Showing posts with label Jurisdiction. Show all posts
Showing posts with label Jurisdiction. Show all posts

Monday, 15 June 2026

Back to the borderless future

An internet jurisdiction retrospective 

The problem

Since the dawn of the internet we have wrestled with the question of how best to reconcile national laws with the inherently cross-border medium of the internet. We are still at it, with resolution seemingly as far away as ever. The periodic eruptions of controversy when some nation state decides to assert its local laws in a way that others view as exorbitantly extraterritorial are testament to that.

If answers are difficult to come by, the nature of the problem was always obvious. Back in 1999 I described the jurisdictional challenges to national legal systems presented by the internet. 

“Time is no longer a barrier: on the Internet content can be delivered instantaneously across geographic and political borders. Distance is irrelevant: not only can messages be transmitted from one part of the globe to another instantaneously, but for the user the location of the content is irrelevant. All that matters is that the content appears on his or her screen. … The Internet also destroys cost barriers.  

These characteristics give the Internet the potential to erode national legal systems based on geographic and political boundaries. While imposed barriers – customs, immigration, tariff and physical – still remain, the Internet challenges their enforceability. … People responsible for content are vulnerable to enforcement in states in which they live or visit, to which they can be extradited, or in which they have assets. But the information is almost immune. … Once telecommunications links are in place it is extraordinarily difficult for national authorities to prevent information flowing across their borders.” Content on the Internet – Law, Regulation, Convergence and Human Rights (Graham Smith, chapter in ‘International Law and the Hague's 750th Anniversary’, T.M.C. Asser Press, 1999)

That probably overstated the immunity of information to technical border controls, at least in the hands of a sufficiently determined government. Nevertheless, the bits and bytes still tend to fly across borders with a fine disregard for nation state boundaries; and politicians continue to debate the efficacy of geo-blocking and to be exercised by VPNs. 

There were some who argued that the internet was nothing new; that we had already had to grapple with cross-border broadcasting. However, a handful of satellite broadcasters bore little resemblance to hundreds of millions of individual online users posting their thoughts direct to a default world-wide audience.

What to do?

How, therefore, can we minimise friction between starkly differing sets of laws and values when, inevitably, they rub up against each other online? Can we achieve peaceful co-existence, or are we condemned to a perpetual contest for superiority between competing national laws? Does that become a race to the most restrictive common denominator?  If so, does that matter?

If a nation state feels strongly enough about the values embedded in its own domestic laws, is it entitled to assert those against all visible online content worldwide? Or should it grit its teeth, exercise jurisdictional self-restraint and accept that its citizens may legitimately be able to seek out content created under other legal systems?

What should count as sufficient connection with a country in order for its authorities to assert jurisdiction over foreign online content? Should those domestic authorities take into account the fundamental rights of users in other countries with less restrictive laws? If so, how? Is it legitimate for a domestic authority to co-opt online intermediaries such as search engines to require them to remove content from their services worldwide?

Is it reasonable to insist that, in order to avoid triggering other countries’ laws or jurisdiction, online content must be rendered technically inaccessible by geofencing? What if a geofence can be circumvented?

Those are some of the specific questions that the broad issue of internet jurisdiction throws up. They have been argued over in the courts and in academic scholarship for decades, going back to the mid-1990s. That was the era of Johnson and Post’s celebrated 1996 essay Law and Borders –The Rise of Law in Cyberspace, counterweighed ten years later by Goldsmith and Wu’s Who Controls the Internet?: Illusions of a Borderless World (OUP, 2006).

In the courts, the mid-1990s saw the CompuServe newsgroup and Radikal magazine cases in Germany. Those were followed in 2000 by the French LICRA/Yahoo! litigation over Nazi memorabilia displayed on Yahoo!’s .com auction site. That was the first case to focus expressly on whether mere accessibility of overseas online content should be sufficient to found jurisdiction, and to examine in detail the technical ability of a foreign website to filter out users from (in this case) France. The litigation carried on, on both sides of the Atlantic, until 2006, attracting world-wide attention as it went. It remains a paradigmatic internet jurisdiction case study.

Uta Kohl’s book Jurisdiction and the Internet (CUP) was published in 2007. She asked:

“Traditionally transnational activity has been ‘shared out’ between States with the aid of location-centric rules and these can be adjusted to suit the Internet. But can these rules be stretched indefinitely and what are the costs of squeezing global online activity into nation-state law?”

By 2017 Dan Svantesson was able to introduce his book Solving the Internet Jurisdiction Puzzle (OUP) thus:

“It is fair to say that the topic of ‘Internet jurisdiction’ is currently gaining an unprecedented level of attention. Indeed, at the moment, Internet jurisdiction is one of the most important, and most talked about, topics in Internet law and related fields.”

In March 2021 Julia Hörnle, commenting on her newly published book Internet Jurisdiction Law and Practice (OUP), observed:

“Essentially, jurisdiction is about the legal authority of state actors to act and that legal authority is limited to the population and territory of the state. It ends at the national border. Since this power of a state agent to act is limited to the territory of that state, but the internet’s reach is not so limited, jurisdiction is the fundamental legal concept behind many, if not most, of the troubles of effectively regulating the global internet. National police forces do not (normally) cross international borders.

If the legal concept of jurisdiction challenges effective policing of the internet, you may ask, why can’t we simply change this old legal concept to something more suitable? The problem lies not in the law but in the international political system of governance by nation states, a political system closely tied to national identities, culture, and geo-political realities.”

Whether we are seeking to adapt existing jurisdiction rules or to attempt something more radical, the reality is that when national legal rules clash, dispassionate application of formal rules can be hard to disentangle from culturally influenced views about what the law ought - and ought not - to be. That is well illustrated by the comments of the French court in the LICRA/Yahoo! case, suggesting that it would cost Yahoo! very little to extend its prohibitions on various other kinds of content to symbols of Nazism, and that:

"such an initiative would have the merit of satisfying an ethical and moral requirement shared by all democratic societies" (judgment on geo-filtering measures, 20 November 2000)

That implicitly contrasts the moral weight to be attributed to French law with that to be given to the USA's attachment to freedom of expression. 

The history of extraterritorial assertion of local laws on the internet is, unsurprisingly, littered with subject-matter about which passions run high: Nazi memorabilia, obscenity, holocaust denial, terrorism and others. 

The most recent controversies have been sparked by various countries’ online safety laws – notably those of the EU and the UK, which (along with some actions of the Brazilian Supreme Court) have attracted the ire of the current US administration.

Online safety is by no means the first, nor will it be the last, subject matter to fuel local enthusiasm to reach out across borders and take aim at non-conforming foreign content. What is perhaps different about online safety is the attempt not just to assert specific content laws against discrete items published online, but to impose entire regulatory regimes on service providers and to penalise non-compliance with administrative regulatory requirements. (In that respect online safety has something in common with EU and UK data protection regimes.)

Whether a foreign service provider has sufficient connection with a state to justify it in asserting a specific content law is a familiar enough question. With a regulatory regime, additional issues arise as to whether a regulatory body such as Ofcom (the UK online safety regulator) is entitled to serve legal notices directly across borders or whether that violates the territorial sovereignty of the state in which the recipient is located. Similar questions have arisen in the context of cross-border evidence requests by law enforcement to online intermediaries. 

Lack of consensus

Lack of consensus on jurisdictional self-restraint is perhaps not surprising: cultural and geopolitical sensitivities readily translate into reluctance to cede ground to another country’s less restrictive laws. 

2012

“Every so often someone in authority feels the urge to put on blinkers, engage tunnel vision and, casting the internet as chief villain, decide to view the rest of the world as an offshore haven that exists for the sole purpose of subverting his home laws.  This even happens at policy level.  EU and US authorities have both gained deserved reputations for trying to forcefeed other countries, and each other, with their pet legislative agendas. 

In the UK you could argue that we asked for it. Our libel courts willingly adopted the startlingly parochial doctrine, first espoused in the Australian case of Gutnick v Dow Jones, that any website in the world that can be read and comprehended in the UK is published here.  Asserting our libel laws against the rest of the world on the basis of minimal UK publication provoked the US to pass the SPEECH Act, preceded by New York’s Libel Terrorism Prevention Act.”
 

See me, sue me? Cyberleagle, March 2012 
It is more frustrating if jurisdictional issues are approached as if the internet has only just been invented and the issues have not been thought about seriously before.

Ultimately, what jurisdictional rules are appropriate for the internet? How far should a nation state’s laws be able to reach extraterritorially? What are the consequences of overreach (in international law terminology, exercise of exorbitant jurisdiction)? What are the practical consequences of different jurisdiction rules?

I have been writing about these issues, on and off, for the best part of 30 years. I hope I can be forgiven for illustrating this thematic retrospective with some extracts from my own efforts. Whatever the reader may think of the views expressed, or how far they have stood the test of time, the exercise does illustrate that while the flashpoints may have changed, the underlying issues have not.

An international convention?

At one time there were suggestions of an international convention to govern the internet. Parallels were drawn with the Law of the Sea Convention. However, the maritime analogy does not really hold water. The internet is not an unowned expanse between states, requiring a separate legal regime to be created for activities that take place in the void between national boundaries. People’s online activities may straddle borders, or move across them instantaneously, but the activities do not in substance occur between them. The issue is one of conflicting laws, not one of no law.

In any case a convention harmonising substantive content laws was always likely to be unachievable. For myself, I was doubtful that it was even desirable; first, because there is intrinsic merit in maintaining a rich and changing variety of substantive content laws worldwide; and second, because any uniform worldwide content law that might be achievable would necessarily have to accommodate nation states with scant regard for liberal principles of freedom of expression. 

