrongfully approach the issue, then they are exposed to fines for non-compliance with their obligations, although particularly very large online platforms can deal with the fines proposed under the DSA.

 

If the second invisible handshake is going to take place, the least we, as a society, deserve is that agreement is made transparent so that public scrutiny can oversight such practices and free speech can be safeguarded. In this respect, the DSA could have addressed the issue of misinformation and fake news in a more democratic manner. Two proposals:

 

 

9. Addressing disinformation more democratically to align 'technology and democracy'

 

Firstly, the distinction between manifestly illegal content and merely illegal content could have been extremely helpful in distributing the workload between the private and public sector in a manner that administrative authorities and judges would only take care of cases where authoritative legal interpretation is necessary. As such, manifestly illegal content, such as apology to crime or intellectual property infringements, could be handled directly by platforms and merely illegal content by courts or administrative agencies. In this respect, a clear modernization in legal procedures to deal with claims about merely illegal content would still be necessary to adjust the legal response time to the speed of our digital society. Content moderation is not alone in this respect but joins the ranks of other mass-related issues, such as consumer protection, where effective legal protection is missing due to the lack of adequate infrastructure to channel complaints.

 

Secondly, as for legal but harmful content, while providers of online intermediary services have a right to conduct their business as to how they see fit and therefore can select which content is allowed or not via terms and conditions, citizens do have a valid right to engage directly in the discussion of those topics and determine how to proceed with them. This is even more important as users themselves are the ones interacting on these platforms and that content is exploited by platforms to ensure that controversy remains on the table to ensure engagement (see here).

 

However, there is a possibility to deal with content moderation, particularly in the case of legal but harmful content, that avoids a second invisible handshake: community-based content moderation strategies (see here) where users have a more active role in the management of online content has proven to be successful in certain online platforms. While categories such as clearly illegal or illegal and harmful content do not provide much margin for societal interpretation, legal but harmful content could be tackled by citizens' involvement. In this respect, community-based approaches, while resource-intensive, allow for citizens to engage directly in the debate about the issue at hand.

 

While community-based content moderation also has its own risks, it could serve as a more democratic method than relying on platforms’ unilateral decisions and it might serve where judges and administrative agencies cannot go due to the legality of content. As noted by the Office of the United Nations High Commissioner for Human Rights, people, rather than technology, should be making the hard decisions but also States, as elective representatives of society, need to make decisions about what is illegal and what is legal (see here).

 

Our alternatives are only a part of a more complete program. Further work is needed at policy level to address fake news. Sadly, as it may be, the matter is not matured yet and ripe for regulation. While the phenomena of political actors actively spreading misleading information (the twittering lies told by political leaders) are well-known and discussed, the role of traditional news media, who are supposed to be the bearers of truth and factual accuracy, is less well understood. Traditional news media are in fact a part of the problem, and play a somewhat paradoxical role with respect to fake news and its dissemination. People learn about fake news, not via obscure accounts that Facebook and others can control, but through regular media that find it important for many reasons to report on disinformation. Tsfatie and others (see here) rightly ask for more analysis and collaborations between academics and journalists to develop better practices in this area.

 

We are also surprised by the lack of attention in the DSA proposal to the algorithmic and technological dimension that seems central to the issue of fake news. More work is needed on the consequences of algorithmic production of online content. More work too is needed to assess the performance of technological answers to technology.  How to organize a space of contestation in a digitally mediated and enforced world? Are the redress mechanisms in the DSA sufficient when the post has already been deleted, i.e. "delete first rectify after"?

 

Art credit: Frederick Burr Opper, via wikimedia commons

Tuesday, 10 August 2021

Copyright and the Internet: Poland v Parliament and Council (Case C-401/19), Opinion of the Advocate General, 15 July 2021


 


Lorna Woods, Professor of Internet Law, University of Essex

 

Introduction

 

The development of ‘web 2.0’, especially social media, has meant that many people are able to post content to potentially large audiences.  The amount of content, however, and how to manage conflicting rights between different users has led to debate about the role of the platforms in helping remedy the problems that the platforms facilitate (that come along with the benefits the platforms enable).  One particular issue is the acceptability of the use of filtering technologies, especially from the perspective of the freedom of expression of the user of the work.  It has come before the courts before, when the courts – in the context of copyright claims - had expressed concerns about those techniques.  Given the quantity of material uploaded, however, it is hard to envisage that in person ex post review of content would be possible, let alone effective.  The problem of copyright enforcement remains – and the ‘value gap’ created by mass unauthorised use of protected works. Platforms have had little incentive to prevent the problem from arising – indeed it could be said the platforms benefitted (through advertising revenue) from the existence of this content. The ex post system – whereby copyright holders notify and the platform removes content to maintain its immunity under Article 14 e-Commerce Directive – has not been seen as effective by rights-holders.

