Algorithmic control over user uploads can remove hosting safe harbour

In a notable development for digital service providers and IP rights-holders alike, the Court of Justice of the European Union has ruled, on a reference from the Conseil d’État, France, that platforms controlling user information through algorithmic ranking or rebroadcasting may lose the hosting safe harbour. [1] The CJEU found that a provider cannot rely on the exemption merely because the information originates from users: if it uses an algorithm to determine when, how and in what order of priority the information is (or is not) rebroadcast, it exercises control over the information and will not benefit from the safe harbour. Nor will such a provider benefit from the prohibition on EU member states on imposing a general monitoring obligation on hosting providers.
Background
Safe-harbour principle
The EU hosting safe harbour is a principle under Article 14 of the Ecommerce Directive, [2] now found in Article 6 of the Digital Services Act. [3] The safe harbour limits the liability of certain online intermediary service providers, such as hosting providers, online platforms, marketplaces and content-sharing services, for unlawful content uploaded by their users. Put simply, a hosting provider is not liable for illegal content stored at the request of a user, as long as it does not have actual or constructive knowledge of the illegality or, once it obtains such knowledge, acts expeditiously to remove or to disable access to the content.
Case background
The underlying cases arose from two different rules under French law (the “contested measures”).
- The first rule required publishers of pornographic websites to implement technical measures for verifying the age of site visitors, with the aim of preventing minors from accessing them. The two Czech companies concerned, WebGroup Czech Republic and NKL Associates, challenged the obligation, arguing that the contested measures were contrary to the “country of origin” principle under the Directive, according to which services falling within the “coordinated field” are subject solely to the law of the member state of establishment. The coordinated field encompasses the legal requirements that apply to information society services, including rules governing both access to, and the pursuit of, the relevant service activity. It therefore covers matters such as authorisation requirements, advertising restrictions, contractual rules and other obligations relating to the operation of online services.
- The second rule allowed authorities to prohibit providers of geolocation or electronic driving-assistance services, including the French company Coyote System, from rebroadcasting user-transmitted information relating to certain roadside checks in France, such as speed cameras. Coyote System contested the prohibition, on the basis that it did not comply with the objectives of the Directive and infringed Article 15 by imposing on operators of an electronic driving assistance or geolocation navigation service a general obligation to monitor the information which they transmit.
Uncertain as to whether the contested measures fell within the “coordinated field” and constituted “requirements” relating to the taking-up or pursuit of the activity of an information society service, within the meaning of Directive, the Conseil d’État referred both cases to the CJEU. The Conseil d’État also sought guidance on the application of Article 15(1); in that regard, the essential question was whether the operator of an electronic driving assistance or geolocation navigation service falls within the scope of the hosting safe harbour in Article 14.
Decision
Country of origin
In relation to the Czech adult-content website companies, the CJEU’s reasoning reflects the balance at the heart of the Directive: the Directive is designed to preserve the free movement of information society services across the EU, while allowing EU member states to intervene where sufficiently important public interests are engaged.
The CJEU confirmed that the “country of origin” principle remains the starting point, and that, in principle, “coordinated field” covers all requirements laid down by the legal systems of the Member States relating to the taking-up or pursuit of an information society service. A provider established in one member state should not, as a general rule, have to comply with a patchwork of different national rules in every member state where its services can be accessed. That is why services falling within the coordinated field are, in principle, regulated by the member state in which the provider is established.
That principle, however, is not absolute. A member state may, subject to the conditions in the Directive, require providers established in another member state to comply with targeted measures where that is necessary on grounds such as public policy or public security. The CJEU noted that the age-verification requirement for the protection of minors pursued public policy, and that the prohibition on rebroadcasting information about certain roadside checks may be justified on grounds of public policy, security or safety.
The CJEU was careful, though, to preserve the Directive’s safeguards. It was not enough for France simply to invoke a legitimate objective. The measures had to be necessary, proportionate and directed at specific information society services. They also had to be adopted by way of individual decisions, rather than operating as a general and abstract restriction on cross-border services. That reflects the Directive’s structure, under which derogations are exceptional. They must not become a means for members to reintroduce fragmented national regulation by another route.
The procedural requirements serve the same purpose. Except in urgent cases, the member state seeking to act must first ask the member state of establishment to take appropriate measures and must notify the Commission and that member state of its proposed action.
