Showing posts with label free speech. Show all posts
Showing posts with label free speech. Show all posts

Monday, 27 July 2026

Reconciling data protection and ‘new media’: The judgment in Legal Newsdesk Sweden (Case C-199/24)

 


 

Lorna Woods, Professor Emerita, University of Essex

 

Photo credit: Océanos y dados, via Wikimedia commons

 

Introduction

This case deals with one of the perennial questions that has faced legal regimes which recognise special treatment for journalism and new media since the advent of “new media”, that is, how far are such exceptions and preferential treatment extended? While a question for individual States to balance the freedom of expression concerns with other rights and societal interests, for the EU there is also the fact that Member States seemingly take very different approaches.  The Swedish rules, the subject of this case, provide broad protections and exemptions from data protection rules; but are they compatible with the GDPR?

 

The Facts

The case originated when ND, who had been convicted a criminal offence, sought to have details of that offence removed from the database provided, for a fee, by Legal Newsdesk Sweden.  The database allows individuals and businesses to search for those who have been subject to criminal prosecution before a Swedish court. ND’s request for erasure of the data was not met and ND sought damages for failure to comply with data protection rules. Legal Newsdesk Sweden relied on a Swedish law exempting journalism from the GDPR, and the fact that the relevant authority had granted Legal Newsdesk Sweden a certificate confirming the protection applied (utgivningsbevis). Further this meant that the only remedies available to ND against Legal Newsdesk Sweden would be criminal prosecution or civil claims for defamation.

 

The Questions

The case revolved around the Swedish law’s compatibility with the GDPR and specifically whether the rules fell within the space created by Article 85. Article 85 provides:

 

(1) Member States shall by law reconcile the right to the protection of personal data pursuant to this Regulation with the right to freedom of expression and information, including processing for journalistic purposes and the purposes of academic, artistic or literary expression.

 

(2) For processing carried out for journalistic purposes or the purpose of academic artistic or literary expression, Member States shall provide for exemptions or derogations from Chapter II (principles), Chapter III (rights of the data subject), Chapter IV (controller and processor), Chapter V (transfer of personal data to third countries or international organisations), Chapter VI (independent supervisory authorities), Chapter VII (cooperation and consistency) and Chapter IX (specific data processing situations) if they are necessary to reconcile the right to the protection of personal data with the freedom of expression and information.

 

The national court referred three questions around the scope of Article 85(1) and (2) and their relationship to one another:

 

Is the list in Article 85(2) exhaustive or does Article 85(1) allow member States to adopt legislative measures in relation to further categories of activity?

 

Does the Swedish approach of limiting the remedies available to a person to criminal proceedings or defamation find an appropriate balance between freedom of expression and data protection?

Can the making available of information based on public documents in a database for a fee  without any processing or editing constitute processing of personal data for the purposes identified in Article 85(2) (specifically journalistic purposes)?

 

Judgment

As regards the first question, the Court held that the right to derogation from data protection rules applies only in relation to the categories enumerated in Article 85(2). The Court noted that Article 85(1) establishes a general rule about reconciliation of freedom of expression and GDPR requirements, but Article 85(2) operationalises it.  Although the term "including" confirms that journalistic, academic, artistic, and literary processing are only part of that reconciliation, paragraph 1 in itself does not grant independent exemption authority; that is the role of Article 85(2). The requirement to provide exceptions only applies to those exceptions listed. Exceptions are interpreted narrowly, and taking this approach provides a “fair balance”, as required by the principle of proportionality, between Charter rights.

 

As regards the second question, Article 85(2) lists the rights that may be limited, and that list does not include the rights to remedies provided for in the GDPR.  While there is Member State procedural autonomy, the GDPR confers directly effective rights and they can only be limited by conditions found in the GDPR. This means limitations such as those found in the Swedish law are not compatible with the GDPR.

 

The third question concerned whether the provision of the database constituted processing of personal data for journalistic purposes.  The Court confirmed, first, that the making available of documents to the public constituted processing. That exemptions were to be provided if necessary to provide the balance specified in Article 85(1). Moreover, the definition of journalism from Article 9 Directive 95/46 was in principle transposable to inform the concept of journalistic purposes, which was not otherwise defined, for the GDPR.  The Court referred to the definition in Satskunnan Markkinaporsii and Satamedia (Case C-73/07):

 

“disclosure to the public of information, opinions or ideas, irrespective of the medium which is used to transmit them”.

 

The Court also referred to Recital 153 GDPR which emphasises that the term should be interpreted broadly. The Court, however, continued to say it

 

“cannot cover all forms of expression but must be understood in a way that takes into account what differentiates, from the point of view of the manner in which they are created, journalistic expression from other forms of expression” [para 64]

 

The Court then referred to the case law of the European Court of Human Rights on protection of journalism within freedom of expression (Article 10 ECHR). From this body of jurisprudence, the CJEU identified three aspects:

  • carrying out the role of editing or adapting material, or publishing according to an editorial line or policy;
  • verification of factual claims for reliability; and
  • compliance with journalistic ethics.

 

The Court suggested that a service that simply makes criminal convictions available to anyone willing to pay, without editorial review or processing, is unlikely to satisfy those requirements.  The Court did emphasise that when the protections apply, they apply also to prior research as to publication.  So convictions can be useful raw material for journalists, but the processing is for  journalistic purposes only if those documents are used exclusively for such activity.

