Best-efforts obligations, stay-down, Article 16 notices and trusted-flagger status - and what they mean when you enforce in Europe.
This is an explainer, not legal advice.
Two EU instruments reshaped enforcement against online platforms in Europe: Article 17 of the Copyright Directive (Directive (EU) 2019/790) and the Digital Services Act (Regulation (EU) 2022/2065). They work differently and apply to different kinds of platform, and rights holders enforcing in the EU should understand both.
Article 17: online content-sharing service providers
Article 17 applies to "online content-sharing service providers" (OCSSPs) - broadly, large platforms whose main purpose is to host and give public access to large amounts of user-uploaded copyright content (YouTube, Meta's platforms, TikTok, SoundCloud and similar are in scope; pure streaming stores like Spotify or Apple Music, where content is delivered by labels and distributors rather than users, are generally not).
Under Article 17 an OCSSP performs an act of communication to the public when it gives access to user uploads, and is liable for unauthorised uploads unless it shows that it (a) made best efforts to obtain authorisation (licences); (b) made best efforts, in accordance with high industry standards, to ensure the unavailability of specific works for which rights holders have provided the relevant and necessary information (in practice, reference files and rights data); and (c) acted expeditiously on notice to remove content and made best efforts to prevent its future upload (stay-down).
For rights holders, the practical effect is that supplying good reference data to OCSSPs gives you proactive blocking and stay-down, not only reactive takedowns - which is why program access (Content ID, Rights Manager and equivalents) is so valuable in the EU. The Court of Justice (Case C-401/19, 2022) upheld Article 17 while stressing that filtering must not block lawful uploads, and the Commission's guidance (COM/2021/288) emphasises safeguards for exceptions such as quotation, criticism and parody.
The DSA: notice-and-action for all hosting providers
The DSA applies to all intermediaries, including hosting providers that are not OCSSPs. Its Article 16 requires hosting providers to put in place easy-to-use, electronic notice-and-action mechanisms through which any person or entity can flag specific items of allegedly illegal content - including copyright infringement. A notice should explain why the content is illegal, give its exact location (URL), identify the notifier, and include a good-faith statement of accuracy. A sufficiently precise and substantiated notice can give the provider actual knowledge for liability purposes.
The DSA also requires providers to give a statement of reasons when they restrict content (Art. 17), to operate an internal complaint-handling system (Art. 20), and to allow referral to certified out-of-court dispute settlement bodies (Art. 21) - the EU analogue of counter-notice. And it creates trusted flaggers (Art. 22): entities awarded that status by a national Digital Services Coordinator whose notices platforms must process with priority.
What this means in practice
- On OCSSPs, provide reference data: you are entitled to best-efforts blocking and stay-down.
- On everything else, send Article 16-compliant notices: precise, substantiated, with a good-faith statement.
- Expect users to have complaint and dispute rights, and handle disputes on their merits.
- Trusted-flagger status is worth pursuing for organisations that send notices at volume and can demonstrate accuracy.
Sources: Directive (EU) 2019/790, Art. 17; European Commission Guidance COM/2021/288; CJEU Case C-401/19; Regulation (EU) 2022/2065, Arts. 16, 17, 20, 21, 22.