Showing posts with label secondary liability. Show all posts
Showing posts with label secondary liability. Show all posts

Thursday, August 06, 2026

IPSC Breakout Session 1 Copyright Secondary Liability

Copyright’s Intent, Mark McKenna (with Laura A. Heymann & Alfred C. Yen)

Cox: Contributory infringement for service providers can be shown only with intent, or with a service tailored to infringement. What happened to Gershwin? Will courts really accept that? Will they expand vicarious liability more to capture intuitions they have about fault?

Common-law tort origin is the claim, but ©’s rules are misaligned from tort. Is this all © exceptionalism? Many of us feel that courts are searching to attribute fault but don’t have the right anchoring in tort law fault principles.

First, ©’s insistence on hard line b/t direct infringement and secondary liability. Tort law more flexibly assigns first-party liability to those whose conduct causes the injury—co-tortfeasors when contributions are deemed sufficient, even when another party’s participation is required for harm and even when co-tortfeasor’s conduct is not the proximate cause. Joint liability—tort doesn’t regard that liability as secondary. They’re not derivatively liable for wrongful conduct of another, but liable b/c of their own wrongful contributions to harm. If party most proximate to harm is batterer, the co-tortfeasor is also a batterer. Tort only very rarely imposes truly secondary liability (wrongs committed by others). Vicarious liability is the standard, but it’s not specific to the particular conduct but rather exists because of the broader relationship (employment) to the tortfeasor. Enterprise liability too.

Basically true even for strict liability like blasting/harboring a wild animal. Even when D’s own conduct is also sufficient to subject them to liability—when landlord engages w/wild animal in ways that could be called a harborer—that’s not derivative liability. Otherwise landlord might be negligent in their own conduct (renting to a known harborer). So © being strict liability doesn’t demand a different approach.

Framing of whole Q of secondary liability is thus already off on the wrong foot from tort perspective.

© ignores wrongful contribution to an injury: party’s own negligent conduct exposes the P to third-party wrongdoing, like landlord who exposes tenants to assault, or train leaving passenger in dangerous area. Liability there is not co-tortfeasor; this category doesn’t put D in same category as other tortfeasor: negligence liability, not battery, for negligently exposing P to third-party battery. Doctrines like causation, act/omission, etc. come into it. The remedies are negligence remedies—no punitive damages even if third party engages in intentional tort.

How does © get misaligned? Courts initially concerned with co-infringers—people who performed part of the act that led to infringement. Drawing on patent cases where infringement requires assembly of lots of parts. A common enterprise, either directly or indirectly where one party makes a component to be combined with another. When co-infringers weren’t amenable to suit, Ps tried to bring in more upstream participants to say they were also co-infringers. Courts started using the term “contributory infringement.” But they weren’t really developing it as a theory of derivative liability, but rather describing why the contributions of Ds made them co-infringers. These were common enterprises—common purpose to cause the infringement.

Part of the confusion in © is emphasis on secondariness of liability, unplugged from fault principles. If we tried to do more faithful mapping to tort law: we should be very reluctant to impose true secondary liability other than vicarious liability, which we would define much more narrowly—a relationship like employer/employee or joint enterprise—relationships not specific to the infringing conduct, with much higher levels of control. Thus, we’d reorient to (1) co-infringers—liable b/c their own conduct makes them fairly labeled an infringer, subject to © remedies, including inducement and providing products w/no substantial noninfringing use; could also include, per Sotomayor, other cases of aiding and abetting where there’s knowledge plus material contribution as in tort law where tort law demands significant contribution at a time when it can be said to reflect a meeting of the minds in furtherance of tortious conduct, not just any time/knowledge of past infringement. (2) negligent exposure to third-party infringement; implication of duty, breach, causation and damages. Not really © infringement but negligence, so the damages are different.

Lea Bishop: so is © not really a strict liability offense?

A: these doctrines aren’t limited to intentional torts, but the way the courts talk about the other party’s contribution is about intent to interact w/other D—so it’s not intent in the “intended to infringe” way but “intended to work with.” Underlying tort doesn’t require proof of intent. Cox’s categories of intent map pretty well if they mean “intent to work together” rather than “intent to carry out infringement.”

The New Law of Vicarious Liability in Copyright, Michael Carroll

Cox tells courts to change their vocabulary. Does that matter? If so how? Restatement (Second) of Agency conceives of two types of principal/agent employment relationships. Master/servant where there’s agency v. independent contractor who may or may not be an agent. It was against that tort law background that the 2d Circuit decided Shapiro, Bernstein about whether a department store owner/operator was liable for sales of infringing recordings by concessionaire. Court rejects independent contractor defense: right and ability to supervise plus obvious and direct financial interest in exploitation of copyrighted materials—looking to © policy and says policy is best served by imposing liability in these circumstances. Courts repeat those terms, not with full consistency.

Sony came along: The use of the term vicarious liability was imprecise in the opinion, but Justice Stevens used the term for any kind of indirect liability. 9th Circuit kept treating Grokster as simply ratifying Shapiro, Bernstein. But Grokster’s formulation is different! Ignored Justice Souter’s restatement; Cox says that the Court is the boss. You’ve got to start using the magic words. If one infringes by profiting from direct infringement, financial interest isn’t enough: profit is revenue minus cost. But maybe it’s not a big deal. Declining to exercise a right to stop or limit direct infringement: to decline to take action implies both knowledge and intent. But as an outgrowth of respondeat superior, vicarious liability has been treated as strict. How can that be reconciled?

Cox’s treatment of Grokster suggests that the Court will rely on its own restatement of vicarious liability when it reaches a relevant case. Courts will need to develop a standard for declining to exercise right/ability. A relationship akin to employment will impute knowledge to hold that supervising party declined to act; but a service provider for an internet user would require more evidence than a contract that said you could be cut off w/o some specific notice.

Example: tape machine manufacturer & its retailers: 8th circuit said they were liable b/c of contracts w/retailers for how machines were used; machines were distributed free; some tape sales were to infringers & manufacturer profited from tape sales. Not sure that could suffice.

Question: where did Souter get his words? Not in the briefs in Grokster.

Eric Goldman: thought that Grokster was p-favorable; what’s the empirics?

RT: wouldn’t it be stronger to start from the point that the real name of/justification for vicarious liability is agency liability? Service user is obviously not agent of service provider, so that would help realign with larger agency/vicarious liability law.

Also: read the SCOTUS sexual harassment cases from 1998 & Ginsburg’s characterization of the liability standard, where she makes similar moves about vicarious liability.

Grimmelmann: as with shadow docket, SCOTUS is telling lower courts to read their tea leaves and comply.

Copyright Exceptionalism in the Supreme Court’s Secondary Liability Cases, Pamela Samuelson

© industries seek broad liability rules for tech companies; industry turned to Gershwin definition from 2d Circuit in Sony, Grokster, & Cox, claiming that Gershwin was the bedrock foundation for their claims. © exceptionalist arguments derived neither from statute nor common law, but claims about massive uncontrolled infringement. But Ct even in Sony didn’t cite to Gershwin except as vicarious case.

Grokster: MGM no longer relying on Gershwin alone, but emphasized that Gershwin’s definition of contributory liability included inducement. Court looked to Gershwin for inducement as well as to patent law. Cox is a lazy opinion; Sotomayor is making more sense. Asks: why not aiding & abetting? Some options: there’s nothing in the statute; the statute says “to authorize” which didn’t happen; no inducement b/c Cox didn’t encourage infringement; no special tailoring, no direct financial benefit; no a&abetting b/c there’s no intent to aid infringers. Material contribution w/knowledge was Sony’s only chance, but broadband service wasn’t proximate cause and Cox’s after the fact knowledge/lack of way to know which user actually infringed was too limited to justify liability.

Pressure on vicarious infringement & volitional conduct will exist, but probably not on inducement b/c Hikma reinforced the requirement of active inducement in patent context.

Did SCt really intend to overturn Netcom such that failure to take something down after notice is no longer material contribution sufficient to justify liability? DMCA is not a dead letter b/c many incentives to comply still exist. [Including incentives to comply for other countries’ regimes.]

Jim Gibson: Even Sotomayor wants to use a&a for a heightened mens rea—intent of helping other person succeed in committing wrongful conduct, not just intent to perform the act that enables infringement. So the common focus on intent seems like the most limiting factor going forward, not whether a&a can also be included.

A: Taamneh was important to Cox despite few mentions—the required intent (to aid terrorists) was something the Court thought about in that context. She expects intent to get watered down.

Fearing (and Loathing) the Common Law of Copyright, Shyam Balganesh

Why the reluctance of the Court to engage with © as a common law system? Thomas says: we’ve recognized specific forms of secondary © liability that predate the Act, but we’re loath to expand liability beyond that. Sotomayor says: why?

Legislative-judicial dynamic around parts of the statute has been essential to the 1976 Act. Typology: Legislative modality: novation; judicial task: interpretation (Congress invented this and didn’t draw from prior case law); example: joint works

L: Codification; J: preservation/interpretation; E: first sale

L: Silence (decided not to speak; mess already existed by 1960s & 1970s); J: unconstrained law-making; E: substantial similarity

L: Delegation; J: constrained law-making; E: fair use.

