In this week’s roundup of the latest news in online speech, content moderation and internet regulation, Ben is joined by Cori Crider, executive director of the Future of Technology Institute, an independent non-profit focusing on technology that serves the public. She previously co-founded legal non-profit Foxglove and led national security litigation at human rights organisation, Reprieve. Together, Ben and Cori discuss:
Legal systems have always struggled to keep up with rapid technological change, and things are no different in the world of generative AI. There are still relatively few rulings on the new issues that the roll-out of AI-based services is raising. That makes a ground-breaking judgment from a court in Germany particularly important. It concerns the AI Overview that sits at the top of the Google’s search results. The Decoder summarizes the court’s ruling:
The Regional Court of Munich hit Google with a temporary injunction barring the company from spreading false claims about two Munich-based publishers through its AI-generated search overviews (case no. 26 O 869/26). The court classified Google as a direct infringer because the “AI overview” is its own content, not just a list of search results.
Google’s AI overviews had falsely tied two publishing companies to scams, subscription traps, and shady business practices for certain search queries. According to the court, the AI mixed up information about other, genuinely sketchy companies with the plaintiffs and drew connections that didn’t appear in any of the linked sources. The publishers sent Google a cease-and-desist letter, but Google didn’t respond appropriately.
The legal innovation here is that the local German court held Google liable for the content of its AI Overview. Unlike traditional search results, which simply point to external sources of information, Google’s AI Overview made statements that were original, the court said:
Google’s AI overviews work nothing like traditional search results, the court argues. The AI rewrites and judges results “in its own words and according to its own structure,” the ruling says. In the case at hand, for example, it opened with confident claims like “Yes, [company] is known for dubious business practices,” then built its own structure with a summary, red flags for the alleged scam, and tips for users.
The court also found that the AI overview made claims “that are not even made in the search results.” None of the linked sources drew any connection between the plaintiffs and the shady companies the AI mentioned. The court called these “the defendant’s own statements.”
Google argued that people using its search engine could check the results, but the court dismissed the idea that this was the responsibility of the users. Leaving aside the fact that research from the Pew Research Center last year found that “Google users are less likely to click on links when an AI summary appears in the results,” there is also the difficulty of checking statements that have been made up (as in this case), which therefore come with no reference links. The court also dealt with the issue of free speech protection for AI-generated content:
An AI’s opinion is “not the expression of an acquired conviction of the persons expressing it, but the result of an algorithm,” the court wrote.
Offering AI-powered research is “above all an expression of Google’s business activities” and “at most a secondary expression of an interest in being able to freely express one’s opinion and beliefs.”
In a statement given to The Decoder, Google said “We invest deeply in the quality of AI Overviews to ensure that the overwhelming majority of responses provide accurate information, and they are designed to reflect the information that exists on the web.”
Since there is no way to ensure that AI responses are 100% correct, this judgment is a big problem for Google, not least because the company plans to place AI Overviews at the heart of its new AI-saturated search engine, as Techdirt reported recently. Not surprisingly, Google has announced that it will appeal against the ruling, which comes from a local German court. If a higher court upholds the judgment, one solution would be for Google to remove AI Overviews in Germany. That would be messy, but doable. But it’s not clear how other AI companies such as chatbots could do the same, since the AI-generated response generally forms the basis of the whole service. Some might choose to discontinue their operations completely in any jurisdiction that adopts a similar position to the Munich court. That would make the roll-out of international services more difficult.
In a post on his blog, the security guru Bruce Schneier points out that if the ruling stands and is adopted elsewhere, it could have important implications not just for things like Google’s AI Overviews and chatbots, but also for the increasingly popular AI agents:
More generally, liability concerns could mean that many current use cases for agents won’t be commercially viable. Companies may not be able to profitably operate AI lawyers, doctors and media influencers if they are held responsible for what they say and do.
Schneier says that he is “OK with this outcome”:
There’s nothing in the law that requires us to accommodate AI systems if they are fundamentally untrustworthy, just as we don’t need to accommodate untrustworthy human systems. Any company that won’t stand by the statements its agents make—whether human or AI—doesn’t deserve users’ time or money.
