Showing posts with label social media. Show all posts
Showing posts with label social media. Show all posts

Monday, 29 June 2026

The End of Immunity for Internet Service Providers? C-188/24 WebGroup Czech Republic and NKL Associates and C-190/24 Coyote System, judgment 16 June 2026



 

Lorna Woods, Professor Emerita, University of Essex

Photo credit: TodayTesting.com, via Wikimedia Commons   

This recent CJEU judgment has been flagged in some quarters as upholding the French rules requiring age verification for porn sites. In others, it has been seen as stripping intermediary immunity from social media sites. Based on the e-Commerce Directive, however, is this just a transient discussion, fading away as the Digital Services Act (DSA) becomes the relevant law?

 

The Facts

 

The national cases in Case C-188/24 concern French rules requiring porn operators to implement technical age verification mechanisms to prevent minors from accessing those sites.  The companies were each the subject of a formal notice pursuant to Decree No 2021/1306 implementing Law No 2020-936 and Article 227-24 of the Criminal Code which prohibits any person from broadcasting a pornographic message likely to be seen by a minor. The rules in Coyote System concern the restriction on the broadcasting of information to drivers about roadside checks (eg in relation to speed or drunk driving). The relevant implementing measures were also derived from the French criminal code. These measures were subject to judicial challenge before the French Conseil d’État. The companies in question were not established in France and questioned the applicability of the French rules.

 

The Issues

 

The first question the CJEU had to address was whether the measures fell within the coordinated field of the  e-Commerce Directive (Directive 2000/31) and would therefore be caught by Article 3, which provides for the country of origin principle (COOP). Recital 22 which states that ‘information society services should be supervised at the source of the activity’. This means that services in general comply with the domestic law of the State in which they are established and do not have to comply with the laws of the States in which their services are capable of being accessed.  Article 3(3) excludes certain areas from the coordinated field and Article 3(4) et seq provide for limited grounds of derogation from the COOP and provide conditions with which the receiving State must comply to access the derogation.   The COOP applies only to laws falling within the coordinated field. Here the relevant laws were not sector specific measures targeting information society services in particular, but the general criminal law. The referring court questioned whether the provisions in issue fell within the coordinated field and referred the issue to the CJEU.

 

The ban on transmission in Coyote System was, according to the applicant, contravening the prohibition on general monitoring found in Article 15 e-Commerce Directive. This application of this article is dependent on the information society services in question falling within one of the categories of service found in Articles 12-14 e-Commerce Directive (mere conduit, caching services or hosting services respectively). The Court thus then had to consider whether the service in Coyote System was a hosting service within the meaning of Article 14 e-Commerce Directive. Article 14(1) provides:

 

Where an information society service is provided that consists of the storage of information provided by a recipient of the service, Member States shall ensure that the service provider is not liable for the information stored at the request of a recipient of the service, on condition that:

 

(a) the provider does not have actual knowledge of illegal activity or information and, as regards claims for damages, is not aware of facts or circumstances from which the illegal activity or information is apparent; or

(b) the provider, upon obtaining such knowledge or awareness, acts expeditiously to remove or to disable access to the information.

 

Judgment

 

The Coordinated Field

 

The Court emphasised that the coordinated field

 

covers all requirements laid down by the legal systems of the Member States relating to the taking up or pursuit of the activity of an information society service, … that definition does not make the coordinated field subject to the condition that only matters harmonised by that directive are covered. [para 52]

 

Following the Advocate General (at para 56 of his Opinion), it remarked that Article 3 is of particular importance precisely for the areas of law not harmonised. The mere fact that the laws apply generally cannot remove them from the coordinated field. Moreover, the Directive excludes certain areas from the scope of the Directive, so the question of exclusion had been taken into account in the Directive. Taking a different approach would undermine the purpose of the Directive.

 

The Court confirmed that requiring age verification sets the conditions for access to the information society services and is a requirement concerning the pursuit of an activity within Article 2(h)(i) (see Case C-649/18 A (Advertising and sale of medicinal products online)). For the roadside broadcasts, the Court took the view that the prohibition constituted a requirement relating to the content of the service. Both sets of measures therefore fall within the coordinated field.

 

The COOP and Derogation

 

The key question for the application of the COOP was whether the measures restricted the free movement of the services. This question the Court answered in the affirmative before considering whether the derogation in Article 3(4) could be used.

 

The derogation has substantive and procedural conditions. Substantively, the measure must be necessary in the interests of one of more of: public policy; protection of public health; public security; or protection of consumers. Further, those measures should be taken against an information society service which actually prejudices those objectives or presents a serious and grave risk to those objectives. Finally, the measures must be proportionate to the objectives. In procedural terms, the recipient Member State must first have issued an unsuccessful request to the host Member State to fix the issue and, secondly, notified the Commission.  A failure to comply renders the obligations unenforceable (Case C-390/18 Airbnb Ireland – following long established case law).

 

General rules applying without distinction do not satisfy the second of the substantive conditions. The rules, however, provided for the issuing of individual notices which satisfy this requirement [para 90]. The third substantive element – that of proportionality – was satisfied in relation to the protection of human dignity and the rights of the child as regards the broadcasting of pornography [para 94] and, without much elaboration, the prohibition on rebroadcasting is also proportionate [para 96]. 

 

So in principle, the national rules could meet the substantive criteria but it was for the referring court to determine whether the procedural rules were satisfied.

 

General Monitoring

 

Hosting

 

As noted above, the possibility of relying on Article 15 depends on whether the service in issue – here the service in Coyote System - is a host within the scope of Article 14 [see para 105]. The Court noted that the definition of hosting did not automatically preclude a service which also has elements of broadcasting from being a host, referring to long-standing caselaw as well as more recent (Case C-360/10 SABAM; Case C-682/18 YouTube and Cyanado and Case C-401/19 Poland v Parliament and Council). Conversely, just because a service includes the storage of information does it mean that the service is a host for the purposes of Article 14. The Court reiterated the limitations arising from Recital 42 – that the services should be of a mere technical, automatic and passive nature. This implies, according to the Court’s case law (Case C-324/09 L’Oréal and Case C-682/18 YouTube and Cyanado), “the information society service provider has neither knowledge of nor control over the information which is transmitted or stored” [para 108].  The Court underlined that “those two conditions requiring knowledge and control should be understood as being alternative to and independent of each other” [para 110].  The Court then held that

 

if, beyond the mere categorisation and indexation of information for the purpose of improving its accessibility, the algorithm used determines, in the interest of the operator or its service, under what conditions, how and in which order of priority that information is or is not be broadcast, that operator exercises control over that information, with the result that the service it offers cannot be classified as an ‘information society service … that consists of the storage of information provided by a recipient of the service’ [para 112].