 

Commentary

This judgment is a strong defence of data protection and the coherence of the GDPR regime.  The main point of interest in this judgment is the Court’s approach to journalistic purposes. Before discussing that, it is also worth noting that in the Court’s approach to the relationship between Article 85(1) and 85(2), it has taken an approach with favours maximum harmonisation rather than allowing too much space for Member States to go their separate ways.  This re-emphasises the supremacy of EU law, and the narrowness of exceptions thereto, even when States’ individual constitutions are in issue. It is arguably a narrow interpretation of Article 85.  There is a question of how the balance that the Court has struck in Article 85(1) might impact other forms of data processing that impact the public information sphere – what for example, about search engines (already the subject of some jurisprudence: Case C-136/17 GC et al and Case C-460/20 TU and RE v Google), social media and – increasingly – chatbots?

 

Rights are a theme throughout this judgment but it is interesting to note that while the rights which the Swedish rules sought to limit were those relating to remedies, the Court did not rely on the right to a remedy as a fundamental right to support its argument. Rather, it relied on the fact that these were directly effective rights derived from the GDPR. The concern was the priority of EU legislative objectives over national concerns.

 

The main significance is the establishment of a three stage test for “journalistic purposes” which had hitherto been undefined.  The previous position had been established in Satamedia, and further elaborated in Google Spain (Case C-131/12) and Buivids (Case C-345/17), all of which seemed to be orientated towards elaborating the idea of informing the public which is the base of the definition in Satamedia.  It is arguable, that Legal Newsdesk Sweden’s activities might not fall within the scope of this definition anyway – though the position was certainly unclear. In identifying further criteria, however, the Court has provided more clarity and likely narrowed the scope of the journalistic purposes exception.  It is interesting to note that the Court has taken cases about the level or protection awarded to journalists within the ECHR jurisprudence to identify qualifying criteria for being a journalist (of carrying out journalistic purposes) in the GDPR context- a shift from assessing how to identifying who. Whether this shift is significant in practical terms is rather uncertain – both Courts seem to be asking if the person is behaving according to relevant standards to gain the benefits of extra protection (and neither require institutional affiliation as a precondition of receiving the status).

 

While the focus in the case was just about resale of public information without any amendment, contextualisation or commentary (and possibly data brokerage generally including digital archives, research platforms, aggregators, and people-search services), the implications go further and impact “citizen journalists”, bloggers, gossip sites and other public communicators who might have assumed that they would benefit from protections, even though they might also not have bothered with fact checking and ethical considerations around news-gathering and publication. While they might have argued that they contributed to informing society, now there are more specific and arguably less vague requirements to satisfy – those around verification and ethics. Although this is a narrowing of their protections, it does not mean such speakers are off air – it means that they have to pay more attention to how they acquire and retell stories.  It is also important to note that the Court has not as a point of principle excluded private actors (rather than those earning a living from journalist) from the scope of state protections, and nor does the fact that such activities are done for money affect the assessment of whether they are done for journalistic purposes or not. And, of course, traditional journalism and media are not affected by this ruling.

 

One final point is also clear: the Swedish system will require significant overhaul if it is to comply with GDPR requirements.

Thursday, 6 June 2024

EU Media Freedom Act: the convolutions of the new legislation

 



Samira Asmaa Allioui, research and tutorial fellow at the Centre d'études internationales et européennes de l'Université de Strasbourg

 

Photo credit: Bin im Garten, via Wikimedia Commons

 

Journalists are under pressure in different ways. Throughout the last few years, media freedom and especially media pluralism are in peril.

On December 15, 2023, the European Council and the European Parliament struck a deal on rules to safeguard media freedom, media pluralism and editorial independence in the European Union. The EU Media Freedom Act (EMFA) promised increased transparency about media ownership and safeguards against government surveillance and the use of spyware against journalists. The agreement comes after numerous revisions of the Audiovisual Media Services Directive (AMSD) and new regulations such as the Digital Market Act (DMA) and Digital Services Act (DSA). As a reminder, the EMFA builds on the DSA.

The aim of this contribution is to present an overview of the EMFA and specifically to analyse to what extent its rules still contribute to the limitation of freedom of speech, the erosion of trust, the breach of democratic processes, disinformation, and legal uncertainty.

The EMFA requires EU countries to respect editorial freedom, no spyware, no political interference, stable funding for public media, protection of online media and transparent state advertising.  It established a European watchdog: a new independent European Board for Media Services to fight interference from inside and outside the EU.

Nevertheless, this new EU legislation tries to set boundaries for the journalists’ actions through Article 18 EMFA on the protection of media content on very large online platforms (VLOPs), and the potential detrimental effects of introducing something akin to a media exemption. But the most significant ambiguity is addressed by Article 2 of the EMFA on the definition of ‘media service’ which appears to be the problem everyone acknowledges. This raises the question of who the EMFA is protecting. Are democracy and the possibility for people to get impartial and unbiased information really strengthened? Not forgetting that for the European Parliament elections, there is a potential danger of political interference by extra-European countries that will try to take advantage of democratic elections to influence the media illegally, by creating fake social media accounts and by launching a massive propaganda campaign to disseminate conflict-ridden content.