2019

"The risks attached to a universal convention to address those issues are twofold: that the prospect of agreement is very low; but also that if an agreement were reached, that would inevitably involve significant worldwide compromise of values such as freedom of expression. Those who would have to agree to such a convention include the very governments who so enthusiastically seek to apply their often restrictive domestic laws to internet activities emanating from other countries."

Internet Law and Regulation (5th ed, 2019, Sweet & Maxwell) Graham Smith, Chapter 6 Cross-border liability

In principle a jurisdiction convention — a set of rules about whose laws should apply — should aim to be agnostic as to the substantive merits of competing national laws. However, where content is concerned, value neutrality is something of a chimera: the greater the permissible reach of national laws online, the greater the prospect of exposure to the more restrictive law or regulatory regime.

Mere accessibility and most restrictive common denominator

The most expansive basis for asserting jurisdiction is mere accessibility, also known as country of receipt, country of destination or mere visibility. Even if there is no consensus about what internet jurisdiction rules should look like, from the start there was at least a strong body of opinion that mere accessibility is overreaching in principle, and that in practice it would lead to application of the ‘most restrictive common denominator’, a geographically fragmented internet, or both. 

1999

“If increased international co-operation were to result in national laws being extra-territorially enforced, … that would effectively amount to a ‘country of receipt’ rather than ‘country of origin’ regime. Under such a regime someone publishing content on the Internet would have to satisfy himself of its lawfulness in all countries of receipt. This is an extremely onerous and effectively impossible task to achieve. If ‘country of receipt’ were to be reinforced, it would result in a ‘most restrictive common denominator approach to Internet content.” 

Content on the Internet – Law, Regulation, Convergence and Human Rights (Graham Smith, chapter in International Law and the Hague's 750th Anniversary, T.M.C. Asser Press, 1999).

Some instruments (including the EU GDPR, the UK GDPR and the EU Digital Services Act) expressly exclude mere accessibility as a basis of jurisdictional competence. However, the consensus against mere accessibility is not universal.
2023

"Over the years a de facto compromise had been emerging, with the steady expansion of the idea that you engage the laws and jurisdiction of another state only if you take positive steps to target it. Recently, however, some states have become more expansive – not least in their online safety legislation.

There has long been a consensus against ‘mere accessibility’ as a test for jurisdiction. It leads either to geo-fencing of websites or to global application of the most restrictive common content denominator. That consensus seems to be in retreat.

Moreover, the more exorbitant the assertion of jurisdiction, the greater the headache of enforcement. Which in turn leads to what we see in the UK Online Safety Bill, namely provisions for disrupting the activities of the non-compliant foreign platform: injunctions against support services such as banking or advertising, and site blocking orders against ISPs.

The concern has to be that in their efforts to assert themselves and their local laws online, nation states are not merely re-erecting national borders with a degree of porosity, but erecting Berlin Walls in cyberspace."


Shifting paradigms in platform regulation Cyberleagle, June 2023
The Australian Online Safety Act 2021 asserts regulatory competence on the basis of mere accessibility. The England and Wales Law Commission has recently proposed mere accessibility as the basis of a reformed law of contempt of court by publication.
2026

Today, the Law Commission exhorts Britannia (or England and Wales, to be exact) to rule the internet worldwide:

           “In our view, contempt laws should apply to all material that is accessible in England and Wales.” (Part 1 Report on Liability for Contempt of Court, November 2025 [4.173])

... Ultimately, the policy reasons that the Law Commission has finally relied upon are domestically focused. They do not go into the broader cross-border legal and geo-political aspects that a full discussion of international law and comity could have illuminated.

Such an analysis would have involved considering whether it is reasonable, from the perspective of the foreign state and its citizens, to impose ‘mere accessibility’ liability on persons in another country. It would require consideration of the position of a variety of potential actors: mainstream foreign press and media, individual bloggers and posters, and online platforms."


Britannia rule the internet Cyberleagle, May 2026. 
Johnson and Post’s ‘Law and Borders’ paper argued in 1996 that the result of asserting a right to regulate whatever a state’s citizens may access on the Net is that:

“All such Web-based activity, in this view, must be subject simultaneously to the laws of all territorial sovereigns.”

Mere accessibility is a species of the ‘effects’ test in international law, a basis on which states may seek to justify extraterritorial assertion of local law. The effects test was described by David Post in 2015 as:

"a wildly inappropriate doctrine for the Internet Age; if you're subject to jurisdiction where the "effects" of your actions or communications are felt, then given that the "effects" of communications over the Internet can plausibly be felt everywhere and anywhere, simultaneously and instantaneously, the [effects test] has the potential to nullify any and all limits on personal jurisdiction and subject everyone to jurisdiction everywhere - not a reasonable outcome."

Mere accessibility and extraterritoriality go hand in hand:
2001

“[W]e cannot assume that only the content laws that we like will be asserted extraterritorially. Take any regime whose idea of objectionable activities includes political or religious expression. Extraterritoriality is the first step towards requiring all Internet speech to respect the most restrictive national common denominator.” 

Letter to The Times legal section, Graham Smith, 30 January 2001. 
The late Max Mosley proposed mere accessibility in his 2012 submission to the Leveson Press Inquiry:

“Anyone using the internet must therefore obey the laws in their country. Similarly, they should obey the law in countries where their posts appear. As a practical matter, it is the search engines and service providers which can best prevent breaches of the law outside the country of origin of the original post.”

That prompted my submission to the Inquiry, in which I pondered what I, as the author of the Cyberleagle blog, should do in response to such a rule.
2012

“So faced with Mr Mosley’s proposed rule, what should I do?  Should I try to ascertain the most restrictive country’s content laws and comply with those?  With the resources of a multinational publisher that is a challenging exercise.  For a lone blogger it is preposterous.  Even if it could be done the result is a monstrously chilling effect on freedom of expression, whereby I (and my UK readers) are deterred from enjoying the benefits of the UK’s imperfect but nonetheless relatively liberal content laws. 

Should I hope that the worst laws will be unenforceable here, hole up in the UK and never set foot in another country (and if so do we wish to encourage such behaviour)? Or will Mr Mosley’s EU-wide law, then international convention, mean that I can be sued or, worst case, extradited, for breach of any non-UK content law, civil or criminal? (Extradition for internet activities can now no longer be regarded as fanciful, even under current laws.) 

So should I try to restrict the blog to a UK audience, or to the UK plus a few selected countries whose laws I might be able to research?” 


Leveson Press Inquiry Graham Smith, submission on internet jurisdiction, September 2012
The third option may be possible, including at the level of individual posts, on platforms where tools or geofencing plug-ins are available.  In my 2012 submission I assumed that the whole blog would have to be geofenced.  Whether it is a good thing to incentivise individual users to geofence is a matter for debate.

Positive conduct and the targeting test

One approach that has held out some promise of evolving into a workable compromise is the targeting test. 

2004

"From the earliest days of the web, lawyers have asked whether the worldwide availability of a website should of itself be sufficient to trigger worldwide liability. If not, what is the appropriate rule for the internet? A pure country of origin approach is politically difficult to achieve, whereas a country of destination approach exposes online actors to an unreasonable degree of liability. This article discusses whether a directing and targeting rule promises an acceptable solution, and if so how such a test should be formulated in order to prevent it degenerating into a country of destination rule.

In general, if a directing and targeting test is to draw an appropriate balance between country or origin and country of receipt, and discourage the erection of national borders in cyberspace, a finding that a website has targeted a particular country should be founded only on positive acts of the website proprietor, not on omissions to act.
...
To require evidence of positive acts is, in the context of the on-line environment, a close analogue to the original assumption underlying many of the rules written for the off-line world, that a trader did not without taking some positive step engage foreign laws and jurisdictions.”


Directing and Targeting - the Answer to the Internet's Jurisdiction Problems? (Graham Smith, Computer Law Review International 5/2004 129-170 May 2004)
2007

“A properly formulated targeting test would mean that, for instance, the court in the French Yahoo! case could not have found that the mere display of Nazi memorabilia was sufficient to violate French law, without some element of targeting or direction at France. Nor would it have been open to it to find jurisdiction, as it did, on the basis that because Nazi memorabilia were of interest to all, the areas containing those items were directed at all countries simultaneously including France. However, it might still have been possible for a court to find that Yahoo's serving up of French banner advertisements to French IP addresses would satisfy a "directed at" test."


Here, There or Everywhere? Cross-border Liability on the Internet (Graham Smith, 2007 C.T.L.R. 41)
2017

"The targeting approach occupies a middle ground, prescribing legal consequences for localisation but stopping short of incentivising or compelling fragmentation. Targeting holds out some promise of allowing national law to be upheld in circumstances when many would think it reasonable that it should do so, while also reducing incentives to fragment the internet. 

However the targeting approach can fulfil this promise only if it is formulated in a way that does not slip towards the country of receipt end of the spectrum. If, for instance, a French blogger writing in English were taken to be targeting all English speaking countries by virtue of using the English language, or the whole world by writing about topics of inter national interest, that would be a targeting approach in name only. A targeting approach still requires an underlying commitment to jurisdictional self-restraint on the part of the legislatures and courts that implement it.


Cyberborders and the right to travel in cyberspace (Graham Smith in The Net and the Nation State (ed Kohl, 2017) Chapter 9).
2026

“Directing and targeting of activities has long been thought to be an appropriate ground on which to assert jurisdiction over internet actors.”


Extraterritoriality and the transatlantic free speech wars Cyberleagle, February 2026
Co-opting online intermediaries

Whilst I took issue with Max Moseley’s 2012 visibility test (above), he was not wrong to say that search engines and service providers would be seen as best able to prevent breaches of the law outside the country of origin of the original post.