 

This problem had led to the overhaul of the copyright regime and the enactment of the Copyright Directive in the Digital Single Market (Directive 2019/790), a proposal that during the legislative process was subject to extensive lobbying.  The result is a directive which aims to reduce the ‘value gap’ and to rebalance matters more in favour of the creators of content with the introduction of a new press publisher’s right (Article 15) and, notably, Article 17 which covers use of protected content by online content-sharing service providers.  Article 17, however, was contentious, leading to this challenge by Poland, and the recent Advocate-General’s opinion. While it is important in understanding the scope of Article 17 itself, we might also ask whether the reasoning here might have broader implications.

 

Provisions in Issue

 

Article 17 changes (or clarifies) the position under copyright that the platforms caught by the definitions in the directive will automatically be considered to be carrying out 'acts of communication to the public or making available to the public' when they give the public access to copyright-protected content uploaded by users, and therefore require authorisation from the relevant content owners. Article 17(3) displaces Article 14 e-Commerce Directive, which provides conditional immunity from penalties to neutral hosts. Article 17(3) provides that, if there are no relevant licensing arrangements in place, the platforms will only be able to maintain immunity if they satisfy the terms of Article 17(4). Article 17(4) introduces 4 cumulative conditions (arranged across 3 subparagraphs) – that the platform has:

 

(a) made best efforts to obtain an authorisation, and

 

(b) made, in accordance with high industry standards of professional diligence, best efforts to ensure the unavailability of specific works and other subject matter for which the right-holders have provided the service providers with the relevant and necessary information; and in any event

 

(c) acted expeditiously, upon receiving a sufficiently substantiated notice from the right-holders, to disable access to, or to remove from their websites, the notified works or other subject matter, and made best efforts to prevent their future uploads in accordance with point (b).

 

While the first part of Article 17(4)(c) is similar to the conditions in Article 14 e-Commerce Directive, the other three elements are new.  Without dealing with any questions around the definitions of the platforms falling within this obligation, a number of questions arise: does Article 17(4) effectively require upload filters (and will they lead to overblocking); what are best efforts, especially in relation to the monitoring which is implied; and does Article 17(4) effectively require ‘general monitoring’ (despite the clarification in Article 17(8) that it should not lead to general monitoring).

 

Article 17(7) might be seen as an effort at counter-balance: it provides

 

The cooperation between online content-sharing service providers and right-holders shall not result in the prevention of the availability of works or other subject matter uploaded by users, which do not infringe copyright and related rights, including where such works or other subject matter are covered by an exception or limitation.

 

Significantly, the directive expressly lists the exceptions for quotation, criticism, review and for caricature, parody or pastiche.  There are also obligations (in Article 17(9)) relating to redress and complaints mechanisms, which some sections of industry have claimed are onerous.  Some of the vagueness around requirements might be dealt with by Commission guidance aimed at aiding coherent implementation of the directive; while this is now available, at the time the case was lodged it was not.

 

The Legal Challenge

 

The Issue

 

Poland issued a judicial review action, seeking annulment of the provision (either just Article 17(4)(b) and (c) or Article 17 in its entirety) on the basis of its incompatibility with freedom of expression as guaranteed by the Charter (Article 11 EUCFR), either by destroying the essence of the right or by constituting a disproportionate interference with that right.

 

The Nature of the Obligation

 

A preliminary issue concerned is the nature of the obligation imposed by Article 17(4) and whether it requires for preventive monitoring purposes the use of upload filters. While this is not explicitly required, the Advocate General took the view that, in many circumstances, the use of those tools are required [para 62]. Further, industry standards will have an impact on the decision as to what best practice is [para 65-6]. So, while the recitals provided considerations to assess what suitable methods would look like (see recital 66), this did not affect the assessment that the reality was the upload filters of some description would be used.

