1. Introduction
The last eight months have seen three judgments from the Court of Justice of the European Union (CJEU) that can have far-reaching implications for the liability of platform operators for content that is shared via their platforms. The three judgments place different and important limitations on the liability exemptions for hosting providers set out in Articles 14 and 15 of the e-Commerce Directive (Directive (EU) 2000/31). Hosting providers, despite the technical name, include any service that stores information at a user’s request, not least online platforms such as marketplaces or social media. The liability exemptions of Articles 14 and 15 of the e-Commerce Directive are considered in a different context in each of these cases.
- In Russmedia (2 December 2025, Case C-492/23), the CJEU held that hosting providers cannot rely on the liability exemption to escape obligations under the General Data Protection Regulation (GDPR).
- In the joined cases WebGroup Czech Republic and Coyote System (16 June 2026, Cases C-188/24 and C-190/24), the CJEU ruled that the use of algorithms to determine what user information is or is not broadcast can give a hosting provider control over this information, with the result that it cannot benefit from the liability exemption.
- In AGCOM v Google Ireland (16 July 2026, Case C-421/24)) the CJEU held that Google could not rely on the hosting-provider liability exemption in respect of YouTube channels with which it concludes revenue-sharing partnerships after examining their content (AGCOM v Google Ireland, Case C-421/24).
Article 14 and 15 of the eCommerce Directive have now been repealed and replaced by Articles 6 and 8 of the Digital Services Act (DSA) respectively. However, the DSA has more or less adopted the liability regime of the eCommerce Directive. These rulings are thus also relevant for liability and enforcement under the DSA.
In this blog post we therefore explore the implications of these three judgments for the liability of platform operators under the DSA. Our main takeaway is that the limitations that the CJEU places on the liability exemptions combined with the additional due diligence leave significantly less room for platform operators to assume the role of neutral intermediary and escape liability from content shared on their platforms. In this respect, we also identify an inherent tension between the neutrality criterion of the liability exemption regime and the DSA’s due diligence obligations for very large online platforms (VLOPs).
2. The liability regime under the e-Commerce Directive
Since the judgments all concerned (the interpretation of) Article 14 and 15 of the e-Commerce Directive, we first provide a brief outline of the liability regime under the e-Commerce Directive that was in place before the entry into force of the DSA. The e-Commerce Directive was the EU’s foundational instrument for regulating online services in the internal market. Among other things, it established the EU’s horizontal regime of conditional liability exemptions for intermediary services.
The e-Commerce Directive was adopted when the internet was at a much earlier stage of development. The eCommerce Directive came into force in 2000, three years before the launch of MySpace, the first major social media network. Viewing the internet primarily as an engine of economic growth, the legislator designed the liability exemptions of Articles 12 to 14 to prevent national law from requiring certain intermediaries to vet everything users upload, as this would have stifled the development of online services. This effort was largely successful, as digital intermediaries have become an important part of the EU economy.
Articles 12 to 14 distinguished between three categories of intermediary services: “mere conduit”, where a provider simply transmits information; “caching”, involving the temporary storage of information to make its transmission more efficient; and “hosting”, where a provider stores information supplied by a recipient of the service (this category includes platform operators). Article 15 complemented those exemptions by prohibiting Member States from imposing general obligations on providers of hosting services to monitor the information they transmit or store.
Article 14 of the e-Commerce Directive protected hosting providers from liability for information stored at a user’s request, subject to two conditions:
- the provider must lack actual knowledge of the illegal activity or information (or, for damages claims, awareness of facts from which illegality would be apparent), and,
- once such knowledge arises, must act expeditiously to remove or disable access to it.
It’s important to note that the provision does not itself establish liability. That remained a matter for the applicable national or EU law. Rather, it sets out the circumstances in which a qualifying intermediary is shielded from being held liable in relation to illegal content provided by the recipient of the service.
The determinative criterion is neutrality. Where a provider’s role is “merely technical, automatic and passive,” it is presumed to have neither knowledge nor control over the information it hosts, and the exemption applies. On the other hand, where the provider assumes a more active role, it is deemed to have such knowledge or control and falls outside the exemption’s scope (Google France and Google, paras 113-114).
3. The three CJEU judgments
As mentioned, the three recent CJEU judgments place important limitations on the e-Commerce Directive liability exemptions.
Russmedia concerned a Romanian online marketplace on which an unidentified user posted an advertisement falsely depicting a woman as offering sexual services, together with her photograph and phone number, without her consent. Although Russmedia removed the advertisement within an hour of notification, it had already been replicated elsewhere. The referring court asked whether Russmedia could invoke the e-Commerce Directive intermediary liability regime against obligations arising under the General Data Protection Regulation (“GDPR”). The CJEU held that it could not: Article 1(5)(b) of the e-Commerce Directive and Article 2(4) GDPR, read together, establish that Articles 12–15 of the e-Commerce Directive “cannot interfere with the GDPR regime.” Since it qualified as a ‘data controller’ under the GDPR, Russmedia remained subject to GDPR obligations irrespective of the hosting exemption, though the exemption remained available to it for claims falling outside data protection.