Co-option of online intermediaries brings into play an important distinction between initial jurisdictional competence and the territorial reach of the measures that a court or regulatory authority may decide to take when exercising that jurisdiction. Court cases seeking to co-opt intermediaries typically boil down to the latter: should a court that has assumed jurisdiction make an order with extraterritorial effect? 

The Canadian Google v Equustek and Australian eSafety Commissioner v X cases took different approaches to that question, the latter having more regard to the effect on individual users in other countries. Two CJEU cases have also considered the question: Google v CNIL (C-507/17, 10 January 2019) and Glawischnig-Piesczek v Facebook Ireland Limited (Case C-18/18, 3 October 2019). 

2017

"When faced with a bad actor, an ugly set of facts and a demand for an effective remedy it is all the more important that a court should anxiously examine the basis for exercising its power and carefully identify and balance competing factors, even – perhaps especially - where the internet is concerned. …

Where an apparent bad actor thumbs its nose at the court’s authority it is perhaps unsurprising that if a well-resourced global intermediary is haled into court, apparently able to take steps to mitigate damage to the plaintiff at little inconvenience to itself, the tribunal may (if satisfied that it has the power) be inclined to enlist its assistance.

Nevertheless if a future court should contemplate a similar order then a more detailed identification of the rights and interests involved, analysis of any territorial aspects of those rights and consideration of the freedom of speech rights of internet users separate from the sensibilities of states may be key to arriving at an appropriate outcome.”


Worldwide search de-indexing orders: Google v Equustek Cyberleagle, July 2017
2024

“A notable aspect of these passages [in the judgment of Kennett J in eSafety Commissioner v X Corp [2024] FCA 499] is the approach to comity of nations, especially in the balance of convenience section which refers to the effect on millions of people unconnected with the litigation. It stands in significant contrast with the approach of the Canadian Supreme Court in Equustek (a trade mark and confidential information case).”


Internet jurisdiction revisited Cyberleagle, May 2024
The UK Online Safety Act also illustrates the distinction between initial jurisdictional competence and territorial scope of measures: Ofcom is granted regulatory competence over certain intermediary services on the basis of whether the service is 'UK-linked', as defined by the Act. However Ofcom can enforce duties against a service provider only in relation to the design, operation and use of the service as it affects United Kingdom users of the service.

Domestic superiority versus peaceful co-existence

The comments of the French court in LICRA/Yahoo! remain a paradigm example of a national authority asserting the superiority of its local laws over those of another country. That, however, is not a recipe for peaceful co-existence. A measure of jurisdictional self-restraint is required.

2017

"Ideally, in a world of mutually respectful nation states, each country’s legal institutions would behave with modest self-restraint when asserting jurisdiction over cross-border online conduct. They would seek at most to govern activities within the country’s own borders or with an overwhelmingly strong domestic connection. They would refrain from asserting the superiority of their own laws over those of any other country that adhered to core human rights norms. Each country’s institutions would strive to avoid imposing their own country’s laws on activities abroad, either directly or through consequential effects in other countries. Such self-denying behaviour tends to encourage porous or open borders.

At some risk of caricature, in the real online world nation states tend to view the internet as little more than a device designed to undermine the efficacy of their domestic laws. In this view of the world visibility of foreign content is equated to importing the alien laws under which it was made. The parochial temptation to reach out and assert jurisdiction over merely accessible foreign content that contravenes a state’s domestic norms can be all but overwhelming. Laws may be asserted extraterritorially via broad concepts of location of activity and attenuated domestic connecting factors. Self-denying principles, such as that a state should refrain from doing that which it would not have done to it, waver in the face of foreign content that affronts local values. Giving maximum effect to local law may be articulated as a matter of national or regional honour.
...
Targeting rules and country of origin rules both imply recognition that the emancipated internet user’s home state should not seek to impose on its people a total monopoly of local laws in order to insulate them from foreign information– a policy that in the pre-internet physical world was attempted only in the most repressive states. We could go so far as to say that by keeping information out we keep people in: we erect not just a border but a virtual Berlin Wall. There is a risk that states, reacting fearfully and defensively to the inherent global nature of the internet, may adopt a policy of seeking to erect closed borders which are less porous than their pre-internet physical equivalents. By doing so they would deny their people the right to travel in cyberspace.”


Cyberborders and the right to travel in cyberspace (Graham Smith in The Net and the Nation State (ed Kohl, 2017) Chapter 9).
2017

"In one respect we have made progress since 1996. In an increasing number of subject matter areas a targeting test has been held (at least within the EU) to define the territorial scope of a right. Targeting rules hold out the prospect of something approaching a peaceful co-existence regime. Properly formulated and applied, a targeting test (a) lays down that mere accessibility does not trigger the laws or jurisdiction of another country and (b) requires relevant positive conduct, not mere omission, in order to do so.

However, the furore that periodically erupts around cross-border internet cases shows that there is still little consensus on these issues. Nuanced approaches may be at greatest risk of being jettisoned when the law in question is said to embody a core value of the state asked to adopt an expansive jurisdictional stance. That is also the time when greatest care should be taken not to let enthusiasm for the perceived merits of domestic law override respect for the different laws of other countries and the principle of peaceful co-existence.”


21 years of cross-border liability on the internet Cyberleagle, August 2017
2018

"Jurisdiction rules are about resolving friction between different legal systems in as agnostic a way as possible, not about ensuring that the best (in someone’s view) law wins.

The jurisdictional problems of the internet manifest themselves in both underreach and overreach. There are situations where arrangements between states are no longer providing adequate means to obtain evidence to support criminal investigations. We can no longer assume that the evidence relating to a domestic crime will be held domestically. It could as easily be in a data centre abroad.  That would suggest a need to improve procedures for obtaining cross-border evidence.

Conversely, we have situations in which domestic legislatures, agencies and courts are at risk of overreaching in the cause of giving maximum effect to their local laws. That can result in the de facto imposition of those laws in countries with different laws. The concern here is the need for jurisdictional self-restraint.

The challenge is to forge rules that enable cross-border reach when appropriate, yet prevent the exercise of jurisdiction when not appropriate.

The premise of jurisdiction rules is that nation states have different laws.  The objective where the internet is concerned should be to achieve peaceful co-existence between conflicting national regimes while protecting to the greatest possible extent universal values such as freedom of expression and privacy.

Peaceful co-existence cannot be achieved without compromise. That means taking a broader view than simply a laser-like focus on securing the effectiveness of one country or region’s most cherished laws. It may mean accepting that your country’s citizens can, if they try hard enough, find somewhere on the internet content that complies with another country’s laws and not your own.”

Peaceful coexistence, jurisdiction and the internet Cyberleagle, February 2018

Peaceful co-existence, however, remains far from the norm:

2026

"The transatlantic free speech wars continue to rage.


Some, no doubt, will be tempted just to plump for one side or the other, motivated by partisan preference for the EU, UK or US approach to governing speech and online platforms, by broader political affinities, or by views on the propriety or otherwise of deploying visa sanctions for this kind of purpose.

Tempting as that may be, simply to declare 'four legs good, two legs bad' will not do when it comes to considering international law rules and extraterritoriality. Taking sides based purely on a preference for the Digital Services Act or the Online Safety Act over the US First Amendment, or vice versa, does not address the underlying legal issue: how, in the inherently cross-border online world, to go about drawing boundaries - or at least minimise friction - between different national or regional legal systems. A more analytical approach is called for.


The more tenuous the connection and the greater the cross-border reach, the more exorbitant the claim to jurisdiction and the less likely that the extraterritoriality can be justified. 

That is the theory. In practice, the customary norms of international law tend to be distinctly malleable and, when push comes to shove, to merge into geopolitics.”


Extraterritoriality and the transatlantic free speech wars Cyberleagle, February 2026




Wednesday, 11 February 2026

Extraterritoriality and the transatlantic free speech wars

The transatlantic free speech wars continue to rage. The US House Judiciary Committee was in action again last week, taking aim at the European Commission (who rejected its latest interim report as ‘pure nonsense’) and provoking EU civil society groups in the process.

The US administration, for its part, fired off its most recent salvo shortly before Christmas last year, when US Secretary of State Marco Rubio added five people to a list of individuals who would not be allowed visas, due to their activities in the 'global censorship-industrial complex'.

The US rogues' gallery included former EU Commissioner Thierry Breton, whose letter to Elon Musk in August 2024, referencing the Digital Services Act, scuppered Breton's prospects of a job in the 2024-2029 European Commission. The Commission have been trying to live down the letter ever since. US critics of the DSA have never let them forget it.

Notably, or perhaps prudently, the no-visa list included no current foreign state officeholders or functionaries. It did not go as far as when the US imposed visa restrictions on the Brazilian Supreme Court judge Alexandre de Moraes in July 2025. The implied threat, however, remains: "The State Department stands ready and willing to expand today's list if other foreign actors do not reverse course."

The next, heavily trailed, US counterstrike may be legislative: a federal ‘GRANITE Act’ Bill. We await to see if such a Bill materialises, and if so what it consists of. A state-level GRANITE Act was introduced into the Wyoming legislature yesterday.

If a federal Bill were framed along the lines of the 2010 SPEECH Act (aimed at libel forum-shopping) it would act as a shield, explicitly preventing enforcement of foreign regulatory and similar orders within the USA. A more radical (and controversial) step would be if it contained a sword: a cause of action on which aggrieved plaintiffs could claim damages in the US courts. The most controversial step would be if that were accompanied by amendment of the US Foreign Sovereign Immunities Act to enable foreign regulators such as Ofcom to be sued, either in the federal courts or under state legislation such as the Wyoming Bill.