 

The Impact on Freedom of Expression

 

Applicability of the Right

 

One precondition for the applicability of fundamental rights is that the actions under challenge could be imputed to the State; here, the actions of the platforms are in issue (and their right to run a business under Article 16 EUCFR). The Advocate General drew a distinction between the circumstances where a platform had real choice and the circumstances here. The provision might formally give operators a choice: do this and get exemption from liability, or choose not to do that and face exposure to liability. The Advocate General emphasised that the assessment as to compliance with Article 11 should take account of what is happening in practice; the reality is that ‘the conditions for exemption laid down in the contested provisions will, in practice, constitute genuine obligations for those providers’ [para 86, emphasis in original].

 

Limitations – Lawfulness

 

The conditions for limiting Article 11 EUCFR are found in Article 52(1) EUCFR. The requirement there that the restriction be ‘provided for by law’ was to be understood in the light of the jurisprudence on lawfulness for the purpose of Article 10(2) ECHR (citing some CJEU decisions on data protection and the right to a private life in support). Lawfulness requires not just a basis in law, clearly satisfied here, but must be accessible and foreseeable. The first aspect is clearly satisfied. As regards the second, the Advocate General noted that the case law allows the legislature ‘without undermining the requirement of “foreseeability” [to] choose to endow the texts it adopts with a certain flexibility rather than absolute certainty’ [para 95, citing the Grand Chamber judgment in Delfi v Estonia, discussed here]. Nonetheless, the case-law on lawfulness also requires safeguards against arbitrary or abusive interference with rights. This issue the Advocate General linked to proportionality.

 

Limitations – the Essence of the Right

 

The requirement to respect the essence of the right provides a limit on the discretion of the legislature to weigh up competing interests and come to a fair balance. It is ‘an “untouchable core” which must remain free from any interference’ [para 99]. According to the Advocate General, an ‘obligation preventively to monitor, in general, the content of users of their services in search of any kind of illegal, or even simply undesirable information’ constitutes such an interference [para 104]. Article 15 e-Commerce Directive is ‘a general principle of law governing the Internet’ [para 106, emphasis in original and referring to Scarlet Extended and SABAM], and binds the EU legislature. Importantly, this principle does not prohibit all forms of monitoring; the jurisprudence of the CJEU has already distinguished monitoring which occurs in specific cases, and a similar position can be seen in the case-law of the ECtHR (Delfi). Tracing the development of the CJEU’s reasoning over time from the early cases of L’Oreal, Scarlet Extended and SABAM, through McFadden to Glawischnig-Piesczek (discussed here), the Advocate General opined that Article 17 is a specific monitoring obligation [para 110]; it focuses on specific items of content and the fact that a platform would have to search all content to find it does not equate to a general obligation.

 

Limitations – Proportionality

 

After reviewing the first two aspects of proportionality (appropriate and necessary), the Advocate General moved to discuss the heart of the matter:  proportionality strictu sensu and the balance achieved between the conflicting rights.  The Advocate General accepted that it was permissible for the EU legislature to change the balance it had adopted in Article 14 e-Commerce Directive for that in the new Copyright in the Digital Market Directive taking into account the different context, and the broad discretion the institutions have in the complex area. The Advocate General identified the following factors: the extent of the economic harm caused due to the scale of uploading; the ineffectiveness of the notice and take down system; the difficulties in prosecuting those responsible and the fact that the obligations concern specific service providers [para 137].

 

The next issue whether platforms would take ‘the easy way out’ and over-block just to be on the safe side in terms of their own exposure to liability. The Advocate-General excluded this possibility in his interpretation of the ‘best efforts’ obligation. So, the obligation to take users’ rights into account ex ante and not just ex post supports the proportionality of the measure; the redress rights and the out-of-court redress mechanism are supplementary safeguards. Service providers may not use any filtering technology but must instead consider the collateral effect of blocking when implementing measures. Systems which block based on just content and not taking into account the legitimate uses would fall foul of the position in Scarlet Extended and SABAM.