Clearly this question of AI and agentic liability requires urgent legal clarification. The German decision should at least help to concentrate people’s minds on the topic.
Just days after we wrote about the EU’s renewed push for chat control, Germany has delivered a very important “no” vote. During discussions with EU countries last Wednesday, Germany’s opposition was decisive enough to kill the proposal’s momentum and remove it from this week’s agenda for EU justice ministers.
But it wasn’t just a procedural objection—Germany’s Justice Minister Stefanie Hubig delivered a statement that drew a very clear and very important line regarding encryption:
“Private communication must never be under general suspicion,” she said, adding that “the state must also not force messengers to scan messages en-masse for suspicious content before sending them.”
This is exactly the kind of clear-eyed recognition of fundamental rights that’s been missing from much of the chat control debate. Hubig didn’t mince words about the broader principle at stake, calling chat control something that “must be a taboo in a state governed by the rule of law.”
The proposal that Germany torpedoed would have required messaging services like WhatsApp, Telegram, and Signal to scan messages and check for images, videos, and URLs that might contain child abuse content—including scanning through end-to-end encrypted communications.
Basically: government mandated spyware. You can understand why a country like Germany, with its history, might be quick to push back on such a thing.
The Netherlands joined Germany in opposition, so it wasn’t just Germany standing up on its own:
The Dutch government said in a letter to parliament late September that the current proposal failed to address its concerns about the protection of fundamental rights at stake, “particularly in the areas of privacy and the confidentiality of correspondence and telecommunications, and the security of the digital domain.”
What’s encouraging here isn’t just that the proposal failed—it’s how it failed. Rather than getting bogged down in technical debates about implementation details or carved-out exceptions, Germany and other opponents focused on the core principle: mass surveillance of private communications is incompatible with fundamental rights, full stop.
This stands in sharp contrast to the usual policy dance where politicians try to thread impossible needles, claiming they can somehow protect both privacy and enable mass scanning. Germany’s position recognizes what anyone with any knowledge of how encryption works has been saying for years: you can’t have secure communications and government backdoors at the same time.
Hopefully, that means countries will continue to take a hard line against chat control and other similar proposals that attack encryption.
The proposal isn’t dead—Denmark could put forward a revised version, and supporters like Bulgaria, France, Hungary and Ireland haven’t given up (it’s kind of amazing how bad France tends to be on this stuff). But Germany’s principled stance, backed actually understanding what this would mean for privacy, makes it much harder for chat control advocates to claim they’re just fine-tuning the details.
Germany’s opposition sends a clear message: some lines shouldn’t be crossed, even with good intentions. Here’s hoping other EU countries are paying attention.
It’s no secret that most publishers (though not us!) hate ad blockers. The idea that ad blockers are illegal or “an attack on free speech” get trotted out every so often, and they’re always silly. You should have control over how your own browser on your own computer works. That’s an important freedom. And that means you should be able to install apps that protect you from potentially malicious content. Or from anything at all. It’s your computer. It’s your browser.
But publishers will bend over backwards to argue otherwise. And for years they’ve been doing so in Germany especially, relying on that country’s truly ridiculous copyright laws. Germany’s Axel Springer, one of the largest media orgs in Germany, has been on the warpath against ad blocking going back at least a decade. They and others kept taking ad blockers to court. And losing. Over and over again. But the German legal system never seems to come out with final precedential rulings, so past wins—even those at the Supreme Court—never quite seem final.
Back in 2022, we thought maybe the issue was finally over, with yet another German court saying that ad blocking does not infringe on copyright.
But apparently claiming that ad blocking infringes on copyright in Germany is a kind of legal zombie that never, ever dies. It just comes back again, once again trying to take a big bite out of the basic concepts of the open internet.