 

THE ACCURACY OF INFORMATION

The EMFA focuses on two main points regarding VLOPs. First, it asserts that platforms limit users’ access to reliable content when they apply their terms and conditions to media companies that practice editorial responsibility and create news conforming with journalistic standards. First, the Regulation takes aim at VLOPs’ gatekeeping power over access to media content. To do so, the EMFA aims to remould the relationship between media and platforms. Media service providers that exercise editorial responsibility for their content have a primary role in the dissemination of information and in the exercise of freedom of information online. In exercising this editorial responsibility, they are expected to intervene diligently and provide reliable information that complies with fundamental rights, in accordance with the regulatory or self-regulatory requirements to which they are subject in the Member States.

Secondly, it asserts that the quality of the media may fight against disinformation. To consider this problem, the EMFA’s objective is to adjust the connection between platforms and media. According to Article 2 EMFA, ‘media service’ means ‘a service as defined by Articles 56 and 57 [TFEU], where the principal purpose of the service or a dissociable section thereof consists in providing programmes or press publications, to the general public, under the editorial responsibility of a media service provider, by any means, in order to inform, entertain or educate’  A ‘media service’ has some protections under the Act.  According to Joan Barrata, the media definition under EMFA is an overly “limited” definition, which is not “aligned” with international and European human rights standards, and “discriminatory”, as it excludes “certain forms of media and journalistic activity”. The DSA classifies platforms or search engines that have more than 45 million users per month in the EU as VLOPs or Very Large Online Search Engines (VLOSEs). As an illustration, according to Article 18 EMFA, media service providers will be afforded special transparency and contestation rights on platforms. In addition to that, according to Article 19 EMFA, media service providers will have the opportunity to engage in a constructed dialogue with platforms on concepts such as disinformation. Under the agreement, VLOPs will have to inform media service providers that they plan to remove or restrict their content and give them 24 hours to answer (except in the event of a crisis as defined in the DSA).

Article 18 of the EMFA enforces a 24-hour content moderation exemption for media, effectively making platforms host content by force. By making platforms host content by force, this rule prevents large online platforms from deleting media content that violates community guidelines. Nevertheless, not only it could threaten marginalised groups, but it could also undermine equality of speech and fuel disinformation. This is a vicious circle between the speaker planting false information on social media, the media platform spreading the false speech thanks to amplifying algorithms or human-simulating bots, and the recipients who view the claims and spread them.

According to the EMFA provides that, before signing up to a social media platform, platforms must create a “special/privileged communication channel” to consider content restrictions with “media service providers”, defined as “a natural or legal person whose professional activity is to provide a media service and who has editorial responsibility for the choice of the content of the media service and determines the manner in which it is organised “. In other words, instead of being forced to host any content, online platforms should provide special privileged treatment to certain media outlets.

However, not only does this strategy impede platforms’ autonomy in enforcing their terms of use (nudity, disinformation, self-harm) but it also imperils the protection of marginalised groups who are frequently the main targets of disinformation and hate speech. Politics remains fertile ground for hate speech as well as disinformation. Online platforms and social media have played a key role in amplifying the spread of hate speech and disinformation. As proof, recent reports reveal the widespread abuse of these platforms by political parties and governments. Indeed, it turns out that more than 80 countries around the world have engaged in political disinformation campaigns.

This could also permit misleading information to remain online which allows sufficient time to see the information transmitted and disseminated, hindering one of the key objectives of EMFA - to give more reliable sources of information to citizens.


ABUSIVE REGULATORY INTERVENTION AND DETERIORATION OF TRUST

Primarily, one can only be concerned about any regulatory intervention by governments on issues such as freedom of expression or media freedom. Through their EU Treaty competencies in security and defence matters, EU Member States seem to be winning because their options to spy on reporters have been reaffirmed. However, according to the final text (April 11, 2024), the European Parliament added important guarantees to allow the use of spyware, which will only be possible on a case-by-case basis and subject to authorization from an investigating judicial authority as regards serious offenses punishable by a sufficiently long custodial sentence.

Furthermore, it must be emphasized that even in these cases the subjects will have the right to be informed after the surveillance and will be able to challenge it in court. It is also specified that the use of spyware against the media, journalists and their families is prohibited. In the same vein, the rules specify that journalists should not be prosecuted for having protected the confidentiality of their sources.

The law restricts possible exceptions to this for national security reasons which fall within the competence of member states or in cases of investigations into a closed list of crimes, such as murder, child abuse or terrorism. Only in such situations or cases of neglect, the law makes it very clear that this must be duly justified, on a case-by-case basis, in accordance with the Charter of Fundamental Rights, in circumstances where no other investigative tool would be adequate.

In this regard, the law therefore allows for new concrete guarantees at EU level in this regard. Any journalist concerned would have the right to seek effective judicial protection from an independent court in the Member State concerned. In addition to that, each Member State will have to designate an independent authority responsible for handling complaints from journalists concerning the use of spyware against them. These independent authorities provide, within three months of the request, an opinion on compliance with the provisions of the law on media freedom.