 

Impact on Article 14(3) and Article 15

 

If a service exercises control over content, it does not fall within Article 14 and therefore the restrictions imposed on Member States by Article 15 are not applicable to such are service. The questions were for the national court to determine.

 

On the assumption that the service were found to be neutral, the national court must decide whether the prohibition on rebroadcasting the information on roadside checks is permitted by Article 14(3) which concerns orders requiring a neutral host to terminate any infringement on the part of the recipient of the service due to, inter alia, the presence of illegal information stored on its website or on its platform by removing or blocking access to that information.

 

Considering Article 15, the Court referred to Recital 47 e-Commerce Directive, which clarifies that Article 15 does not apply to monitoring in specific cases. Referring to the test laid down in Glawischnig-Piesczek (Case C-18/18), paras 46 and 47, the Court noted in this case that the information targeted by the prohibitions “is circumscribed in such a way that its rebroadcasting may be automatically prevented by the operator concerned” [para 121].

 

 

Comment

 

Coordinated Field and COOP

 

The Court has taken a typical approach here, a broad approach to the areas covered: criminal law rules and public policy rules can fall within the scope of the directive, provided they impose requirements on the access or conduct of an information society service. Furthermore, none of the criminal law in general, public policy and public security measures appear on any of the exclusions from the scope of the directive. The Court’s ruling makes explicit that this absence from the exclusions is deliberate. This position is in the interests of ensuring that a service is not subject to multiple regulation, but it can lead to unevenness and gaps in protection from the viewpoint of a person expecting the rules of the member state in which they reside to apply to services providers providing services in that self-same Member State. This is especially the case when the aspect potentially taking the national rule outside the derogation regime is about its form, not its substance.  The COOP principle has long given rise to concerns about forum shopping and a race to the bottom (as can be seen also in the broadcasting sector and the Audiovisual Media Services Directive) but has been re-affirmed as a central tenet of the EU regime (see eg Case C-769/22 Commission v Hungary (Values of the European Union)). 

 

It is also worth noting that the Court in principle accepted that both sets of rules in the cases referred were aimed at achieving legitimate aims and were proportionate. The Court drew on the fact that the AVMSD requires age verification in relation to pornography to reach this latter assessment. In so doing, the Court engaged in a joining up the dots activity between different piece of EU digital legislation. 

 

In this ruling, the Court underlined both the importance of the right to human dignity and the rights of the child.

 

Impact on Article 14

 

The headline news from this ruling is the impact on Article 14 and the test for neutral intermediary. The hosting safe harbour in Article 14 was always meant for neutral, passive intermediaries – entities whose activity is “purely technical, automatic and passive”, implying that the provider “has no knowledge of or control over” the information stored (Recital 42 e-Commerce Directive). This has been the standard position since the early case law – for example L’Oreal.  What this means, and in particular the impact of automated tools, has been the subject of some discussion. In a different context (copyright infringement), the Court even if an operator automatically indexes infringing content to recommended videos based on each users’ use did not necessarily mean that the host had specific knowledge of the infringing content, and the Court determined that this sort of specific knowledge was what was required. This could be seen as quite a generous view towards the hosting services and the scope of immunity. It might almost be said that there was an assumption that platforms would benefit from Article 14 (provided they responded to notices). In Coyote there is a shift of focus.

 

The first point to note is the Court’s statement that hosting services do not automatically benefit from Article 14. While this is not new – and, indeed, can be seen the Court’s previous jurisprudence – the reminder feels significant, especially in the light of the rest of the ruling. The Court here confirmed that a service has to satisfy both the knowledge and the control tests, a point not laboured in previous judgments. The Court (at para 110) makes this really clear: if a service exercises control, even if it has no knowledge, it will fall outside the intermediary immunity provision.

 

Whereas Cyanado dealt with knowledge, System Coyote looks at control. Significantly, the Court held that algorithmic curation constitutes “control”.  The Court (following its Advocate General) held (para 111):

 

it is, inter alia, by means of the algorithm used that such an operator exercises control over the information stored. So long as it has predetermined, by means of that algorithm, the conditions under which such information may or may not be broadcast, it is irrelevant that that operator does not itself carry out additional interventions which have the effect of promoting, modifying or deleting information stored with a view to it being broadcast.

 

In other words, when a service which stores information uses an algorithm to determine – in its own interest or that of its service – under what conditions, in what manner, and in what order of priority information is or is not disseminated it has control (see para 112). It does not matter that this is automatic. So creating the algorithmic system is exercising control.  In focussing on control, the Court avoids outright conflict with its earlier position (for example in Cyanado), but it certainly signals a change in emphasis and (in line with thinking underpinning parts of the DSA) a recognition that the algorithm is not necessarily neutral.

 

Not all categorisation or prioritising satisfies the control test. Simple categorisation and indexing of information to improve its accessibility do not on their own constitute control. Essentially, the Court is trying to draw the line between a neutral index, or chronological feed, and something more editorial (and it is telling to remember that the services themselves have claimed first amendment rights – is relating to their speech – in relation to how results are provided). 

 

Nonetheless, this ruling will affect a wide range of services based on curating user generated content, from social networks, video-sharing services and – of course – services that rebroadcast user reports (eg about police checks), as well as recommended products on a marketplace. The judgment could be read as stripping most (if not all) of the large social media platforms of their immunity (though this does not mean they will automatically be liable in all cases – that will depend on national law and the facts in individual cases). It could also be said to follow a similar path to the Russmedia decision (Case C-492/23), discussed here, which also took a narrow view of immunity (hosting defence does not apply to liability under the GDPR).