Last month, Germany’s Federal Supreme Court (the BGH) decided to partially overturn a lower court’s sensible ruling and reopen this can of worms. The court is now asking whether modifying a website’s Document Object Model (DOM) or Cascading Style Sheets—which is exactly what ad blockers and countless other browser extensions do—constitutes copyright infringement.
Let’s be crystal clear about what this means. If this logic holds, then basically any browser extension that changes how you experience the web could theoretically infringe someone’s copyright. As Mozilla’s Daniel Nazer points out in an excellent blog post breaking down the implications:
Imagine you are watching television and you go to the kitchen for a snack during an ad break. Or you press the fast-forward button to skip some ads while listening to a podcast. Or perhaps you get a newspaper delivered to your house, and you see that it includes a special section made up ofhallucinated AI content, so you drop the inset into the trash before taking the rest of the paper inside. Were these acts of copyright infringement? Of course not. But if you do something like this with a browser extension,a recent decision from the German Federal Supreme Courtsuggests that maybe you did infringe copyright. This misguided logic risks user freedom, privacy, and security.
Think about the absurdity of this for a second. Using your browser’s built-in reader mode? Potentially copyright infringement. Changing the font size because you have vision issues? Maybe infringement too. Installing a dark mode extension because you don’t want to burn your retinas? Better call a lawyer first.
This isn’t just about ad blocking, though that’s obviously the specific target here. As Mozilla notes, there are countless legitimate reasons users might want their browser to modify how a webpage appears:
There are many reasons, in addition to ad blocking, that users might want their browser or a browser extension to alter a webpage. These include changes toimproveaccessibility, toevaluate accessibility, or toprotectprivacy. Indeed, the risks of browsing range from phishing, to malicious code execution, to invasive tracking, to fingerprinting, to more mundane harms like inefficient website elements that waste processing resources. Users should be equipped with browsers and browser extensions that give them both protection and choice in the face of these risks.A browser that inflexibly ran any code served to the user would be an extraordinarily dangerous piece of software.Ad blockers are just one piece of this puzzle, but they are an important way that userscan customize their experienceand lowerrisks to their securityand privacy.
The stakes here are enormous. If German courts decide that users don’t have the right to control how web content displays on their own machines, it would represent a fundamental break from how the web has always worked. It would essentially give publishers veto power over user choice and innovation in browser technology.
And let’s not forget who’s behind this: Axel Springer, the same company that has spent years trying to break the internet through things like the EU’s link tax. This is the same publisher that thinks Google should pay them for the privilege of sending them traffic. Their track record on understanding how the internet works—or should work—is abysmal.
As Mozilla warns, if Germany becomes the second country (after China) to effectively ban ad blockers, it could:
… significantly limit users’ ability to control their online environment and potentially open the door to similar restrictions elsewhere. Such a precedent could embolden legal challenges against other extensions that protect privacy, enhance accessibility, or improve security. Over time, this could deter innovation in these areas, pressure browser vendors to limit extension functionality, and shift the internet away from itsopen, user-driven naturetoward one with reduced flexibility, innovation, and control for users.
The most maddening part? We already know how this plays out. Courts have looked at this question repeatedly and consistently concluded that ad blocking is legal. The court rulings in the past got it exactly right when they noted that HTML files aren’t actually changed by ad blockers—they just affect how browsers process and display that content. As the court ruling in 2022 sensibly observed, “It would also represent a disproportionate encroachment on the user’s freedom of action if it were not up to the user to decide whether and how to execute a legally acquired program.”
But here we are, yet again, apparently because some publishers can’t accept that users have agency over their own computing devices.
The case will continue to drag on, which means we’re in for more rounds of this tiresome debate. But the principle at stake couldn’t be clearer: Users should have the right to control their own browsing experience, and that includes using software that blocks, modifies, or filters content according to their preferences.
If German courts decide otherwise, they won’t just be making a mistake about copyright law—they’ll be helping to break the open web itself.
While politicians from both parties race to dismantle Section 230, we’re missing a crucial part of the story: how this uniquely American law helped US internet companies succeed globally. In the latest episode of Otherwise Objectionable, I explore with legal scholar Anupam Chander what might seem paradoxical — how a domestic liability shield became America’s most successful tech export without a single international treaty.