Sovereignty exercised or violated?

What exactly is the US administration aggrieved about? Secretary of State Rubio's social media announcement referred to:

"egregious acts of extraterritorial censorship" by “ideologues in Europe [who] have led organized efforts to coerce American platforms to punish American viewpoints they oppose.”

The official State Department statement added:

“These radical activists and weaponized NGOs have advanced censorship crackdowns by foreign states—in each case targeting American speakers and American companies.”

It went on:

“President Trump has been clear that his America First foreign policy rejects violations of American sovereignty. Extraterritorial overreach by foreign censors targeting American speech is no exception.”

Stripped of the rhetoric, this is at least in part an accusation that the EU and UK, implicitly breaching international law on territorial sovereignty, have overreached in asserting their local regulatory regimes across the Atlantic.

The European Commission's response to the US visa bans asserted the EU's own:

"sovereign right to regulate economic activity in line with our democratic values and international commitments .... If needed, we will respond swiftly and decisively to defend our regulatory autonomy against unjustified measures."

The reported UK response was more anodyne:

"While every country has the right to set its own visa rules, we support the laws and institutions which are working to keep the internet free from the most harmful content."

Neither response directly addressed the US’s complaint about extraterritoriality. Since Secretary of State Rubio’s announcement did not identify any specific foreign state act that had prompted the visa sanctions, that was perhaps unsurprising. Moreover the visa restrictions were aimed, Thierry Bretton apart, at private persons who had not held public office. As against them, the US complaint was of ‘advancing’ censorship crackdowns by foreign states.

The French Foreign Minister, for his part, claimed that the DSA:

“…has absolutely no extraterritorial reach and in no way affects the United States.” (Jean-NoĂ«l Barrot, tweet, 23 Dec 2025)

Taking sides

What should a dispassionate legal observer make of all this? Some, no doubt, will be tempted just to plump for one side or the other, motivated by partisan preference for the EU, UK or US approach to governing speech and online platforms, by broader political affinities, or by views on the propriety or otherwise of deploying visa sanctions for this kind of purpose.

Tempting as that may be, simply to declare 'four legs good, two legs bad' will not do when it comes to considering international law rules and extraterritoriality. Taking sides based purely on a preference for the Digital Services Act or the Online Safety Act over the US First Amendment, or vice versa, does not address the underlying legal issue: how, in the inherently cross-border online world, to go about drawing boundaries - or at least minimise friction - between different national or regional legal systems. A more analytical approach is called for.

Prescriptive versus enforcement jurisdiction

For that we have first to distinguish between prescriptive and enforcement jurisdiction. Prescriptive jurisdiction is the territorial ambit of legislation: how far, and on what basis, does it claim to apply to persons or conduct outside its borders? Enforcement jurisdiction, on the other hand, is about concrete exercise of powers by a state authority. In the case of the Online Safety Act that authority is the designated regulator, Ofcom.

Where extraterritoriality is concerned, international law gives more leeway to prescriptive than to enforcement jurisdiction. That is because the state’s conduct in legislating is merely assertive. Although laws are an expression of state power, writing something into a state’s own legislation does not of itself involve conduct on the territory of another state.

Typically it is enforcement that causes problems, both in its own right - steps that the authorities have taken, especially cross-border, to enforce against a foreign person - and in the light that enforcement shines on the prescriptive territorial reach of the substantive legislation.

The US complaint – prescriptive or enforcement?

Did the US complaint concern prescriptive or enforcement jurisdiction? An interview given by Under-Secretary of State Sarah B. Rogers to the Liz Truss Show before Christmas put a little more flesh on the bones as far as the Online Safety Act is concerned. She suggested that European, UK and other governments abroad were trying to nullify the American First Amendment and that: 

"when British regulators decree that British law applies to American speech on American sites on American soil with no connection to Britain, then we're kind of forced to have this conversation." 

She went on:

"The position that Ofcom has taken in the 4Chan litigation is essentially that I, an American, could go set up a website in my garage, it could be Sarah's hobby forum, it could be all about America, it could be all about the 4th of July or whatever. It could have no employees in Britain, no buildings in Britain, my speech wouldn't even need to reach into Britain. I'm not posting about the Queen or anything, I'm posting about American concepts, American political controversies. Ofcom's legal position nonetheless is that if I run afoul of British content laws, then I have to pay money to the British government. When that happens, I think you should expect a response from the American government, and I expect to see one shortly." 

On the face of it Rogers’ concern is about the substantive territorial ambit of the OSA: in other words, prescriptive jurisdiction. 

Prescriptive jurisdiction

International law recognises various grounds on which extraterritorial prescriptive jurisdiction can be regarded as justified, some of them potentially very broad. These tend to reflect a broader principle that there must be sufficient connection between the person or conduct and the state asserting jurisdiction to justify the extraterritoriality in question. The more tenuous the connection and the greater the cross-border reach, the more exorbitant the claim to jurisdiction and the less likely that the extraterritoriality can be justified. 

That is the theory. In practice, the customary norms of international law tend to be distinctly malleable and, when push comes to shove, to merge into geopolitics.

Enforcement jurisdiction

In contrast, for exercise of investigative or enforcement jurisdiction, the traditional view is that nothing less than consent of the target state will do. Unlike for prescriptive jurisdiction, there is no balancing exercise to justify the degree of extraterritoriality of the asserted jurisdiction. The focus is entirely on the conduct of the state and whether it is an incursion on the territorial sovereignty of the target state.

However, this principle has come under strain. When electronic communication and the internet enable state authorities to act remotely without setting foot in another state’s territory or sending a physical document across the border, does that violate another state’s territorial sovereignty? Should, as for prescriptive jurisdiction, other factors come into play that could justify the state's conduct?

For one answer we can go back to 1648 and the Peace of Westphalia. This was the birth of the modern nation state, in which each state has exclusive sovereignty over its own territory. The corollary of that principle is an aversion to projection of state power into another state's territory: most obviously, sending troops across the border.

That, however, is not the only way of violating a state's sovereignty. Enforcement actions such as serving a court order or an arrest warrant within a foreign state's territory also project state power across the border and are considered to require the consent of the nation state concerned:

"Persons may not be arrested, a summons may not be served, police or tax investigations may not be mounted, and orders for production of documents may not be executed on the territory of another state, except under the terms of a treaty or other consent given." (Brownlie's Principles of Public International Law (9th edn) J. Crawford, Oxford, 2019. p.462)

That is why there is a proliferation of international treaties dealing with issues such as cross-border service of legal proceedings, assistance from overseas authorities in obtaining evidence for criminal prosecutions (MLAT) or, more recently, enabling direct service of information requests on foreign telecommunications operators. 

Enforcement jurisdiction and regulators

A requirement for consent of the target state creates a potential problem for regulators, whose procedures are highly bureaucratic: inevitably so since considerations of due process and fundamental rights will require them to give enforcement targets full and fair notice of their proposed and actual decisions. They are also often given powers to serve mandatory demands for information, backed up by sanctions (sometimes criminal offences, sometimes civil penalties).

On what basis can a regulator send such official documents across borders without impinging on the sovereignty of the target state? The answer is not immediately obvious, especially since the activities of regulators do not necessarily fall into simple categories of civil or criminal upon which international treaties regarding service of legal documents tend to be founded.

A typical solution to the territorial sovereignty problem is to enlist the assistance of the relevant authorities in the target state. If such assistance is not covered by a multinational or bilateral treaty, a regulator might come to an arrangement such as a memorandum of understanding between agencies in a group of states.

The 2020 multilateral Competition Authorities Mutual Assistance Framework model agreement, for instance, envisages that requests for voluntary provision of information could be made by a direct approach to persons in another territory. For mandatory process the route is via the authorities in the other country.

However, courts have sometimes held that serving a cross-border notice is not like trespassing on the territory of the receiving state. In the UK the Court of Appeal in Jimenez considered an HMRC taxpayer information notice (with the potential sanction of civil, but not criminal, financial penalties) served by post on someone in Dubai, in order to check his UK tax position. Jimenez argued that sending the notice was contrary to international law, as it would:

“offend state sovereignty by violating the principle that a state must not enforce its laws on the territory of another state without that other state’s consent.”

Leggatt LJ (as he then was) said:

“I do not accept that sending a notice by post to a person in a foreign state requiring him to produce information that is reasonably required for the purpose of checking his tax position in the UK violates the principle of state sovereignty. Such a measure does not involve the performance of any official act within the territory of another state – as would, for example, sending an officer of Revenue and Customs to enter the person’s business premises in a foreign state and inspect business documents that are on the premises…”.

The Jimenez decision postdated the current edition of Brownlie quoted above. In KBR the UK Supreme Court emphasised that Jimenez concerned civil, not criminal, penalties. 

All this is not to say that a domestic statute can never expressly grant powers to take steps that, as a matter of enforcement jurisdiction, could go further than envisaged by international law. A UK statute may indeed do that, but in the expectation that the powers will be used with restraint, in a way that does not offend the sensibilities of another nation state (a.k.a. comity).

This passage from the Court of Appeal judgment in Competition and Markets Authority v Volkswagen and BMW, a case upholding CMA information notices served on German companies, is illuminating:

“All competition authorities worldwide face the same conundrum. Their statutory duty is to preserve the integrity of their domestic markets and protect consumers; yet, to perform that task regulators frequently have to focus their fire power upon actors located abroad where, if they seek enforcement, they might confront a variety of legal and practical problems. … How do legislatures square the circle? They achieve this by conferring broad extraterritorial regulatory and investigatory powers which can be exercised in undiluted form within their territorial jurisdictions, but which are exercised with circumspection and pragmatism when dealing with undertakings physically located elsewhere.”