 

Impact on Article 15

 

The prohibition on general monitoring only relates to those services covered by intermediary immunity. Although this follows the language of Article 15(1) there had been some dispute as to who could claim the protection of Article 15. The answer is now clear: fall outside Article 14 (or 12 or 13) and Article 15 does not apply. 

 

The Court also reiterates its position on the distinction between general and specific monitoring and highlighting the possibility of using automated techniques to identify particular types of content. This could be relevant for Member States’ ability to impose monitoring or filtering obligations (in services of some public interest) – these (in relation to copyright infringements, e.g. SABAM, above) had been thought problematic in the relatively early days of the e-Commerce Directive, and platforms have often challenged such obligations as constituting general monitoring. The Court’s discussion here is focussed tightly on content; it does not discuss behavioural monitoring or profiling (which might be techniques by services to reduce the incidence of illegal content or behaviour across their services). It will be interesting to see how this line of case law joins up with the jurisprudence under the e-Privacy directive on collection of metadata and intrusions into communications privacy (see eg Case C-746/18 Prokurator).

 

Impact on DSA

 

Article 6 DSA, which replaces Article 14 e-Commerce Directive, provides that hosting providers are not liable for information stored at the request of a recipient of the service, provided that they do not have actual knowledge of illegal activity or content, unless the recipient acts under the authority  “or control” of the provider. It has been assumed given the similarity in the text, that the case law on Article 14 is relevant for understanding Article 6 DSA, including as regards the threshold condition of neutral. The wording of the relevant recitals in the DSA differ, however, from the text in the e-Commerce Directive (noted above) – and the Court has relied heavily on that text in its interpretation of Article 14.  Indeed, Article 14 itself does not refer to control. Recital 22 DSA specifies:

[i]n order to benefit from the exemption from liability for hosting services, the provider should, upon obtaining actual knowledge or awareness of illegal activities or illegal content, act expeditiously to remove or to disable access to that content. … The provider can obtain such actual knowledge or awareness of the illegal nature of the content, inter alia, through its own-initiative investigations or through notices submitted to it by individuals or entities in accordance with this Regulation in so far as such notices are sufficiently substantiated to allow a diligent economic operator to reasonably identify, assess and, where appropriate, act against the illegal content. However, such actual knowledge or awareness cannot be considered to be obtained solely on the ground that the provider is aware, in a general sense, of the fact that its service is also used to store illegal content. Furthermore, the fact that the provider automatically indexes information uploaded to its service, that it has a search function or that it recommends information on the basis of profiles or preferences of the recipients of the service is not a sufficient ground for considering that provider to have ‘specific’ knowledge of illegal activities carried out on that platform or of illegal content stored on it. [emphasis added]

 

At first glance, the recital seems to contradict the ruling in Coyote System. The wording of the recital seems to follow the approach the Court adopted in Cyanado and like that judgment deals with the question of knowledge. We have noted earlier, the Court’s sidestep in this case, to talk about control. The recital says nothing about control and is therefore not inconsistent with the approach in Coyote System.  Of course, this means that there is no reference to “control” in the text of the DSA because Article 6, like its predecessor Article 14, is silent on the point. It is far from clear, however, that the change in wording in the recital was intended to mark a change in meaning from Article 14 resulting in an expansion of the scope of immunity. Rather it seems an intention to align the DSA with the case law on Article 14 e-Commerce Directive. Presumably, there will be much litigation on this point as well as the linked question as to where the boundary between control and “mere categorisation and indexation of information” [para 112].


Sunday, 7 December 2025

The Digital Service’s Act Main Character: the EU Commission finally fines X

 


 

Steve Peers, Professor of Law, Royal Holloway University of London

Photo credit: Animated Heaven, via Wikimedia Commons

 

Introduction

The EU’s Digital Services Act (DSA) was conceived before Elon Musk bought Twitter (soon renaming it X); but they were literally born simultaneously, with the DSA being published in the EU’s Official Journal on the same day that Musk completed his takeover. Since then, Musk’s behaviour running X (see my review of a book on the takeover and the aftermath) has exemplified many of the reasons why the EU (and other jurisdictions) contemplated regulating social media in the first place: in particular arguments about the legality of its content and the fairness of its algorithms.

A Twitter user coined the phrase ‘today’s main character’ to describe a poster who becomes the centre of attention for a day – usually due to an absurd or obnoxious post that prompts many negative responses. For the DSA, X has been its main character since its creation, with much of the public debate about the potential use of the Act focussing on how it might apply to the controversial social network.

This debate has now come to a head. Last week, following its preliminary findings back in July 2024, the EU Commission adopted a final decision imposing a fine to enforce the DSA for the first time: €120 million for three breaches of the Act by X. This initial decision is likely to impact upon the broader debate over the Act’s implementation, and – due to Musk’s influence in the current Trump administration – also play a role in the fast-deteriorating relations between the EU and the US.

This blog post first provides an overview of the DSA, then examines the legal issues arising from this specific enforcement decision, and concludes with an assessment of the broader context of this decision: the enforcement of the DSA more generally, and the relations between the EU and the USA.

 

Background: overview of the Digital Services Act

Adoption of the DSA

Although the critics of the EU Commission fining X are quick to argue that the EU is undemocratic, EU legislation needs the support of elected Member State governments and elected Members of the European Parliament (MEPs) to be adopted. In fact, the Act received unanimous support from Member States and a large majority of MEPs.  

In any event, even without the Act, Member States would likely regulate social media – perhaps more quickly and more stringently than the EU has applied the Act in some cases. And even if the whole EU ceased to exist, as Elon Musk and Russian government mouthpieces demand, those countries would still be regulating Big Tech, with national equivalents of the Digital Markets Act and the GDPR, for instance. Indeed, despite leaving the EU, the UK has its own national versions of all three laws: the Online Safety Act, the Digital Markets, Competition and Consumers Act, and the UK GDPR, which sits alongside the Data (Use and Access) Act. While UK regulators may be famously timid about enforcing these laws, Australia – a long way from the EU – was not dissuaded from banning under-16 year olds from social media.