We discuss how other places regulate the internet, including Europe, Japan, Australia, South Korea, Brazil and more. And how each of their approaches created real burdens — the exact kinds of burdens that Chris Cox and Ron Wyden were trying to avoid while drafting Section 230.
What’s particularly striking is how Section 230 functioned as a kind of incubator. The early freedom from crushing legal uncertainty allowed companies to build services compelling enough that international users demanded access to them, creating pressure on foreign regulators to accommodate these platforms rather than block them entirely. This explains what seems like a contradiction: how platforms built under Section 230’s protection can operate in jurisdictions with much stricter liability regimes. They succeeded not despite Section 230, but because of the head start it provided, reinforcing the idea that Section 230’s biggest value is in protecting smaller, newer platforms.
But this era of American digital success may be fading. As regulations globally become increasingly stringent (with the EU’s Digital Services Act, Australia’s Online Safety Act, and dozens of similar regulatory regimes), we’re witnessing the early stages of internet fragmentation. We discuss how platforms will need to make difficult decisions about which markets to exit when compliance becomes untenable.
The irony shouldn’t be lost on American legislators rushing to “reform” Section 230: they’re dismantling the very legal framework that made American digital innovation possible, just as the rest of the world is recognizing — through increasingly desperate regulatory measures — how effective it was.
We’ve seen this sort of thing before, but it never really works. One of the symptoms of the permission culture we’ve built for ourselves, largely in the Western world, is that people or organizations think they can game otherwise legitimate systems in order to silence others. Intellectual property is one of those systems, where we’ve seen everything from churches to corporations attempting to use things like trademarks to silence speech they don’t like. The idea is to trademark some word, term, or slogan that has become a nuisance in order to preclude the victim from using it.
As I said, this never works. Either the speech changes just enough so that it continues or else the backlash is so overwhelming that the opposite end is achieved, not unlike the Streisand Effect. And in the case of some otherwise well-meaning Germans attempting to trademark a neo-Nazi slogan, it almost certainly won’t work for them either.
Here’s the background. Last year a video was taken at a club on the island of Sylt in which a bunch of Germans danced to an Italian song and chanted an anti-immigrant slogan along with it. The slogan roughly translated to “Germany for the Germans, foreigners out.” From there, the video unfortunately went viral, as did the chant. While much of this happened out in public, the neo-Nazi population in the country also took note. But since that is a group that can’t exactly come out and say the direct things they want to say, these racist assbags instead have to use code, such as:
Meanwhile, the musical motif – “Döp dö dö döp” – which alludes to the tune of the Ausländer raus lyric, was adopted as a coded meme in neo-Nazi circles. One especially popular far-right clothing supplier, Druck 18, has been selling t-shirts referencing the Sylt song since summer last year.
And that’s when some activist groups got involved, thinking they could combat the neo-Nazis through trademark law. One group managed to secure the trademark rights to the meme. Then, either due to direct contact or due to platforms like Druck 18 proactively taking action, merch with the slogan was quickly taken down.
According to the activists, this helps cut off a vital source of funding for neo-Nazi groups.
“They finance their right-wing extremist activities by selling the merchandise,” campaign chairman Jörn Menge told Tagesspiegel on Thursday. “We are putting an end to this behaviour.”
That’s true and they just got a shit ton of free advertising as all kinds of media outlets are writing about this, both in Germany and internationally. I, for one, had never heard of Druck 18 until working on this story, for instance, but now I doubt I’ll forget the name anytime soon. And, while I’m not exactly the target audience for a place like that, being, you know, not an asshole, other fascists or those who are fascist-curious will be.
Rule of thumb: defeating fascists by employing fascist tactics, such as the attempt to silence speech, doesn’t generally work out well. And, even if you get some short-term wins out of it, you still end up getting some of the fascist on you.
Germany’s history informs its current laws. That much is undeniable. But it doesn’t excuse the over-correction applied by legislators in hopes of heading off another Hitler.