The judgment went on to discuss comity:

“The creation of a power to be exercised with comity in mind … is, in our judgment, an eminently apt device to enable regulators to address, flexibly, issues of comity if and when they arise. [Counsel] for the CMA explained how comity worked. She acknowledged candidly that, notwithstanding the existence of broad investigatory powers, it was ‘out of the question’ that the CMA would for instance ever seek to conduct an on the spot investigation (a dawn raid) at the premises of an undertaking physically located outside the jurisdiction. Equally, she did not shirk from acknowledging that there could be difficulties in the exercise of mandatory powers of enforcement or sanction against a foreign undertaking which failed to comply with a statutory request for information. Such practical difficulties were simply the stuff of a regulator’s life.” 

Thus from a comity perspective a national regulator seeking to take enforcement steps against a foreign person may decide to tread carefully, especially where the subject matter may touch on particular sensitivities of the target state, even if the domestic legislation gives it power to act across borders. A combination of ambitiously extraterritorial prescriptive jurisdiction and broad investigatory and enforcement powers has the potential to become a combustible mixture.

Online Safety Act – prescriptive jurisdiction

With that background out of the way, how do Under-Secretary Rogers’ comments stack up?

In terms of its overall ambit, the UK Online Safety Act is extraterritorial but does not go as far as the mere accessibility position taken by Australian online safety legislation. The Australian Online Safety Act 2021 baldly asserts that a social media service is in scope of the Act unless “none of the material on the service is accessible to, or delivered to, one or more end-users in Australia”.

That legislation gave rise to civil litigation for an injunction brought by the eSafety Commissioner in the Australian courts, arguing that X should be required to take down certain videos worldwide and that geofencing to exclude Australia was insufficient. The regulator lost. 

The UK OSA sets out three grounds on which a service can be regarded as ‘UK-linked’ and so be a regulated service within scope of the Act. In the US litigation brought by 4Chan, Ofcom relies on two of those grounds: first, a significant number of UK users (based on statistics gleaned from 4Chan's website), and second the UK as a target market of the site (based on 4Chan seeking advertisers by reference to the percentage of UK users stated on its website).

Ofcom's position is thus that a sufficient UK connection (as stipulated in the OSA) exists in order for the OSA to apply to 4Chan. Ofcom did not (and could not) assert that the OSA safety duties apply to a site regardless of whether it has any UK connection.

How, then, should we interpret Under-Secretary Rogers' comment: “…when British regulators decree that British law applies to American speech on American sites on American soil with no connection to Britain”? That must presumably reflect a view of what should constitute a UK connection that is at odds with the OSA's criteria, or perhaps with Ofcom's interpretation of those criteria. It cannot, however, be argued that the OSA contains no UK connection criteria at all.

As to compliance with international law, the UK government would no doubt argue that as a matter of prescriptive jurisdiction the criteria for UK links stipulated in the OSA provide a sufficiently close connection with the UK to justify bringing a foreign service provider into scope, and are not exorbitant. It would also no doubt point to the fact that the substantive measures that can be required of an in-scope provider apply only to UK users of the service.

The Online Safety Act UK links criteria

The UK links set out in the OSA vary in the closeness of the stipulated UK connection. Some of them could be regarded as overreaching.  

The first ground - a 'significant' number of UK users - suffers from the vagueness of the term 'significant'. The Act does not elaborate on what that might mean and Ofcom has avoided specifics in its published guidance.

Speaking for myself, I have long proposed that extraterritorial jurisdiction on the internet should depend on whether a foreign site has engaged in positive conduct towards the jurisdiction. On that basis a self-contained test based only on number or proportion of users is potentially problematic: users may come to a site in numbers without the site operator ever having engaged in any positive conduct towards the country in which they are located. (This criticism can be applied to the DSA as well as the OSA).

The second ground - the UK as a target market - is reasonably conventional, if interpreted so as to reflect a requirement for positive conduct. Directing and targeting of activities has long been thought to be an appropriate ground on which to assert jurisdiction over internet actors.

The third ground - 'material risk of significant [physical or psychological] harm " is the most far-reaching and comes closest to a ‘mere accessibility’ test.

So far as prescriptive jurisdiction is concerned then, the OSA does stretch the limits of extraterritoriality, but – unless one were to take the position that a site is connected only to the country of its location - does not purport to apply to sites regardless of whether they have any connection to the UK.

Online Safety Act – enforcement jurisdiction

Although Under-Secretary Rogers’ comments are framed in terms of the OSA’s prescriptive jurisdiction, the point that 4Chan has emphasised in its US litigation concerns Ofcom’s exercise of its enforcement jurisdiction – serving a series of documents, including a mandatory information request under Section 100 of the OSA, directly on 4Chan by email.

As already noted, a regulator such as Ofcom proceeds against a service provider by way of a series of official notices. These present no jurisdictional problems if they can be served within the UK, but can Ofcom serve a notice on a foreign operator without violating the territorial sovereignty of its host country? As a matter of UK domestic law the OSA provides a variety of methods of service, including cross-border service by post and service by email.

Some might suggest that that, as a matter of international law, is an impermissible exercise of enforcement or investigatory jurisdiction unless done with the consent of the USA. But as Jimenez illustrates, a UK court would not necessarily agree; and in any case, if the words of the domestic statute are sufficiently clear to rebut any interpretative presumption against extraterritoriality, a UK court will give effect to them. 

Consequences

The consequences of exceeding acceptable limits of extraterritoriality may vary widely, depending on how exorbitant is the exercise of jurisdiction and how sensitive is the subject matter. They range from no response (often the case for merely prescriptive jurisdiction), to diplomatic, to refusal by foreign courts to recognise or enforce, to enactment of various kinds of blocking legislation.

One example of the latter was the US SPEECH Act 2010, which prevents enforcement of certain foreign libel judgments in the US courts and enables US persons to start proceedings for a declaration of non-enforceability in the US courts.

Another was the UK Protection of Trading Interests Act 1980. This was a response to a long period of US anti-trust legislation being enforced against conduct outside the USA by non-US companies. Years of diplomatic activity had failed to resolve the conflictwhich had become more acute in the late 1970s.

As already mentioned, a state-level GRANITE Act has been introduced as a Bill into the Wyoming legislature. It is both a shield and a sword, albeit that the sword would be dependent on a federal amendment to the Foreign Sovereign Immunities Act. We await to see if a federal GRANITE Act will materialise. 

The Court of Appeal in the BMW case noted that it had been said that antitrust law was the best illustration of the problem of national public interest risking conflicting with issues of international sovereignty. Speech on the internet – today, online safety in particular - is bidding fair to seize that mantle.


Sunday, 24 May 2020

A Tale of Two Committees

Two Commons Committees –the Home Affairs Committee and the Digital, Culture, Media and Sport Committee – have recently held evidence sessions with government Ministers discussing, among other things, the government’s proposed Online Harms legislation. These sessions proved to be as revealing, if not more so, about the government’s intentions as its February 2020 Initial Response to the White Paper.

As a result on some topics we know more than we did, but the picture is still incomplete. Some new issues have surfaced. Other areas have become less clear than they were previously.

Above all, nothing is set in stone. The Initial Response was said to be indicative of a direction of travel and to form an iterative part of a process of policy development. The destination has yet to be reached – if, that is, the government ever gets there at all. It may yet hit a road block somewhere along the way, veer off into a ditch, or perhaps undergo a Damascene conversion should it finally realise the unwisdom of creating a latter-day Lord Chamberlain for the internet. Or the road may eventually peter out into nothingness. At present, however, the government is pressing ahead with its legislative intentions.

I’m going to be selective about my choice of topics, in the main returning to some of the key existing questions and concerns about the Online Harms proposals, with a sprinkling of new issues added for good measure. Much more ground than this was covered in the two sessions.

Borrowing from the old parlour game, each topic starts with what the White Paper said; followed by what the Initial Response said; then what the Ministers said; and lastly, the Consequence. The Ministers are Oliver Dowden MP (Secretary of State for Digital, Culture, Media and Sport); Caroline Dinenage MP (Minister for Digital and Culture) and Baroness Williams (Lords Minister, Home Office).  

Sometimes the government’s Initial Response to Consultation recorded consultation submissions, but came to no conclusion on the topic. In those instances the Initial Response is categorised as saying ‘Nothing’. Some repetitive statements have been pruned.

Since this is a long read, here is a list of the selected topics:


1. Will Parliament or the regulator decide what “harm” means?


The White Paper said:

“… government action to tackle online content or activity that harms individual users, particularly children, or threatens our way of life in the UK, either by undermining national security, or by reducing trust and undermining our shared rights, responsibilities and opportunities to foster integration.”

“This list [Table 1, Online harms in scope] is, by design, neither exhaustive nor fixed. A static list could prevent swift regulatory action to address new forms of online harm, new technologies, content and new online activities.”

The Initial Response said:

Nothing.

The Ministers said:

Oliver Dowden: “The only point that I have tried to make is that I am just keen on this proportionality point because it is often the case that regulation that starts out with the best of intentions can, in its interpretation if you do not get it right, have a life of its own. It starts to get interpreted in a way that Parliament did not intend it to be in the first place. I am just keen to make sure we put those kinds of hard walls around it so that the regime is flexible but that in its interpretation it cannot go beyond the intent that we set out in the first place in the broad principles.” (emphasis added)

Caroline Dinenage: “For what you might call the “legal but harmful” harms, we are not setting out to name them in the legislation. That is for the simple reason that technology moves on at such a rapid pace that it is very likely that we would end up excluding something….  We want to make sure that this piece of legislation will be agile and able to respond to harms as they emerge. The legislation will make that clearer, but it will be for the regulator to outline what the harms are and to do that in partnership with the platforms.” (Q.554) (emphasis added)

The Consequence: It is difficult to reconcile the desire of the Secretary of State to erect “hard walls”, in order to avoid unintended consequences, with the government’s apparent determination to leave the notion of harm undefined, delegating to the regulator the task of deciding what counts as harmful. This kind of approach has serious implications for the rule of law.