 

This was followed by a consideration of Glawischnig-Piesczek. In the light of the CJEU’s emphasis  on the platform in that case not having to make an independent decision as to the acceptability of content to take down (and to stay down), the Advocate General suggested that platforms cannot be expected to make independent assessments of the legality of content. He concluded:

 

to minimise the risk of ‘over-blocking’ and, therefore, ensure complaince with the right to freedom of expression, an intermediary provider may, in my view, only be required to filter and block information which has first been established by a court as being illegal or, otherwise, information the unlawfulness of which is obvious from the outset, that is to say, it is manifest, without, inter alia, the need for contextualisation [para 198].

 

Referring back to his own opinion in YouTube and Cyando, ‘an intermediary provider cannot be required to undertake general filtering of the information it stores in order to seek any infringement’ [200, emphasis in original].

 

The Advocate General concluded that Article 17 contained sufficient safeguards. Article 17(7), which states that measures taken ‘shall not result in the prevention of the availability of works or other subject matter uploaded by users, which do not infringe copyright and related rights’ means that wide blocking is not permitted and that in ambiguous cases, priority should be given to freedom of expression [para 207] and that ‘“false positives” of blocking legal content, were more serious than “false negatives”, which would mean letting some illegal content through’ [para 207]. Rights-holders can still request infringing content be taken down [para 218]. Having said that, a nil error rate for false positives is not required, though the error rate should be as low as possible and those techniques that result in a significant false positive rate being precluded. Article 17(10), which providers for stakeholder cooperation, is in the view of the Advocate-General the place to determine the practical implementation of these requirements [213].

 

Comment

The Opinion constitutes the attempts of the Advocate-General to steer a course through the radically different interpretations of Article 17, a fact which perhaps reflects the provision’s contentious nature.  The outcome of the case will be significant beyond the enforcement of copyright, as similar mechanisms might be required under other legislation: TERREG (Regulation 2021/784 on  addressing  the  dissemination  of  terrorist  content  online) for example, envisages hosting service providers putting in place ‘specific measures’ (recitals 22-23, Article 5(2)) that include the possibility of ‘technical means’ to address dissemination of terrorism content online.  The highlight news is, of course, that the Advocate-General did not find Article 17 to be contrary to Article 11 EUCFR though what that means for the obligations under Article 17 is potentially complex. Before discussing that issue, a number of other points can be noted.

 

The first point is the complex context for assessing fundamental rights. As the Advocate General noted, the platforms are private actors; it is not as simple as a user saying ‘because of freedom of expression I can upload what I like on this platform’.  There are two points.  The first is whether the platforms’ choices can be attributed to the Member States? This is relevant because the rights are not addressed to private actors (Article 51 EUCFR; this is also true under the ECHR).  This is an issue on which there has not – in the context of the EUCFR – been much case law to date.  The responsibility of the State, however, subsequently forms a significant element of the Advocate general’s approach to Article 17 and its safeguards: attributing the interference to the State means that the framework for analysis is that of the state’s negative obligations, rather than introducing questions of positive obligations.

 

At this early stage in his Opinion, however, the Advocate General was content to flag up the relevance of the rights. He referred to the jurisprudence of the ECHR to support his position:

 

-          Appleby, which concerned the access of peaceful protesters to a privately-owned shopping centre. There, the ECtHR held that they had no right under Article 10; they could make their views known in other venues.  This is a case about positive obligations.

 

-          Tierfabriken, concerning the refusal of the Commercial Television Company to allow the broadcast of an animal rights advert because it breached the company’s terms of business and the terms of national law. In the view of the regulatory authorities, the company was free to purchase its ads wherever it chose. The Court held that, irrespective of the formal status of the actors, the State was implicated because the company had relied on the prohibition of political advertising contained in the regulatory regime when making its decision. Domestic law “therefore made lawful the treatment of which the applicant association complained” [para 47]. 

 

Neither case seems to be making precisely the argument that the Advocate General made – that the platforms had no choice. Nonetheless, the point seems fair. The implications of this point should be considered; does this mean that whenever platforms make a decision based on elements of their terms of service that reflect national law that freedom of expression is implicated?  Beyond this point, it seems clear that platforms may set their own terms of service to reflect their business choices and that (subject to concerns about individuals losing all possibility of communicating) there would be no freedom of expression based complaint related to the enforcement of those terms. Further, it seems that were the State to try to interfere with the platforms’ choices in this regard, that interference would need to recognise Article 16 EUCFR or even Article 11.