But until Musk and his sympathisers manage to destroy the EU, we have the DSA. It contains rules that govern online platforms generally, regardless of size, but its most prominent rules concern a special regulatory regime for the biggest platforms, defined as ‘very large online platforms’ (VLOPs) and ‘very large online search engines’ (VLOSEs), which subjects them to greater regulation. The Act gives the EU Commission power to designate such platforms and search engines (on the basis that 10% of the EU population visit them monthly) and to enforce the provisions of the DSA against them.

While some claim that the DSA was adopted only to punish US tech firms, the list of designated VLOPs and VLOSEs includes also Chinese companies (AliExpress, TikTok, Temu, Shein), EU companies (Booking.com, Zalando, and two porn sites), and a Canadian site, Pornhub. Overall, nearly half of the companies designated as operating VLOPs and VLOSEs are non-American (although some of the American companies operate more than one platform).

Content of the DSA

For VLOPs, enforcement of the DSA involves a number of measures, including requests for information, a start of an investigation into possible breach of the Act, a preliminary finding of a breach, and a final decision finding a breach – which can result in a fine (of up to 6% of worldwide annual turnover) and orders to change practices. A VLOP or VLOSE can also agree avoid a fine by agreeing binding commitments to change its practices with the Commission (in effect, a settlement) before it reaches a final decision. If a finding of breach is not complied with, the Commission can impose very high fines – up to 5% of worldwide annual turnover per day.

While many critics of X excitedly demand that the EU Commission ban it, the Act imposes a very high threshold before a ban can be imposed – essentially a refusal to remove illegal content, with additional safeguards including involvement of a court. The case law has not yet fleshed out the relationship between the DSA and Member States’ laws on overlapping issues, or clarified whether there can be private enforcement of the DSA (ie individuals challenging the VLOPs and VLOSEs in court for breach of the Act, rather than the Commission enforcing it) in parallel.

Substantively, the Act’s requirements on VLOPs and VLOSEs (in its Articles 33-43) start with risk assessment: they must ‘diligently identify, analyse and assess any systemic risks in the Union stemming from the design or functioning of their service and its related systems, including algorithmic systems, or from the use made of their services’. Systemic risks are further defined as including ‘dissemination of illegal content through their services’, ‘negative effects’ upon various human rights, ‘actual or foreseeable negative effects on civic discourse and electoral processes, and public security’, and ‘actual or foreseeable negative effects in relation to gender-based violence, the protection of public health and minors and serious negative consequences to the person’s physical and mental well-being’.  

Very large platforms and search engines are also obliged to (as further defined): mitigate these risks; comply with a decision requiring a response to a crisis; perform independent audits; offer a recommender system not based on profiling, at least as an option; make public a repository of advertising data; provide access to their data to researchers; explain their algorithms to regulators; establish independent compliance bodies; provide further public data on their operations; and pay an annual supervisory fee to the EU Commission.

The DSA in the EU courts

Even before the first fine was imposed to enforce the DSA last week, its application in practice has been frequently litigated. First of all, Amazon, Zalando and several porn sites have challenged their designation as VLOPs. Zalando lost its challenge in the EU General Court in September, but has appealed to the EU’s Court of Justice (appeal pending). More recently Amazon also lost its challenge in the EU General Court against designation as a VLOP, but it still has time to appeal that judgment to the Court of Justice (Amazon had won an interim measures ruling in this case – delaying its obligation to publish information about its advertisers – but that interim measure was overturned by the Court of Justice, following a successful appeal by the Commission).

The porn companies’ legal challenges to their designations as VLOPs are still pending (see the summary of the arguments made by Pornhub, XNXX and XVideos; a challenge by Stripchat is also still pending even though the Commission has dropped its designation as a VLOP); their applications for interim measures as regards publishing advertisers’ information have been dismissed (see the General Court orders re Pornhub and XVideos, and the failed appeals to the Court of Justice as regards Pornhub and XVideos).  

Of these cases, the recent Amazon judgment has broad implications for the DSA as a whole, considered further below.

Secondly, the Commission’s decisions on fees for regulation (for 2023) have also been challenged. These challenges were all successful in the EU General Court (see the judgments as regards Tiktok and Meta), although the Commission has appealed both the Tiktok and Meta judgments to the Court of Justice (appeals pending). In the meantime, Tiktok, Meta and Google have brought a further round of legal challenges (all still pending) to the regulation fees imposed for 2024.

We can also now expect X to challenge the enforcement decision against it. (If it also requests interim measures, at least that aspect of the case will be decided soon).

Other enforcement of the DSA

In addition to the new decision enforcing the DSA against X, other Commission enforcement actions under the DSA have been adopted or are pending against VLOPs. Leaving aside requests for information (such as the one recently sent to Shein as regards reports of sales of child-like sex dolls):

-          The Commission has accepted binding commitments from AliExpress on various issues, but at the same time also adopted a preliminary finding that its risk assessment as regards illegal products was insufficient;

-          It has opened proceedings against porn sites for inadequate protection of children;

-          It has adopted a preliminary finding that Meta (Facebook and Instagram) is in breach as regards researchers’ access to data, and as regards flagging illegal content and allowing for appeals against content moderation decisions; an investigation as regards deceptive advertising, political data, and misinformation on Meta is still underway; and

-          It has adopted a preliminary finding that Temu has breached the DSA as regards illegal products, and an investigation continues as regards other issues

Finally, the Commission has been particularly active as regards TikTok. It has accepted a commitment to suspend the ‘TikTok Lite’ programme, which was apparently designed to (further) encourage social media addiction by children, having used the threat of issuing an intention to impose interim measures under the DSA earlier on in this case. A new decision, following a preliminary finding, accepts further commitments regarding information on advertisers – also a great irritant to Amazon and the porn companies, as can be seen in the litigation summarised above, as well as an issue in the X case, discussed below. TikTok has deadlines to implement the various commitments it has made, and there are specific powers to monitor whether it is complying with them under the DSA. The Commission has also adopted a preliminary finding against TikTok as regards researchers’ access to data, and further investigations against Tiktok are still underway.