Coyote System involved a community-based navigation service through which users report road hazards and the location of speed checks which the platform’s algorithm rebroadcasts to other users. French legislation permitted the prohibition of such rebroadcasting on public-safety grounds; Coyote sought annulment of the decree before the French Conseil d’État, arguing that the rebroadcasting prohibition was incompatible with the objectives of the e-Commerce Directive and, in particular, that it imposed a general monitoring obligation contrary to Article 15. The preliminary reference therefore required the CJEU to consider whether Coyote fell within Articles 14 and 15 of the e-Commerce Directive in the first place.
The CJEU clarified that the key question in determining whether the operator could rely on the hosting exemption, and on the prohibition against general monitoring obligations, was whether it exercised ‘control’ over the information that was stored and subsequently rebroadcast (paras 112-113).
Following the Advocate General’s reasoning, the CJEU held that: “where, by means of an algorithm, the operator of an information society service consisting, inter alia, in the storage of information provided by a recipient of the service determines, in its own interest or that of its service, under what conditions, how and in which order of priority that information is or is not broadcast as part of that service, it exercises control over that information.” In other words, where a platform operator uses algorithms to decide what information provided by users of its platform is or is not made available through its platform, it cannot benefit from the liability exemptions of Articles 14 and 15 of the e-Commerce Directive.
AGCOM concerned a €750,000 fine imposed on Google by the Italian communications regulator (AGCOM) for permitting gambling advertising on YouTube channels enrolled in its Partner Programme. Before entering revenue-sharing agreements with these creators, Google reviewed each channel’s theme, leading content, and metadata. The CJEU first confirmed that the e-Commerce Directive applies to the hosting of gambling-related videos, since hosting is content-neutral even where the underlying activity (gambling advertising) falls outside the e-Commerce Directive’s scope.
On the exemption itself, the CJEU held that comprehensive knowledge of every uploaded item on the part of the hosting provider is not required to render Article 14 inapplicable; it suffices that the provider’s activity gives it knowledge of the “essential content” of what is hosted. Google’s pre-partnership review was found capable of conferring such knowledge, irrespective of its commercial purpose or automated execution.
Whereas in Russmedia the CJEU carved out a specific subject-matter (data protection) from the scope of the liability exemptions based on a clash with another piece of EU legislation that was arguably provided for explicitly in the text of the eCommerce Directive,[1] we see that the limitations imposed by Coyote and AGCOM are broader-reaching and more general in nature. As we discuss in the next section, this development matches the increased (economic) importance of platform providers, their evolving business models, and the corresponding shift in how these providers are perceived by regulators.
4. Observations: what do the judgments mean for platform liability and enforcement under the DSA?
A narrower concept of ‘neutral host’
The three judgments concern the same requirement for exemption from liability, namely that the intermediary must play a “merely technical, automatic and passive” role to classify as a “hosting” provider eligible for the exemption of Article 14 of the e-Commerce Directive (recital 42 e-Commerce Directive). The test essentially revolves around whether the operator has a neutral role, as first set out in Google France and Google (Joined Cases C-236/08 to C-238/08, paras 113-114), applied to online marketplaces in L’Oreal and Others (Case C-324/09, paras 112-113, 116) and then to video-sharing and file-hosting platforms in Youtube and Cyando (Joined Cases C-682/18 and C-683/13, paras 105-106).
However, while building on this earlier line of case law, Russmedia, Coyote and AGCOM show that the business models of modern platform operators are increasingly difficult to square with the concept of neutrality. Using an algorithm to organize content already suggests a degree of influence over it, and being aware of a channel’s content is sufficient to confer knowledge or control on the provider, eliminating the liability exemptions.
The reach of this narrowing of the exemption is also evident when looking at how platforms make revenue from user content. The type of revenue-sharing agreement at stake in AGCOM is not unique to YouTube. For example, X (formerly Twitter) operates a ‘Creator Revenue Sharing’ programme which rewards eligible accounts that comply with its rules and monetization standards. Similarly, the Facebook ‘Content Monetisation’ programme allows invited creators to earn revenue from content that meets the platform’s policies. The existence of such incentives does not, by itself, establish that a platform knows the essential content of a creator’s account. However, the question is whether participation in such an agreement involves reviewing the creator’s channel, its content or associated metadata. If that is the case, the platform is unlikely to be able to argue that it remained unaware of the ‘essential content’ concerned, and therefore to fall under the hosting exemption. As AGCOM confirms, the fact that this review is carried out through automated systems does not lead to a different outcome (paras 45-46).