 

The Advocate-General considered the lawfulness requirement in Article 52(1), something that the Court does not always do (assuming it is satisfied). As well as the formal required of being based in law, the lawfulness test has qualitative requirements. In carrying out his analysis, the Advocate-General treated questions about the safeguards against abuse which are part of the lawfulness test as part of questions of proportionality. In this, he followed the approach of the ECtHR under Article 8 ECHR (right to a private life) in the surveillance cases.  This approach has been criticised in that context as blurring two different questions aimed at two separate concerns and in so doing lowering the threshold of protection.  The approach has not so far been adopted in relation to freedom of expression even by the Strasbourg court and so is novel here.  The issue of safeguards in this Opinion is central, as we shall see below.

 

Another novelty is the discussion of the ‘essence of the right’, which has not received that much attention. The Advocate General helpfully started with a clear statement as to what the requirement is – an untouchable core – where the usual balancing of rights cannot take place.  Given the complex array of potentially conflicting rights in play in this context, that principle could be important. Once again, the Advocate General drew on the surveillance case law, perhaps because it is the only place where there is much discussion of the point. In the context of surveillance, the Court has held that general monitoring of content would damage the essence of the right, but that the general retention of metadata did not (though it might still be hard to justify). On one level the prohibition on general monitoring covers the same ground as the prohibition on mass content interception under Article 7 EUCFR (and Article 8 ECHR) – though Article 7 operates in the context of private communications rather than content that could well be made publicly, effectively broadcast. What is arguably a similar boundary was drawn here: general monitoring would undermine the core of the right but specific monitoring, as a form of prior restraint, would not.  In this, the Advocate General pointed out that although prior restraints are very intrusive of freedom of expression and tightly controlled under the Strasbourg jurisprudence, they are not automatically impermissible.  Significantly, the Advocate-General claimed that the prohibition on general monitoring is a general principle of Internet law – though it is far from clear what weight the status as ‘general principle’ has in this specific context. Is a general principle of Internet law different from a general principle within EU law more generally? Of course, this discussion is based on the assumption that filtering for specific content is somehow different from looking at everything and also leaves the question of how broad the category of content searched for can be before it ceases to be ‘specific’.

 

What then of the Advocate-General’s approach to Article 17?  From his analysis of the freedom of expression framework, the scope of the obligation is important with determining its acceptability. Clearly, the discussion of general versus specific monitoring is one aspect of this, but the safeguards required to legitimate an interference with freedom of expression also protect in the Advocate-General’s view against over-blocking. The inventive interpretation of the platforms’ ‘best efforts’ is central to this approach. Essentially, this interpretation narrows the scope of when and what is permissible; automated techniques can be used when they are functionally able to do the job.  On one viewpoint this is good; preventing platforms from over-reliance on possibly not very good technologies to the detriment of their users (and potentially exhibiting bias in that process too). It is a way of balancing the reality of scale with the concerns of over-blocking and could be seen as a clever way of reconciling conflicting demands. 

 

Does this interpretation, however, suggest, that the balance of Article 17 is still heavily shifted towards ex post moderation and take down systems because effectively the conditions that the Advocate General has set on the use of technology mean that there is no technology that can be used (and little incentive to develop it) or can only be used in a very limited way?  Where we are balancing copyright and business rights against freedom of expression, this shift towards a less effective content control system might not seem so bad (even if it flies in the face of the stated concerns driving the legislation), but would the same analysis be deployed in relation to child sexual exploitation and abuse material? The difficulty here is that the Advocate General’s framework for analysis is content blind. While it is based on the text of Article 17(7) and could therefore be understood as relevant just to this directive, his interpretation of that provision is given impetus by his introduction of the requirement for safeguards derived from freedom of expression. This would then have a wider application. The Advocate General here explicitly prioritises freedom of expression over another Charter right (Article 17 EUCFR) and there does not seem to be an obvious place within the safeguards framing where issues around the importance of speech or importance of other rights can easily be taken into account.