Sony has the right result but made a methodological error: Stevens says that Act doesn’t expressly render anyone liable for infringement committed by another & talks about absence of express language requiring courts to jump in. This is only partially true b/c of “to authorize” in 106, which Sony & Cox don’t mention—it has clear instantiated meaning and long history. Thomas has a theory of congressional primacy; the legitimacy of court-made law is always tested against backdrop of congressional action or inaction; seemingly a majority of the Court has accepted/acquiesced to this view. Clear patterns in his opinions in Star Athletica, dissents in Public.resource.org and Oracle: you’re using fair use to annul the statutory treatment of software. Even in Fogerty v. Fantasy: text of statute is clear; interpretation ends.

Thomas’s disdain for common law; three views. If there’s a backdrop of rules against which Congress legislates, appealing to those rules is legit but frozen in time. For delegated lawmaking—ongoing elaboration required for open-ended terms with express or implicit recognition that judge-made law will follow—he thinks it’s legitimate if the text constrains it with guardrails; securities law is an example of his objection b/c there’s not enough guardrails. Finally, independent lawmaking is wholly illegitimate (no gov’t edicts doctrine).

Maybe this was a category error: failing to discuss “to authorize.” Doesn’t think so, though, b/c briefs raised it. But he wasn’t convinced that there was a textualist hook. Raises Q: what does this do to other parts of © law if this vision of interpretive structure has a majority? Fair use implications: only if it is compatible w/the rest of the statute. Originality: same plane. Infringement analysis: implications for legislative reform. Beware of textualists when advocating for reform: how a court would handle that.

RT: Textualism masks that placement in categories is contestable: Glynn Lunney: reproduction/derivative works could have replaced substantial similarity; codification could have been read as novation in interpreting first sale versus exhaustion.

NO FAKES and similar ROP proposals often have language like “to the extent protected by the 1A” in their exclusions—how could this form of textualism handle that? Would Thomas’s approach ignore those exclusions just like he ignored the open ended language about useful articles in Star Athletic.

A: irony of Thomas’s MO: claiming that there’s plain meaning while refusing to look at legislative intent—he ignores “to authorize” b/c explaining what its plain meaning was would require a citation to the legislative history.

Our Byzantine Secondary Infringement System, James Grimmelmann

Conventional view: in US, there’s vicarious infringement and then intent-based contributory liability. He wants to do a thorough survey of all the secondary liability doctrines in US law, describe & critique it as a system, and then possibly suggest fixes.

True secondary liability doctrines: liability for someone else’s completed act of direct infringement.

What about infringement by authorization? Issuing a purported license w/o the right to do so—seems literalist but probably killed by Subafims.

Agency law: respondeat superior is used all the time where companies are held liable for employee’s actions. Agent’s actions and knowledge are imputed to their principal, often invisibly, even when not actuated by purpose to serve employer [not sure this last is true—looking forward to cites]. Especially in PRO licensing cases where employees at a bar are used to hold owners liable even when corporate law wouldn’t do it.

Volitional conduct/the server test: these often cut in opposite directions and interact weirdly with licenses granted to platforms by users.

Quasi-secondary liability: for conduct that could facilitate infringement regardless of whether there is actually infringement.

Scaffolding doctrines: direct infringement has no mental state requirement; makes stakes much higher for direct/secondary. Willful & innocent infringement also matter to statutory damages.

Criminal liability for willful infringement; brings in general criminal doctrines of aiding & abetting; there’s also a “causing” criminality but no federal attempts criminal liability. There’s also conspiracy liability: it’s a crime to conspire to criminally infringe; Pinkerton: conspiracy to commit any crime subjects conspirator to liability for any criminal infringement that’s reasonably foreseeable and in furtherance of criminal conspiracy. RICO: © infringement is a predicate crime.

512: Does it displace common law? Volitional conduct? Apply beyond enumerated services? Courts generally say no to all. Tony Reese has given good reasons to think it’s a bit more complicated. The exceptions it carves out all sound in secondary liability (quasi-contributory; quasi-vicarious—presumed that direct liability wasn’t possible so how could it be the same as common law liability?); what about the repeat infringer suspension—what is a reasonable policy? Recreated a lot of secondary infringement doctrine under the head of 512.

TPMs also matter: Serial copy management systems—you must implement them and you’re liable for distributing tech w/o them—that’s a kind  of quasi secondary liability.

1201 is too, arguably mapping onto Cox intent prongs—distributing tech “primarily designd for,” knowingly marketed for use in circumvention, or have limited commercial use except for circumvention.

1202 is too: knowingly language but not in any coherent/organized fashion.

This is far too complicated. There are way too many minor variations and overlaps. What happens to 512’s quasi contributory liability exception now that Cox has repudiated knowledge plus material contribution? Overlapping but inconsistent tests. Confused relationship of statutory codification to common-law elaboration: volitional conduct, server test, and 512 all seem to do similar work. Loopholes and traps for the unwary—Aereo was $100 million waste.

Jim Gibson: distribution liability can be thought of as secondary liability for the underlying reproduction, though the statute doesn’t say that.

Friday, October 27, 2023

New comment on a paper about YouTube and music

 Here.

This useful article about the effects of music on YouTube on consumption of the same music elsewhere should be understood for what it is: An empirical investigation of YouTube’s effects. It allows no conclusions about “safe harbors” both because YouTube was not relying on the safe harbor regime either before or after the relevant policy change and because, as YouTube’s lack of reliance shows, the safe harbor regime primarily protects thousands of websites that don’t behave like YouTube. Under the European Union’s new Article 17, sites like YouTube are now required to negotiate with copyright owners to license works uploaded by users who do not own the copyright thereto. YouTube, however, was already doing this. The article [Wlömert N, Papies D, Clement M, Spann M (2023) Frontiers: The interplay of user-generated content, content industry revenues, and platform regulation: Quasi-experimental evidence from YouTube. Marketing Sci., ePub ahead of print October 27, https://doi.org/10.1287/mksc.2022.0080] has implications for what music companies should ask for in these negotiations. However, it would be a mistake to generalize from YouTube to the Internet as a whole.

RT: This was kind of frustrating! The authors seem to think that, with a licensing/filtering requirement, there wouldn't be much music on a given site, whereas with a notice and takedown regime, there would be a lot. (You know, the way there is on Wikipedia and Ravelry and all those other DMCA-compliant sites.) So they insist that their evidence--which is about music consumption on other sites before and after YouTube cut a deal with GEMA--shows something about the effects of "safe harbors" generally. But since YouTube was not relying on safe harbors before the change--when it just blocked GEMA music in Germany--or after--when it licensed--their evidence cannot stand for the proposition they claim it stands for. If anything, it shows the opposite, that licensing leads to more reliable availability (and thus makes YouTube a better substitute for other sources of music). 

Wednesday, September 06, 2023

claims about legality of insurance service are falsifable

Route App, Inc. v. Heuberger, 2023 WL 5334192, No. 2:22-cv-00291-TS-JCB (D. Utah Aug. 18, 2023) (magistrate)

Route is a package tracking company that provides shipping insurance to e-commerce merchants. Heuberger was a Route customer who then launched a competitor, Navidium. Route sued for breach of contract, commercial disparagement and defamation per se, intentional tortious interference with contractual relations, false advertising, and contributory trademark infringement.

The breach of contract claim survived.

Commercial disparagement/trade libel/injurious falsehood/defamation per se: The challenged statements were opinion. Even potentially verifiable facts—such as whether claims are “more often than not denied,” whether Route requires a police report to be filed for a lost package, or whether Route commits a “serious breach of customer data”—“when read in the statement’s full context, would be understood as hyperbolic or figurative and clearly representing an opinion.”

Route also alleged that Heuberger tortiously interfered with valid contracts between Route and third-party merchant partners by: using confidential information to develop Navidium; engaging in commercial disparagement; making fraudulent misrepresentations about Route and Navidium; inducing Route’s merchant partners to use Navidium; and engaging in unlawful activity, including collecting a fee without proper insurance licenses or permits. Route alleged that Heuberger stated in online posts and messages that he “created Navidium to ‘screw with’ and ‘tak[e] down’ Route, because he ‘hate[s] Route.’ ” Route argued that Heuberger misled Route’s then-clients by portraying Navidium as a “technology that facilitates the lawful sale [of] shipping insurance” despite such services being “illegal.” The court wasn’t sure whether Route could show causation, though Route alleged that an increasing number of merchants who discontinue Route’s services appear to cite “the false statements made in Heuberger and Navidium’s solicitations.” Whether these acts were justified was fact-intensive and couldn’t yet be resolved.

False advertising:  The comments about Route were opinion and not actionable under the Lanham Act. But Route’s allegations that Navidium misrepresented or implied that merchants can lawfully offer shipping insurance or shipping protection without obtaining insurance licenses or permits and that Navidium is a shipping insurance company or technology “are straightforwardly factual assertions the veracity of which may be determined” by a review of the applicable law and an investigation of Heuberger’s marketing of Navidium. Other cases say that legality claims are usually opinion unless offered by someone with legal expertise, but the court doesn't discuss the issue.

Contributory trademark infringement: Defendants allegedly knowingly facilitated infringement of Route’s trademarks by installing versions of the Navidium widget under the names “Route Plus” and “Route Pro,” infringing its registered “Route” mark for shipping protection/e-commerce tracking. Defendants responded that Navidium is fully merchant-run after installation, and that Heuberger did not know and had no reason to know that merchants were replacing the Navidium name. Route counters that “[b]ecause Navidium has no product offerings that do not include expert installation, Heuberger or another Navidium representative modifies the Navidium widget code to include the name and/or text chosen by the merchant every time the white-labeled Navidium widget is installed.” This was sufficiently pled. Not clear to me: does anyone but the merchant internally see the widget? If not, what confusion could there be?