Some governments in Europe have tried to interfere in the work of journalists recently which is a blatant demonstration of how far politicians can go against media using national security as an excuse. To avoid an erosion of trust, media service providers must be totally transparent about their ownership structures. That is why, in its final version (April 2024), the EMFA enhances transparency of media ownership, responding to rising concerns in the EU about this issue. The EMFA broadens the scope of the requirements of transparency, providing for rules guaranteeing the transparency of media ownership and preventing conflicts of interest (Article 6) as well as the creation of a coordination mechanism between national regulators in order to respond to propaganda from hostile countries outside the EU (Article 17).

To do that, there is a need to deepen safeguards to shield all media against economic capture by private owners to avoid media capture. It can be worse when no official intervention can mean non-transparent and selective support for pro-government media. As a matter of fact, it demonstrates that a combination of political pressure and corruption can be risky for the free press.

Secondly, the EMFA’s content moderation provisions could ruin public trust in media and endanger the integrity of information channels. Online platforms moderate illegal content online. Moderation provisions include: a solution-orientated conversation between the parties (VLOPs, the media and civil society) to avoid unjustified content removals; obligatory annual reporting (reports on content moderation which must include information about the moderation initiative, including information relating to illegal content, complaints received under complaints-handling systems, use of automated tools and training measures) by very large online platforms (VLOPs); any complaint lodged under complaints-handling systems by media service providers must be processed with priority; and additional protection against the unjustified removal by VLOPs of media content produced according to professional standards. These platforms will need to take every precaution to communicate the reasons for suspending content to media service providers before the suspension becomes effective. The process consists of a series of safeguards to ensure that this rapid alert procedure is consistent with the European Commissions’ priorities such as the fight against disinformation. In this regard, the Electronic Frontier Foundation states that « By creating a special class of privileged self-declared media providers whose content cannot be removed from big tech platforms, the law not only changes company policies but risks harming users in the EU and beyond ».


MEDIA COMPANIES AND PLATFORMS BARGAINING CONTENT

Yet the EMFA still does not deal with the complex issue of who would oversee controlling the self-declarations (Article 18(1) EMFA). More precisely, according to Article 18 EMFA “Providers of [VLOPs] shall provide a functionality allowing recipients of their services to declare” that they are media service providers. This self-declaration can be done, mainly, according to three criteria: if public service media providers fulfill the definition of Article 2 EMFA; if public service media providers “declare that they are editorially independent from Member States, political parties, third countries and entities owned or controlled by third countries”; and if public service media providers “declare that they are subject to regulatory requirements for the exercise of editorial responsibility in one or more Member States” or adhere “to a co-regulatory or self-regulatory mechanism governing editorial standards that is widely recognised and accepted in the relevant media sector in one or more Member States”. According to Article 18(4), when a VLOP decides to suspend its services regarding the content provided by a self-declared media service provider, “on the grounds that such content is incompatible with its terms and conditions”, it must “communicate to the media service provider concerned a statement of reasons” accompanying that decision “prior to such a decision to suspend or restrict visibility taking effect”.

Aside from that, Article 18 EMFA  splits the rules implemented by the Digital Services Act (DSA), a horizontal instrument that aims to create and ensure a more trustworthy online environment by putting in place a multilevel framework of responsibilities targeted at different types of services and by proposing a set of asymmetric obligations harmonized at EU level with the aim of ensuring regulatory oversight of the EU transparency, online space and accountability. Those rules covering all services and all types of illegal content, including goods or services are set by the DSA. This implies that media regulators will be enrolled in the cooperation mechanisms that will be set up for the aspects falling under their mandate. The inception of a specific “structured cooperation” mechanism is intended to contribute to strengthening robustness, legal certainty, and predictability of cross-border regulatory cooperation. This entails enhanced coordination and more precisely collective deliberation between national regulatory authorities (NRAs) which can bring significant added value to the application of the EMFA. This implies that media regulators will be involved in the cooperation mechanisms that will be set up for the aspects falling under their remit, even if it is still unclear how this will look in practice.

Above all, how will the new legislation be applied in practice and how will it work to ensure that it neither undermines the equality of speech and democratic debate nor endangers vulnerable groups? Excluding the fact that Article 18 of the EMFA incorporates safeguards about AI-generated content, details about which remain undisclosed as of now (see also Hajli et al on ‘Social Bots and the Spread of Disinformation in Social Media’ and Vaccari and Chadwick on ‘Deepfakes and Disinformation’), there is clearly reason to be concerned about the use of generative AI to promote disinformation and deep fakes. In an era where new technologies dominate, voluntary guidelines are not enough. Stronger measures are urgently needed to balance free speech and to have control over AI systems. It is admitted that while AI can be an excellent tool for journalists, it can also be used for bad purposes.

 

INEQUALITY BETWEEN MEDIA PROVIDERS: THE ATTRIBUTION OF A SPECIAL STATUS

In terms of platforms and media companies negotiating content, since not all media providers (media companies negotiating content) will receive a special status, it creates inequality. Platforms will have to guarantee that most of the reported information is publicly accessible. The main privilege resulting from this special status is that VLOP providers are more restricted in the way they moderate the content, but not in the sense of a ban on acting against this content but rather in the form of advanced transparency and information towards the information provider concerned. This effectively leads to an uncertain negotiation situation in which influential media and platforms negotiate over what content remains visible. This is especially true since the media have financial interests in seeking a rapid means of communication and in ensuring that their content remains visible even if it is at the expense of small providers.