 

One final point to note is, of course, that this is an Opinion and not binding. The Advocate General referred to his reasoning in YouTube and Cyando. The Court decided that case without reference to his reasoning. It remains to be seen how much it will influence the Court here – or in relation to discussions around other legislation which envisage proactive technical measures.

 

Photo credit: via wikicommons media





Thursday, 14 January 2021

The proposed Digital Markets Act: overview and analysis


 


 

Professor Lorna Woods, University of Essex

 

Background

 

The Digital Markets Act (DMA) proposal is stable-mate to the Digital Services Act (DSA) proposal (discussed here) developed as part of a suite of actions to tackle concerns about the operation of the digital environment.  If enacted, it will form part of a complex tapestry of measures dealing with information society and electronic communications services of one form or another – found in to name but a few - the European Electronic Communications Code (which covers OTT voice services); the Audiovisual Media Services Directive (which covers video on demand potentially including some YouTube channels for example, as well as video sharing platforms); the P2B Regulation; and, of course, the e-Commerce Directive (which the DSA develops).  It will also be developed against a backdrop of increasing competition law enforcement actions against a number of large players in the market.  The EU is not the only actor taking steps and one important question will be how compatible these various initiatives are, as well as how effective.

 

Overview of the Proposal

 

Based on the recognition that platforms are a key structuring element of the current digital economy, the proposal provides for ex ante restrictions on an identified list of services, but only when those services are provided by operators which meet certain thresholds.  The Commission has enforcement responsibilities and powers, with similarities to those found in the competition field.

 

The relevant services are those which the Commission has identified as “core platform services” (CPS) (defined Art. 2(2)):

 

a)      online intermediation services;

b)      online search engines;

c)      online social networking services;

d)     videosharing platform services;

e)      number-independent interpersonal communication services;

f)       operating systems;

g)      cloud computing services; and

h)      advertising services provided by an operator which provides any of the services in (a)-(g).

 

While some of these terms are defined in other instruments (eg ‘information society service’, ‘online search engine’ and ‘video sharing platform service’, included no doubt to try to ensure coherence across the digital regulatory space, some are novel (eg ‘online social networking service’ and ‘software application stores’).  It remains to be seen how clear these definitions are.

 

The service operators who will be caught by the rules in this regulation are those designated as a “gatekeeper” according to Article 3. Article 3(1) contains a three stage test:

 

-          the existence of a significant impact on the internal market;

-          the operation of a CPS “which serves as an important gateway for business users to reach end users”; and

-          an entrenched and durable position in its operations.

 

These are assessed by quantitative criteria (based on turnover or market value, and user reach), producing a rebuttable presumption about the status of the operator, and refined by reference to qualitative criteria.  It is initially for the company itself to make this assessment and to notify the Commission.

 

Article 5 lists the obligations for gatekeepers and Article 6 contains a list of further actions that may be specified in respect of a gatekeeper. The obligations include positive obligations and prohibitions, essentially behaviours identified from previous competition investigations and against which competition rules seem insufficiently effective. These rules have been set down in some detail though the proposal envisages that the Commission may update the list of prohibited practices in the light of enforcement experience. This is important as otherwise closely specified rules could be overly rigid and not deal with developments in the market or practice. This, then, could introduce some element of future proofing.  The Regulation also provides for the possibility of exceptions, including exemption for overriding reasons of public interest (public morality, public health and public security).

 

            Prohibited Practices

 

-          refrain from combining personal data sourced from these core platform services with personal data from any other services offered by the gatekeeper or with personal data from third-party  services, and  from signing  in  end  users  to  other  services  of  the gatekeeper in order to combine personal data (this would catch, for example, the situation where logging into Gmail leads to you being logged into YouTube – this has come up in investigations into Facebook also) (Art5(a));

-          refrain from preventing or restricting business users from raising issues with any relevant public authority relating to any practice of gatekeepers (Art 5d);

-          refrain from requiring business users to use, offer or interoperate with an identification service of the gatekeeper (Art 5e);

-          refrain from requiring business users or end users to subscribe to or register with any other core platform services – this is a ban on tying (Art 5f);

-          refrain from using any not publicly available data about the activities of business users or their end users to compete with those business users, an issue that arose in the Amazon investigation (Art 6(1)(a));

-          Prevent end users from un-installing any pre-installed software applications (Art 6(1)(b));

-          Rank the own products of the gatekeeper more favourably than similar third-party products – this came up in the Google Shopping decision (Art 6(1)(d));

-          Technically restrict the ability of end users to switch between and subscribe to different software applications and services to be accessed using the gatekeeper’s operating system – ie, lock ins are not permitted (Art 6(1)(e)).