Safe harbour
The CJEU also considered when a service provider can rely on the hosting exemption where the relevant information has been supplied by users. The answer turned on whether the provider had knowledge of, or control over, that information.
That question has clear practical importance. Many online services do not simply store material uploaded or supplied by users. They often deploy provider-designed systems to organise, prioritise and rebroadcast it. The CJEU had to decide whether algorithmic decision-making of that kind could amount to control.
The court held that, to qualify as a hosting provider capable in principle of benefitting from the liability exemption for information stored at the request of a user, the provider’s role must be neutral, meaning technical, automatic and passive. In that context, knowledge or control are grounds for losing the exemption. The court noted that the operator of an information society service that controls the stored information is excluded from the benefit of the safe harbour, “even if it does not become aware of that information due to the automation of the information processing” ([110]).
The court commented that, as long as the provider has predetermined, by means of an algorithm, the conditions under which the information may or may not be broadcast, it is irrelevant that the provider does not itself carry out additional interventions that have the effect of promoting, modifying or deleting information stored with a view to its being broadcast ([111]). Accordingly, a provider that determines, by means of an algorithm in its own interest or that of its service, the conditions, manner and priority of any rebroadcast of information exercises control over that information and will not be exempted from liability ([112]).
By contrast, simply categorising and indexing for the purposes of enhancing accessibility of content may be insufficient to remove the hosting exemption.
The CJEU added that, even where a provider could rely on an exemption, it may still be prohibited from rebroadcasting information such as that relating to roadside checks for reasons of public policy, public security or public safety.
Monitoring
The CJEU’s conclusion added in effect, in a passing reference to Article 15 of the Directive, that only providers benefitting from the safe harbours can benefit from providers’ effective freedom under Article 15 of the Directive (now found in Article 8 of the Digital Services Act) from a general obligation (a) to monitor information that they transmit or store or (b) actively to seek facts or circumstances indicating illegal activity ([122]).
In keeping with settled case law, however, the CJEU confirmed that the prohibition on EU member states under those Articles is limited to a general monitoring obligation, i.e. permitting states to impose specific monitoring obligations on providers.
Comment
It is the ruling on the safe harbour that is likely to attract the attention of technology and content lawyers. The hosting exemption is intended for providers whose role is essentially technical, automatic and passive. Its rationale is that a provider should not be liable for user-supplied information where it merely stores that information without knowledge of, or control over, it. That rationale falls away where the provider controls how the information is disseminated.
Accordingly, the CJEU looked not simply at who supplies the information, but at who determines the conditions of rebroadcast. Its treatment of algorithmic control is clear: automation does not, by itself, preserve safe-harbour protection where the provider has predetermined the conditions under which user-supplied information is rebroadcast. That is a potentially uncomfortable conclusion for many providers of digital services. Recommendation, ranking and prioritisation systems are not peripheral to modern online platforms: they are often central to how those services operate. The judgment does not state that every use of an algorithm removes the hosting exemption; it does, however, emphasise that algorithmic design can matter, and that automation does not, by itself, preserve safe-harbour protection.
A provider is not deprived of safe-harbour protection merely because it uses technology to organise information. That explains the importance of the judgment for platform operators and, conversely, rights-holders whose content may have been unlawfully hosted. The legal analysis turns less on the label attached to the service, and more on the practical role played by its systems in shaping what users see.
For online service providers, then, the practical question will be whether their systems merely organise information supplied by users, or whether they play a more active role in shaping its dissemination. That is likely to be a fact-sensitive enquiry. It may require close analysis of how ranking, recommendation, suppression and display systems are configured, and whether they are designed in the interests of the operator or its service.
The ruling also has broader resonance under the EU’s current digital regulation framework. Although the case concerns the Directive, the issue that it raises of when an intermediary is passive, and when it is exercising control, remains central to the allocation of responsibility online. The more a service shapes what users see, when they see it and the order in which it appears, the harder it may be to characterise that service as merely storing information supplied by others.
Crucially, the ruling does not abolish the safe harbour. It does, however, confirm that the harbour is not available simply because the information originates from users. Where a platform plays a meaningful role in determining what users see, when they see it, and the prominence it receives, the provider may find it increasingly difficult to categorise itself as a passive intermediary.
Article written for Entertainment Law Review.