Left undelineated, the concept of harm is infinitely malleable. The Home Office Minister Baroness Williams suggested in the Committee session that 5G disinformation could be divided into “harmless conspiracy theories” and “that which actually leads to attacks on engineers”, as well as a far-right element. One Committee member (Ruth Edwards M.P.) responded that she did not think that any element of the conspiracy theory could be categorised as ‘harmless’, because “it is threatening public confidence in the 5G roll-out” — a proposition with which the DCMS Minister Caroline Dinenage agreed.

Harm is thus equated with people changing their opinion about a telecommunications project. This unbounded sense of harm is on a level with the notorious “confusing our understanding of what is happening in the wider world” phraseology of the White Paper.  

Statements such as the concluding peroration by Baroness Williams: “I, too, want to make the internet a safer place for my children, and exclude those who seek to do society harm” have to be viewed against the backdrop of an essentially unconstrained meaning of harm.

When harm can be interpreted so broadly, the government is playing with fire. But it is we  not the government, the regulator or the tech companies  who stand to get our fingers burnt.

2. The regulator’s remit: substance, process or both?


The White Paper said:

“In particular, companies will be required to ensure that they have effective and proportionate processes and governance in place to reduce the risk of illegal and harmful activity on their platforms, as well as to take appropriate and proportionate action when issues arise. The new regulatory regime will also ensure effective oversight of the take-down of illegal content, and will introduce specific monitoring requirements for tightly defined categories of illegal content.” (6.16)

The Initial Response said:

“The approach will be proportionate and risk-based with the duty of care designed to ensure companies have appropriate systems and processes in place to improve the safety of their users.”

“The focus on robust processes and systems rather than individual pieces of content means it will remain effective even as new harms emerge. It will also ensure that service providers develop, clearly communicate and enforce their own thresholds for harmful but legal content.

“The kind of processes the codes of practice will focus on are systems, procedures, technologies and investment, including in staffing, training and support of human moderators.”

“As such, the codes of practice will contain guidance on, for example, what steps companies should take to ensure products and services are safe by design or deliver prompt action on harmful content or activity.”

“Rather than requiring the removal of specific pieces of legal content, regulation will focus on the wider systems and processes that platforms have in place to deal with online harms, while maintaining a proportionate and risk-based approach.”

“In fact, the new regulatory framework will not require the removal of specific pieces of legal content. Instead, it will focus on the wider systems and processes that platforms have in place to deal with online harms, while maintaining a proportionate and risk-based approach.”

“Of course, companies will be required to take particularly robust action to tackle terrorist content and online Child Sexual Exploitation and Abuse. The new regulatory framework will not remove companies’ existing duty to remove illegal content.”

The Ministers said:

Caroline Dinenage: “the codes of practice are really about systems and processes, rather than naming individual harms in the legislation. There are two exceptions to that: there will be codes of practice around child sexual exploitation and terrorist content, because those are both illegal.” (Q554)

“It is for the regulator to set out codes of practice, but they won’t be around individual harms; they will be around systems and processes—what we expect the companies to do. Rather than focusing on individual harms, because we know that the technology moves on so quickly that there could be more, it is a case of setting out the systems and processes that we would expect companies to abide by, and then giving the regulator the opportunity to impose sanctions on those that are not doing so.” (Q.556)

Q562 Stuart C. McDonald: “…if the regulator feels that algorithms are working inappropriately and directing people who have made innocent searches to, say, far-right content, will they be able to order, essentially, the company to make changes to how its algorithms are operating?


Caroline Dinenage: Yes, I think that they will. That is clearly something that we will set out in the full response. The key here is that companies must have clear transparency, they must set out clear standards, and they must have a clear duty of care. If they are designing algorithms that in any way put people at risk, that is, as I say, a clear design choice, and that choice carries with it a great deal of responsibility. It will be for the regulator to oversee that responsibility. If they have any concerns about the way that that is being upheld, there are sanctions that they can impose.”

The Consequence: As with the specific issue around the status of terms and conditions for “lawful but harmful” content (see below), it is difficult to see how a bright line can be drawn between substance and process.  Processes cannot be designed, risk-assessed or their effectiveness evaluated in the abstract — only by reference to goals such as improving user safety and reducing risk of harm. A duty of care evaluated without reference to the kind of harm intended to be guarded against makes no more sense than the smile without the Cheshire Cat. 

In Caparo v Dickman Lord Bridge cautioned against discussing duties of care in the abstract:
"It is never sufficient to ask simply whether A owes B a duty of care. It always necessary to determine the scope of the duty by reference to the kind of damage from which A must take care to save B harmless."

Risk assessment is familiar in the realm of safety properly so-called: danger of physical injury, where there is a clear understanding of what constitutes objectively ascertainable harm. It breaks down when applied to undefined, inherently subjective harms arising from users' speech. If "threatening public confidence in the 5G roll-out” (see above) can be labelled an online harm within scope of the legislation, that goes far beyond any tenable concept of safety.

The government’s approach appears to be to adopt different approaches to illegal and “legal but harmful”, the latter avowedly restricted to process (although see next topic as to how far that can really be the case). 

In passing, the Initial Response is technically incorrect in referring to “companies’ existing duty to remove illegal content”. No such general duty exists. Hosting providers lose the protection of the ECommerce Directive liability shield if they do not remove unlawful content expeditiously upon gaining actual or (for damages) constructive knowledge of the illegality. Even then, the eCommerce Directive does not oblige them to remove it. The consequence is that they become exposed to the risk of possible liability (which may or may not exist) under the relevant underlying law (see here for a fuller explanation). In practice that regime strongly incentivises hosting providers to remove illegal content upon gaining relevant knowledge. But they have no general legal obligation to do so.


3. For “lawful but harmful” content seen by adults, will the regulator be interested only in whether intermediaries are enforcing whatever content standards they choose to put in their TandCs?


The White Paper said:

“As indication of their compliance with their overarching duty of care to keep users safe, we envisage that, where relevant, companies in scope will:

  • Ensure their relevant terms and conditions meet standards set by the regulator and reflect the codes of practice as appropriate.
  • Enforce their own relevant terms and conditions effectively and consistently. …”
“To help achieve these outcomes, we expect the regulator to develop codes of practice that set out: 

  • Steps to ensure products and services are safe by design.
  • Guidance about how to ensure terms of use are adequate and are understood by users when they sign up to use the service. …
  • Steps to ensure harmful content or activity is dealt with rapidly. …
  • Steps to monitor, evaluate and improve the effectiveness of their processes.”
The Initial Response said:

“We will not prevent adults from accessing or posting legal content, nor require companies to remove specific pieces of legal content. The new regulatory framework will instead require companies, where relevant, to explicitly state what content and behaviour is acceptable on their sites and then for platforms to enforce this consistently.”

“To ensure protections for freedom of expression, regulation will establish differentiated expectations on companies for illegal content and activity, versus conduct that is not illegal but has the potential to cause harm. Regulation will therefore not force companies to remove specific pieces of legal content. The new regulatory framework will instead require companies, where relevant, to explicitly state what content and behaviour they deem to be acceptable on their sites and enforce this consistently and transparently. All companies in scope will need to ensure a higher level of protection for children, and take reasonable steps to protect them from inappropriate or harmful content.”

“Recognising concerns about freedom of expression, the regulator will not investigate or adjudicate on individual complaints. Companies will be able to decide what type of legal content or behaviour is acceptable on their services, but must take reasonable steps to protect children from harm. They will need to set this out in clear and accessible terms and conditions and enforce these effectively, consistently and transparently.”

The Ministers said:

Oliver Dowden: “The essence of online harms legislation is holding social media companies to what they have promised to do and to their own terms and conditions. My focus in respect of those is principally on two things: underage harms and illegal harms. Clearly, the trickiest category is legal adult harms. In respect of that, we are looking at how we tighten the measures to ensure that those companies actually do what they promised they would do in the first place, which often is not the case.” (Q20) (emphasis added)

“Clearly, in respect of legal adult harms, that is the underlying principle anyway in the sense that what we are really trying to do is say to those social media companies and tech firms, “Be true to what you say you are doing. Just stick by your terms and conditions”. We would ask the regulator to make sure that it is enforcing them, and then have tools at our disposal to require it to do so.” (Q89) (emphasis added)

Caroline Dinenage: “A lot of this is about companies having the right regulations and standards and duty of care, and that will also be in the online harms Bill and online harms work. If we can have more transparency as to what platforms regard as acceptable—there will be a regulator that will help guide them in that process—I think we will have a much better opportunity to tackle those things head-on.” (Q513) (emphasis added)

“With regard to our role in DCMS, it is more as a co-ordinator bringing together the work of all the different Government Departments and then liaising directly with the platforms to make sure that their standards, their regulations, are reflective of some of the concerns that we have—make sure, in some cases, that harmful content can be anticipated and therefore prevented, and, where that is not possible, where it can be stopped and removed as quickly as possible.” (emphasis added) (Q525)

Baroness Williams: “There is obviously that which is illegal and that which breaches the CSPs’ terms of use. It is that latter element, particularly in the area of extremism, on which we have really tried to engage with CSPs to get them to be more proactive.” (emphasis added) (emphasis added) (Q.527)

The Consequence: This is now one of the most puzzling areas of the government’s developing policy. The White Paper expected that codes of practice would ensure that terms and conditions meet “standards set by the regulator” and that terms of use are “adequate”. These statements were not on the face of them limited to procedural standards and adequacy. They could readily be interpreted as encompassing standards and adequacy judged by reference to harm reduction goals determined by the regulator (which, as we have seen, would be able to decide for itself what constitutes harm) – in other words, extending to the substantive content of intermediaries' terms and conditions.