Coyote in particular points to a risk for social media platforms. The service at issue primarily organized and rebroadcast user-generated information, yet the Court held that an intermediary may exercise control where its algorithm determines, in the intermediary’s interest, the conditions, manner and order of priority in which information is displayed. That reasoning could easily extend to social media recommender systems, whose primary function is to curate and rank user content. However, the judgment leaves the precise threshold unclear and does not establish that every form of algorithmic ranking or recommendation necessarily amounts to control.
The three judgments illustrate a similar shift, namely that the liability exemption is not an unconditional safe haven for hosting providers and that it may no longer be applicable to some platforms because of changes to their business model and their broader role within the digital economy. The online realm of 2026 cannot be compared to the one the e-Commerce Directive was written for in 2000. It has become larger, more complex and less safe. For this reason, if platforms are to be regulated in a way that keeps pace with that change, the hosting exemption had to adapt too.
The DSA framework as a continuation of the e-Commerce regime
As mentioned, the DSA has preserved the core of the e-Commerce Directive’s intermediary-liability framework. It replaces Articles 14 and 15 with Articles 6 and 8 (see Annex 1), but leaves the substance of the regime almost unchanged. The aim was to preserve a regime that had allowed new services to scale up across the internal market, while addressing the divergences caused by national transposition (recital 16 DSA). As a Regulation, the DSA now applies directly and uniformly throughout the EU. The neutrality test is carried over too, as the DSA re-introduces the “knowledge of” and “control over” criteria which all three judgments focus on (recital 18 DSA).
The continuity of the framework is clearest in Article 6, which reproduces the former hosting exemption. Its single addition is the consumer-protection carve-out in Article 6(3), which prevents a marketplace from invoking the exemption where it presents a third-party listing in a way that would lead an average consumer to believe the platform itself, rather than the third-party seller, is the selling party.
Article 8 similarly restates the prohibition on general monitoring obligations of Article 15 e-Commerce Directive, but its wording is broader now. The ban is now a freestanding rule for intermediary services, meaning that a provider must not necessarily fall under the hosting exemption of Article 6 for it to benefit from the monitoring obligation ban (see the below Annex for a side-by-side comparison of the relevant DSA and e-Commerce Directive provisions).
Article 7 DSA complements Article 8 and completes the picture. It stipulates that an intermediary does not lose the exemption merely because it carries out voluntary own-initiative investigations or takes good-faith measures to comply with EU law, including the obligations of the DSA itself. This means that the DSA acknowledges that its implementation requires intermediaries to comply with potentially significant due diligence obligations, which might require content moderation, fact-finding, and overall engagement with content. It looks to ensure that compliance with these obligations does not automatically deprive the providers from benefiting from the exemption regime. It also addresses the hesitation that platforms may have previously felt to moderate illegal content beyond the legal minimum under the e-Commerce, as it clarifies that good faith content moderation efforts will not remove the applicability of exemption.
The DSA regime, therefore, preserves in the most part the liability framework of the e-Commerce Directive. This also means that the limitations placed on this regime by the three CJEU judgments must be considered directly relevant to the DSA’s liability exemption regime.
The spectacular growth of intermediaries, and platform operators in particular, has brought challenges that were not anticipated when the e-Commerce Directive was adopted. This includes the breadth of services that would eventually qualify as hosting providers and the scale at which they would store, organize and disseminate user-generated content. As user bases grew, so did the volume and range of illegal content available through those services, raising questions about whether platforms were taking adequate steps to address it. The e-Commerce framework therefore became insufficient to adequately govern platforms of the scale and influence we see today (recital 1 DSA).
Against this background, the DSA adopted, separately from the liability-exemption regime, due diligence and accountability obligations calibrated to the nature, size and reach of the intermediary service provider. This raises the question of how these due diligence obligations interact with the hosting exemptions.
The liability exemption and the DSA’s tiered due diligence obligations
Although the DSA treats the hosting-exemption framework (Articles 4-6) as separate to its due diligence obligations in Chapter III, there seems to be an inherent tension between the two regimes, especially with regard to VLOPs and VLOSEs (i.e. online platforms and search engines with over 45 million monthly active users in the European Union). The liability exemption only benefits a provider when it acts as a neutral host who does not have knowledge of nor control over the content it stores. However, the most important due diligence obligations for VLOPs, namely Articles 34 and 35 DSA which require platforms to assess and mitigate systemic risks, seem to pull in the opposite direction. To comply with these obligations, platforms must actively engage with content and gather knowledge in order to implement mitigation measures and protect users and their fundamental rights. The question is therefore whether compliance with these duties may itself generate the very knowledge that defeats the neutral host classification and therefore the exemption.