CONCLUSION

As a conclusion, the risk to tamper with public opinion by disguising disinformation and propaganda as legitimate media content is still reflected in Article 18’s self-proclamation mechanism. In top of that, the risk of establishing two categories of freedom of speech arises from the fragmentation of legislation, not aligning with the DSA. Then, our capacity to create informed decisions could be undermined by Article 18 EMFA, an article that allows self-proclaimed media entities to operate with insufficient oversight. Furthermore, our democratic processes risk to be severely damaged by the unregulated spread of disinformation. Finally, the opacity of Article 18 in the determination of the authenticity of self-proclaimed media engenders problems of compliance enforcement.

The elements recalled here highlight the underside of the new legislation and corroborates that efforts must be made in the future to remedy the critical situation of press freedom within the EU.

 

Tuesday, 11 January 2022

A democratic alternative to the Digital Services Act's handshake between States and online platforms to tackle disinformation

 



 

By Paul De Hert* and Andrés Chomczyk Penedo**

 

* Professor at Vrije Universiteit Brussel (Belgium) and associate professor at Tilburg University (The Netherlands)

** PhD Researcher at the Law, Science, Technology and Society Research Group, Vrije Universiteit Brussel (Belgium). Marie Skłodowska-Curie fellow at the PROTECT ITN. The author has received funding from the European Union’s Horizon 2020 research and innovation programme under the Marie Skłodowska-Curie grant agreement No 813497

 

 

 

1. Dealing with online misinformation: who is in charge?

 

Misinformation and fake news are raising concerns for the digital age, as discussed by Irene Khan, the United Nations Special Rapporteur on the promotion and protection of the right to freedom of opinion and expression (see here). For example, during the last two years, the COVID19 crisis caught the world by surprise and considerable discussions about the best course of action to deal with the pandemic were held. In this respect, different stakeholders spoke up but not all of them were given the same possibilities to express their opinion. Online platforms, but also traditional media, played a key role in managing this debate, particularly using automated means (see here).

 

A climate of polarization developed, in particular on the issue of vaccination but also around other policies such as vaccination passports, self-tests, treatment of the virus in general, or whether the health system should focus on ensuring immunity through all available strategies (see here). Facebook, YouTube, and LinkedIn, just to name a few, stepped in and started delaying or censoring posts that in one way or another were perceived as harmful to governmental strategies (see here). While the whole COVID19 crisis deserves a separate discussion, it serves as an example of how digital platforms are, de facto, in charge of managing online freedom of expression and, from a practical point of view, have the final say in what is permissible or not in an online environment.

 

The term 'content’ has been paired with adjectives such as clearly illegal, illegal and harmful, or legal but harmful, just to name the most relevant ones. However, what does exactly each of these categories entail, and why are we discussing these categories? What should be the legal response, if any, to a particular piece of content and who should address it? While content and its moderation is not a new phenomenon, as Irene Khan points in her previously mentioned report, technological developments, such as the emergence and consolidation of platforms, demand new responses.

 

With this background, the European Union is currently discussing at a surprisingly, very quick speed the legal framework for this issue through the Digital Services Act (the DSA, previously summarised here). The purpose of this contribution is to explore how misinformation and other categories of questionable content are tackled in the DSA and to highlight the option taken in the DSA to transfer government-like powers (of censorship) to the private sector. A more democratic alternative is sketched. A first one is based on the distinction between manifestly illegal content and merely illegal content to distribute better the workload between private and public enforcement of norms. A second alternative consists in community-based content moderation as an alternative or complementary strategy next to platform-based content moderation

 

 

2. What is the DSA?

 

The DSA (see here for the full text of the proposal and here for its current legislative status) is one of the core proposals in the Commission’s 2019-2024 priorities, alongside the Digital Markets Act (discussed here), its regulatory ‘sibling’. It intends to refresh the rules provided for in the eCommerce Directive and deal with certain platform economy-related issues under a common European Union framework. It covers topics such as: intermediary service providers liability - building up from the eCommerce Directive regime and expanding it -, due diligence obligations for a transparent and safe online environment -including notice and takedown mechanisms, internal complaint-handling systems, traders traceability, and advertising practices-, risk management obligations for very large online platforms and the distribution of duties between the European Commission and the Member States. Many of the these topics might demand further regulatory efforts beyond the scope of the DSA, such as political advertisement which would be complemented by sector-specific rules as, for example, the proposal for a Regulation on the Transparency and Targeting of Political Advertising (see here).

 

As of late November 2021, the Council has adopted a general approach to the Commission’s proposal (see here) while the European Parliament is still dealing with the discussion of possible amendments and changes to that text (see here). Nevertheless, as with many other recent pieces of legislation (see here), it is expected that its adoption is sooner rather than later in the upcoming months.

 

3. Unpacking Mis/Disinformation (part1): illegal content as defined by Member States

 

We started by discussing misinformation and fake news. If we look at the DSA proposal, the term 'fake news' is missing in all its sections. However, the concept of misinformation appears as disinformation in Recitals 63, 68, 69, and 71. Nevertheless, both terms are nowhere to be found in the Articles of the DSA proposal.