 

Friday, April 07, 2023

27th Annual BTLJ-BCLT Symposium: From the DMCA to the DSA: Panel 3: Intended and Unintended Consequences of the DSA

 Moderator: Pamela Samuelson, Berkeley Law School

From Notice-and-Takedown to Content Licensing and Filtering: How the Absence of

UGC Monetization Rules Impacts Fundamental Rights       

João Quintais, University of Amsterdam with Martin Senftleben, University of Amsterdam

Human rights impact of the new rules. When we say notice and takedown is no longer extant in EU, that’s not entirely true—DSA has it. We look at safe harbors not from an industry perspective—allowing them to develop services regardless of what users upload—but from a user human rights perspective—we allow users to upload whatever they want and correct it later. DSA has a © interface that says insofar as there’s specific © legislation it is lex specialis and prevails over DSA. Thus, the safe harbor comes to an end w/r/t © content. Art. 17 instead controls for OCCSP systems. Licensing and filtering replaces safe harbor.

That has a human rights impact. Risk of outsourcing human rights obligation to private entities, and conceding these mechanisms by putting responsibility for correcting excesses in hands of users. Regulator is hiding behind other parties.

W/r/t platforms like YouTube, requirement of not allowing upload w/o licensing is a major intrusion on user freedom, leading to public demonstrations against upload filters that can’t distinguish b/t piracy and parody. DSA says you have to take care of human rights in proportionate manner in moderation/filtering. But regulator doesn’t do the job itself. Guardians of UGC galaxy are the platforms themselves. Regulator hides behind industry and says we’ve solved the issue.

Reliance on industry is core of Art. 17—cooperation b/t creative industry and platform industry. One industry sends info on works that should be filtered, and the platforms have to include that info in their filtering systems. But regulator says that this cooperation shouldn’t result in preventing noninfringing content—but how realistic is this? They aren’t at the table maximizing freedom of communication; they are at the table maximizing profit. That’s ok as a goal but these actors are not intrinsically motivated to do the job assigned to them.

Concealment strategy: Empirical studies show that users are not very likely to bring complaints; system excesses will stay under the radar. Legislator suggests a best practice roundtable among big players. ECJ has spoken in Poland decision; what the court did confirmed that this outsourcing/concealment strategy was ok, rubberstamping the approach. The Court says the filtering systems have to distinguish b/t lawful and unlawful content, but that’s an assumption and not a very realistic one. The incentive to filter more than necessary is higher than the incentive to maximize freedom of expression. The court says the filtering is only set in motion if rightsholders send a notification, but again the incentives are to send lots of notices.

Audit system could be a solution, involvement of member states could be a solution, but we have to discuss the issues openly.

Monetization is an area where the issues are particularly bad. YouTube, Instagram, TikTok are the subjects: an action of obtaining monetary benefit/revenue from UGC provided by the user. There are restrictions in DSA on demonetization. Most discussion has been about upload filters, but YT’s © transparency reports show that actually most of the action is not blocking via filtering—it’s mostly monetization through Content ID. 98.9% of claims are through Content ID, and 90% are monetized.

Art. 17 doesn’t say anything specific about monetization; it’s all about filtering and staydown. Provisions for fair remuneration for authors are very difficult to apply. Lots of actions are not covered by the regulation, especially visibility measures and monetization. DSA has two clear provisions covering statement of reasons for in platform complaint resolution/ADR, but most of what users can do is ex post.

Big platform practices change regularly. Content ID and Rights Manager (Meta) are the big hitters; you can get other third party solutions that intermediate b/t rightsholders and platforms like Audible Magic and Pex. Legibility of access to monetization in Content ID and Rights Manager: available only to large firms. If you take Poland decision seriously, it should only be filtered for manifestly infringing content, but these systems are designed to allow parameters below the legal threshold.

On the monetization side, it’s billed as ex post licensing; as a rule this is not available to small UGC creator, though there are exceptions. There is a lack of transparency; left to private ordering.

Human rights deficits: Misappropriation of freedom of expression spaces & encroachment on smaller creators’ fundamental right to ©. If a use is permissible and does not require permission, larger rightsholders can nonetheless de facto appropriating and being given rights over content for which they have no legal claim. Creates the illusion that there’s no expressive harm b/c the content stays up, but there’s unjustified commercial exploitation. UGC creator is often a © owner, with protection for that as a work. Only they should logically be allowed to monetize. Interferes w/ UGC creator’s fundamental right, but this is not a default option on the platform for historical reasons, leaving them only to ex post remedies, which are weak sauce.

Recommendations: bring these problems to light. Audit reports should focus on these questions. Human rights safeguard clause: must take care to protect parody, pastiche—if they pass the filter they should not lead to monetization. Confining filtering to manifestly infringing UGC also helps. German solution: collective licensing schemes w/a nonwaivable remuneration right for UGC creators, not just to industry players. Inclusion of creative users in a redesign of a more balanced monetization system.

An Economic Model of Intermediary Liability         

James Grimmelmann, Cornell Law School; Cornell Tech

Economic claims about effects of liability regimes are common. Chilling effects; whether platforms do or don’t have sufficient incentives to police content; claims that 230/DMCA don’t’ adequately balance free expression with safety concerns; etc. These are statements about incentives, but primarily policy arguments, not empirically tested. There are some empirical studies, but our project is to create an economic model to provide a common framework to compare arguments. This can help create predictions and visualize the effects of different rules. Mathematical model forces us to make explicit the assumptions on which our views rest.

Start w/question of strict liability v. blanket immunity; look at possible regimes; map out core elements of 512, DSA, and 230. Not going to talk about policy responses to overmoderation/must-carry obligations or content payment obligations.

Basic model: users submit discrete items of content. Each item is either harmful or harmless. Platform chooses to host or take down. If hosted, platform makes some money; society gets some benefits; if the content is harmful, third party victims suffer harm. Key: platform does not know w/certainty whether content is harmful, only the probability that it is. These are immensely complicated functions but we will see what simplification can do. [What happens if harmful content is profitable/more profitable than nonharmful content? Thinking about FB’s claim that content that is close to the line gets the most engagement.]

A rational moderator will set a threshold. Incorporates judgments about acceptable risk of harm in light of likelihood of being bad v benefits of content to platform and society.

The optimal level of harmful content is not zero: false positives and false negatives trade off. We tolerate bad content b/c it is not sufficiently distinguishable from the good, valuable content. Users who post and victims harmed may have lots of info about specific pieces—they know which allegation of bribery is true and which is not—but platforms and regulators are in positions of much greater uncertainty. Platform can’t pay investigators to figure out who really took bribes.

Under immunity, platform will host content until it’s individually unprofitable to do so (spam, junk, other waste of resources). This might result in undermoderation—platform’s individual benefit is costly for society. But it’s also possible that platform might overmoderate if platforms take stuff that’s not profitable down but was net beneficial for society. There is no way to know the answer in the abstract; depends on specifics of content at issue.

Focusing on undermoderation case: one common law and econ response is strict liability. This is always less than the benefit to society—it will always overmoderate content that would be unprofitable under strict liability but would be beneficial to society. This is Felix Wu’s theory of collateral censorship: good content has external benefits and is not distinguishable from bad from outside. If those two things are true, strict liability won’t work b/c platform only internalizes all harm, but not all benefit.

Other possible liability regimes: actual knowledge, when no investigation is required—this allows costless distinctions between good and bad. But does actual knowledge really mean actual knowledge or is it a shorthand for probabilistic knowledge of some kind? Intuition is that notices lower cost of investigation. Fly in the ointment: notices are signals conveying information. But the signal need not be true. When investigations cost money, many victims will send notice w/o full investigation. Turns out notices collapse into strict liability—victims send notices for everything. Must be costly to send false notices; 512(f) could have done this but courts gutted it. DSA does better job with some teeth to “don’t send too many false notices.” Trusted flagger system is another way to deal with it.

Negligence is another regime—more likely than not to be harmful. Red flag notice under DMCA. Gives us a threshold for platform action. Conditional immunity is different: based on total harm caused by the platform—if too much, platform is liable for everything. This is how the repeat infringer provisions of 512 work: if you fail to comply, you lose your safe harbor entirely. These can be subtly different. Regulator has to set threshold correctly: a total harm requirement requires more knowledge of the shape of the curve b/c that affects the total harm; the discontinuity at the edge is also different.

512 is a mix: it has a negligence provision; a financial benefit provision—if it makes high profits from highly likely to be bad content; repeat infringers. DSA has both actual knowledge and negligence regimes. Art. 23 requires suspension of users who provide manifestly illegal content, but only as a freestanding obligation—they don’t lose the safe harbor for doing it insufficiently; they simply pay a fine. 230 is immunity across the board, but every possible regime has been proposed. It is not always clear that authors know they propose different things than each other—negligence and conditional immunity look very similar if you aren’t paying attention to details.

Although this is simplified, it makes effects of liability rules very obvious. Content moderation is all about threshold setting.

Interventions   Rebecca Tushnet, Harvard Law School

Three sizes fit some: Why Content Regulation Needs Test Suites

Despite the tiers of regulation in the DSA, and very much in Art. 17, it’s evident that the broad contours of the new rules were written with insufficient attention to variation, using YouTube and Facebook as shorthand for “the internet” in full. I will discuss three examples of how that is likely to be bad for a thriving online ecosystem and offer a suggestion. 

