Normal view

New EU Court of Justice Ruling on Platform Liability Could Cause Collateral Damage to Freedom of Expression

22 July 2026 at 10:34

Intermediary liability laws around the world recognize that social media platforms, search engines, and other online service providers have become an integral part of our lives: they shape how we access information, communicate with others and participate in public debate, and foster innovation online. These laws generally shield platforms, to varying degrees, from legal liability for user content: the responsibility for unlawful speech should rest primarily with the speaker, not with those who merely host it.  

These liability protections are not a gift for platforms. They exist so that platforms are not encouraged to proactively monitor and filter what we say online, or to remove even lawful speech simply to avoid legal risk. 

This is why a recent judgment by the EU Court of Justice, Coyote System (Joined Cases C-188/24 and C-190/24), is concerning: it could deprive online platforms of liability protection because of how they organize and disseminate user content. The consequences for freedom of expression could be significant. 

Liability Protections in the EU 

The European Union has long embraced a system of limited liability for online service providers. Under the e-Commerce Directive and now the Digital Services Act (DSA), platforms benefit from liability exemptions for user content. To discourage censorship, they also cannot be required to generally monitor user content or actively search for illegal activity. But that liability protection comes with qualifications: Platforms lose this benefit if they play an "active role" such that they have knowledge of, or control over, user-provided information (Recital 42 ECD, Recital 18 DSA, and case law, for example para. 113 in L’Oréal v eBay)For hosting services, providers must remove or disable content they know to be illegal. The DSA has introduced extensive due diligence obligations for platforms but left these foundational immunities intact. The message is clear: platforms bear responsibility for proper systems and processes, but generally not for users' speech. 

Coyote System, however, could undermine this balance. Confronted with a case about restrictions on navigation systems that transmit information to drivers about roadside checks, the Court formulated a general test for when an intermediary ceases to be a "neutral" host and therefore loses the hosting liability exemption. In essence, the Court held that where an intermediary's algorithm goes beyond merely categorizing and indexing user information to determine, "under what conditions, how and in which order of priority" (para. 122) information is disseminated, the intermediary "controls" that information and is deprived of protection under the e-Commerce Directive. 

Let's be clear: the case is not about a service that ranked or recommended user-generated content in the way social media platforms do. It is about the collection and real-time relay of user alerts about roadside checks. However, the Court's reasoning is not confined to navigation services. Recommendation algorithms determine how and in what order user content is disseminated across virtually every major online platform. Should such platforms now cease to qualify as neutral intermediaries and lose the protection of the hosting liability exemption? The answer should be no. 

The Meaning of Control 

Control has never been understood this broadly. Nor should it be. Every hosting service provider, think of Facebook, Amazon or Bluesky, will have some control over users’ content. If that ability alone ruled the analysis, the liability exemption would become largely meaningless. Instead, the disqualifying “active role” must relate to the actual content itself, not merely the technical means by which that content is organised or disseminated. 

The Court’s own case law reinforces this conclusion: In YouTube and Cyando, it examined a platform that categorises, ranks and recommends user content through algorithms, yet still proceeded on the basis that it could generally benefit from the hosting liability exemption. To be sure, the Court was mainly addressing specific knowledge of illegal content rather than the separate category of control. Even so, the underlying premise is clear: those features do not, by themselves, place a platform outside of protection. Advocate General therefore explained that what matters is the provider's "intellectual control of that content" (para 152). The relevant question is who controls the information itself, makes it their own, not who determines how it appears. 

That is precisely where Coyote System breaks new ground and offers a dangerous change of emphasis. By equating algorithmic organisation with content control, the ruling risks excluding social networks and other platforms from the liability exemption and encouraging proactive monitoring of what users say online and removal of lawful content. 

That outcome would have terrible consequences for freedom of expression in the EU. It’s also difficult to reconcile with the structure of the DSA, which certainly does not treat recommendation algorithms as incompatible with intermediary immunity. On the contrary, it accepts them as a defining feature of modern platforms, regulates them extensively through dedicated due diligence obligations, and still leaves the hosting liability regime untouched (it even integrated the YouTube ruling in its preamble!).  

This was no accident: During the DSA negotiations, proposals to deprive platforms of the hosting liability exemption if they optimize, classify, organize or otherwise promote online content were rejected, following successful advocacy by EFF and allies. Would the Court have decided this case differently under the DSA? Probably not. It’s more plausible that the EU judges were influenced by the specific nature of the service, which could explain why the judgment says remarkably, and sadly, little about why intermediary liability exists in the first place and the fundamental rights it serves. Coyote System did not merely transmit user reports but aggregated them into what the Advocate General described as a new "information layer," a distinction omitted by the Court. 