When the Initial Response was published, great play was made of the shift to a differentiated duty of care: that it would be up to the intermediary to decide – for lawful content for adults - what standards to put in its terms and conditions. 

The remit of the regulator would be limited to ensuring those standards are clearly stated and enforced “consistently and transparently” (or “effectively, consistently and transparently”, depending on which part of the Initial Response you turn to; or “effectively and consistently”, according to the White Paper). Indeed the Secretary of State said in evidence that "The essence of online harms legislation is holding social media companies to what they have promised to do and to their own terms and conditions

But it seems from the other Ministers’ responses that the government has not disclaimed all interest in the substantive content of intermediaries’ terms and conditions. On the contrary, the government evidently sees it as part of its role to influence (to put it at its lowest) what goes into them. If the regulator’s task is to ensure enforcement of terms and conditions whose substantive content reflects the wishes of a government department, that is a far cry from the proclaimed freedom of intermediaries to set their own standards of acceptable lawful content.

Ultimately, what can be the point of emphasising how, in the name of upholding freedom of speech, the role of an independent regulator will be limited to enforcing the intermediaries’ own terms and conditions, if the government considers that part of its own role is to influence those intermediaries as to what substantive provisions those TandCs should contain?

This is one aspect of an emerging issue about division of responsibility between government and the regulator. It is tempting to think that once an independent regulator is established the government itself will withdraw from the fray. But if that is not so, then reducing the remit of the independent regulator concomitantly increases the scope for the government itself to step in.

That is especially pertinent in the light of the government’s desire to cast itself as a ‘trusted flagger’, whose notifications of unlawful content the intermediaries should act upon without question. Thus Caroline Dinenage appears to regard the platforms as obliged to remove anything that the government has told them it considers to be illegal (with no apparent requirement of prior due process such as independent verification), and would like them to take seriously anything else that the government notifies to them:

“We have found that we have become—I forget the proper term, but we have become like a trusted flagger with a number of the online hosting companies, with the platforms. So when we flag information, they do not have to double-check the concerns we have. Clearly, unless something is illegal, we cannot tell organisations to take it down; they have to make their own decision based on their own consciences, standards and requirements. But clearly we are building up a very strong, trusted relationship with them to ensure that when we flag things, they take it seriously.” (Emphasis added)


4. Codes of Practice for specific kinds of user content or activity?


The White Paper said:

“[T]he White Paper sets out high-level expectations of companies, including some specific expectations in relation to certain harms. We expect the regulator to reflect these in future codes of practice.”

It then set out a list of 11 harms, accompanied in each case by a list of areas in relation to that harm that it expected the regulator to include in a code of practice. For instance, in relation to disinformation a list of 11 specific areas included:

“Steps that companies should take in relation to users who deliberately misrepresent their identity to spread and strengthen disinformation.”; and

“Promoting diverse news content, countering the ‘echo chamber’ in which people are only exposed to information which reinforces their existing views.”

The Initial Response said:

“The White Paper talked about the different codes of practice that the regulator will issue to outline the processes that companies need to adopt to help demonstrate that they have fulfilled their duty of care to their users. … We do not expect there to be a code of practice for each category of harmful content, however, we intend to publish interim codes of practice on how to tackle online terrorist and Child Sexual Exploitation and Abuse (CSEA) content and activity in the coming months.”

The Ministers said:

Caroline Dinenage: I think I need to clear up a bit of a misunderstanding about the White Paper. The 11 harms that were listed were really intended to be an illustrative list of what we saw as the harms. The response did not expect a code of practice for each one, because the codes of practice are really about systems and processes, rather than naming individual harms in the legislation. There are two exceptions to that: there will be codes of practice around child sexual exploitation and terrorist content, because those are both illegal.” (Q.554) (emphasis added)

The Consequence: The different approach to CSEA and terrorism probably owes more to the different areas of responsibility of the Home Office and the DCMS than to any dividing line between illegality and non-illegality. The White Paper covers many more areas of illegality than those two alone.

5. Search engines in scope?


The White Paper said:

“… will apply to companies that allow users to share or discover user-generated content, or interact with each other online.” (emphasis added)

“These services are offered by…  search engines” (Executive Summary)

The Initial Response said:

“The legislation will only apply to companies that provide services or use functionality on their websites which facilitate the sharing of user generated content or user interactions, for example though comments, forums or video sharing” (emphasis added)

The Ministers said:

Caroline Dinenage: Again, we are probably victims of the fact that we published an interim response, which was not as comprehensive as our full response will be later on in the year. The White Paper made it very clear that search engines would be included in the scope of the framework and the nature of the requirements will reflect the type of service that they offer. We did not explicitly mention it in the interim response, but that does not mean that anything has changed. It did not cover the full policy. Search engines will be included and there is no change to our thoughts and our policy on that.”   (Q.560)

The Consequence: Notwithstanding the Minister’s explanation, the alterations in wording between the White Paper and the Initial Response (omitting “discover”, adding “only”) had the appearance of a considered change. The lesson for the future is perhaps that it would be unwise to parse too closely the text of anything else said or written by the government.

6. Everything from social media platforms to retail customer review sections?


The White Paper said:

“… companies of all sizes will be in scope of the regulatory framework. The scope will include… social media companies, public discussion forums, retailers that allow users to review products online, along with non-profit organisations, file sharing sites and cloud hosting providers.” (emphasis added)

The Initial Response said:

“To be in scope, a business would have to operate its own website with the functionality to enable sharing of user-generated content, or user interactions.”

The Ministers said:

Oliver Dowden: “We are a Europe leader in this. I have seen, as I am sure you have seen, the unintended consequences of good-intended legislation then having bureaucratic implications and costs on businesses that we want to avoid.

For example, in respect of legal online harms for adults, if you are an SME retailer and you have a review site on your website for your product and people can put comments underneath that, that is a form of social media. Notionally, that would be covered by the online harms regime as it stands. The response to that is they will go through this quick test and then they will find it does not apply to them. My whole experience of that for SMEs and others is that it is all very well saying that when you are sat have no idea what this online harms thing is, this potentially puts a big administrative burden on you. (emphasis added)

Are there ways in which we can carve out those sorts of areas so we focus on where we need to do it? Those kinds of arguments pertain less to illegal harms and harms to children. I hope that gives you a flavour of it.” (Q.88)

Q89 Damian Hinds: “Yes, quite so. I think in the previous announcement there was quite a high estimate of the number of firms or proportion of total firms that would somehow be counted in the definition of an online platform, which was rather a disturbing thought. It would be very welcome, what you can do to limit the scope of who counts as a social media platform.”

The Consequence: This exchange does shine a light on the expansive scope of the proposed legislation. The Secretary of State said that SME retailers with review sections were “notionally” covered. However, there was nothing notional about it.  Retailer review sections were expressly included in the White Paper, as were companies of all sizes.

As the Secretary of State suggests, it is little comfort for an SME to be told “don’t worry, you’ll be low risk so it won’t really apply to you” if: (a) you are in scope on the face of it, and (b) it is left to the regulator to decide whether the duty of care should bear less heavily on some intermediaries than others. 

There are, of course, many other kinds of non-social media platform intermediary who are in scope as well as SME retailers with review sections: apps, online games, community discussion forums, non-profits and many other online services.  The Initial Response said “Analysis so far suggests that fewer than 5% of UK businesses will be in scope of this regulatory framework.” Whether 5% is considered to be small or large in absolute terms (not to mention the apparent indifference to non-UK businesses), there has been no indication of the assumptions underlying that estimate.

7. Will journalism and the press be excluded from scope?


The White Paper said:

Nothing. In a subsequent letter to the Society of Editors the then DCMS Secretary of State Jeremy Wright said:

“… as I made clear at the White Paper launch and in the House of Commons, where these services are already well regulated, as IPSO and IMPRESS do regarding their members' moderated comment sections, we will not duplicate those efforts. Journalistic or editorial content will not be affected by the regulatory framework.”

The Initial Response said:

Nothing. It limited itself to general expressions of support for freedom of expression, such as:
“…freedom of expression, and the role of a free press, is vital to a healthy democracy. We will ensure that there are safeguards in the legislation, so companies and the new regulator have a clear responsibility to protect users’ rights online, including freedom of expression and the need to maintain a vibrant and diverse public square.”

The Ministers said:

Caroline Dinenage: Obviously, we know that a free press is one of the pillars of our society, and the White Paper, I must say from the outset, is not seeking to prohibit press freedom at all, so journalistic and editorial content is not in the scope of the White Paper. Our stance on press regulation has not changed.” (Emphasis added)

“As for what has been in the papers recently, the Secretary of State wrote a letter to the Society of Editors, and this was about what you might call the below-the-line or comments section. They were concerned that that might be regulated. I think what the Secretary of State is saying is that, where there is already clear and effective moderation of that sort of content, we do not intend to duplicate it. For example, there is IPSO and IMPRESS activity on moderated content sections. Those are the technical words for it. This is still an ongoing conversation, so we are working at the moment with stakeholders to develop proposals on how we are going to reflect that in legislation, working around those parameters. (Q.558)

“Stuart C. McDonald: But there is no suggestion that below-the-line remains unregulated. It is where that regulation should lie that is the issue.