The first issue is the smallest but reveals the underlying complexity of the problems of regulation. As Martin Husovec has written in The DSA’s Scope Briefly Explained, https://ssrn.com/sol3/papers.cfm?abstract_id=4365029,

Placement in some of the tiers is defined by reference to monthly active users of the service, which explicitly extends beyond registered users to recipients who have “engaged” with an online platform “by either requesting the online platform to host information or being exposed to information hosted by the online platform and disseminated through its online interface.” Art. 3(p). While Recital 77 clarifies that multi-device use by the same person should not count as multiple users, that leaves many other measurement questions unsettled, and Husovec concludes that “The use of proxies (e.g., the average number of devices per person) to calculate the final number of unique users is thus unavoidable. Whatever the final number, it always remains to be only a better or worse approximation of the real user base.” And yet, as he writes, “Article 24(2) demands a number.” This obligation applies to every service because it determines which bucket, including the small and micro enterprise bucket, a service falls into.

This demand is itself based on assumptions about how online services monitor their users that are simply not uniformly true, especially in the nonprofit or public interest sector. It seems evident—though not specified by the law—that a polity that passed the GDPR would not want services to engage in tracking just to comply with the requirement to generate a number. As DuckDuckGo pointed out, by design, it doesn’t “track users, create unique cookies, or have the ability to create a search or browsing history for any individual.” So, to approximate compliance, it used survey data to generate the average number of searches conducted by users—despite basic underlying uncertainties about whether surveys could ever be representative of a service of this type—and applied it to an estimate of the total number of searches conducted from the EU. This doesn’t seem like a bad guess, but it’s a pretty significant amount of guessing.

Likewise, Wikipedia assumed that the average EU visitor used more than one device, but estimated devices per person based on global values for 2018, rather than for 2023 or for Europe specifically. Perhaps one reason Wikipedia overestimated was because it was obviously going to be regulated no matter what, so the benefits of reporting big numbers outweighed the costs of doing so, as well as the stated reason that there was “uncertainty regarding the impact of Internet-connected devices that cannot be used with our projects (e.g. some IoT devices), or device sharing (e.g. within households or libraries).” But it reserved the right to use different, less conservative assumptions in the future. In addition, Wikipedia also noted uncertainty about what qualified as a “service” or “platform” with respect to what it did—is English Wikipedia a different service or platform for DSA purposes than Spanish Wikipedia? That question obviously has profound implications for some services. And Wikipedia likewise reserved the right to argue that the services should be treated separately, though it’s still not clear whether that would make a difference if none of Wikipedia’s projects qualify as micro or small enterprises.

The nonprofit I work with, the Organization for Transformative Works (“OTW”) was established in 2007 to protect and defend fans and fanworks from commercial exploitation and legal challenge. Our members make and share works commenting on and transforming existing works, adding new meaning and insights—from reworking a film from the perspective of the “villain,” to using storytelling to explore racial dynamics in media, to retelling the story as if a woman, instead of a man, were the hero. The OTW’s nonprofit, volunteer-operated website hosting transformative, noncommercial works, the Archive of Our Own, as of late 2022 had over 4.7 million registered users, hosted over 9.3 million unique works, and received approximately two billion page views per month—on a budget of well under a million dollars. Like DuckDuckGo, we don’t collect anything like the kind of information that the DSA assumes we have at hand, even for registered users (which, again, are not the appropriate group for counting users for DSA purposes). The DSA is written with the assumption that platforms will be extensively tracking users; if that isn’t true, because a service isn’t trying to monetize them or incentivize them to stay on the site, it’s not clear what regulatory purpose is served by imposing many DSA obligations on that site. The dynamics that led to the bad behavior targeted by the DSA can generally be traced to the profit motive and to particular choices about how to monetize engagement. Although DuckDuckGo does try to make money, it doesn’t do so in the kinds of ways that make platforms seem different from ordinary publishers. Likewises, as a nonprofit, the Archive of Our Own doesn’t try to make itself sticky for users or advertisers even though it has registered accounts.

Our tracking can tell us how many page views or requests we're getting a minute and how many of our page views come from which browsers, since those things can affect site performance. We can also get information on which sorts of pages or areas of the code see the most use, which we can use to figure out where to put our energy when optimizing the code/fixing bugs. But we can’t match that up to internal information about user behavior. We don’t even track when a logged in account is using the site—we just record the date of every initial login, and even if we could track average logins per month, a login can cover many, many visits across months. The users who talk to us regularly say they use the site multiple times a day; we could divide the number of visits from the EU by some number in order to gesture at a number of monthly average users, but that number is only a rough estimate of the proper order of magnitude. Our struggles are perhaps extreme but they are clearly not unique in platform metrics, even though counting average users must have sounded simple to policymakers. Perhaps the drafters didn’t worry too much because they wanted to impose heavy obligations on almost everyone, but it seems odd to have important regulatory classes without a reliable way to tell who’s in which one.

These challenges in even initially sorting platforms into DSA categories illustrates why regulation often generates more regulation—Husovec suggests that, “[g]oing forward, the companies should publish actual numbers, not just statements of being above or below the 45 million user threshold, and also their actual methodology.” But even that, as Wikipedia and DuckDuckGo’s experiences show, would not necessarily be very illuminating. And the key question would remain: why is this important? What are we afraid of DuckDuckGo doing and is it even capable of doing those things if it doesn’t collect this information? Imaginary metrics lead to imaginary results—Husovec objects to porn sites saying they have low MAUs, but if you choose a metric that doesn’t have an actual definition it’s unsurprising that the results are manipulable.

My second example of one size fits some design draws on the work of LLM student Philip Schreurs in his paper, Differentiating Due Process In Content Moderation: Along with requiring hosting services to accompany each content moderation action affecting individual recipients of the service with statements of reasons (Art. 17), platforms that aren’t micro or small enterprises have due process obligations, not just for account suspension or removal, but for acts that demonetize or downgrade any specific piece of content.

Article 20 DSA requires online platform service providers to provide recipients of their services with access to an effective internal complaint-handling system; although there’s no notification requirement before acting against high-volume commercial spam, even for high-volume commercial spam, platforms have to provide redress systems. Platforms’ decisions on complaints can’t be based solely on automated means.

Article 21 DSA allows users affected by a platform decision to select any certified out-of-court dispute settlement body to resolve disputes relating to those decisions. Platforms must bear all the fees charged by the out-of-court dispute settlement body if the latter decides the dispute in favor of the user, while the user does not have to reimburse any of the platforms’ fees or expenses if they lose, unless the user manifestly acted in bad faith. Nor are there other constraints on bad-faith notification, since Article 23 prescribes a specific method to address the problem of repeat offenders who submit manifestly unfounded notices: a temporary suspension after a prior warning explaining the reasons for the suspension.  The platform must provide the notifier with the possibilities for redress identified in the DSA. Although platforms may “establish stricter measures in case of manifestly illegal content related to serious crimes,” they still have to provide these procedural rights.

This means that due process requirements are the same for removing a one-word comment as for removing a 1 hour video: for removing a politician’s entire account and for downranking a single post by a private figure that uses a slur. Schreurs suggests that the process due should instead be more flexible, depending on the user, violation, remedy, and type of platform.

The existing inflexibility is a problem because every anti abuse measure is also a mechanism of abuse. There seem already to be significant demographic differences in who appeals a moderation decision, and this opens up the possibility of use of the system to harass other users and burden platforms, discouraging them from moderating lawful but awful content, by filing notices and appealing the denial of notices despite the supposed limits on bad faith. Even with legitimate complaints about removals, there will be variances in who feels entitled to contest the decision and who can afford to pay the initial fee and wait to be reimbursed. That will not be universally or equitably available. The system can easily be weaponized by online misogynists who already coordinate attempts to get content from sex-positive feminists removed or demonetized. We’ve already seen someone willing to spend $44 billion to get the moderation he wants, and although that’s an outlier there is a spectrum of willingness to use procedural mechanisms including to harass.

One result is that providers’ incentives may well be to cut back on moderation of lawful but awful content, the expenses of which can be avoided by not prohibiting it in the terms of service or not identifying violations, in favor of putatively illegal content. But forcing providers to focus on decisions about, for example, what claims about politicians are false and which are merely rhetorical political speech may prove unsatisfactory; the difficulty of those decisions suggests that increased focus may not help without a full-on judicial apparatus.

Relatedly, the expansiveness of DSA remedies may water down their realistic availability in practice—reviewers or dispute resolution providers may sit in front of computers all day, technically giving human review to automated violation detection but in practice just agreeing that the computer found what it found, thus allowing the human to complete thousands of reviews per day as Propublica has found with respect to human doctor review of insurance denials at certain US insurance companies.

And, of course, the usual anticompetitive problems of mandating one size fits all due process are present: full due process for every moderation decision benefits larger companies and hinders new market entrants. Such a system may also encourage designs that steer users away from complaining, like BeReal’s intense focus on selfies or Tiktok’s continuous flow system that emphasizes showing users more like what they’ve already seen and liked—if someone is reporting large amounts of content, perhaps they should just not be shown that kind of content any more. The existing provisions for excluding services that are only ancillary to some other kind of product—like comments sections on newspaper sites, for example—are partial at best, since it will often be unclear what regulators will consider to be merely ancillary. And the exclusion for ancillary services enhances, rather than limits, the problem of design incentives: it will be much easier to launch a new Netflix competitor than a new Facebook competitor as a result.