And it certainly doesn’t excuse prosecutors who are prosecuting “hate speech” in Germany. The country’s hate speech law has been problematic since its inception. Within days of its debut in 2018, it was causing collateral damage by treating satire as illegal speech and generating a whole lot of false positives.
Still, prosecutors seemed to like it. So did the cops on the hate speech beat. Perhaps a bit too much.
Authorities in Lower Saxony raid homes up to multiple times per month, sometimes with a local television crew in tow.
Thanks to CBS’s 60 Minutes, TV crews are back in tow while homes are raided by cops over things people say online. Devices are seized and people are arrested. And the prosecutors see nothing wrong with this sort of armed reaction to certain speech — speech that may not be actually “hateful” but merely insulting.
The interview with German prosecutors is perhaps far more enlightening than the participants expected it to be.
First, it makes it clear that the law criminalizes things most people don’t actually believe are criminal acts, which is a pretty good indication the German government is using a shotgun to handle a housefly problem.
It’s 6:01 on a Tuesday morning, and we were with state police as they raided this apartment in northwest Germany. Inside, six armed officers searched a suspect’s home, then seized his laptop and cellphone. Prosecutors say those electronics may have been used to commit a crime. The crime? Posting a racist cartoon online. At the exact same time, across Germany, more than 50 similar raids played out. Part of what prosecutors say is a coordinated effort to curb online hate speech in Germany.
Sharyn Alfonsi [CBS]: What’s the typical reaction when the police show up at somebody’s door and they say, “Hey, we believe you wrote this on the internet,”?
Dr. Matthäus Fink [prosecutor]: They say– in Germany we say, “Das wird man ja wohl noch sagen dürfen.” So we are here with crimes of talking, posting on internet, and the people are surprised that this is really illegal to post these kind of words.
That’s a problem. While it’s true ignorance of the law is rarely a great excuse, it’s quite another thing to see the same behavior repeated when cops show up to beat on doors, seize devices, and arrest citizens because they went a bit too far online. This isn’t law enforcement addressing potential threats to public safety. It’s armed officers raiding houses because someone might have done something as seemingly harmless as referring to a disliked politician as a “penis.”
That isn’t a hypothetical. It’s something that has already actually happened.
[A] 2021 case involving a local politician named Andy Grote […] captured the country’s attention. Grote complained about a tweet, that called him a “pimmel,” a German word for the male anatomy. That triggered a police raid and accusations of excessive censorship by the government. As prosecutors explained to us, in Germany, it’s OK to debate politics online. But it can be a crime to call anyone a “pimmel,” even a politician.
While it’s true that relying on personal insults is rarely an effective form of debate, it’s insane to firmly believe that this constitutes a criminal act that should involve armed officers, government prosecutors, and — because this was handled by the Lower Saxony office — a TV crew.
Frank-Michael Laue is the prosecutor heading up the Lower Saxony office. And he’s super-enthused about raiding homes and seizing devices belonging to people who say mean stuff on social media. And it’s this enthusiasm that really exposes how much of a boondoggle this law is.
Sharyn Alfonsi: How many cases are you working on at any time?
Frank-Michael Laue: In our unit, we have about 3,500 cases per year.
Wow. That’s like 10 cases a day. Seems like the law isn’t much of a deterrent if prosecutors are able to generate 3,500 cases per year.
That’s where Laue really steps in it, apparently inadvertently.
Laue says his unit has successfully prosecuted about 750 hate speech cases over the last four years.
Someone should do the math because Lower Saxony prosecutors apparently aren’t: 14,000 cases managed to deliver 750 successful prosecutions. That’s a hit rate of 5.35%. Does that seem to be a good use of law enforcement resources? On top of the cops handling the raids, there are the expenses generated by Lower Saxony prosecutors, who have nearly a 95% failure rate when it comes to prosecuting people engaged in so-called hate speech.