 

In literature, the terms are used interchangeably or are distinguished, with disinformation defined as the intentional and purposive spread of misleading information, and misinformation as ‘unintentional behaviors that inadvertently mislead’ (see here). But that distinction does not help in recognizing either mis- or disinformation, from other categories of content.

 

Ó Fathaigh, Helberger, and Appelman (see here) have pointed that disinformation, in particular, is a complex concept to tackle and that very few scholars have tried to unpack its meaning. Despite the different policy and scholarly efforts, a single unified definition of mis- or disinformation is still lacking, and the existing ones can be considered as too vague and uncertain to be used as legal definitions. So, where shall we start looking at these issues? A starting point, so we think, is the notion of content moderation, which according to the DSA proposal, is defined as follows:

 

'content moderation' means the activities undertaken by providers of intermediary services aimed at detecting, identifying, and addressing illegal content or information incompatible with their terms and conditions, provided by recipients of the service, including measures taken that affect the availability, visibility, and accessibility of that illegal content or that information, such as demotion, disabling of access to, or removal thereof, or the recipients' ability to provide that information, such as the termination or suspension of a recipient's account (we underline);

 

Under this definition, content moderation is an activity that is delegated to providers of intermediary services, particularly online platforms, and very large online platforms. Turning to the object of the moderation, we can ask what is exactly being moderated under the DSA? As mentioned above, moderated content is usually associated with certain adjectives, particularly illegal and harmful. The DSA proposal only defines illegal content:

 

illegal content’ means any information, which, in itself or by its reference to an activity, including the sale of products or provision of services is not in compliance with Union law or the law of a Member State, irrespective of the precise subject matter or nature of that law;

 

So far, this definition should not provide much of a challenge. If the law considers something as, it makes sense that it is similarly addressed in the online environment as in the physical realm. For example, a pair of fake sneakers constitute a trademark infringement, regardless of if the pair is being sold via eBay or by a street vendor in Madrid’s Puerta del Sol. In legal practice, regulating illegal content is not black and white. A distinction can be made between clearly illegal content and situations where further exploration must be conducted to determine the illegality of certain content. This is how it is framed in the German NetzDG, for example. In some of the DSA proposal articles, mainly Art. 20, we can see the distinction between manifestly illegal content and illegal content. However, this distinction is not picked up again in the rest of the DSA proposal.

 

What stands is that the DSA proposal does not expressly cover disinformation but concentrates on the notion of illegal content. If Member State law defines and prohibit mis- or disinformation -which Ó Fathaigh, Helberger and Appelman have reviewed and found to be inconsistent across the EU- , then this would fall under the DSA category of illegal content. Rather than creating legal certainty, this further reinforces legal uncertainty and pegs the notion of illegal content to be dependent on each Member State's provisions. But where does this leave disinformation that is not regulated in in Member State laws? The DSA does not like it, but its regulation is quasi hidden.

 

 

4. Unpacking Mis/Disinformation (part2): harmful content non defined by the DSA

 

The foregoing brings us to the other main concept dealing with content in the DSA, viz. harmful content. To say that this is a (second) 'main' concept might confuse the reader, since the DSA does not define it or regulate it at great lengths.  The DSA’s explanatory memorandum states that `[t]here is a general agreement among stakeholders that ‘harmful’ (yet not, or at least not necessarily, illegal) content should not be defined in the Digital Services Act and should not be subject to removal obligations, as this is a delicate area with severe implications for the protection of freedom of expression’.

 

As such, how can we define harmful content? This question is not new by any means as we can trace back policy documents from the European Union dating back to 1996 (see here) dealing with this problem. Since then, little has changed in the debate surrounding harmful content as the core idea remains untouched: harmful content refers to something that, depending on the context, could affect somebody due to it being unethical or controversial (see here).

 

In this respect, the discussion on this kind of content does not tackle a legal problem but rather an ethical, political, or religious one. As such, it is a valid question to be asked if laws and regulations should even mingle in this scenario. In other words, does it make sense to talk about legal but harmful content when we discuss new regulations? Should our understanding of illegal and harmful content be construed in the most generous way to accommodate for the most amount of situations possible to avoid this issue? And more importantly, if the content seems to be legal, does it make sense to add the adjective of ‘harmful’ rather than using, for example, ‘controversial’? Regardless of the terminology used, this situation leaves us with three types of content categories: (i) manifestly illegal content; (ii) illegal, both harmful and not, content; (iii) legal but harmful content. Each of them demands a different approach, which shall be the topic of our following sections.

 

 

5. Illegal content moderation mechanisms in the DSA (content type 1 & 2)

 

The DSA puts forward a clear, but complex, regime for dealing with all kinds of illegal content. As a starting point, the DSA proposal provides for a general no monitoring regime for all intermediary service providers (Art. 7) with particular conditions for mere conduits (Art. 3), caching (Art. 4), and hosting service providers (Art. 5). However, voluntary own-initiative investigations are allowed and do not compromise this liability exemption regime (Art. 6). In any case, once a judicial or administrative order mandates the removal of content, this order has to be followed to avoid incurring liability (Art. 8). In principle, public bodies (administrative agencies and judges) have control over what is illegal and when something should be taken down.