© specific rules are not unique: subject to same problem of legislating for YouTube as if YouTube were the internet. Assumes that all OSSCPs are subject to same risks. But Ravelry—a site focused on the fiber arts—is not YouTube. Cost benefit analysis is very different for a site that is for uploading patterns and pictures of knitting projects than for a site that is not subject-specific. Negotiating with photographers for licensing is very different than negotiating with the music labels, but the framework assumes that the licensing bodies will be functioning pretty much the same no matter what type of work is involved. Sites like the Archive of Our Own receive very few valid © claims per works uploaded, per time period, per any metric you want to consider, and so the relative burden of requiring YouTube-like licensing is both higher and less justified. My understanding is that the framework may be flexible enough to allow a service to decide that it doesn’t have enough of a problem with a particular kind of content to require licensing negotiations, but only if the authorities agree that the service is a “good guy.” And it’s worth noting, since both Ravelry and the Archive of Our Own are heavily used by women and nonbinary people, that the concept of a “good guy” is likely both gendered and racially coded, which makes me worry about its application.

Suggestion: Proportionality is much harder to achieve than just saying “we are regulating more than Google, and we will make special provisions for startups.” To an American like me, the claim that the DSA has lots of checks and balances seems in tension with the claim yesterday that the DSA looks for good guys and bad guys—a system that works only if you have very high trust that the definitions of same will be shared.

Regulators who are concerned with targeting specific behaviors, rather than just decreasing the number of online services, should make extensive use of test suites. Daphne Keller of Stanford and Mike Masnick of Techdirt proposed this two years ago. Because regulators write with the giant names they know in mind, they tend to assume that all services have those same features and problems—they just add TikTok to their consideration set along with Google and Facebook. But Ravelry has very different problems than Facebook or even Reddit. Wikipedia was big enough to make it into the DSA discussions, but the other platforms burdened most because they haven’t built the automated systems that the DSA essentially requires are now required to do things that Facebook and Google weren’t able to do until they were much, much bigger.

A few examples of services that many people use but not in the same way they use Facebook or Google, whose design wasn’t obviously considered: Zoom, Shopify, Patreon, Reddit, Yelp, Substack, Stack Overflow, Bumble, Ravelry, Bandcamp, LibraryThing, Archive of Our Own, Etsy.

The more complex the regulation, the more regulatory interactions need to be managed. Thinking about fifty or so different models, and considering how and indeed whether they should be part of this regulatory system, could have substantially improved the DSA. Not all process should be the same just like not all websites should be the same, unless we want our only options to be Meta and YouTube.

Q: Another factor: how do we define harm and who defines it—that’s a key that’s being left out. Someone stealing formula from Walgreens is harmful but wage theft isn’t perceived as the same harm.

Grimmelmann: Agree entirely. Model takes as a given that regulator has a definition of harm, and that’s actually hugely significant and contested. Distribution of harms is also very important—who realizes harm and under what conditions.

Q: Monetization on YT: for 6-7 years, there’s been monetization during dispute. If rightsholder claim seems wrong to user, content stays monetized until dispute is resolved. We might still be concerned over claims that should never have been made in the first place. YT has a policy about manual claims made in Content ID. Automatic matching doesn’t make de minimis claims; YT changed policy for manual claims so they had to designate start and stop of content experience and that designation had to be at least 10 seconds long. A rightsholder who believes that 9 seconds is too much can submit a takedown, but not monetize. Uploaders that sing cover songs have long been able to share revenue w/© owners.

Quintais: the paper goes into more detail, but it’s not clear that these policies are ok under new EU law. [Pastiche/parody is the obvious problem since it tends to last more than 10 seconds.] Skeptical about the monetization claims from YT; YT says there are almost no counterclaims. If the system can’t recognize contextual uses, which are the ones that are required by law to be carried/monetized by the uploader? A lot of monetization claims are allegedly incorrect and not contested. Main incentive of YT is pressure from rightsholders w/access to the system further facilitated by Art. 17.

Q: platforms do have incentives to care about fundamental rights of users. We wouldn’t need a team at YT to evaluate claims if we just took stuff down every time there was a claim. [You also wouldn’t have a service—your incentives are to keep some stuff up, to be sure, but user demand creates a gap as Grimmelmann’s paper suggests.]

Quintais: don’t fundamentally disagree, but Art. 17 leaves you in a difficult position.

Hughes to Grimmelmann: Why assume that when harm goes up, societal benefit goes down? Maybe as harm to individual goes up so does societal benefit (e.g. nude pictures of celebrities).

A: disagrees w/example, but could profitably put a consideration of that in model.

27th Annual BTLJ-BCLT Symposium: From the DMCA to the DSA—A Transatlantic Dialogue on Online Platform Liability and Copyright Law

Tutorial “The EU Digital Services Act – Overview and Central Features”

General DSA Architecture and Approach     

Martin Senftleben, University of Amsterdam

Formally, the safe harbor system is still in place for mere conduit, caching and hosting services for third-party information they transmit and store. For ©, voluntary own initiative investigations done in good faith shouldn’t lead to more liability. More intermediary services are covered under DSA. Points of contact for authorities/legal representatives are existing obligations but new are terms of service/content moderation policies and tools disclosure requirements, including algorithmic decision-making and human review, as well as rules of procedure of internal complaint handling. How much information must be disclosed? Must be balanced against trade secrets. Another new obligation: diligent, objective and proportionate application to safeguard fundamental rights. Obligation is on the service provider.

Transparency: reports on content moderation, including judicial orders, notices, number and type of content moderation, use of automated means and related training, and number of complaints.

Special rules for hosting providers, including online platforms; online platforms, including distance contracts, and very large online platforms and very large online search engines.

What about the copyright interface w/ the DSA? Art. 2(4): this is all w/o prejudice to rules laiid down by the © laws. So on top of all those distinctions, there are OCSSP obligations from Art. 17: online content sharing services. So where the © regime is silent, use the DSA. And there’s where the safe harbors have been gotten rid of: using the Art. 17 rules of required licensing—there’s direct liability if you’re unlicensed, but you can decrease the risks by using filtering to police the borders of your licensing deals.

OCSSPs are a controversial category in itself. YouTube is an OCSSP, but other than that much is unclear—are all different types of social media OCSSPs? We don’t have definite caselaw.

DSA requires VLOPs and VLOSES to have reasonable, proportionate and effective mitigation measures tailored to specific systematic risks w/particular consideration to the impacts on fundamental rights. Art. 17 is more specific and thus a further addition to DSA requirements.

“Sufficiently substantiated notice from the rightsholders” and rightsholders should “duly justify the reasons” for their requests—opening for more specific requirements like Art. 16 of DSA which say that notices have to be sufficiently precise/adequately substantiated; so to statements of reasons must be “clear and specific.”

DSA Art. 23: suspend, for reasonable period of time, and after warning, users who have violated rules; so too processing of notices and complaints by complainants that frequently submit notices or complaints that are manifestly unfounded—not present in © framework so additive to it. Also Art. 22 requirement to ensure that notices submitted by trusted flaggers w/in their designated area of expertise, should be processed w/o undue delay. Must comply w/quality standards—status awarded by Digital Services Coordinator of Member State if flagger has particular expertise of detecting/notifying illegal content; is independent of any provider of online platforms (but does not need to be independent of © rightsholders); and carries out its activities diligently, accurately and objectively.

DSA also requires VLOPs and VLOSEs to get annual independent audit opinions, reporting to Commission, potential for fines, so they can’t just wait for court cases to identify whether they’re doing it right.

Fred von Lohmann: For enforcement: other than the intervention of the Commission through the audit process—how will enforcement be done? Private rights of action?

A: DSA enforcement is very much by the Commission itself in his understanding. Drafter of DSA, Irene Roche-Laguna: it depends on the kind of platform—hosting service, platform, or VLOP. EC has exclusive powers for enforcement of obligations that apply only to VLOPs/VLOSEs—auditing/risk assessment. But content moderation requirements for platforms in general are for country of establishment (if in Europe) and where the legal representative is (if not). If a platform neglects notices it becomes a systemic issue; the Commission can jump in. [I wasn’t sure whether she meant that was true even for non-VLOPs.]

Q: can a recipient of the service receive money damages for violation of these obligations? Is that governed by Member State law?

A: In DSA 54, there is an avenue for private actors to bring damage claims to complement audit-based or other executive activities.

Pam Samuelson: will audits be publicly available?

Roche-Laguna: Audit reports will be published w/transparency reports every 6 months, and audit implementation reports have to be published. They will have a bit of time to respond.

A: given the transparency requirements, the audit report should be able to provide more insights, but we don’t know for sure yet.

Q: what makes an online platform?

A: central aspect is dissemination of information. [Husovec’s piece says Blogger and Wordpress aren’t platforms, which seems bizarre to me.] What is a public? It may not have to be a large public. In © we accept that dissemination to a circle like 12 or 50 people can already be a public, so would that also apply under the DSA? The Court of Justice could set a relatively low threshold.

Roche-Laguna: there is a gray area. A hosting service that disseminates to the public as ancillary feature, like a comments section on a website, that wouldn’t be a platform. But we have questions about messenger services with open chats/groups—100,000 people in chat. Or music service that has licensed content and user-uploaded content: what is the platform part? [That doesn’t seem to answer questions like, is email dissemination to the public?]