Perhaps the worst thing about the interview with German prosecutors is that they don’t seem to care that this is mostly a waste of time and money. They seem to view this constant futility as (1) essential to protecting Germany from its own citizens, and (2) pretty fucking funny when keyboard warriors get their shit jumped by police officers.
At about 4:10 into the interview, this happens:
Sharyn Alfonsi: How do people react when you take their phones from them?
Frank-Michael Laue: They are shocked. It’s a kind of punishment if you lose your-smartphone. It’s even worse than the fine you have to pay.
What’s not detailed in this transcript is the laughter of Laue and the other prosecutors (Matthaus Fink, Svenja Meininghaus), who seem to think it’s incredibly amusing that people who are already baffled they’re being accosted by law enforcement over a social media post are “shocked” to see their electronics seized by officers. That’s a hideous reaction that makes it clear — as we say so often here in the States — the cruelty is the point. It certainly can’t be anything else, not when Laue and his Lower Saxony prosecutors can barely convert 5% of these raids/seizures into a criminal case that usually ends with nothing more than monetary fine.
I’m sure good intentions played a part in the crafting of this law. And Germany’s concerns about steering clear of a Fourth Reich are certainly legitimate. But those enforcing the law just seem happy to be inflicting misery on German citizens who’ve done nothing more than insult politicians or expose their racism and bigotry to others. Maybe this is will keep the Nazis at bay, but it also suggests some German politicians and prosecutors still yearn for the good old days of the Berlin Wall and all the suppression of speech that regime enabled.
Love it or loathe it, there’s no denying that the EU’s General Data Protection Regulation (GDPR) is the most important piece of data protection law around. GDPR stories are often about big, bad companies failing to respect the legislation, but there’s a small but amusing group of incidents in which the EU itself has been caught violating its own privacy laws.
Shortly after the GDPR came into force on 25 May 2018, somebody noticed that the European Parliament’s Web site was not compliant. A few days later, it was discovered that the European Commission breached its own rules — they went on to claim that the GDPR didn’t actually apply to them in the same way that it did for everyone else. The European Commission did eventually bring in an equivalent set of rules for EU institutions, but conveniently ones with lower fines.
Those rules were put to the test in July 2022, when someone in Germany complained that the European Commission had infringed on his right to data protection when he visited a Web site of the Conference on the Future of Europe, managed by the Commission, in 2021 and 2022. The complainant had registered for an event using his Facebook account to sign in. Here’s why that was a problem under the GDPR (pdf), as explained by the General Court of the Court of Justice of the European Union (CJEU), the top EU court that deals with legal issues involving EU bodies:
as regards that person’s registration for the ‘GoGreen’ event, the General Court finds that, by means of the ‘Sign in with Facebook’ hyperlink displayed on the EU Login webpage, the Commission created the conditions for the transmission of his IP address to Facebook. That IP address constitutes personal data which, by means of that hyperlink, were transmitted to Meta Platforms, an undertaking established in the United States. That transfer must be imputed to the Commission.
At the time of that transfer, on 30 March 2022, there was no Commission decision finding that the United States ensured an adequate level of protection for the personal data of EU citizens. Furthermore, the Commission has neither demonstrated nor claimed that there was an appropriate safeguard, in particular a standard data protection clause or contractual clause. The displaying of the ‘Sign in with Facebook’ hyperlink on the EU Login website was entirely governed by the general terms and conditions of the Facebook platform.
As that notes, at the time, in March 2022, there was no legal framework that protected the personal data of EU citizens when it was sent to the US. The previous frameworks — Safe Harbor and Privacy Shield — had been struck down by the CJEU in 2015 and 2020 respectively. The current EU–US Data Privacy Framework did not come into force until July 2023. As a result:
The General Court finds that the Commission committed a sufficiently serious breach of a rule of law that is intended to confer rights on individuals. The individual concerned suffered non-material damage, in that he found himself in a position of some uncertainty as regards the processing of his personal data, in particular of his IP address. There is, moreover, a sufficiently direct causal link between the Commission’s infringement and the non-material damage sustained by the individual concerned.