Chipping Away at Intermediary Liability Protections 

The danger is that the Court's broad language on algorithmic curation reaches well beyond that narrow category and, unintentionally or not, chips away at one of the most important safeguards for freedom of expression online.  

Unfortunately, Coyote System does not stand alone. It is the latest in a line of judgments that have gradually narrowed intermediary liability protections. Recently, in Russmedia, the Court privileged preventive content control in the name of data protection, paying little regard to the possibility of reconciling both regimes and the privacy costs of increased monitoring of user content. And in AGCOM, concerning Google's liability for YouTube videos uploaded by creators participating in its Partner Programme, the Court appears to leap from eligibility reviews to specific knowledge of illegal content. 

There is a political risk too. While the top court’s reasoning will be applied by national courts and further refined over time, the European Commission has shown little hesitation in incorporating landmark rulings into legislation. Just recently, in its digital omnibus proposal, it selectively restated part of a recent Court of Justice judgment to justify narrowing privacy rights of users. 

If these trends continue, freedom of expression online will become collateral damage in the EU. 

European Commission Chooses to Keep EU Users Locked Up Behind Big Tech’s Gates

9 July 2026 at 20:30

Users are always seeking more control over their social networking experience to make it better, whether to improve privacy or enhance flexibility. Interoperability between social networking platforms like Facebook and TikTok has so many benefits that solve those issues.  

Say you’re on multiple platforms because you have friends you follow on different networks, but you’ve decided to choose one platform with better privacy practices. With interoperability, you could switch and still interact with friends who remain on larger platforms. It could also enable independent apps with better privacy controls and more user choice. These are the untapped possibilities that could benefit users in the European Union under the 2022 Digital Markets Act (DMA).  

Yet, the European Commission, in its first review of the DMA, announced in April it had decided not to extend the DMA’s interoperability mandate to social networking and didn’t give a deadline or a timeline for enforcing that part of the Act. The Commission said “there is no clear demand” from users and businesses for social networking interoperability and, in any case, it’s too technically complex at the moment. Meanwhile, the Big Tech platforms that have been slow-walking interoperability over the last two years, erecting a myriad of hurdles for users seeking more freedom to choose other platforms, get a pass.

This is a huge disappointment and a missed opportunity by the Commission. Interoperability dismantles one of the biggest barriers faced by users who want to leave the tech giants’ platforms: the choice between changing to a platform you prefer or staying behind on a platform where all your friends, communities, and customers are.

The DMA, which went into force in 2024, aims to foster more choices for European Union users and encourage competition and innovation by forcing so-called gatekeeper platforms like Meta, Apple, and Google, to open their ecosystems to competitors. The regulation does a great deal to foster the integration of competing services and devices with the ecosystems of very large online platforms that act as gatekeepers. It even requires interoperability for messaging services, despite the significant technical and privacy challenges involved.

So, it’s odd that the Commission is using complexity as a shield against taking on social networking interoperability. The internet already runs on complex interoperable systems. Approaches like ActivityPub, the decentralized networking protocol behind the “Fediverse,” which gave rise to decentralized networks like Mastodon, already exist. The DMA shouldn’t mandate a specific protocol, but it can require meaningful interoperability outcomes.

The argument that there’s no real demand for social networking interoperability also falls flat. Users want the ability to move across platforms, choose the content they’d like to see from platforms, and not be tied down to a single platform. But there’s no way to get there—the platforms are doing little to open their social networking ecosystems. And now you have the DMA’s enforcer saying it’s not going to make them change. Demand for alternatives won’t materialize at scale until users see real progress towards interoperability, something the Commission has the power to do.

Having decided there’s little demand and too much complexity to proceed with mandating social networking interoperability, the Commission said it “will continue to monitor and assess how these services evolve.” This wait-and-see-posture only hurts users and strengthens and further entrenches Big Tech incumbents.

The DMA is supposed to center on the rights of technology users and be the pathway to an internet experience where you decide which software runs on your devices, where it’s easy to find the best products and services, and where you can leave a platform for a better one without forfeiting your social relationships.

Meanwhile, Big Tech is also resisting the DMA’s openness requirements. For example, Apple is supposed to be opening up iOS devices to rival app stores. Yet, the smartphone giant’s plan for opening its App Store levies junk fees and onerous conditions on app makers and is effectively impossible for any competitor to use.

It’s not just Apple pushing back against DMA enforcement. Meta's response is a “pay for privacy “system, in which users who do not consent to Meta’s surveillance will have to pay to use the service, or be blocked from it. Whether their plan complies with the DMA remains under review.

Nowhere in the DMA does it say social networking companies get to install a toll booth for users seeking to benefit from privacy rights the regulation grants them. The future EU Digital Fairness Act is another opportunity to protect users from such practices by declaring them unfair.