Q: do platform rules have to be observed for the ancillary service? It’s a lawyer’s paradise. [Roche-Laguna is laughing but I’m not finding it funny that they actually can’t seem to answer those questions.]

Rules for Hosting Providers, Online Platforms and Very Large Online Platforms  

Martin Husovec, London School of Economics

DSA is about content moderation, construed very broadly. Not just removal of content as w/© infringement but decisions about violations that aren’t based on legality but are purely contractual—FB and breastfeeding images; suspending individual users. Also about institutions lower in the stack like app stores. Hiding/demonetizing content is also covered. DSA covers almost everyone, though advertising providers and payment providers are touched only tangentially. Infrastructure providers like access providers, transit services, DNS/VPN services, domain registrars and registers, generally have very few obligations other than transparency. But distribution and content layer have more obligations.

Part of the second generation that replaced the first generation like section 230 designed to create breathing space for speech and industries; focus on is regulation of risks posed by services.

For content moderation: fairness in design ex ante, due process in implementation, transparency, and risk management. Due process constrains the moderation of both illegal content and contractual breaches. Risk management for very large players: required to think about product design and operations; w/some risk management obligations for smaller platforms.

Online platforms are covered if 50+ employees/EU turnover of 10 million euros. VLOPs/VLOSEs: Alphabet, Microsoft, Meta, Bytedance, Snap, Pinterest, Twitter, Amazon, Wikipedia as the only nonprofit.

Decide what rules are; open to notification from third parties about content that might be illegal or violate terms & conditions; make decisions (hosting services and any-size companies); allow appeals/internal contestation (midsize and above); allow external contestation by users (VLOP/VLOSE); transparency. Any content restrictions has to be codified in terms and conditions, and decisions must be made on the basis of the rules. But the rules must be diligent, objective and proportionate, including in their design according to the recitals. What does it mean for design of rules? His take: only extreme outlier policies would have an issue.

Core of DSA: tries to discipline providers in how they make decisions. They must issue a statement of reasons, including for visibility, monetization, etc. Specific explanation of reasons required, useful enough to allow user to argue against them. They can be automated, but DSA says you need to provide a free opportunity to appeal where a human has to be present in some step of the process. Internal appeal must be easy to access and user-friendly; not solely automated; must occur in timely, diligent, and objective manner.

Who can complain or appeal? External players: trusted flagger, regular notifier, content creator, NGOs.

Possibility of external dispute resolution/ADR: Regulators certify entities independent of platforms and users; FB’s Oversight Board is not independent. Content creators and notifiers and reps can use the option. ADR provider is complainants’ choice; no need to exhaust appeals. ADR decisions are nonbinding; platforms must engage in good faith. Plaintiff compensates complainants who win (fees and possibly costs). Complainants that lose pay their own fees and costs. Trying to improve quality of decisionmaking within company.

The proceduralist approach constrains implementation more than rule formulation. Consider: for 5 EUR a month, you can say whatever you want on the service as long as it’s legal in your country—disinformation, nudity, etc. all ok. Everyone else is moderated on ToS violations and illegality. Is this a violation of art. 14(1)? No if disclosed. Art. 14(4): probably no—paying 5 EUR to be unmoderated doesn’t seem disproportionate. What if you have a list of VIPs whose content is not moderated at all b/c they are leaders of countries? Again, 14(1) is ok if properly described. But 14(4) would be a problem in his view due to the impact of illegal content.

Open issues: big guys can easily automate statement of reasons; what about small providers? Licensed content moderation solutions from third parties? What about users of services, like newspaper’s FB page—are they considered to be a separate entity for purposes of people whose content they moderate? How will there be standard transparency database if different people are sending their reports in nonstandard format and with anonymization?

Risk management for VLOPs/VLOSEs will likely not be subject to private enforcement—mostly extended or intensified reporting obligations; researcher data access; unique obligations for profiling-free choice on recommender systems (whether organic or advertising), or advertising archives. Subject to regulatory dialogue w/whole community, including national regulator, NGOs, researchers, where main thing is to figure out what companies are doing w/r/t certain types of risks on their platforms. Dialogue b/c of opacity of system and info asymmetry: regulators can’t instruct on what to do w/out knowing what’s going on. Must assess systemic risks stemming from design or functioning of services including algorithms and use made of their services, as well as back end governance, taking into account the risks’ severity and probability. Risks include: illegal content; fundamental rights; public security and elections; health and well-being (including gender-based violence, public health, minors, physical well-being, and mental well-being). Nothing of concern to civil society is left out. If a social network adopts ChatGPT into design, that becomes regulated along with anything else the platform uses.

Metaphor: authorities can partly restrict how and when protest activities take place (streets, hours, use of amplification tools) and take measures to prevent harm to protestors or others (e.g. by boosting police presence) but can’t select speakers or dictate content.

Q: why is business to business included here? Why can’t Amazon say “one strike and you’re out” to a business?

A: b/c the design was about risks of hosting services, not just harms to individuals or individuals as consumers. Advertising marketplaces are available to the public.

Q: what about risk mitigation for humans conducting content moderation/labor harms?

A: sure.          

Interplay with OCSSP Rules in the Directive on Copyright in the Digital Single Market

João Quintais, University of Amsterdam

Background of lots of attempts to interpret previous rules under InfoSoc Directive. Primary liability is harmonized. But secondary liability was mostly unharmonized; ended up with mostly a notice and takedown regime. Court of Justice expanded right of communication to the public to the point where there was a Q of whether YT’s own services triggered direct liability. Poster child was YouTube/claims of “value gap” (sigh).

Six states haven’t met the implementation deadline; still waiting to figure out what the rules actually should be. Poland decision: CJEU said Art. 17 was ok but had to give due regard to uploaders’ interests. OCSSPs cover UGC platforms with large amounts of works that organize and promote them and have a commercial/competitive effect. Exclusions: encyclopedias, ecommerce, B2B/cloud hosting: Wikipedia and GitHub/ArXiv.org, Skype, Dropbox, and eBay are excluded—partly down to who had good lobbyists. But you are still covered by InfoSoc directive plus DSA. Startup provisions: under 3 years and 10 million Euros, only notice & takedown, but if above 5 million visitors also notice and staydown. Not much there. Could be excluded from DSA but covered by Art. 17.

A bipolar copyright system/an employment program for EU lawyers. You might have to look service by service to figure out whether you are an OCSSP. Etsy? Wordpress?

Non-OCSSP: default no direct liability/hosting safe harbor and moderated duties of care, based on YT case and national law. OCSSP: default is direct liability w/exemptions tied to best efforts licensing and filtering.

Most online platforms for DSA will be OCSSPs so you have to figure out what applies—DSA may cover things only partially, and it’s not very clear/depends on your normative preferences. Bonanza for lawyers! If you’re a non-OCSSP, DSA will probably apply to almost everything.

Von Lohmann: Secondary liability seems to have disappeared. It’s not just OCSSP/non-OCSSP—there’s no harmonization for secondary liability, and safe harbors are interpreted as not precluding injunctive relief in most jurisdictions—so don’t you also have an entire category of secondary liability injunctions that are outside of both of these regimes or they displaced by DSA/Art. 17?

A: you are right, there might be that category. YouTube case is designed for YouTube, but is now covered by Art. 17: need to apply that to other platforms, and how to do so is unclear. German courts are deciding how to modulate duties of care and will continue to do so unless ECJ tells them to stop. In all cases, you assess liability also on the basis of compliance w/duties of care, but DSA duties are different: obligations regarding user-uploaded content are about your role as platform.

Comment by Senftleben: may not be as bad as that—the CJEU has extended primary liability so far that there’s not much room left for platform secondary liability. The crucial question, and an open one, is what can be expected from a reasonably diligent operator in this situation—will this be influenced by the new DSA duties?

A: court will likely look at whether this is a good faith player—will reason backwards to find no liability if so. The “good guy” theory of EU copyright law: court finds a way around liability for a good faith player, and a way for direct liability if there’s not. You can’t really get from the text to the outcomes; the court just makes up a bunch of conditions.

Comment: primary and secondary liability are no longer distinct categories. Now all under the umbrella of primary, but if you can’t get authorization you have to filter, so the duty of care is now embedded in primary liability.

Beyond Copyright Infringement: DSA Review, Moderation and Liability Rules Compared to Previous National Review and Takedown Approaches for Illegal Content

Matthias Leistner, LMU Munich Faculty of Law

Need to know whether national rules are preempted, and they also provide evidence of experience that might be useful for implementing DSA. There were differences in applying and enforcing rules; national authorities might have leeway in applying DSA rules, which might lead to forum shopping about where to have a company seat.

German NetzDG regulates allegedly criminal content on social media (obvious v. non-obvious are treated differently). Austria has a similar law; France’s law was partly invalidated b/c of extremely short blocking periods for certain content, but it also has a law against fake news in 3 months before a national election; Italy has a law against “cybermobbing” and dealing with parents/minors; Baltic states have their own.

NetzDG has limited scope: social networks, video sharing platforms v. DSA’s comprehensive/four-tiered approach.

NetzDG: catalogue of substantial/hard-core criminal offenses, continuously extended v. DSA’s all illegal content including minor violations (including consumer protection law), plus special notification duties for criminal acts etc.

NetzDG: persons affected in their rights can notify; DSA: everyone can notify.