Overall, it can be seen that to date the majority of enforcement actions under the DSA have been initiated against companies that are not American. Also, to date all the offers of binding commitments that have been accepted, in place of fines and enforcement orders, have come from Chinese companies. The potential of negotiating binding commitments instead of an enforcement order is, however, open to a VLOP based anywhere.  

 

The non-compliance decision against X

What did the decision address?

First and foremost, the non-compliance decision against X only concerns certain issues, namely deceptive practices as regards X’s ‘blue ticks’,* researchers’ access to data, and the repository of advertisers. The Commission complaint about ‘blue ticks’ is that they are a ‘deceptive practice’ banned by the DSA (note that this rule applies to platforms generally, not just VLOPs), in that they purport to indicate that an account has been verified, when it has not been. Under Musk, X has earned revenue from the blue ticks by selling them to anyone willing to pay for them, although the sale of the ticks, and the monetisation programme (ie giving money to X users whose posts lead to large numbers of reactions) are apparently not the subject of the non-compliance decision as such. The preference given to blue ticks in the X algorithm is not the subject of the decision as such either.

(*Disclosure: I applied for and obtained a ‘blue tick’ from Twitter prior to Musk’s purchase, when a proper verification system applied. I did not pay for the tick under Musk, and it was initially removed as a result. However, it was reinstated involuntarily – not at my request, and without my paying for it, or monetising my posts – as part of a process of reducing the social opprobrium of having a blue tick under Musk, in which the ticks were reinstated for some accounts. I initially hid the reinstated tick, but the facility to do that was removed. It remains there today; I have not used X since August 2024, due to my objection to Musk encouraging violent racial conflict in the UK, except for a handful of posts encouraging others to leave the platform. I have retained my account there to reduce the risk of anyone impersonating me, which has happened several times.)

The Commission has not yet made a final decision – or even a preliminary finding – as regards other issues involved in its opening of proceedings against X, namely the dissemination of illegal content and the effectiveness of rules against disinformation.

How can the decision be enforced?

X now has 60 days to inform the Commission about measures it will take to enforce the non-compliance decision as regards blue ticks. It has 90 days to submit an action plan to address the other two issues, and the Commission must respond to the action plan two months after that. In the event of non-compliance with the decision, as noted above the DSA gives the Commission the power to impose much higher fines. The method of calculation of last week’s fine is not explained in the press release. (The non-compliance decision itself may explain the calculation, but like most DSA decisions of the Commission, it has unfortunately not been made public; Article 80 of the DSA requires the main content of this decision to be published though)

If X challenges the decision in the EU courts, it can request an interim measures ruling suspending all or part of the decision; the EU General Court will decide on that (subject to appeal to the Court of Justice), as it has done in several DSA cases already, as detailed above. The final judgment of the EU courts can annul the Commission’s non-compliance decision in whole or part, and the DSA (Article 81) gives the EU courts unlimited jurisdiction to cancel, increase or reduce the fine. As for the collection of the fine (and any further fines that might be imposed on X for continued breach of the DSA), Article 299 TFEU sets out the process of enforcing fines imposed by EU bodies; although if X removes all its assets from the EU to the US, it might try to prevent collection by using US law that blocks the enforcement of foreign judgments on ‘free speech’ grounds (perhaps the SPEECH Act, although that concerns defamation; other routes may be available, or fresh routes adopted in light of the Commission decision).

This brings us neatly to the question of whether the non-compliance decision is arguably invalid on ‘free speech’ (or other) grounds.

Is the decision legal?

What are the legal issues as regards last week’s non-compliance decision? As noted above, the recent judgment in the Amazon case addresses two of the issues in the non-compliance decision (advertising repositories and access to data), while also addressing broader criticisms of the Act, some of which may be relevant if X challenges the finding as regards ‘deceptive practices’, or takes this opportunity to challenge the legality of the Act more generally (as Amazon did when challenging the legality of its designation as a VLOP; on such challenges, see Article 277 TFEU).

Amazon’s legal challenge to its VLOP designation did not advance the obviously untenable argument that fewer than 10% of the EU population uses Amazon monthly (conversely, Zalando and the porn sites are arguing about the calculation of the numbers). Rather, Amazon argued that the entire system of special rules for VLOPs in the DSA was invalid, because it violated a number of human rights set out in the EU Charter of Fundamental Rights. All of these arguments were rejected by the EU General Court.

First of all, the Court rejected the argument that the VLOP regime breached the freedom to conduct a business (Article 16 of the Charter). In the Court’s view, although the regime interfered with the freedom to conduct a business, because it imposed significant costs on VLOPs and also had a considerable impact on their organisation or required complex technical solutions, that freedom was not absolute, and the interference with it was justified. According to Article 52(1) of the Charter, limitations on Charter rights have to be prescribed by law, have public interest objectives, respect the essence of the right and be proportionate. Here the limits were admittedly prescribed by law (being set out in the Act) and respected the essence of the right (as Amazon could still carry out its core business); Amazon instead argued mainly that the limits were disproportionate, as online shops did not present systemic risks, the objectives could be satisfied by less onerous means, and the costs were significant. However, the Court believed that there was a systemic risk of illegal content in online marketplaces; other means of designating VLOPs were not necessarily more proportionate; making advertising repositories open to the public was justified in the interests of consumer protection; and the arguments about economic impact made by Amazon as regards recommender systems, researchers’ access to data and advertiser repositories were unconvincing.

Secondly, Amazon’s argument that its right to property was infringed (Article 17 of the Charter) was dismissed at the outset, as it had not identified any of its property rights that were affected by the DSA: an administrative burden did not constitute interference with a property right. Thirdly, the Court rejected the argument that the VLOP regime breached the general right to equal treatment (Article 20 of the Charter), by treating larger companies differently from smaller ones, on the grounds that larger companies presented bigger risks.

Fourthly, Amazon’s arguments about freedom of expression (Article 11 of the Charter) were rejected too. This argument was only made as regards applying the DSA rules on recommender systems to Amazon. On this point, the Court reiterated that the Charter freedom of expression rules must be interpreted consistently with the freedom of expression set out in Article 10 of the European Convention on Human Rights (ECHR), referring also to the case law of the European Court of Human Rights (ECtHR). The Court did not see how the freedom of expression of third-party sellers might be affected by the DSA rules, but it accepted that Amazon’s freedom of expression was limited by having to offer a recommender system not based on profiling.