Since the conditions for establishing the European Union’s non-contractual liability are satisfied, the General Court orders the Commission to pay the individual concerned the sum of €400 claimed.
The fine of €400 (about $410) doesn’t even count as a slap on the wrist – more of a light tickle. The most interesting aspect of the whole saga — apart from the schadenfreude at seeing the European Commission fined for violating its own laws — concerns the key issue of transatlantic data transfers. Although the EU–US Data Privacy Framework is still in place, which means that transatlantic data flows are legal provided its requirements are met, there’s still the possibility that it will be overturned by the CJEU, just like its two predecessors were. The person mostly responsible for the previous frameworks being thrown out, Max Schrems, said in July 2023 that his organization, Noyb, would challenge the new framework in the courts, but nothing seems to have happened yet. However, Noyb has recently notched up a privacy win over the European Commission in a different matter, explained here on its Web site:
The EDPS (European Data Protection Supervisor) has issued a decision finding that the European Commission has illegally targeted advertising at citizens using “sensitive” personal data on their political views.
Specifically:
EU Commission tried to influence political views in the Netherlands. In the contentious fight over the heavily criticised chat control regulation (a proposed EU law that could undermine all encrypted online communication to allow authorities to read online chats), the European Commission has identified the Netherlands as a Member State that they wanted to politically influence. In an attempt to “flip” the views in the Netherlands, the Commission went to X/Twitter and made posts indirectly promoting this regulation.
Political Targeting on X/Twitter. However, the European Commission did not only post these political messages, but also targeted users who weren’t interested in keywords like: #Qatargate, brexit, Marine Le Pen, Alternative für Deutschland, Vox, Christian, Christian-phobia or Giorgia Meloni. The clear intention was to only target politically liberal or left users, but not conservative or right-wing users. Advertisers often use so-called “proxy data” (so data closely associated with political thinking) to target political views. By doing so, the European Commission has clearly triggered the processing of personal data of EU citizens to target them with ads.
Fortunately, the attempt to influence people’s views in the Netherlands failed. This abuse of microtargeted advertising for political purposes is clearly rather more serious than the sending of some personal data across the Atlantic, even if only the latter attracted a (token) fine. Noyb’s win shows how the GDPR for all its flaws can still be a useful weapon for highlighting privacy abuse by the authorities, in this case as part of an attempt to push through the extremely-contentious “chat control” legislation using dirty tricks.
Whether you like the results or not, there’s no denying that the EU’s GDPR legislation has tackled a wide range of privacy problems in the online world. Other countries around the globe — including the US — may lack comparable national legislation but there are alternative ways of protecting people’s privacy, as a recent ruling in India shows. The Competition Commission of India (CCI) has imposed a fine of ₹213.14 crore (about $25.25 million) on Meta for exploiting its dominant position through WhatsApp’s 2021 Privacy Policy update. The Internet Freedom Foundation of India explains how what it calls a “landmark penalty” will improve the privacy of users:
The policy update, which compelled users to accept expanded data collection and sharing within the Meta group on a ‘take-it-or-leave-it’ basis, violated user autonomy by offering no opt-out option. The [CCI] ruling reinforces the need for greater accountability from tech giants, ensuring that users’ rights are protected, and the principles of fair competition are upheld in digital markets.
The CCI found that Meta’s actions violated Indian competition law under Section 4(2)(a)(i) by imposing unfair conditions and abusing its dominant position in the market.
That is, it was competition law rather than privacy law that was used, an approach Germany also adopted some years ago. In India’s case, it has led to a fine (admittedly pretty small given the size of Meta) and restrictions on how Meta operates in India. The press release from the Competition Commission of India (pdf) spells out what those are:
WhatsApp will not share user data collected on its platform with other Meta Companies or Meta Company Products for advertising purposes, for a period of 5 (five) years from the date of receipt of this order.
After that time, Meta must abide by the following:
Sharing of user data collected on WhatsApp with other Meta Companies or Meta Company Products for purposes other than for providing WhatsApp services shall not be made a condition for users to access WhatsApp Service in India.