The Commission has responded to these developments with investigations, preliminary rulings, and fines. Meanwhile, users are missing out on greater choice and flexibility in how they communicate and connect online.  

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Getting Digital Fairness Right: EFF's Recommendations for the EU's Digital Fairness Act

4 May 2026 at 17:33

Digital Fairness in the EU

The next few years will be decisive for EU digital policymaking. With major laws like the Digital Services Act, the Digital Markets Act, and the AI Act now in place, the EU is entering an enforcement era that will show whether these rules are rights-respecting or drift toward overreach and corporate control. With the proposed EU’s Digital Fairness Act (DFA), the Commission is now turning to increasingly visible risks for users, such as dark patterns and exploitative personalization. Its “Digital Fairness Fitness Check” makes clear that existing consumer rules need updating to reflect how digital markets operate today.

But not all proposed solutions point in the right direction. Regulators are already flirting with measures that rely on expanded surveillance, such as age verification mandates—surface-level fixes that risk undermining fundamental rights while offering little more than a false sense of protection.

For EFF, digital fairness means addressing the root causes of harm, not requiring platforms to exert more control over their users. It means safeguarding privacy, freedom of expression, and the rights of users and developers.

If the DFA is to make a real difference, it must tackle structural imbalances. Lawmakers should focus on two interlocking principles. First, prioritize privacy. Reforms should address harms driven by surveillance-based business models, alongside deceptive design practices that impair informed choices. Second, strengthen user sovereignty, which is also a necessary precondition for European digital sovereignty more broadly. Strengthening user sovereignty means taking measures that address user lock-in, coercive contract terms, and manipulative defaults that limit users’ ability to freely choose how they use digital products and services.

Together, these principles would support the EU’s objectives of consistent consumer protection, fair markets, and a more coherent legal framework. If implemented properly, the EU could address power imbalances and build trust in Europe’s digital economy.

Ban Dark Patterns

Dark patterns are practices that impair users’ ability to make informed and autonomous decisions. Many companies deploy these tactics through interface design to steer choices and influence behavior. Their impact goes beyond poor consumer decisions. Dark patterns push users to share personal data they would not otherwise disclose and undermine autonomy by making alternatives harder to access.

The DFA should address this by clearly prohibiting misleading interfaces that distort user choice in commercial contexts. While the Digital Services Act introduced a definition, it only partially bans such practices and leaves gaps across existing consumer law rules. The DFA should close these gaps by, at the very least, introducing explicit prohibitions and clearer enforcement rules, without resorting to design mandates.

Tackle Commercial Surveillance

At the core of digital unfairness lies the pervasive collection and use of personal data. Surveillance and profiling drive many of the harms regulators are trying to address, from dark patterns to exploitative personalization. The DFA should tackle these incentives directly by reducing reliance on surveillance-based business models. These practices are fundamentally incompatible with privacy and fairness, and they distort digital markets by rewarding data exploitation rather than quality of service. At a minimum, the DFA should address unfair profiling and surveillance advertising by strengthening privacy rights and banning pay-for-privacy schemes. Users should not have to trade their data or pay extra to avoid being tracked. Accordingly, the DFA should support the recognition of automated privacy signals by web browsers and mobile operating systems, which give users a better way to reject tracking and exercise their rights. Practices that override such signals through banners or interface design should be considered unfair.

Addressing surveillance and profiling also protects children, since many online harms are tied to the collection and exploitation of their data. Systems that serve ads or curate content often rely on intrusive profiling practices, raising concerns about privacy and fairness, particularly when applied to minors. Rather than turning to invasive age verification, the focus should be on limiting data use by default.

Strengthen User Sovereignty

There is a major gap in how EU law addresses user autonomy in digital markets: many digital products and services still restrict what people can do with what they pay for through opaque or one-sided licensing terms, technical protection measures, and remote controls. These mechanisms increasingly limit lawful use, modification, or access after purchase, allowing providers to revoke access, disable functionalities, or degrade performance over time. In practice, this turns ownership into a conditional rental.

Consumers must be able to use and resell digital goods without hidden limitations and with clear licensing terms. Too often, technical and contractual lock-ins, including remote lockouts and unilateral restrictions on functionality, erode that control. Recent legal reforms show that progress is possible. Rules such as those under the Digital Markets Act have begun to curb technical and contractual barriers and promote user choice. However, many restrictions persist.

The DFA must address these practices by targeting unfair post-sale restrictions and strengthening users’ ability to control and switch services. This means setting clear limits on unfair terms and misleading practices, alongside robust transparency on how digital services function over time. It should also strengthen interoperability and support user control, allowing people to access third-party applications and to let trusted applications act on their behalf, reducing lock-in and expanding meaningful choice in how users interact with digital services.

❌