Caroline Dinenage: Exactly.” (Q.559)

The Consequence: There are three distinct issues around inclusion or exclusion of the press from the regulatory scope of the Bill:

1. User comments on newspaper websites.  On the face of it, news organisations would be subject to the duty of care as regards user comments on their websites. The position of the government appears to be that whether the duty of care would apply would depend on whether the comments are already subject to another kind of regulation (or at least the existence of “clear and effective moderation”). Potentially, therefore, newspapers that are not regulated by IPSO or IMPRESS would be in scope for this purpose. Whether this demarcation would be achieved by a hard scope exclusion written into the Bill is not clear.

2. Journalistic or editorial material. Whilst the Minister may say that the government’s stance on press regulation has not changed, her statement that journalistic and editorial content is not “in the scope” of the White Paper is new — at least if we are to understand that as meaning that the Bill would contain a hard scope exclusion for journalistic or editorial content. Previously the government had said only that such content would not be affected by the regulatory framework. A general exclusion of journalistic or editorial material would on the face of it go much wider than newspapers and similar publications. It would be no surprise to find this statement being “clarified” at some point in the future.

3. Newspaper social media feeds and pages. Newspapers and other publications maintain their own pages, feeds and blogs on social media and other platforms. Newspapers would not themselves be subject to a duty of care in relation to their own content. But as far as the platforms are concerned the newspapers are users, so that their pages and feeds would fall under the platforms’ duty of care. As such, they would be liable to have action taken against their content by a platform in the course of fulfilling its own duty of care.

The government has said nothing about whether, and if so how, such press content would be excluded from scope. If the government is serious about excluding “journalistic or editorial” material generally from scope, that would achieve this. However that would create immense difficulties around whether a particular feed or page is or is not journalistic or editorial material (what about this Cyberleagle blog, or the Guido Fawkes blog, for instance?), and how a platform is supposed to decide whether any particular content is or is not in scope.  

8. End to end encryption


The White Paper said:

Nothing. (Although the potential for the duty of care to be applied to prevent the use of end to end encryption was evident.)

The Initial Response said:

Nothing.

The Ministers said:

Baroness Williams: “[Facebook] then announced that they were going to end-to-end encrypt Messenger. That, for us, is gravely worrying, because nobody will be able to see into Messenger. I know there is going to be a Five Eyes engagement next week, and I do not know if the Committee knows, but the Five Eyes wrote to Mark Zuckerberg last year, so worried were we about this development.” (Q538)

Q566 Chair: “On that basis, does end-to-end encryption count as a breach of duty of care?

Baroness Williams:It is criminal activity that would breach the duty of care. Allowing criminal activity to happen on your platform would be the breach of duty of care. End-to-end encryption, in and of itself, is not a breach of duty of care.

Chair: Presumably, for this regulation to have any bite at all, they will have to be able to take some enforcement against the policies that fail to prevent criminal activity. On that logic, introducing the end-to-end encryption, if it knowingly stops the company from preventing illegal activity—for example, the kind of online child abuse you have talked about—that would surely count as a breach of duty of care.

Baroness Williams: I fully expect that that is what some of the Five Eyes discussions, which will be happening very shortly, will look at.”

The Consequence: This is the first indication that the government is alive to the possibility that a regulator might be able to interpret a duty of care so as to affect the ability of an intermediary to use end to end encryption. The “in and of itself” phraseology used by the Minister appears not to rule that out. This issue is related to the question of how the legislation might apply to private messaging providers, a topic on which the government has consulted but has not yet published a conclusion.

9. Identity verification


The White Paper said:

“The internet can be used to harass, bully or intimidate. In many cases of harassment and other forms of abusive communications online, the offender will be unknown to the victim. In some instances, they will have taken technical steps to conceal their identity. Government and law enforcement are taking action to tackle this threat.”

“The police have a range of legal powers to identify individuals who attempt to use anonymity to escape sanctions for online abuse, where the activity is illegal. The government will work with law enforcement to review whether the current powers are sufficient to tackle anonymous abuse online.”

“Some of the areas we expect the regulator to include in a code of practice are:

  • Steps to limit anonymised users abusing their services, including harassing others. …
  • Steps companies should take to limit anonymised users using their services to abuse others.”

The Initial Response said:

Nothing.

The Ministers said:

Q25 John Nicolson: Would you like to see online harms legislation compel social media companies to verify the identity of users, not of course to publish them but simply to verify them before the accounts are up and running?

Oliver Dowden: There is certainly a challenge around, as you mentioned, bots, which are sometimes used by hostile state activity, and finding better ways of verifying to see whether these are genuine actors or whether it is co-ordinated bot-type activity. That is through online harms but there is obviously a national security angle to that as well.”

Q530 Ms Abbott: “Finally, would you consider changing the regulation, so you could post anonymously on a website or Twitter or Facebook, but the online platform would have your name and address? In my experience, when you try to pursue online abuse, you hit a brick wall because the abuser is not just anonymous when they post, the online platform doesn’t have a name and address either.

Caroline Dinenage: That is a really interesting idea. It is definitely something that we have been discussing. With regard to the online harms legislation that we are putting together at the moment, we have said very clearly that companies need to be much more transparent. They need to set out standards and they need to clarify what their duty of care is and to have a robust complaints procedure that people can use and can trust in. That is why we are also appointing a regulator that will set out what good looks like and will have expectations but also powers to be able to demand data and information and to be able to impose sanctions on those that they do not feel are abiding by them.

Q531 Chair: What does that actually mean? Does that mean that you think that the regulator should have the power to say that social media companies should not allow people to be … [a]nonymous to the platform?

Caroline Dinenage: This is something that we are considering at the moment. There are a number of things here. In the online harms legislation, the regulator will set out their expectations.

Chair: We can’t devolve everything to the regulator. Something like this is really important—should social media companies be allowed to not know who it is that is using their platforms? That feels like a big question that Parliament should take a view on, not something we just hand over to a regulator and say, “Okay, whatever you think,” later on.

Caroline Dinenage: Yes, exactly. That is why we are considering it at the moment, as part of the online harms legislation, and that, of course, will come before Parliament.”

Q545 Tim Loughton: “… If I want to set up a bank account and all sorts of other accounts, I must prove to the bank or organisation who I am by use of a utility bill and other things like that. It is quite straightforward. What is the downside of a similar requirement being enforced by social media platforms before you are allowed to sign up for an account? This is an issue that we have looked at before on the Committee. Many of us have suggested that we should go down that route. I gather that it already happens in South Korea. You say that you are looking at it, Minister Dinenage. What, in your view, is the downside of having such scrutiny?

Caroline Dinenage: You make a very compelling argument, Mr Loughton. A lot of what you said is extremely correct. The only thing we are mulling over and trying to cope with is whether there is any reason for anonymity for people who are victims, who want to be able to whistleblow, and who may be overseas and might not want to identify themselves because they fear for their lives or other harm. There are those issues of anonymity and protecting someone’s safety and ability to speak up. That is what we are wrestling with.

Q546 Tim Loughton: By the same token, you could have somebody with a fake identity who is falsely whistleblowing or pushing around propaganda, so it cuts both ways. I fail to see the downside of having a requirement that you have to prove who you are—not least because we know what happens when people are caught and have their sites taken down. Five minutes later, they set up another new anonymous site peddling the same sort of false information.

Caroline Dinenage: You make a very compelling argument. This is such an important piece of legislation, and we have to get it right. As I say, it is world-leading. Everybody is looking at us to see how we do it. We need to make sure that we have taken into consideration every angle, and that is what we are doing at the moment.”

The Consequence: Identity verification is evidently an issue that is bubbling to the surface. The most fundamental objection is that the right of freedom of expression secured by Article 19 of the Universal Declaration of Human Rights is not conditioned upon identity verification. It does not say:

"Everyone has the right to freedom of opinion and expression upon production of any two of the following: driving licence, passport, recent utility or council tax bill...".

In South Korea, legislation imposing online identity verification obligations was declared unconstitutional in 2012.

The Home Affairs Committee raised, to the best of my knowledge for the first time in any Parliamentary deliberation on the Online Harms project, the question of what should be decided by Parliament and what delegated to a regulator. That is not limited to the question of identity verification. It is an inherent vice of regulatory powers painted with such a broad brush that many concrete issues will lie hidden behind abstractions, to surface only when the regulator turns its light upon them – by which time it is far too late to object that the matter should have been one for Parliament to decide. That vice is compounded when the powers affect the individual speech of millions of people.

10. Extraterritoriality


The White Paper said:

“The new regulatory regime will need to handle the global nature of both the digital economy and many of the companies in scope. The law will apply to companies that provide services to UK users.” (6.9) (emphasis added)

“We are also considering options for the regulator, in certain circumstances, to require companies which are based outside the UK to appoint a UK or EEA-based nominated representative.” (6.10)

The Initial Response said:

Nothing of relevance.

The Ministers said:

“Q569: Andrew Gwynne: Presumably the regulations will apply to all content visibly available in the UK—is that correct?

Baroness Williams: Yes.”

The Consequence: Charitably, perhaps we should assume that the Minister misspoke. There is a vast difference between providing services to UK users and mere visibility in the UK. Given the inherent cross-border nature of the internet, asserting a country’s local law against content on a mere visibility basis is tantamount to asserting world-wide extra-territoriality. 

It would be more consistent with the direction in which internet jurisdictional norms have moved over the last 25 years to apply a test of whether the provider is targeting the UK.