 

            Positive Obligations

 

-          allow business users to offer the same products or services to end users through third party online  intermediation  services  at  prices or  conditions  that  are  different  from those offered through the online intermediation services of the gatekeeper (MFN clauses) – currently platforms impose significant restraints on their business users in this regard as can be seen for example in the eBooks settlement (Art 5b));

-          allow  business  users  to  promote  offers  to  end  users  acquired  via  the  core  platform service, and to conclude contracts with these end users regardless of whether for that purpose they  use  the  core  platform  services  of  the  gatekeeper  or  not (so for example Apple’s requirement to use its in-app purchase system or even its app store) (Art 5c));

-          allow end users to access and use software application of a business user where software was  acquired  without using the core platform services of the gatekeeper (Art 5c));

-          provide  advertisers  and  publishers  to  which  it  supplies  advertising  services price information in relation to advertising services (Art 5g);

-          allow  the  installation  and  effective  use  of  third  party  software  applications  or software  application  stores  using,  or  interoperating  with,  operating  systems  of that gatekeeper  and  allow  these  software  applications  or  software  application stores  to  be accessed  by  means  other  than  the  core  platform  services  of  that gatekeeper (Art 6(1)(c));

-          apply FRAND conditions to rankings (Article 6(1)(d)), which might also reflect concerns in the P2B Regulation;

-          give business users and providers of ancillary services (eg payment processors, cloud hosts, digital identity providers, and ad-tech sellers) access to and interoperability with the same operating system, hardware or software features that are available or used by the gatekeeper itself (Art 6(1)(f));

-          provide data to allow independent verification of ad inventory (Art 6(1)(g));

-          ensure effective data portability – and real-time access (art 6(1)(h));

-          provide business users free of charge with effective, high-quality, continuous and real-time access to and use of aggregated and non-aggregated data (subject to GDPR) – this essentially ensures businesses can have access to their own business data (Art 6(1)(i));

-          provide third-party providers of search engines with access on fair, reasonable and non-discriminatory (FRAND) terms to ranking, query, click and view data generated by end users (Art 6(1)(j));

-          FRAND conditions for access for business users to the gatekeeper’s app store (Art 6(1)(k)).

 

By contrast to the position under competition law, in acting against these behaviours the Commission would not have to prove their impact on competition on the market, though the Commission’s ability to intervene under its competition powers remain unaffected.  The Commission seems therefore to have decided that concerns about pro-competitive effects of some behaviours (including self-preferencing) do not outweigh gains from clear rules for efficient enforcement. There have been some concerns that these closely defined prohibitions may not be appropriate for all gatekeepers, and it remains to be seen how the refinement levers of qualitative factors (as regards the designation as gatekeeper in the first place) and the obligations that are susceptible to specification (in Article 6) operate.

 

Note that these provisions apply to services that are offered across the gatekeeper’s core services; they do not require the interoperability of core services necessarily, nor benefit third party service providers who do not operate on the core services. 

 

The regulation also introduces provisions empowering the Commission to carry out market investigations for any of three purposes: identifying gatekeepers that are not captured by the quantitative thresholds of the DMA; identifying other services that should be added to the list of core platform services or new practices that may be unfair; identifying proportionate behavioural or structural remedies in the case of systematic infringement of the rules by a gatekeeper. Article 10 gives the Commission the power to adopt delegated acts to update the lists in Articles 5 and 6 when it discovers unfair practices in a market investigation.  This new tool is arguably less far reaching than the new competition tool originally envisaged because of competence issues and the limits of Article 114 TFEU.