NetzDG: expeditious blocking: 7 days or 24 hours in obvious cases; DSA: expeditious/without undue delay.

NetzDG: redress for both sides; another human in the loop; DSA: role of complainant surprisingly unclear, no standing for the other party in the complaint.

NetzDG: No further prioritization b/c of limited scope; DSA: system of trusted flaggers given priority; dynamic adaptation through provisions on misuse and suspension.

NetzDG: limited and crisp; DSA: wide and wobbly.

Provisions on transparency of user contracts are similar to German case law; reasonable and cost-efficient b/c contracts exist anyway. But may not be easy to implement b/c some transparency obligations relate to what the algorithms actually do. [I think this may undersell the difficulty of figuring out what is, for example, abusive or hateful speech, especially for non-dominant communities.] Protection of trade secrets is also a huge issue.

Most probably, NetzDG will be repealed in 2023, but does the DSA entirely preempt Member State laws? Depends on the harmonized subject matter—access for research purposes? Research access for other public policy purposes?

Was there overblocking b/c of NetzDG? No empirical evidence under the procedural mechanism, but a backlash to unjustified blocking under different user policies. Was preventive blocking under user policies/community standards perhaps indirectly due to NetzDG? Avoiding cumbersome statutory mechanism by overcompliance? Hard to assess w/o access for research.

Indirect regulatory effects have probably worked quite well w/o overblocking; proposed self-regulation boards for notice and takedown don’t seem to have worked. Platforms didn’t want to cooperate and platforms have different policies w/regard to user communities.

CJEU has responsibility for hard questions, along with national coordination; resources and coordination are issues and GDPR experience is disheartening though antitrust experience is better.

Q: regulations require clear and understandable rules in terms that are neither clear nor understandable: how are platforms going to establish such rules for billions of pieces of content?

A: it’s not new that the legislator can do things that a private entity can’t. German FB case established certain basic standards for typical user policies that would be easy to comply with. There must be certain reasonable rules on what is allowed and what isn’t. DSA requires examples for rules of what is prohibited and what is not. Pretty much about procedures. [But people will always be able to argue that their slur is closer to the not-prohibited side than the prohibited side, if their slur isn’t in the list of examples. This reassurance might work for legal/illegal but it is not helpful at all for lawful but awful.] It’s about the bad guys with self-contradictory community policies that block without reasonability.

Midsize platforms can game the system by choosing a friendly jurisdiction like Ireland. Carveouts don’t protect enough small providers and will be problems for Baltic startups.

Q: it’s nice to say that Germany doesn’t require too much detail but this is a new regime, and France is going to be different.

A: agree to a certain extent; also important that some standards are new—certainty will take 10 years and that’s not great. But the transparency obligation doesn’t come from a vacuum—consumer protection law/transposing concepts of standard terms to the platforms [where the subject matter of the transaction, the user’s speech, is pretty different!]. While we were discussing DSA, it made sense to object and discuss our concerns, but now we have it, so it’s time to think about ways to make it workable to the extent possible. The only way forward is to implement it.

Daphne Keller: share concerns about private litigation in different member states, lack of harmonization. How many states might be interested in allowing this?

A: We had this problem before, w/27 different standards—how many of them really matter? Here we have to distinguish b/t public and private enforcement. Public enforcement, the Commission will matter/establish standards that might trickle down from VLOPs to smaller platforms. Germany, France, Netherlands, Scandinavian countries will matter.

Keller: DSA is silent on question of what injunctions can say.

A: private enforcement: new provision on damages and injunctions might be possible; would have to look at different states’ laws. Largest dangers are Germany and France national unfair competition laws, where competitors might be able to sue—real problem w/GDPR that we are still grappling with. Practically limited to Germany, France, maybe Austria and some others. So far, Austria legislated specifically that compliance obligations don’t qualify for injunctions, period; caused quite a number of problems in the market.

Free Speech Challenges and Potential Risk Reduction in the DSA

Eleonora Rosati, Stockholm University

Balancing freedom to conduct a business and the need to protect recipients of services through transparency. Enhanced obligations for VLOPs and special provisions for micro/small enterprises. Art. 17 tries to protect users with certain exceptions.

Copyright and free speech: EU Charter of Fundamental Rights is a primary source of EU law, and recognizes IP within right to property; also recognizes free speech. Also recognizes freedom of artistic expression, freedom to conduct a business, respect for private and family life, and protection of personal data—not just integration of markets but integration of morals. Balancing framework, though how the balancing is to be done is the key. Level of protection for © needs to be high—what does that mean? High level of protection for whom and of what? InfoSoc Directive refers to authors, performers, producers, and culture industry alike, as well as consumers and public at large. There are other kinds of rightsholders. ECJ has been clear that high level of protection does not mean highest level of protection; the goal is a fair balance of different interests. Increasingly characterized by a fundamental rights discourse.

Many concerns about free speech from Art. 17, resulting in action by Poland:. Resulting judgment: ECJ didn’t say Poland was wrong that it restricted free speech—free speech is not absolute and can be restricted under certain conditions. ECJ said there were enough safeguards: filtering tools must be capable of adequately distinguishing b/t unlawful and lawful content; users must have rights; rightsholders must provide relevant and necessary information; no general monitoring obligation; procedural safeguards must exist; and there should be stakeholder dialogue and fair balance.

Inconsistent approaches at the national transposition level, so Art. 17 won’t be the stopping point. Also, lex specialis/lex generalis relationship is likely not to be frictionless. CJEU will have to smooth things out.

Comment: if you overblock, all you face is user complaints. If you underblock, you get sued and it’s costly. That’s where the balance is.

A: mostly the remedy for overblocking is to let the thing up; though national law might have some other remedies.

Comment: German law has a sort of must-carry obligation if a user asserts the applicability of an exception. But it’s the minority approach.

A: Italy does the opposite—if there’s a complaint, content must be disabled during the dispute. From platform point of view, you may have to divide treatment of Germany and Italy/geoblock.

Q: is Italy compliant with the Poland CJEU decision?

A: neither Italy nor Germany is—you can’t have a blanket approach. [I don’t understand what that means—I would appreciate hearing what a provider is supposed to do.]

Exceptions and limitations might mean something different in terms of whether they establish user rights—or maybe not! The new data mining provisions are characterized differently from each other, but not clear whether that makes a difference to whether, for example, one is entitled to remuneration and one isn’t.

Comment: if you take auditing seriously, maybe there can be changes/real examination of the practices.

Von Lohmann: but who selects and pays the auditors?

Comment: they’re supposed to be independent!

VL: that’s not the question.

Q: will this get rid of small platforms b/c all rights have to be equally honored?

A: it depends. ECJ is adamant that fair balance depends on circumstances of the case. Some rights might take precedence on a particular platform; not all content is created alike. There might be situations in which certain concerns override other types of rights. France would maybe answer your question in the affirmative, but not all would.

Comment: situating different categorization options under DSA, might see cases that the more you diversify the types of content you host, the more obligations you have.

Q: for US lawyers, we look at the Texas and Florida laws that are clearly politically motivated attempts to suppress content moderation in favor of a political agenda. Hard time understanding how that’s going to be handled in Europe, but the language of nondiscrimination suggests that it can and will happen in Europe too, which also has culture wars [and backsliding democracies].

A: indeed, the concerns around © are also in line with those concerns. The discourse is broader than ©--Afghanistan papers case, where German gov’t attempted to repress publication of military reports about operations of German army in Afghanistan. Used © as a tool. Advocate General and ECJ emphasized that © can’t be used to suppress free speech and one should be careful to limit © to its purposes.

Wednesday, March 22, 2023

Supplement guide was plausibly an agent of supplement company; direct and secondary liability available

Ariix LLC v. Usana Health Sci., Inc., 2023 WL 2574319, No. 2:22-cv-00313-JNP-DAO (D. Utah Mar. 20, 2023)

The parties compete in the supplement market using direct marketing, so compete in both consumer supplement sales and in sales representative recruitment. “Nutritional supplements are largely unregulated, and there have been several recent scandals regarding supplement quality. To empower consumers and sales representatives to make informed decisions, NutriSearch … publishes the NutriSearch Comparative Guide to Nutritional Supplements …, which is the leading source regarding nutritional supplement quality.” It’s written by Lyle MacWilliam and purports to provide independent and unbiased supplement reviews.

Ariix sued NutriSearch and MacWilliam with similar claims to those raised here about Nutrisearch’s alleged lack of independence from and bias towards Usana, resulting in false advertising. Ariix alleged that Usana paid MacWilliam to give Usana’s supplements the top rating in the Guide. As a result, “[t]he misstatements directly reduced Ariix’s revenues by causing both consumers and professionals to select Usana over Ariix.” The Guide, and promotions for it, contained several statements depicting itself as an independent, unbiased source of information, e.g., “This guide was not commissioned by any ... company whose products may be represented herein. The ... findings are the sole creative effort of the author and NutriSearch Corporation, neither of whom is associated with any manufacturer or product represented in this guide.”

Usana has also taken advantage of these neutrality claims. “For example, when Usana receives a new award from the Guide, it contextualizes the award by quoting language from the Guide claiming that it provides independent and objective evaluations. Usana’s website includes pictures of MacWilliam and the Guide next to quotes made by MacWilliam about his confidence in the quality of Usana’s supplements.”