However, limitations of the right could be justified: the limitation here was prescribed by law; it did not affect the essence of the right (as Amazon could still offer a profiling-based recommender system as an option); it had an objective of general interest (consumer protection); and it was proportionate by only requiring the offer of one non-profiling based recommender system as an option – taking account of ECtHR case law that allows more interference with commercial expression than political expression.

Finally, Amazon complained about a breach of the right to privacy (Article 7 of the Charter). This was a remarkable thing for a company with a business model based on surveillance of its customers to argue about, but the Court considered its arguments seriously nonetheless. Again it followed the ECtHR case law on the corresponding rule (Article 8 ECHR), which states that businesses could invoke the right to privacy. Here the argument concerned the DSA rules on ad repositories and researchers’ access to data. Again the EU court agreed that the DSA interfered with the right, but ruled that it could be justified: it was prescribed by law, did not infringe the essence of the right, and complied with the principle of proportionality, particularly because of the limits built in to the obligations (for instance, no obligation to disclose the personal data of advertising recipients, or about the success of advertising; controls on which researchers can access the data).

How does this judgment (noting that Amazon could still appeal it to the Court of Justice) apply to a legal challenge that X might make to last week’s non-compliance decision? First of all, the judgment in principle disposes of many arguments that X might make about two aspects of the non-compliance decision, as regards ad repositories and researchers’ access to data – although X might try different arguments, or contend that the nuances of its case are different.

While the main US response to the EU Commission’s decision has been to claim that the EU is engaged in censorship, note that Amazon did not even argue that the DSA rules on ad repositories or researchers’ access to data infringed freedom of expression, and remember that X is only being investigated for the dissemination of illegal content and the effectiveness of rules against disinformation. Obviously a freedom of expression argument might be made in respect of those issues, but, as noted above, X has not been subjected to a final decision or even a preliminary finding in respect of them.

Furthermore, according to the Amazon judgment, a VLOP challenging a Commission decision under the DSA can only challenge the validity of those parts of the DSA that are the legal basis for the decision made against them: so X cannot, at this point, specifically attack the validity of the DSA rules on risk assessment or risk mitigation, since there is no decision that it has breached them yet.  X can attack the validity of the DSA system for VLOPs generally, which includes the rules on risk assessment and risk mitigation. Although Amazon has already tried this and failed, X might try to argue its case differently; but it looks like a long shot, given that a non-compliance decision is inherently more narrowly focussed than designation as a VLOP.

Another key point to remember in this debate is that, as the Amazon judgment confirms, the human rights standards applied by the EU courts are those of the EU Charter, interpreted (where relevant) in light of the corresponding ECHR rights, and the ECtHR case law on those rights. The ECHR approach to rights differs in some respects from that of the US courts, arguably providing greater protection for the right to privacy (although not enough for Amazon to win its arguments on this point), but lesser protection for the right to free speech (allowing more leeway for interference with the right). But that is the nature of doing business in another jurisdiction. US law may take the view that (hypothetical) X user ‘ZyklonB1488’, regularly posting ‘Next year in Auschwitz!’ at Jewish people, has the right to set out his stall in the marketplace of ideas. But other legal systems may legitimately take the view that he does not.

Applying this to the sole remaining issue in the Commission’s non-compliance decision – the deceptiveness of X’s blue tick system – this is not directly connected to the content of what blue tick holders (still less anyone else) may post on X. Any effect on freedom of expression of last week’s decision is therefore marginal – although again, free speech arguments would be stronger as regards future decisions the Commission might make in respect of X as regards other issues still under investigation (or Meta – subject to some broadly similar investigations, as summarised above), especially because ‘illegal content’ is the one breach of the DSA that might (subject to many conditions and safeguards) lead to a ban on the whole platform. And to the extent that the non-compliance decision on blue ticks does interfere with freedom of expression, there is a strong argument that the interference is justified both on the ground of consumer protection (cf the scams featuring impersonations of consumer advocate Martin Lewis) and (as Article 52 of the Charter also provides for) on the ground of ‘the need to protect the rights and freedoms of others’ (ie anyone being impersonated, including myself!).

 

Context: enforcing the DSA

Last week’s decision is a definitive sign that the Commission is willing to enforce the DSA, even to the extent of adopting non-compliance decisions. The world is full of ‘light-touch’ regulators – perhaps one of Britain’s more unappealing exports. Usually, the Commission is not seen as such; but its obvious stalling on taking a final decision regarding X, for 17 months since its provisional findings, may have given the impression that – on the DSA, at least – the lion had turned pussycat.

The non-compliance decision should be viewed alongside with the Amazon judgment, which it likely also takes account of. VLOPs now know not only that the Commission is willing to act to enforce the DSA, but also that the EU courts (subject to possible appeal) back up at least some key provisions of the Act. Also, the recent judgment may explain TikTok’s simultaneous willingness to agree on its compliance with the ad repository rules; and the Commission’s willingness (again) to accept commitments, combined with the recent judgment, shows VLOPs that it may be less hassle to negotiate commitments with the Commission, rather than embark upon court action that is unlikely to succeed.  The context also includes a dog that did not bark: the Commission did not propose any amendment to the DSA (or the Digital Markets Act) in its recent proposal for an ‘omnibus’ bonfire of some provisions of EU tech laws.

Having said that, it is striking that the Commission is moving forward on non-compliance decisions and preliminary findings other than on the issues relating more closely to content on social media networks (cf the ongoing investigations into Meta and X), which raise not only the more difficult legal issues (given their greater impact upon freedom of expression) but also have the greater political impact (given the subject-matter, and the closeness of both zillionaire owners to the US government). And this brings us nicely to the impact of the decision upon US/EU relations.  

 

Context: EU-USA relations

Coincidentally, the non-compliance decision was released the day after the US government published a foreign policy review that was intrinsically hostile to the EU, and hyperpartisan in its support of right wing populist parties in Member States. In that context, the decision against X is just a drop in the rapidly-widening Atlantic Ocean. Famously, US diplomat Dean Acheson was ‘present at the creation’ of the post-war alliance; the Trump administration’s goal seems to be to preside over its destruction.