 

However, beyond this general regime, there are certain stakeholder-specific obligations spread out across the DSA proposal also dealing with illegal content that challenge the foregoing state-controlled mechanism. In this respect, we can point out the mandatory notice and takedown procedure for hosting providers with a fast lane for trusted flaggers notices (Arts. 14 and 19, respectively), in addition to the internal complaint-handling system for online platforms paired with the out-of-court dispute settlement (Arts. 17 and 18, respectively) and, in the case of very large online platforms, these duties should be adopted following a risk assessment process (Art. 25). With these set of provisions, the DSA grants a considerable margin to certain entities to act as law enforcers and judges, without a government body having a say in if something was illegal and its removal was a correct decision.

 

6. Legal but harmful content moderation mechanisms in the DSA (content type 3)

 

But what about our third type of content, legal but harmful content, and its moderation? Without dealing with the issue of content moderation directly, the DSA transfers the delimitation of this concept to providers of online intermediary services, mainly online platforms. In other words, a private company can limit apparently free speech within its boundaries. In this respect, the DSA proposal grants all providers of intermediary services the possibility of further limiting what content can be uploaded and how it shall be governed via the platform’s terms and conditions and, by doing so, these digital services providers are granted substantial power in regulating digital behavior as they see fit:

 

‘Article 12 Terms and conditions

 

1. Providers of intermediary services shall include information on any restrictions that they impose concerning the use of their service in respect of information provided by the recipients of the service, in their terms and conditions. That information shall include information on any policies, procedures, measures, and tools used for content moderation, including algorithmic decision-making and human review. It shall be set out in clear and unambiguous language and shall be publicly available in an easily accessible format.

 

2. Providers of intermediary services shall act in a diligent, objective, and proportionate manner in applying and enforcing the restrictions referred to in paragraph 1, with due regard to the rights and legitimate interests of all parties involved, including the applicable fundamental rights of the recipients of the service as enshrined in the Charter.’

 

In this respect, the DSA consolidates a content moderation model heavily based around providers of intermediary services, and in particular, very large online platforms, acting as lawmakers, law enforcers, and judges at the same time. They are lawmakers as the terms and conditions lay down what is permitted as well as forbidden in the platform. While there isn't a general obligation to patrol the platform, they must react to notices from users and trusted flaggers and enforce the terms if necessary. And, finally, they act as judges by attending to the replies from the user who uploaded illegal content and dealing with the parties involved in the dispute, notwithstanding the alternative means provided for in the DSA.

 

Rather than using the distinction between manifestly illegal content and ordinary illegal content and refraining from regulating other types of content, the DSA creates a governance model for moderation of all content in the same manner. While administrative agencies and judges can request content to be taken down, under Art. 8, the development of the further obligations mentioned above poses the following question: who is the main responsible to define what is illegal and what is legal? Are the existing institutions subject to checks and balances or rather private parties, particularly BigTech and very large online platforms?

 

 

7. The privatization of content moderation: the second (convenient?) invisible handshake between the States and platforms

 

As seen with many other areas of the law, policymakers and regulators have slowly but steadily transferred government-like responsibilities into the private sector and mandated their compliance relying on a risk-based approach. For example, in the case of financial services, banks, and other financial services providers have turned into the long arm of financial regulators to tackle money laundering and tax evasion rather than relying on government resources to do this. This resulted in financial services firms having to process vast amounts of personal data to determine whether a transaction is illegal (either because it is laundering criminal proceedings or avoiding taxes) with nothing but their planning and some general guidelines; if they fail in this endeavor administrative fines (and in some cases, criminal sanctions) can be expected. The result has been an ineffective system to tackle this problem (see here) yet regulators keep on insisting on this approach.

 

A little shy of 20 years ago, Birnhack and Elkin denounced the existence of an invisible handshake between States and platforms for the protection and sake of national security after the 9/11 terror attacks (see here). At that time, this invisible handshake could be considered by some as necessary to deal with an international security crisis. Are we in the same situation as we speak when it comes to dealing with disinformation and fake news? This is a valid question. The EU policy makers seems to be impressed by voices such as Facebook’s whistleblower Frances Haugen who wants to align 'technology and democracy' by enabling platforms to moderate post. The underlying assumption seems to be that platforms are in the best position to moderate content following supposedly clear rules and that 'disinformation' can be identified (see here).

 

Content moderation presents a challenge for States given the amount of content generated non-stop across different intermediary services, in particular, social media online platforms (see here). Facebook employs a sizable staff of almost 15,000 individuals as content moderators (see here) but also relies heavily on automated content moderation, authorized by the DSA proposal under Arts. 14 and 17, in particular, to mitigate mental health problems to those human moderators given the inhuman content they sometimes have to engage with. To put this in comparison, using the latest available numbers from the Council of Europe about the composition of judiciary systems in Europe (see here), the Belgian judiciary employs approximately 9200 individuals (-the entire judiciary dealing with issues about commercial law up to criminal cases-), a little more than half of Facebook’s content moderators.

 

As such, one can argue that courts could be easily overloaded with cases that demand a quick and agile solution for defining what is illegal or harmful content if platforms didn't act as a first-stage filter for content moderation. Governments would need to heavily invest in administrative or judicial infrastructure and human resources to deal with such demand from online users. This matter has been discussed by scholars (see here). The available options they see either (i) strengthening platform content moderation by requiring the adoption of judiciary-like governance schemes, such as social media councils as Facebook has done; or (ii) implementing e-courts with adequate resources and procedures suited to the needs of the digital age to upscale our existing judiciary.