 

The DMA obliges gatekeepers to inform the Commission of any proposed merger or acquisition involving another provider of core platform services or of any other services provided in the digital sector. For these purposes, it is irrelevant whether such an acquisition triggers a notification requirement under the EU (or national) merger control rules. This is not a specialist merger regime, but is to allow the Commission to review gatekeeper designations and obligations.

 

The DMA provides for up to 10 percent of a gatekeeper’s global annual revenue in fines for violating its rules, similar to those penalties available in competition cases.   Structural remedies remain a possibility in the case of ongoing problems or recalitrant actors (Article 16) but only where there are no equally effective behavioural remedies.

 

Comment

 

The Commission’s proposal is based on the assumption that there are problems and that reliance on competition tools is insufficient to deal with the problems, partly because of the length of time an investigation may take – for example, the Google Search case took in excess of 6 years.  The European Court of Auditors has recently published a report to similar effect.  Specifically as regards the DMA, the Regulation flags at Recital 10 the need to ensure contestability of markets – and in this it seems to reflect ordoliberal concerns found in many decisions where it has sought to protect the market, with knock on benefits perhaps to small and medium sized enterprises.  The proposal therefore adds additional measures as a complement to competition rules.  It seeks to introduce ex ante regulation to the generally ex post competition provisions and so avoid questions about the definition of markets, assessment of dominance and identification of the theory of harm (for example impact on nascent competition or on innovation).  Instead the key question is whether an operator is a “gatekeeper”.

 

Admittedly the cases that have come up under the competition rules in relation to the digital environment have been based on complex facts and raised difficult questions about application of the usual principles, but the resort to ex ante additional regulation is not new. This double pronged approach has been used before, notably in the not-so-very-distant field of telecommunications – though it should be noted that this approach is not unique to electronic communications sectors.  The EU approach to telecommunications can be seen as a model for the DMA as regards another aspect too: the decision not to embark on structural separation of big players, or at least not as a first port of call, but instead to rely on requiring them to open their platforms to providers of other services, whether direct substitutes or related services.  This approach can be seen in the liberalisation of the telecommunications sector from the late 80’s on, for example in the Access Directive.  As in the debate for data protection, there is the question as to whether financial penalties will ever be enough for companies as rich as the big tech companies.  Some (probably American commentators) see the unwillingness to break companies up as a significant weakness.

 

Another notable point is the role of the Commission.  By contrast to the telecommunications regime, where the national regulatory authorities have had a distinct and important role, enforcement powers lie with the Commission exclusively – perhaps reflecting the early position with regard to competition enforcement, where implementation of EU competition law was consolidated at EU level.  National authorities will however participate in a Digital Markets Advisory Committee that will assist the Commission.  This location of power at the EU level can be seen in other aspects of the proposal. The form of instrument proposed is a regulation, meaning it would be directly applicable in Member States’ legal systems without implementation. Moreover, the regulation seems to be envisaged as total harmonisation in this field.  Article 1(5) specifies that:

 

 “Member States shall not impose on gatekeepers further obligations by way of laws, regulations or administrative action for the purpose of ensuring contestable and fair markets”,

 

though the field to which this prohibition applies is restricted.  Nonetheless, this point is likely to be contentious.

 

As noted, a central question is the identification of gatekeepers and there are likely to be questions about the operators to which the DMA applies (and no specific platform has been named).Arguably, there will be difficulties in identifying criteria that work across the range of activities that platforms provide.  The assessment (which falls on the companies themselves) is a mix of assessing whether CPS are in issue and then looking at the Gatekeeper criteria.  Two points should be noted; the existing definitions are themselves complex and the developing market challenges them; secondly, it is unclear how the qualitative criteria will operate to rebut the presumptions based on the numbers.  There have been some comments that this definition will need to be improved as the proposal makes it way through the legislative process.

 

One final question relates to the relationship between this instrument (and its motivations) and that of the GDPR (and possibly the ePrivacy Directive) with their emphasis on the user and the user’s privacy.  While some of the ex ante prohibitions seem to flow in the same direction as data protection rules (notably the obligation to refrain from combining personal data as well as the tying of identity services), there might be some tension with data portability by businesses and access to user data, which will likely be – at least to some extent – subject to GDPR controls.  It remains to be seen how the two will operate together, and whether competition concerns operate to undercut data protection.

 

Photo credit: via Wikimedia commons