Yet, as noted already, supporters of Trump are nevertheless enraged by the decision, despite its limited impact. Even though, as explained above, the DSA was approved by elected governments and MEPs, does not solely apply to US companies and is not solely enforced against US companies, and the recent decision has at best a marginal impact upon freedom of expression, the response is the same: “They’re eating our free speech!”

Of course, it’s hard to take concerns about free speech from the Trump administration seriously: these are folks who want to expel legal migrants for criticism of a foreign government, and whose leader, between naps, frequently insults and threatens journalists who are insufficiently North Korean in their adoration of him. If these people are genuine free speech defenders, then I’m Alexander Hamilton.

As hypocritical and inaccurate as the Trumpian reactions to the decision are, they were presumably anticipated by the Commission before it took its decision. Even if the EU courts rule in the Commission’s favour in the event of a legal challenge, its MAGA critics will likely remain just as irrational (“They’re eating the snails!”). Yet the Commission took the decision anyway.

The choice to go ahead with the decision regardless can be understood either as a calculated risk that the US will not punish the EU for it – at least no more than it was inclined to punish the EU anyway, for various other reasons – or that even if the US does punish the EU for the decision, it is worth exercising its regulatory powers anyway. Perhaps this is a response to the perception that the Commission had seemed unwilling to stand up to Trump to date. Or maybe the assumption is that Trump is unlikely to pay much attention to this matter for long, particularly if the EU can devise a way to distract him: something like a shiny gold award for ‘best European’, for ending the war between Narnia and Freedonia, may work.  

Whatever happens, the Commission’s decision was certainly a gamble, in the current context of fraught EU/US relations, with far broader trade and security issues at stake. Time will tell whether this assertion of regulatory strength is worth it in light of the reaction it may trigger.

 

Wednesday, 5 November 2025

From COVID-19 to digital well-being: Precaution in the internal market




Daan Bodson, LL.M in European Union Law, Université Panthéon-Assas (Paris 2)

Photo credit: US Dept of Defense, via Wikimedia Commons

 

Introduction

More than two years after the WHO declared COVID-19 no longer a global emergency, its impact is still felt. Remote work has become routine in many sectors, younger generations speak more openly about mental health, and the pandemic has left its mark on EU law. Faced with extraordinary circumstances, Member States adopted extraordinary restrictions, which in turn prompted courts to revisit how fundamental freedoms like free movement are balanced against public health.

Many of the measures aimed at restricting the spread of the virus involved limiting the free movement of individuals, one of the fundamental rules of the EU legal order. When these restrictions were challenged before the EU courts, both the ECJ and the EFTA Court delivered landmark rulings. For the first time, they brought the precautionary principle squarely into free movement case law.

This contribution revisits that jurisprudence and asks what it means beyond the pandemic. Since neither court confined its reasoning to COVID-19, the question arises: can precaution also justify restrictions in other policy fields marked by scientific uncertainty? I argue that Nordic Info (C-128/22, 5 Dec 2023) and LDL (E-5/23, 21 Mar 2024) lowered the threshold for Member States to justify restrictions under the precautionary principle, and that this reasoning can also support measures against mental health risks from social media usage.

 

The case law: Nordic Info and LDL

Setting the stage: National measures aimed at limiting the spread of COVID-19

On December 5th of 2023, the ECJ rendered its Nordic Info judgement, in which it ruled on the legality of a Belgian measure banning all non-essential travel to “red-listed countries”. These red-listed countries were designated based on epidemiological data available at the time. The national measure was challenged by a travel agency specializing in trips to Scandinavia. In the LDL judgement, rendered by the EFTA Court a few months after Nordic Info, the Court ruled on the legality of a Norwegian law requiring individuals travelling from abroad into Norway to subject themselves to a quarantine period spent in a specific “quarantine hotel”.

Both courts readily classified these measures as restrictions on the free movement of persons under the EU Citizens’ Directive (and its extension to the EEA). This legislation, however, allows for restrictions on grounds of public health (Art. 27 & 29), yet sets some safeguards to these limitations, such as a right to an effective remedy, and a proportionality check (Art. 31).

In both cases, the main legal question thus was whether or not the restrictions were considered proportionate. Remarkably, and for the first time in free movement case law, both courts expressly included the precautionary principle into this proportionality test. This novel introduction could significantly reshape the proportionality assessment in situations where the precautionary principle applies.

Understanding the precautionary principle

The precautionary principle is well-established in EU law. It regularly appears in judgments of both the ECJ and the EFTA Court and informs many policy fields. At its core, the principle provides a legal and policy tool for decision-makers faced with scientific uncertainty combined with potential risks. Where evidence of harm is insufficient, inconclusive, or uncertain, but the stakes are significant, legislators may intervene proactively without waiting for full scientific proof. As the ECJ stated in Nordic Info: “if there is uncertainty as to the existence or extent of risks to human health, a Member State must be able, under the precautionary principle, to take protective measures without having to wait until the reality of those risks becomes fully apparent” (para. 79).

In practice, the principle applies when there are indications of risk but no certainty about its precise magnitude, its long-term effects, or the most effective mitigating measures. In such cases, national or EU legislators retain discretion to determine the level of protection they wish to guarantee. The degree of scientific uncertainty will, however, shape the extent of that discretion: the greater the uncertainty, the broader the space for precautionary action.

This principle features in many fields of EU policy. The TFEU explicitly prescribes that the principle shall guide the EU’s environmental policy. ECJ case law (e.g., C-157/96) and legislation (e.g., regulation 178/2002) has further broadened the scope of application of the principle to all types of risks to environmental, human, animal, or plant health.

The European Commission’s 2000 Communication on the precautionary principle further clarified its scope and criteria. The Communication underlined that the precautionary principle doesn’t allow for arbitrary restrictions. Measures must still comply with broader EU law requirements, such as proportionality, non-discrimination, consistency, examination of costs and benefits and dynamic review. These principles ensure that precaution remains balanced and doesn’t overly interfere with the internal market.