A possible answer lies in the type of knowledge each regime concerns. The liability exemption turns on specific knowledge, namely “actual knowledge of illegal activity or information” (L’Oréal and Others, paras 119-120). By contrast, Articles 34 and 35 require VLOPs principally to identify and mitigate risks at a systemic level. A platform may therefore understand that its service creates a significant risk of disseminating illegal content without necessarily knowing which individual items are illegal. How this distinction will operate in practice, however, has yet to be tested.
As mentioned, Article 7 DSA helps to reconcile the two regimes. It provides that a provider does not lose the liability exemptions solely because it carries out voluntary, good-faith investigations into illegal content or takes measures necessary to comply with EU law, including the due diligence obligations under the DSA. In other words, the Regulation seeks to avoid discouraging platforms from moderating content to preserve their neutral status. But Article 7 does not guarantee that the exemption applies: where those activities give a hosting provider specific knowledge or control over certain information it may lose protection under Article 6. Exactly when this happens remains to be seen and will likely be determined by the CJEU in future cases. Further, Article 7 shields platforms against systemic knowledge gained through good-faith moderation or legal compliance, yet it says nothing about knowledge gained through a commercial arrangement, which caused Google to fall outside the exemption in AGCOM.
5. Takeaways: liability exemption for platform operators under pressure from both sides
The three CJEU judgments discussed in this blog place significant limitations on the liability exemption framework of the e-Commerce Directive. Since that framework now lives on in the DSA, platform operators will find it increasingly hard to escape liability based on this exemption. This narrowing of the hosting exemption is in line with the more prominent role that platform operators and other intermediaries play in today’s society, as evidenced by the Commission’s priority of making that environment safer and fairer.
The DSA’s additional layers of due diligence obligations put further pressure on platform operators’ position as neutral intermediaries. These new obligations also prompt the question to what extent large platforms can engage with, assess and moderate the content on its service while still qualifying as a neutral host. Where exactly this boundary lies is yet to be established.
Annex
Overview of statutory changes between e-Commerce Directive and DSA regarding hosting-provider liability exemption and ban on monitoring obligation
| E-Commerce Directive (2000/31) | Digital Services Act (DSA) |
| Article 14: Hosting 1. Where an information society service is provided that consists of the storage of information provided by a recipient of the service, Member States shall ensure that the service provider is not liable for the information stored at the request of a recipient of the service, on condition that: the provider does not have actual knowledge of illegal activity or information and, as regards claims for damages, is not aware of facts or circumstances from which the illegal activity or information is apparent; orthe provider, upon obtaining such knowledge or aware ness, acts expeditiously to remove or to disable access to the information. 2. Paragraph 1 shall not apply when the recipient of the service is acting under the authority or the control of the provider. 3. This Article shall not affect the possibility for a court or administrative authority, in accordance with Member States’ legal systems, of requiring the service provider to terminate or prevent an infringement, nor does it affect the possibility for Member States of establishing procedures governing the removal or disabling of access to information. | Article 6: Hosting 1. Where an information society service is provided that consists of the storage of information provided by a recipient of the service, the service provider shall not be liable for the information stored at the request of a recipient of the service, on condition that the provider: does not have actual knowledge of illegal activity or illegal content and, as regards claims for damages, is not aware of facts or circumstances from which the illegal activity or illegal content is apparent; or upon obtaining such knowledge or awareness, acts expeditiously to remove or to disable access to the illegal content. 2. Paragraph 1 shall not apply where the recipient of the service is acting under the authority or the control of the provider. 3. Paragraph 1 shall not apply with respect to the liability under consumer protection law of online platforms that allow consumers to conclude distance contracts with traders, where such an online platform presents the specific item of information or otherwise enables the specific transaction at issue in a way that would lead an average consumer to believe that the information, or the product or service that is the object of the transaction, is provided either by the online platform itself or by a recipient of the service who is acting under its authority or control. 4. This Article shall not affect the possibility for a judicial or administrative authority, in accordance with a Member State’s legal system, to require the service provider to terminate or prevent an infringement. |
| Article 15: No general obligation to monitor 1. Member States shall not impose a general obligation on providers, when providing the services covered by Articles 12, 13 and 14, to monitor the information which they transmit or store, nor a general obligation actively to seek facts or circumstances indicating illegal activity. 2. Member States may establish obligations for information society service providers promptly to inform the competent public authorities of alleged illegal activities undertaken or information provided by recipients of their service or obligations to communicate to the competent authorities, at their request, information enabling the identification of recipients of their service with whom they have storage agreements. | Article 8: No general monitoring or active fact-finding obligations No general obligation to monitor the information which providers of intermediary services transmit or store, nor actively to seek facts or circumstances indicating illegal activity shall be imposed on those providers. |
[1] See eCommerce Directive, Article 1(5)(b).
Leave a Reply