 

8. The consequences of the second invisible handshake

 

The DSA seems to have, willingly or not, decided on the first approach. Via this approach, -the privatization of content moderation-, States do not have to deal with the lack of judicial infrastructure to deal with the amount of content moderation that digital society requires. As shown by our example, Facebook has an infrastructure, just on raw manpower available, that doubles that of a country’s judiciary, such as Belgium. This second invisible handshake between BigTech and States can be situated in the incapacity of States to deal with disinformation effectively with the current legal framework and institutions.

 

If the DSA proposal is adopted ‘as is’, then platforms would have a significant power over individuals. First, through the terms and conditions, they would in position to determine what is allowed to be said and what cannot be discussed, as provided for by Art. 12. Not only that but also any redress before decisions adopted by platforms would have to be first channeled through the internal complaint handling mechanisms, as provided for by Arts. 17 and 18, for example, rather than seeking judicial remedy. As it can be appreciated, the power scale has clearly shifted towards platforms, and by extension to governments, in detriment of end-users.

 

Besides this, the transfer of government-like powers to platforms contributes to avoiding making complicated and hard decisions that could cost political reputation. Returning to our opening example, the lack of a concrete decision from our governments regarding sensitive topics has left platforms in charge of choosing what is the best course of action to tackle a worldwide pandemic by defining when something is misinformation that can affect the public health and when something could help fight back something that is out of control. Not only that but if platforms wrongfully approach the issue, then they are exposed to fines for non-compliance with their obligations, although particularly very large online platforms can deal with the fines proposed under the DSA.

 

If the second invisible handshake is going to take place, the least we, as a society, deserve is that agreement is made transparent so that public scrutiny can oversight such practices and free speech can be safeguarded. In this respect, the DSA could have addressed the issue of misinformation and fake news in a more democratic manner. Two proposals:

 

 

9. Addressing disinformation more democratically to align 'technology and democracy'

 

Firstly, the distinction between manifestly illegal content and merely illegal content could have been extremely helpful in distributing the workload between the private and public sector in a manner that administrative authorities and judges would only take care of cases where authoritative legal interpretation is necessary. As such, manifestly illegal content, such as apology to crime or intellectual property infringements, could be handled directly by platforms and merely illegal content by courts or administrative agencies. In this respect, a clear modernization in legal procedures to deal with claims about merely illegal content would still be necessary to adjust the legal response time to the speed of our digital society. Content moderation is not alone in this respect but joins the ranks of other mass-related issues, such as consumer protection, where effective legal protection is missing due to the lack of adequate infrastructure to channel complaints.

 

Secondly, as for legal but harmful content, while providers of online intermediary services have a right to conduct their business as to how they see fit and therefore can select which content is allowed or not via terms and conditions, citizens do have a valid right to engage directly in the discussion of those topics and determine how to proceed with them. This is even more important as users themselves are the ones interacting on these platforms and that content is exploited by platforms to ensure that controversy remains on the table to ensure engagement (see here).

 

However, there is a possibility to deal with content moderation, particularly in the case of legal but harmful content, that avoids a second invisible handshake: community-based content moderation strategies (see here) where users have a more active role in the management of online content has proven to be successful in certain online platforms. While categories such as clearly illegal or illegal and harmful content do not provide much margin for societal interpretation, legal but harmful content could be tackled by citizens' involvement. In this respect, community-based approaches, while resource-intensive, allow for citizens to engage directly in the debate about the issue at hand.

 

While community-based content moderation also has its own risks, it could serve as a more democratic method than relying on platforms’ unilateral decisions and it might serve where judges and administrative agencies cannot go due to the legality of content. As noted by the Office of the United Nations High Commissioner for Human Rights, people, rather than technology, should be making the hard decisions but also States, as elective representatives of society, need to make decisions about what is illegal and what is legal (see here).

 

Our alternatives are only a part of a more complete program. Further work is needed at policy level to address fake news. Sadly, as it may be, the matter is not matured yet and ripe for regulation. While the phenomena of political actors actively spreading misleading information (the twittering lies told by political leaders) are well-known and discussed, the role of traditional news media, who are supposed to be the bearers of truth and factual accuracy, is less well understood. Traditional news media are in fact a part of the problem, and play a somewhat paradoxical role with respect to fake news and its dissemination. People learn about fake news, not via obscure accounts that Facebook and others can control, but through regular media that find it important for many reasons to report on disinformation. Tsfatie and others (see here) rightly ask for more analysis and collaborations between academics and journalists to develop better practices in this area.

 

We are also surprised by the lack of attention in the DSA proposal to the algorithmic and technological dimension that seems central to the issue of fake news. More work is needed on the consequences of algorithmic production of online content. More work too is needed to assess the performance of technological answers to technology.  How to organize a space of contestation in a digitally mediated and enforced world? Are the redress mechanisms in the DSA sufficient when the post has already been deleted, i.e. "delete first rectify after"?

 

Art credit: Frederick Burr Opper, via wikimedia commons