The novelty: introduction of the precautionary principle in free movement case law

Whilst the precautionary principle itself is far from new in the EU legal order, its application in free movement case law in the Nordic Info and LDL cases is new. In both cases, the courts were confronted with a situation of scientific uncertainty: at the time, there was no conclusive knowledge about how COVID-19 spread, how lethal it was, or which measures were most effective. Yet Member States had to act to protect public health. Against this background, the courts held that the precautionary principle applied, granting national authorities wider discretion to define their own level of health protection and to adopt restrictive measures to limit contagion.

Ordinarily, the proportionality test for restrictions on free movement follows three steps:

-          Suitability: the measure must be capable of achieving its stated aim.

-          Necessity: there must be no less restrictive measure that is equally effective.

-          Proportionality stricto sensu: the benefits of the measure must outweigh the rights it restricts.

What changed in these cases is that the precautionary principle softened the evidentiary demands at each stage:

-          Suitability: Instead of requiring proof that the measure was demonstrably effective, it was sufficient that, in light of limited scientific knowledge, the measure appeared reasonably capable of achieving its aim.

-          Necessity: Courts did not demand a fully substantiated comparison of alternatives. A measure passed this step unless it was evident that another, less restrictive option would be equally effective (Nordic Info, para. 90).

-          Proportionality stricto sensu: In the balancing of interests, scientific uncertainty itself tipped the scales in favor of public health. Far-reaching restrictions were upheld even without full certainty as to their effectiveness.

In short, the precautionary principle did not replace the proportionality test but recalibrated it: lowering the threshold of proof and granting Member States greater leeway when acting under conditions of scientific uncertainty.

 

Beyond COVID-19: precautionary principle and digital well-being

The case law on COVID-19 restrictions carries implications well beyond the pandemic itself. Crucially, neither the ECJ nor the EFTA Court confined their reasoning to emergency circumstances, and Advocate General Emiliou even stressed in his Opinion in Nordic Info that the case had to be assessed under the “ordinary” rules of EU law. This suggests that the interpretive shift brought by the precautionary principle is not an exceptional tool for crisis management, but part of the general framework for justifying restrictions on free movement.

This raises a broader question: if precaution can justify far-reaching measures in times of scientific uncertainty about public health, could it also apply in other fields where risks are emerging but not yet conclusively proven? One particularly pressing area is digital well-being. With growing evidence of the mental health risks linked to social media and addictive algorithms, especially for young people, the same legal reasoning could potentially empower Member States to adopt preventive measures.

Social media, addictive algorithms and associated mental health risks

Social media platforms rely on algorithms that continuously predict and adapt to user preferences. By generating personalized feeds designed to maximize engagement, these systems keep users online longer and, in turn, increase advertising revenues.

Growing evidence links such addictive algorithms and the use of social media generally to negative mental health outcomes, particularly among children and adolescents. Users are frequently exposed to harmful content, such as unrealistic body images, and research increasingly associates prolonged social media use with depression, anxiety, body dysmorphia, and even suicidal thoughts.

Because social media is a relatively recent phenomenon, the long-term effects are not yet fully known. Scientific studies are emerging, but uncertainty remains inherent: it is difficult, perhaps impossible, to precisely measure the long-term mental health consequences of algorithm-driven platforms, especially for young people.

The EU has begun to acknowledge these risks. The Digital Services Act (“DSA”) of October 2022 introduces obligations for “very large online platforms and search engines,” requiring them to conduct risk assessments, explicitly covering algorithmic systems, and to implement reasonable mitigation measures. This reflects a policy shift toward more stringent obligations for these large platforms, aimed at enhancing, among other things, user well-being.

The precautionary principle: more space for Member States to act?

Despite the DSA, Member States may wish to go further in protecting citizens’ mental health. Insofar as measures do not interfere with harmonized EU law, Member States can determine their desired level of protection and take adequate measures. In practice, this could mean considering specific obligations on tech manufacturers (e.g., better parental control tools) or even on the accessibility of devices to minors.

National measures in this area are likely to restrict the free movement of services, and possibly freedom of establishment or free movement of goods. Ordinarily, such measures would face steep hurdles, since they would need to be justified and proportionate, which typically was a high bar. However, under the Nordic Info and LDL rulings, Member States now enjoy wider leeway to justify such restrictions. The introduction of the precautionary principle into free movement law means that scientific uncertainty no longer necessarily blocks preventive regulation.

For precaution to apply, three conditions must be present:

-          a potential risk, including mental health risks for humans;

-          scientific uncertainty about its scope or effects, and

-          the absence of full proof or consensus related to the extent of the risk and / or the most suitable mitigating measures.

In the case of digital well-being, these conditions seem to be met. Academic research points to a range of mental health risks from social media use, but the extent of the danger and the precise causal links remain unsure. Member States could take precautionary measures in multiple forms. Even though harmonized EU legislation, such as the DSA, bars Member States from introducing measures within this field, some measures are still imaginable. For example, States could require phone manufacturers to include robust parental control tools by default. Alternatively, Member States could consider a ban on design features such as auto-play or endless scroll for under-16s, or even impose an age limit for the sale of smartphones (as considered by the UK government).

The significance of Nordic Info and LDL is that these measures no longer need conclusive scientific proof to survive judicial scrutiny. It is enough that they seem reasonably appropriate, and that no evident less restrictive alternative exists. In balancing fundamental rights, the courts signaled that precaution may tilt the scales in favor of public health, even when other freedoms, such as free movement of services or freedom to conduct business, are affected.

 

Conclusion

The COVID-19 pandemic was not only an unprecedented test for Europe’s health systems, but it also challenged the boundaries of EU law. In Nordic Info and LDL, the courts expanded the role of the precautionary principle in free movement, potentially lowering the evidentiary threshold for Member States to justify restrictive measures. Importantly, this reasoning was not tied to emergency conditions, which opened the door for its application in other contexts.

The growing, though inconclusive, evidence linking social media usage and addictive algorithms to mental health issues raises the question of whether the evolving case law could justify regulatory measures to protect mental health in the digital space. By extending the application of the precautionary principle, the legal precedents set in these cases could pave the way for stronger regulations aimed at safeguarding online well-being, particularly regarding social media platforms and their addictive features.