In respect of sharing of WhatsApp user data for purposes other than for providing WhatsApp Services, all users in India (including users who have accepted 2021 update) will be provided with:
a) the choice to manage such data sharing by way of an opt-out option prominently through an in-app notification; and
b) the option to review and modify their choice with respect to such sharing of data through a prominent tab in settings of WhatsApp application
Those are quite similar to GDPR requirements, and show that the same results may be obtained by different means. As to the motivation for the Competition Commission of India’s investigation into Meta, the Internet Freedom Foundation of India noted back in 2021 that it was “suo moto” — that is, begun by the Indian authorities without being requested to do so by any other party — but also that it was “a huge opportunity to present the user’s point of view to the Commission!” The final result certainly seems like a win for WhatsApp users in India. It will also serve as a warning to other major online players not to adopt a ‘take-it-or-leave-it’ approach when it comes to their data collection practices in India.
The copyright world is currently trying to assert its control over the new world of generative AI through a number of lawsuits, several of which have been discussed previously on Walled Culture. We now have our first decision in this area, from the regional court in Hamburg. Andres Guadamuz has provided an excellent detailed analysis of a ruling that is important for the German judges’ discussion of how EU copyright law applies to various aspects of generative AI. The case concerns the freely-available dataset from LAION (Large-scale Artificial Intelligence Open Network), a German non-profit. As the LAION FAQ says: “LAION datasets are simply indexes to the internet, i.e. lists of URLs to the original images together with the ALT texts found linked to those images.” Guadamuz explains:
The case was brought by German photographer Robert Kneschke, who found that some of his photographs had been included in the LAION dataset. He requested the images to be removed, but LAION argued that they had no images, only links to where the images could be found online. Kneschke argued that the process of collecting the dataset had included making copies of the images to extract information, and that this amounted to copyright infringement.
LAION admitted making copies, but said that it was in compliance with the exception for text and data mining (TDM) present in German law, which is a transposition of Article 3 of the 2019 EU Copyright Directive. The German judges agreed:
The court argued that while LAION had been used by commercial organisations, the dataset itself had been released to the public free of charge, and no evidence was presented that any commercial body had control over its operations. Therefore, the dataset is non-commercial and for scientific research. So LAION’s actions are covered by section 60d of the German Copyright Act
That’s good news for LAION and its dataset, but perhaps more interesting for the general field of generative AI is the court’s discussion of how the EU Copyright Directive and its exceptions apply to AI training. It’s a key question because copyright companies claim that they don’t, and that when such training involves copyright material, permission is needed to use it. Guadamuz summarizes that point of view as follows:
the argument is that the legislators didn’t intend to cover generative AI when they passed the [EU Copyright Directive], so text and data mining does not cover the training of a model, just the making of a copy to extract information from it. The argument is that making a copy to extract information to create a dataset is fine, as the court agreed here, but the making of a copy in order to extract information to make a model is not. I somehow think that this completely misses the way in which a model is trained; a dataset can have copies of a work, or in the case of LAION, links to the copies of the work. A trained model doesn’t contain copies of the works with which it was trained, and regurgitation of works in the training data in an output is another legal issue entirely.
The judgment from the Hamburg court says that while legislators may not have been aware of generative AI model training in 2019, when they drew up the EU Copyright Directive, they certainly are now. The judges use the EU’s 2024 AI Act as evidence of this, citing a paragraph that makes explicit reference to AI models complying with the text and data mining regulation in the earlier Copyright Directive.
As Guadamuz writes in his post, this is an important point, but the legal impact may be limited. The judgment is only the view of a local German court, so other jurisdictions may produce different results. Moreover, the original plaintiff Robert Kneschke may appeal and overturn the decision. Furthermore, the ruling only concerns the use of text and data mining to create a training dataset, not the actual training itself, although the judges’ thoughts on the latter indicate that it would be legal too. In other words, this local outbreak of good sense in Germany is welcome, but we are still a long way from complete legal clarity on the training of generative AI systems on copyright material.