Joined cases WebGroup (C-188/24) and Coyote (C-190/24): information service providers may lose safe-harbour protection where algorithms exercise control over user information

News type
Legal news
Author(s)

In WebGroup and Coyote, the Court of Justice clarified that a hosting provider may lose the benefit of the liability exemption where, beyond mere categorisation or indexing, its algorithms determine, in the provider’s own interest or that of its service, whether, how, under what conditions and in what order of priority user-transmitted information is disseminated.

Facts of the case 

Both cases concerned the compatibility of French national measures with Directive 2000/31/EC (“E-Commerce Directive”). WebGroup addressed whether operators of pornographic websites could be required to implement a technical age-verification system going beyond a mere declaration by users that they are over 18 years old. Coyote dealt with whether providers of geolocation-based driving assistance services may be prohibited from rebroadcasting user-transmitted information concerning certain roadside checks on French territory. Both measures were being disputed before the French Council of State, which referred questions to the Court of Justice for a preliminary ruling on the interpretation of EU law, specifically Directive 2000/31/EC

Findings of the Court of Justice 

  1. The exemption of liability under Article 14 of the E-Commerce Directive

The Court’s judgment addresses several distinct issues. This note, however, focuses on a separate but significant aspect of the judgment: the Court’s clarification of when a hosting provider may be considered to exercise control over user-transmitted information.

This question carries significant weight, as Article 14(1) of the E-Commerce Directive – currently Article 6(1) of the Digital Services Act – exempts hosting providers from liability for stored information where they have no actual knowledge of illegal activity or information and, upon obtaining such knowledge, act expeditiously to remove or disable access to that information. However, for a hosting provider to fall within the scope of Article 14(1), and thus potentially rely on the liability exemption, it must play a neutral role, meaning that it does not play an active role of such a kind as to give it knowledge of, or control over, the information stored.

  1. Who has control when using algorithms 

The Court held that, where a hosting provider uses an algorithm which, in the interest of the operator or its service, determines under what conditions, how and in what order of priority user-transmitted information is or is not disseminated, that provider may be regarded as exercising control over that information. 

The Court clarified that the conditions of knowledge and control are alternative and independent of each other: a provider that exercises control over stored information through algorithmic processing is therefore excluded from the benefit of the exemption even if, owing to the automated nature of that processing, it never becomes personally aware of the information concerned.

The judgment does not imply that every use of algorithmic ranking or recommendation mechanisms deprives a provider of the hosting exemption. Rather, the decisive question is whether the algorithm effectively determines the dissemination of information in the provider's own interest or that of its service, going beyond mere categorisation or indexing.

Such a situation must be distinguished from one in which the hosting provider uses an algorithm solely for the categorisation and indexing of user-transmitted information, with a view to improving its accessibility. In such a case, the hosting provider is not considered to exercise control, and could, if the other requirements were equally satisfied, benefit from the exemption of liability. 

In the present case, the algorithm put in place by Coyote was used to aggregate users’ reports of roadside checks, filter out reports whose reliability had not been confirmed and generate traffic information that was then rebroadcast to other users. Advocate General Szpunar considered that the algorithm did not merely relay user information, but generated a new corpus of information. The Court itself did not rule on whether Coyote’s algorithm in fact constituted control within the meaning of Article 14(1); that assessment was left to the referring court.

Final remarks 

This ruling is significant because it clarifies the potential liability of hosting providers in a digital environment increasingly shaped by algorithms. 

Since the exemption from liability provided for in Article 14(1) of the E-Commerce Directive is now reflected in Article 6(1) of the Digital Services Act, the judgment also has implications for the application of the DSA. 

In practical terms, information society service providers, regardless of the scale at which they operate, may find it more difficult to argue that they merely store user-transmitted information and are therefore shielded from liability, where their algorithmic systems actively determine the conditions, manner or priority of disseminationThe use of algorithms or artificial intelligence does not, in itself, preclude a finding that the provider exercises control over the information concerned.

Practice areas