However, plaintiff alleged, “Usana has directly paid NutriSearch and MacWilliam hundreds of thousands of dollars per year in fixed stipends, speaking fees, promotion fees, and promotion costs.” MacWilliam allegedly concocted the Guide as a sales tool while working as a Usana sales representative. Then he informed Usana executives that “I should not be on the board or a representative anymore because it looks like I’m biased. I am going to create more of a third-party appearance, but I’d like you to use me for speaking and support me.” Usana responded, “Yes, if you give us the number-one rating.”

Usana withdrew its support after NutriSearch awarded several other supplement companies, alongside Usana, with a Gold Medal rating in the Guide. This caused a sharp decline in book sales and speaking opportunities; Usana “told him that it preferred being the only company that received the Guide’s highest accolade.” MacWilliam asked “would it help if Usana is number one in some way?” Usana said yes, and MacWilliam added a new “Editor’s Choice” award to the Guide, which was solely bestowed upon Usana; the payments resumed.

The next year, plaintiff alleged,

MacWilliam informed Usana that, as calculated by the Guide’s publicly disclosed criteria, Usana would not receive the Guide’s top ranking. Usana reminded MacWilliam that “we pay you to make us number one.” MacWilliam stated that he would either need to alter the Guide’s ranking algorithm or Usana would need to reformulate its supplements. Usana and MacWilliam then collaborated to ensure that Usana maintained the top position.

Usana allegedly benefited financially from the Guide. It arranged the initial publishing agreement between NutriSearch, MacWilliam, and the publisher. “As a result of arranging the initial publication agreement, Usana receives a portion of the profits derived from the Guide’s sales.” [So it’s literally NutriSearch’s literary agent?]

Usana incorporates the Guide into its marketing training. Sales representatives are told to purchase the guide, “learn it, refer to it in making sales, and ... pitch the guide to end consumers.” Usana characterizes payments to NutriSearch and MacWilliam as marketing expenses. Usana reposts testimonial statements made by MacWilliam on its website and social media pages, and issues press releases announcing the awards it receives from the Guide.

Usana is also allegedly involved in editorial changes to the Guide and “orders” MacWilliam to meet with Usana’s chief product officer every year.

In 2013, Usana increased the Vitamin D and Iodine content in its supplements and rebranded to focus on these additions. The Fifth Edition of the Guide was then “rewritten from cover to cover” to highlight “the most recent and exciting scientific findings on two super-nutrients: Vitamin D and Iodine.” Prior to the Sixth Edition of the Guide, Usana reprinted its supplement labels to emphasize the potency of its products with regards to “cell signaling.” The Sixth Edition noted that the Guide had been “completely rewritten” to account for “groundbreaking discoveries” in cell-signaling. Usana ordered NutriSearch to add a new platinum tier of achievement to the Sixth Edition and Usana was the only company awarded with a platinum level rating in the Sixth Edition.

Usana has also allegedly used its relationship to harm competitors, as when, based on information from Usana,  NutriSearch initially awarded Ariix a three-and-a-half stars rating for a new product, later revised to five stars. “Usana instructed NutriSearch to print a new version of the Guide displaying Ariix Optimal’s three-and-a-half stars rating prior to Ariix’s product launch.” Ariix also had various difficulties obtaining the Guide’s Gold Medal of Achievement; while Usana was grandfathered in using old verification methods, NutriSearch rejected the same type of evidence from Ariix; after Ariix invested significant financial resources working with NutriSearch to develop new testing protocols, NutriSearch again rejected it because it “could no longer confidently assure the consumer that what is on the label is what is in the bottle.” “At the same time that NutriSearch claimed that its concerns regarding testing accuracy precluded it from awarding Ariix a Gold Medal certification, NutriSearch and MacWilliam represented to consumers that they were confident in the Guide’s verification abilities.”

MacWilliam declined Ariix’s offer to speak on behalf of Ariix, saying that he no longer wanted to travel, but he continued to travel and promote Usana. When Ariix confronted him, MacWilliam responded by admitting that Usana would “cut [him] off the second I ... [speak for Ariix.]”

This case is proceeding separately from the case against NutriSearch because of personal jurisdiction issues.

Timeliness: Utah has a three-year statute of limitations for fraud, and Ariix sued NutriSearch nearly five years before suing Usana with very similar allegations. Because the Lanham Act has no limitations period, the court used laches as the framework. To prove the affirmative defense of laches on a motion to dismiss, the complaint must clearly establish that “there has been an unreasonable delay in asserting the claim, and that the defendant was materially prejudiced by the delay.” This complaint didn’t do that.

Usana’s claim of prejudice from “fading memories, lost evidence, and the other difficulties associated with defending against stale claims” was conclusory and there was nothing in the complaint to suggest that Usana has lost relevant evidence. “On the contrary, the complaint alleges that Usana was either in a principal-agent relationship with MacWilliam and NutriSearch or that Usana conspired with them. Under these theories, Usana would have been aware of the ongoing litigation between MacWilliam, NutriSearch, and Ariix.”

As for economic prejudice, a defendant

must demonstrate that it continued to invest in the allegedly challenged behavior to its own detriment, in reliance that plaintiff would not bring a suit. But the mere fact that Ariix alleges damages does not establish that Usana continued to invest in the Guide or otherwise took actions in reliance on Ariix’s delay in filing suit….  Indeed, Usana vehemently denies any suggestion that it invested in or controlled the Guide.

Failure to state a claim: Ariix argued that Usana could be either directly liable for the Guide’s false statements or secondarily liable under a principal-agent theory. The court agreed that the compliant sufficiently alleged both.

Direct: Usana used MacWilliam and NutriSearch’s alleged misrepresentations in its own marketing. Usana argued that it couldn’t be liable for false statements made by third parties. But the cited cases all protected retailers, including digital retailers, who sold allegedly falsely labeled products: “[A] retailer is not liable if the retailer played no role in making the products or in formulating or disseminating the alleged false statements ....” This rule creates “a limited exception to liability when the defendant is a retailer who had no knowledge or role in the third party’s misrepresentation.” [I’ve never found this particularly convincing, and the knowledge part is particularly unjustified, but ok.]

Usana didn’t qualify for a retailer exception. “MacWilliam and NutriSearch’s misrepresentations directly promote Usana’s supplements and Usana did not inadvertently display third-party products with misleading labels.” As courts have held, quoting someone else counts for 43(a)(1)(B) purposes: “[T]o fall within the text of the Lanham Act, a defendant does not need to make a statement but only needs to use a statement or other form of conduct specified in the Act.” And the facts here supported a claim of “use.” The complaint alleged that “Usana was both aware of and encouraged MacWilliam and NutriSearch’s misrepresentations.” [That sounds like contributory liability—I think the liability is direct, without any agency issues, when they quoted MacWilliam and NutriSearch; the court notes facts recited above that go both to Usana’s encouragement and Usana’s own republications of their statements.] “Every time Usana won a medal of achievement, it issued a press release quoting the Guide’s statements that the Guide employed an independent and objective ranking mechanism, despite Usana knowing and actively encouraging the contrary. Although Usana itself did not state that the Guide was independent, Usana directly used MacWilliam and NutriSearch’s misrepresentations to promote Usana’s supplements.” [Knowledge is not an element of direct liability!]

Secondary liability: The complaint plausibly alleged that MacWilliam and NutriSearch were acting as Usana’s agents in making the misrepresentations. At common law, principals are vicariously liable for torts committed by their agents within the scope of the agency relationship. “To establish agency, a party must show (1) the principal manifested its intent that the agent act on its behalf, (2) the agent’s consent to act on the principal’s behalf, and (3) that both the principal and the agent understood that the agent is subject to the principal’s control.”  A plaintiff does not need to show an actual written agreement or plead specific details regarding the terms of the agency agreement. The court rejected Usana’s argument that there was no plausible allegation of an agreement because the complaint does not provide “the terms of performance, when it was entered, or other basic terms.” But the complaint did include the time and (some) terms of the agreement, which was enough. “A principal’s manifestation of assent to an agency relationship may be informal, implicit, and nonspecific.” Five years after the agreement had allegedly been entered into, one of Usana’s executives told MacWilliam that “we pay you to make us number one”; Usana receives a portion of the profits generated from sales of the Guide; Usana encourages its representatives to “get the Guide, learn it, refer to it in making sales, and even pitch the Guide to end consumers”; at Usana’s annual conference, MacWilliam is the only independent speaker who is allowed to sell his own product; Usana displays the Guide on its social media pages and issues press releases quoting the Guide’s claims of independent objectivity when Usana wins an award; Usana characterizes payments to MacWilliam and NutriSearch as marketing expenses. That was (possibly more than) sufficient.

Likewise, telling Usana executives that “I should not be on the board or a representative of the company anymore because it looks like I’m biased. I am going to create more of a third-party appearance, but I’d like you to use me for speaking and support me,” manifested MacWilliam’s consent and objective understanding that he was acting for Usana’s benefit, as did the instances in which he allegedly tried to not be so tilted in Usana’s direction and got financially punished for it, then got rewarded when he reversed course.

As for control, there are multiple nondispositive factors; fundamentally, the court asks whether “both [parties] understood that [the principal] was to be in charge of the undertaking.”  The complaint was sufficient there too, given the allegations above, e.g., that Usana conditioned speaking gigs and book sales on MacWilliam meeting this requirement and had MacWilliam rewrite the Guide to focus on Usana’s marketing priorities.

And it was plausible that the agents had actual authority to make the misrepresentations, including that the Guide was independent and objective.